sk183557 - Hotfix for Check Point Firewall 3900 Appliances
Hotfix for Check Point Firewall 3900 Appliances
Solution
Show the Entire Article
Availability | List of Resolved Issues | Installation instructions | Uninstall instructions | Revision History
For more info on all Check Point releases, refer to Release map and Release Terminology articles.
Introduction
Hotfix for Check Point Firewall 3900 Appliances is an accumulation of stability and quality fixes resolving multiple issues.
For more information about Check Point Firewall 3900 Appliances, refer to sk183199.
Important:
To manage 3900 appliances that run R82.10, use:
Option 1- R82.10 Management server - see sk183506
Option 2 - R82 Management server
- The Management Server must run R82 Jumbo Hotfix Accumulator, Take 19 or higher.
- You must use R82 SmartConsole, Build 1053 or higher.
The content of Hotfix for Check Point Firewall 3900 Appliances Take 22 is included in Check Point R82.10 Take 467. You do not need to install Hotfix for Check Point Firewall 3900 Appliances Take 22 on top of R82.10 Take 467.
- For upgrading the Security Gateway to Check Point R82.10 Take 467 it is mandatory to install Hotfix for Check Point Firewall 3900 Appliances Take 22. See Check Point R82.10 Homepage > Upgrading Quantum Security Gateway > For Quantum Force 3900 Appliances.
- For clean installation of Check Point R82.10 Take 467, see Check Point R82.10 Homepage > Clean Install of Security Gateway and Management Server > For Quantum Force 3900 Appliances.
Effective March 31, 2026, the R82.10 GA version was updated to Take 467, which includes the certificates and CRL fix ( sk184766).
Availability
- Take 22 is the Recommended Hotfix for Check Point Firewall 3900 Appliances with R82.10 Take 271 installed
| Product | Take # | Release Date | Offline package |
| Security Gateways 3920, 3950, 3970, 3980 |
Take 22 | 14 Sep 2025 | (TAR) |
For further Jumbo Hotfix Accumulator Takes for Check Point Firewall 3900 Appliances, refer to R82.10 Jumbo Hotfix Accumulator.
Note: if you choose not to upgrade to R82.10 Take 467, then to install R82.10 Jumbo Hotfix, you should use only the TGZ package.
List of Resolved issues
| ID | Product | Description |
| Take 22 - Released on 14 September 2025 | ||
| PRJ-63341, PRHF-41560 |
HTTPS Inspection,VPN | UPDATE: Updated CRL and OCSP validation in Remote Access VPN, Site-to-Site VPN, and HTTPS Inspection to use HTTP/1.1 instead of HTTP/1.0. This ensures continued compatibility with DigiCert's updated requirements and prevents certificate validation failures. Refer to sk183884. |
| PRJ-61137, PMTR-109056 |
Security Management | The " Management rejected fetch for this module - version matching problem" error is displayed when running the " fw vsx fetch" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server. Refer to sk183298. |
| PRJ-62501, PMTR-117250 |
Security Gateway | Possible packet loss and / or latency when connecting a 1 GbE switch port to the 10 GbE ports (Mgmt, eth11) on the Check Point Firewall 3950 appliances. This Hotfix Take performs a UEFI firmware update that resolves the issue. Refer to sk183766. |
| PRJ-61779, PMTR-116315 |
Threat Extraction | The Threat Extraction Software Blade may inadvertently delete some system files on the Security Gateway. Refer to sk183512. |
| PRJ-61402, PRHF-38747 |
SecureXL | After a VSX reboot, other Virtual Systems (VS's) enter a Down/Lost state while USIM core files are generated. |
| PRJ-61989, PRJ-61915 |
SecureXL | The USIM process may crash during route updates when the Hardware Acceleration offloading connection is active. |
| PRJ-61828, PMTR-115846 |
Routing | Traffic routing may fail between the host and PPPoE / DNS Server through the Security Gateway, even though host-to-gateway and gateway-to-DNS connections work as expected. |
| PRJ-62662, PMTR-117551 |
Routing | DHCP broadcast packets are not visible on the intended VLAN when working in SecureXL User Mode (UPPAK). Refer to sk183675. |
| PRJ-62538, PRHF-40540 |
Routing | A memory leak occurs in the ROUTED daemon when CoreXL is running OSPF and handling large numbers of LSAs combined with frequent route flaps. |
| PRJ-61241, PMTR-115436 |
Gaia OS | On the 3900 appliances, the synchronization of Gaia Cloning Groups never completes (in Gaia Portal > the "System Management" section > the "Cloning Group" page > in the "Cloning Group" section, the "Member Status" field constantly shows "Synchronizing"). |
| PRJ-61144, PRHF-38271 |
SD-WAN | SD-WAN policy installation may fail during the configuration of MDPS on the Security Gateway. |
Installation Instructions
Procedure:
- Show / Hide instructions for installation in Gaia Clish
- Download the TAR package from the Availability section of this SK article and place it to the
/tmpdirectory on the 3900 Security Gateway. - Install the latest build of CPUSE Agent from sk92449.
- Connect to command line on target Security Gateway.
- Log in to Gaia Clish.
- Obtain the lock over the Gaia configuration database:
HostName:0> lock database override
6. Import the package from the hard disk:
HostName:0> installer import local /<Full_Path>/<Package_File_Name>.TAR
7. Show the imported packages:
HostName:0> show installer packages imported
8. Verify that this Hotfix package can be installed without conflicts:
HostName:0> installer verify <Package_Number>
9. Install the imported package:
HostName:0> installer install <Package_Number>
Uninstall Instructions
Important Note: This Hotfix removes all its packages during uninstall.
Procedure:
- Show / Hide instructions for uninstall in Gaia Clish
- CPUSE Software Updates Policy should be configured to allow self-update of CPUSE Agent.
Otherwise (and if this machine is offline), users should manually install the latest build of CPUSE Agent from sk92449. 2. Connect to command line on Gaia OS. 3. Log in to Gaia Clish. 4. Obtain the lock over the Gaia configuration database:
HostName:0> lock database override
5. Uninstall the package:
HostName:0> installer uninstall <Package_Number>
Note: The progress in percentage appears in Gaia Clish. 6. Server reboots automatically.
Revision History
Show / Hide revision history
| Date | Description |
| 29 Dec 2025 | Updated the Introduction section |
| 14 Sep 2025 | First release of Hotfix for Check Point Firewall 3900 Appliances - Take 22 |