sk181842 - CloudGuard Controller Release Updates

CloudGuard Controller Release Updates

Introduction

CloudGuard Controller manages security in public and on-premises environments with one unified management solution.

The CloudGuard Controller dynamically learns about objects and attributes in Data Centers, such as changes in subnets, security groups, virtual machines, IP addresses and tags.

After using the vendor’s API to establish a trust relationship with a Data Center, CloudGuard Controller regularly checks the connected environments for changes in objects and object attributes used in the Security Policy and automatically push the changes to the Security Gateway.

202511030923001.png)

The CloudGuard Controller package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see sk175504, section 2-B).

If Automatic Updates are disabled, you must first manually install the latest AutoUpdater Take and then install CloudGuard Controller package manually using the steps below.

Prerequisites

CloudGuard Controller self-updatable package requires Jumbo Hotfix Accumulator installed with the minimum version:

Version Required
R82 and higher No requirements
R81.20 R81.20 Jumbo Hotfix Accumulator Take 99 or higher

Manual Installation (Offline)

  1. Transfer the offline package to the CloudGuard Controller server.

  2. Connect to the command line on the CloudGuard Controller server.

  3. Log in to the Expert mode.

  4. Install the offline package:

    autoupdatercli install <full path to the .tar file>

    Example:

    autoupdatercli install /home/admin/Check_Point_CloudGuard_Controller_R81_20_AutoUpdate_T7_AutoUpdate.tar

  5. Make sure the installation completed successfully:

    1. Examine this log file:

      /opt/CPInstLog/AutoUpdateLogs/CloudGuard_Controller

    2. Run:

      cpinfo -y CPUpdates 2>&1 | grep CLOUDGUARD_CONTROLLER The take number in the output must be the Take that you installed.

Note - The installation does not require cpstop; cpstart or a reboot. Once installed, no further action is required, the update will be applied immediately.

Important Notes for Security Management / Multi-Domain Security Server (MDS) in the High Availability mode:

Availability

Version Release Take Release Date Download
R82.10 Recommended 9 07 Jun 2026 (TAR)
R82 Recommended 32 07 Jun 2026 (TAR)
R81.20 Recommended 37 26 Apr 2026 (TAR)
R82.10 Latest 10 19 Jul 2026 (TAR)
R82 Latest 33 19 Jul 2026 (TAR)
R81.20 Latest 38 19 Jul 2026 (TAR)

Documentation

List of Resolved Issues and New Features per CloudGuard Controller Update

R82.10 Release

ID Description
Take 10 - Gradual deployment from 19 Jul 2026
CGNSIS-2375 In rare scenarios, Cisco ACI Data Center scans may receive an empty response from the Cisco APIC, causing Data Center objects to be temporarily removed.
CGNSIS-2136 Enhancement: CloudGuard Controller now supports the Nozomi, ServiceNow CMDB and Akamai Guardicore Data Centers. Refer to the R82 CloudGuard Controller Administration Guide.
CGNSIS-960 Added CloudGuard Controller integration with AIOps in Check Point Portal to provide centralized visibility of CloudGuard Controller alerts.
CGNSIS-2049,
CGNSIS-2094,
CGNSIS-758
Additional improvements.
Take 9 - Gradual deployment from 07 Jun 2026
CGNSIS-1907 Enhancement: CloudGuard Controller now supports the Claroty Continuous Threat Detection (CTD) Data Center.
CGNSIS-1729 Minor fix.
Take 8 - Gradual deployment from 26 Apr 2026
VSECC-3008 Enhancement: Added support for new IoT tags for third-party vendor discovery.
CGNSIS-1242 Memory issue is caused when the VPN Cloud monitor (VCM) feature is disabled in Azure Data Centers.
CGNSIS-1240 In rare scenarios, the scanner process gets stuck, as a result, the Data Center may not be scanned.
CGNSIS-1130 Minor fix.
Take 7 - Gradual deployment from 05 Apr 2026
CGNSIS-1182 Enhancement: CloudGuard Controller now supports the Illumio Data Center. Refer to the R82.10 CloudGuard Controller Administration Guide.
CGNSIS-968 Enhancement: Enhanced reliability of vCenter Data Center scanner connections. Refer to sk184856.
CGNSIS-535 Enhancement: Added partial-success support for Google Cloud Platform data center scans, consistent with existing Azure support. When a scan covers multiple GCP projects, and some fail, the successfully scanned projects are now updated instead of the entire scan being blocked.
CGNSIS-979 The cprid_util_debug.sh script fails.

R82 Release

ID Description
Take 33 - Gradual deployment from 19 Jul 2026
CGNSIS-2376 In rare scenarios, Cisco ACI Data Center scans may receive an empty response from the Cisco APIC, causing Data Center objects to be temporarily removed.
CGNSIS-2135 Enhancement: CloudGuard Controller now supports the Nozomi, ServiceNow CMDB and Akamai Guardicore Data Centers. Refer to the R82 CloudGuard Controller Administration Guide.
CGNSIS-1828,
CGNSIS-2093
Additional improvements.
Take 32 - Gradual deployment from 07 Jun 2026
CGNSIS-1906 Enhancement: CloudGuard Controller now supports the Claroty Continuous Threat Detection (CTD) Data Center.
CGNSIS-1730 Minor fix.
Take 31 - Gradual deployment from 26 Apr 2026
VSECC-3008 Enhancement: Added support new IoT tags for third-party vendor discovery.
CGNSIS-1241 Memory issue is caused when the VPN Cloud monitor (VCM) feature is disabled in Azure Data Centers.
CGNSIS-1130 In rare scenarios, the scanner process gets stuck, as a result, the Data Center may not be scanned.
CGNSIS-1230 Minor fix.

Installation Troubleshooting

These issues can rise when running the installation package:

Solution: CloudGuard Controller bundle has already been installed for the first time and is configured to receive updates automatically. If you have no Internet access, follow the instructions for "Offline Package Installation Procedure" in the Installation Instructions section above.

Solution: We highly recommend to use the latest take of CloudGuard Controller package. If you still want to revert to the previous Take:

  1. Connect to the command line on the CloudGuard Controller server.
  2. Log in to the Expert mode.
  3. Revert the package to the previous Take: autoupdatercli revert CloudGuard_Controller The revert takes up to 1 minute.
  4. Make sure CloudGuard Controller Bundle was reverted to the previous Take:
    1. Run: cpinfo -y CPUpdates 2>&1 | grep CLOUDGUARD_CONTROLLER The Take number in the output must be the one to which you reverted.
    2. Examine this log file: /opt/CPInstLog/AutoUpdateLogs/CloudGuard_Controller

Notes:

Solution:

  1. Connect to the command line on the CloudGuard Controller server.
  2. Log in to the Expert mode.
  3. Remove the package: autoupdatercli revert-completely CloudGuard_Controller The revert takes up to one minute.
  4. Make sure the CloudGuard Controller package was removed:
    1. Run: cpinfo -y CPUpdates 2>&1 | grep CLOUDGUARD_CONTROLLER
    2. Examine this log file: /opt/CPInstLog/AutoUpdateLogs/CloudGuard_Controller

Solution:

  1. Connect to the command line on the CloudGuard Controller server.
  2. Log in to the Expert mode.
  3. Run: autoupdatercli disable CloudGuard_Controller

Symptoms:

  1. This error shows in the /opt/CPInstLog/Autoupdater.log file: Problem with local certificate Error code: 10 ...Abandoned file removed from the system ...Failed to download metadata package for component auto_updater Solution: Refer to sk184474.

For additional troubleshooting instructions, refer to the sk115657 - ATRG: CloudGuard Controller.
If your issue is not resolved by one of the above solutions, contact Check Point Support and attach the /opt/CPInstLog/AutoUpdateLogs/CloudGuard_Controller log file.

Article Properties

Access Level: General

Status: Approved

Date Created: 2023-12-26

Last Modified: 2026-07-19