sk183557 - Hotfix for Check Point Firewall 3900 Appliances

Hotfix for Check Point Firewall 3900 Appliances

Solution

Show the Entire Article

Availability | List of Resolved Issues | Installation instructions | Uninstall instructions | Revision History

For more info on all Check Point releases, refer to Release map and Release Terminology articles.

Introduction

Hotfix for Check Point Firewall 3900 Appliances is an accumulation of stability and quality fixes resolving multiple issues.

For more information about Check Point Firewall 3900 Appliances, refer to sk183199.

Important:

To manage 3900 appliances that run R82.10, use:

Option 1- R82.10 Management server - see sk183506

Option 2 - R82 Management server

  1. The Management Server must run R82 Jumbo Hotfix Accumulator, Take 19 or higher.
  2. You must use R82 SmartConsole, Build 1053 or higher.

The content of Hotfix for Check Point Firewall 3900 Appliances Take 22 is included in Check Point R82.10 Take 467. You do not need to install Hotfix for Check Point Firewall 3900 Appliances Take 22 on top of R82.10 Take 467.

Effective March 31, 2026, the R82.10 GA version was updated to Take 467, which includes the certificates and CRL fix ( sk184766).

Availability

Product Take # Release Date Offline package
Security Gateways
3920, 3950, 3970, 3980
Take 22 14 Sep 2025 (TAR)

For further Jumbo Hotfix Accumulator Takes for Check Point Firewall 3900 Appliances, refer to R82.10 Jumbo Hotfix Accumulator.

Note: if you choose not to upgrade to R82.10 Take 467, then to install R82.10 Jumbo Hotfix, you should use only the TGZ package.

List of Resolved issues

ID Product Description
Take 22 - Released on 14 September 2025
PRJ-63341,
PRHF-41560
HTTPS Inspection,VPN UPDATE: Updated CRL and OCSP validation in Remote Access VPN, Site-to-Site VPN, and HTTPS Inspection to use HTTP/1.1 instead of HTTP/1.0. This ensures continued compatibility with DigiCert's updated requirements and prevents certificate validation failures. Refer to sk183884.
PRJ-61137,
PMTR-109056
Security Management The " Management rejected fetch for this module - version matching problem" error is displayed when running the " fw vsx fetch" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server. Refer to sk183298.
PRJ-62501,
PMTR-117250
Security Gateway Possible packet loss and / or latency when connecting a 1 GbE switch port to the 10 GbE ports (Mgmt, eth11) on the Check Point Firewall 3950 appliances.
This Hotfix Take performs a UEFI firmware update that resolves the issue. Refer to sk183766.
PRJ-61779,
PMTR-116315
Threat Extraction The Threat Extraction Software Blade may inadvertently delete some system files on the Security Gateway. Refer to sk183512.
PRJ-61402,
PRHF-38747
SecureXL After a VSX reboot, other Virtual Systems (VS's) enter a Down/Lost state while USIM core files are generated.
PRJ-61989,
PRJ-61915
SecureXL The USIM process may crash during route updates when the Hardware Acceleration offloading connection is active.
PRJ-61828,
PMTR-115846
Routing Traffic routing may fail between the host and PPPoE / DNS Server through the Security Gateway, even though host-to-gateway and gateway-to-DNS connections work as expected.
PRJ-62662,
PMTR-117551
Routing DHCP broadcast packets are not visible on the intended VLAN when working in SecureXL User Mode (UPPAK). Refer to sk183675.
PRJ-62538,
PRHF-40540
Routing A memory leak occurs in the ROUTED daemon when CoreXL is running OSPF and handling large numbers of LSAs combined with frequent route flaps.
PRJ-61241,
PMTR-115436
Gaia OS On the 3900 appliances, the synchronization of Gaia Cloning Groups never completes (in Gaia Portal > the "System Management" section > the "Cloning Group" page > in the "Cloning Group" section, the "Member Status" field constantly shows "Synchronizing").
PRJ-61144,
PRHF-38271
SD-WAN SD-WAN policy installation may fail during the configuration of MDPS on the Security Gateway.

Installation Instructions

Procedure:

  1. Download the TAR package from the Availability section of this SK article and place it to the /tmp directory on the 3900 Security Gateway.
  2. Install the latest build of CPUSE Agent from sk92449.
  3. Connect to command line on target Security Gateway.
  4. Log in to Gaia Clish.
  5. Obtain the lock over the Gaia configuration database:

HostName:0> lock database override 6. Import the package from the hard disk:

HostName:0> installer import local /<Full_Path>/<Package_File_Name>.TAR 7. Show the imported packages:

HostName:0> show installer packages imported 8. Verify that this Hotfix package can be installed without conflicts:

HostName:0> installer verify <Package_Number> 9. Install the imported package:

HostName:0> installer install <Package_Number>

Uninstall Instructions

Important Note: This Hotfix removes all its packages during uninstall.

Procedure:

  1. CPUSE Software Updates Policy should be configured to allow self-update of CPUSE Agent.

Otherwise (and if this machine is offline), users should manually install the latest build of CPUSE Agent from sk92449. 2. Connect to command line on Gaia OS. 3. Log in to Gaia Clish. 4. Obtain the lock over the Gaia configuration database:

HostName:0> lock database override 5. Uninstall the package:

HostName:0> installer uninstall <Package_Number>

Note: The progress in percentage appears in Gaia Clish. 6. Server reboots automatically.

Revision History

Show / Hide revision history

Date Description
29 Dec 2025 Updated the Introduction section
14 Sep 2025 First release of Hotfix for Check Point Firewall 3900 Appliances - Take 22