sk183199 - Check Point Firewall 3900 Appliances

Check Point Firewall 3900 Appliances

Solution

Overview  |  Key Features  |  Upgrade path  |  Documentation  |  Known Limitations  |  Revision History

Visit Check Point CheckMates Community to ask questions or start a discussion and get our experts assistance.

See Support Life Cycle Policy for End-of-Support dates and successor appliance series.

3920 3950 3970 / 3980

Overview

The Check Point Firewall 3900 Security Gateway appliance series is built to protect branch offices from both known and unknown threats with Anti-Virus, Anti-Bot, SandBlast Threat Emulation (Sandboxing), and SandBlast Threat Extraction technologies.

The Check Point 3900 Security Gateway appliance series combines the most comprehensive security protections to safeguard your branch and small office deployments.

The 3900 Security Gateway appliance series is available in a compact desktop form factor, while the latest generation offers a 1U form factor for enhanced scalability.

Optimized for real-world threat prevention, this powerful Security Gateway secures critical assets and environments.

The latest 3900 appliances, 3920, 3950, 3970, and 3980, come with a first-year subscription to the full SandBlast Prevention suite.

For the 3920 appliances, these Sync ports are recommended: eth9 (default), eth10 and eth11.

Key Features

Upgrade path

To upgrade the Check Point Firewall 3900 with R82.10 Take 271 installed:

  1. Install the Hotfix for Check Point Firewall 3900 Appliances, Take 22. For more information, see sk183557.
  2. Install R82.10 Take 467. For more information, see sk183506 > Downloads and installation > Upgrading Security Gateway > For Check Point Firewall 3900 Appliances.

Effective March 31, 2026, the GA version was updated to Take 467, which includes the certificates and CRL fix (sk184766).

Notes:

Note that if you choose not to upgrade to R82.10 Take 467, then to install R82.10 Jumbo Hotfix, you should use only the TGZ package.

Documentation

Quick Start Guides
Check Point Firewall 3900 Appliances Quick Start Guide
Check Point Firewall 3900 Appliances Getting Started Guide (English)
Check Point Firewall 3900 Appliances Getting Started Guide (Spanish)
Check Point Firewall 3900 Appliances Getting Started Guide (Portuguese - Brazil)
Check Point Firewall 3900 Appliances Getting Started Guide (Chinese - Simplified)
Check Point Firewall 3900 Appliances Getting Started Guide (Chinese - Traditional)
Installation Guides
Rack Mounting for Check Point Appliances
Installing and Removing an AC Adapter
Installing and Removing Transceivers and DAC Cables
Administration Documentation
Zero Touch Administration Guide
Additional Documentation
R82 Installation and Upgrade Guide
Product Catalog

Known Limitations

ID Description Resolved In
- All R82 limitations apply as described in sk181128 - R82 Known Limitations. -
- By design, the 3900 appliances do not support the Standalone configuration. -
PMTR-114921 The 3900 appliances do not support the ElasticXL configuration. Resolved in R82.10 take 464
PMTR-106079,
PMTR-114923
The 3900 appliances do not support the Maestro configuration. -
PMTR-114894 The 3900 appliances do not support the VSNext mode. Resolved in R82.10 take 464
PMTR-115040 The 3900 appliances do not support the Mail Transfer Agent (MTA) feature. Resolved in R82.10 take 464
PMTR-115051 On the 3900 appliances, the Data Loss Prevention (DLP) Software Blade does not support email inspection and enforcement. Inspection of HTTP, HTTPS, and FTP is supported. -
PMTR-115010 On the 3900 appliances, the Threat Emulation Software Blade does not support Local Emulation. -
PMTR-115468 On the 3900 appliances, after you enable the Data Loss Prevention (DLP) Software Blade with the Management API "set simple-gateway ... data-loss-prevention true" or "set simple-cluster ... data-loss-prevention true", you must follow these steps in SmartConsole:
1. Open the Security Gateway / Cluster object.
2. Navigate to "Data Loss Prevention" > "Protocols".
3. Select "Apply the DLP policy to these protocols only".
4. Clear the checkbox "SMTP (Outgoing Emails)".
5. Click OK.
6. Install the Access Control Policy.
-
PMTR-114608 On the 3900 appliances, the Threat Extraction Software Blade does not support the action "Convert to PDF". Resolved in R82.10 take 464
PMTR-112848 On the 3900 appliances, if in addition to the default Firewall Software Blade, you enable other Software Blades in the Security Gateway / Cluster object:
1. VxLAN traffic terminating on the Security Gateway will not be accelerated (will go through Slow Path instead of Medium Streaming Path).
2. GRE traffic terminating on the Security Gateway will not work.
Resolved in R82.10 take 464
PMTR-114940 On the 3900 appliances:
1. VxLAN over VPN is not supported. It is not supported to initiate encapsulation of VxLAN tunnel traffic from the Security Gateway and send it over a VPN tunnel.
2. GRE over VPN is not supported. It is not supported to initiate encapsulation of GRE tunnel traffic from the Security Gateway and send it over a VPN tunnel.
Resolved in R82.10 take 464
PMTR-114617, PMTR-115239 By design, on the 3900 appliances, the LED of the  Network Port that should receive IP address from DHCP for Zero Touch configuration does not blink. -
PMTR-114598,
GWAPP-2011
On the 3900 appliances, the "Network test" in "HW Diagnostics" (in the Boot Menu) is not supported. -
PMTR-113632 On the 3900 appliances, the ClusterXL Load Sharing modes are not supported. Resolved in R82.10 take 464
PMTR-111169 On the 3900 appliances, ClusterXL in the Active-Active mode is not supported. Resolved in R82.10 take 464
PMTR-113240 By design, on the 3900 appliances, changing the value of any of these parameters on one of the interfaces will change this value on all switch interfaces:
- rx-ringsize
- tx-ringsize
- mq
This may briefly interrupt the traffic through the interfaces.
-
GWAPP-2213 By design, on the 3900 appliances, the Power LED and other LEDs remain lit even after running shutdown or halt command.
To shut down the appliance completely, you must also use the power switch.
-
PMTR-115436,
PMTR-115974
On the 3900 appliances, the synchronization of Gaia Cloning Groups never completes (in Gaia Portal > the "System Management" section > the "Cloning Group" page > in the "Cloning Group" section, the "Member Status" field constantly shows "Synchronizing"). Resolved in R82.10 take 464
GWAPP-2229 On the Check Point Firewall 3920 model, the 1 GbE SFP port (eth9) does not support the transceiver CPAC-TR-1SX-D. -
PMTR-115198 On the Check Point Firewall 3920 model, the 1 GbE SFP port (eth9) does not support the transceiver CPAC-TR-1T-D. -
PMTR-113472 - In the 3920 model, you must use only 10 Gbps transceivers in the interfaces eth10 and eth11.
- In the 3970 and 3980 models, you must use only 10 Gbps transceivers in the interfaces from eth27, eth28, eth29, and eth30.
- When replacing a 1Gbps transceiver with a 10Gbps transceiver, and the reverse, you must reboot the appliance.
-
PMTR-115220 By design, on the Check Point Firewall 3950, 3970, 3980 models, the 2.5 GbE RJ45 ports operate with the auto-negotiation enabled at the speeds of 1 Gbps and faster. This may lead to a mismatch between user-configured speeds and the actual speed. -

Revision History

Date Description
29 December 2025 Updated the Downloads and Known Limitations sections
14 September 2025 Updated the Downloads and Known Limitations sections
01 September 2025 Updated the Documentation section - Added 3900 Getting Started Guide links (Chinese - Simplified and Chinese - Traditional).
13 July 2025 Updated the Documentation section.
08 June 2025 Updated the Known Limitations section.
04 June 2025 Updated the Known Limitations section.
01 June 2025 First release of this article.