# Hotfix for Check Point Firewall 3900 Appliances

## Solution

Show the Entire Article

**Availability | List of Resolved Issues | Installation instructions | Uninstall instructions | Revision History**

**For more info on all Check Point releases, refer to [Release map](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk152052) and [Release Terminology](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk95746) articles.**

## Introduction

**Hotfix for Check Point Firewall 3900 Appliances** is an accumulation of stability and quality fixes resolving multiple issues.

For more information about Check Point Firewall 3900 Appliances, refer to [sk183199](https://support.checkpoint.com/results/sk/sk183199).

**Important:**

To manage 3900 appliances that run R82.10, use:

**Option 1**- R82.10 Management server - see [sk183506](https://support.checkpoint.com/results/sk/sk183506)

**Option 2** - R82 Management server

1. The Management Server must run [R82 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm), Take 19 or higher.
2. You must use [R82 SmartConsole](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82_SC/Default.htm), Build 1053 or higher.

The content of **Hotfix for Check Point Firewall 3900 Appliances Take 22** is included in **Check Point R82.10 Take 467**. You do not need to install Hotfix for Check Point Firewall 3900 Appliances Take 22 on top of R82.10 Take 467.

- For upgrading the Security Gateway to Check Point R82.10 Take 467 it is mandatory to install Hotfix for Check Point Firewall 3900 Appliances Take 22. See [Check Point R82.10 Homepage](https://support.checkpoint.com/results/sk/sk183506) \> Upgrading Quantum Security Gateway > For Quantum Force 3900 Appliances.
- For clean installation of Check Point R82.10 Take 467, see [Check Point R82.10 Homepage](https://support.checkpoint.com/results/sk/sk183506) \> Clean Install of Security Gateway and Management Server > For Quantum Force 3900 Appliances.

**Effective March 31, 2026, the R82.10 GA version was updated to Take 467, which includes the certificates and CRL fix ( [sk184766](https://support.checkpoint.com/results/sk/sk184766)).**

## Availability

- **Take 22** is the Recommended Hotfix for Check Point Firewall 3900 Appliances with R82.10 Take 271 installed

|     |     |     |     |
| --- | --- | --- | --- |
| **Product** | **Take #** | **Release Date** | **Offline package** |
| **Security Gateways**<br>**3920, 3950, 3970, 3980** | **Take 22** | 14 Sep 2025 |  (TAR) |

**For further Jumbo Hotfix Accumulator Takes for Check Point Firewall 3900 Appliances, refer to [R82.10 Jumbo Hotfix Accumulator](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm).**

**Note:** if you choose not to upgrade to R82.10 Take 467, then to install R82.10 Jumbo Hotfix, you should use only the TGZ package.

## List of Resolved issues

|     |     |     |
| --- | --- | --- |
| ID | Product | Description |
| **Take 22 - Released on 14 September 2025** |
| PRJ-63341,<br>PRHF-41560 | HTTPS Inspection,VPN | **UPDATE**: Updated CRL and OCSP validation in Remote Access VPN, Site-to-Site VPN, and HTTPS Inspection to use HTTP/1.1 instead of HTTP/1.0. This ensures continued compatibility with DigiCert's updated requirements and prevents certificate validation failures. Refer to [sk183884](https://support.checkpoint.com/results/sk/sk183884). |
| PRJ-61137,<br>PMTR-109056 | Security Management | The " _Management rejected fetch for this module - version matching problem_" error is displayed when running the " _fw vsx fetch_" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server. Refer to [sk183298](https://support.checkpoint.com/results/sk/sk183298). |
| PRJ-62501,<br>PMTR-117250 | Security Gateway | Possible packet loss and / or latency when connecting a 1 GbE switch port to the 10 GbE ports (Mgmt, eth11) on the Check Point Firewall 3950 appliances. <br>This Hotfix Take performs a UEFI firmware update that resolves the issue. Refer to [sk183766](https://support.checkpoint.com/results/sk/sk183766). |
| PRJ-61779,<br>PMTR-116315 | Threat Extraction | The Threat Extraction Software Blade may inadvertently delete some system files on the Security Gateway. Refer to [sk183512](https://support.checkpoint.com/results/sk/sk183512). |
| PRJ-61402,<br>PRHF-38747 | SecureXL | After a VSX reboot, other Virtual Systems (VS's) enter a Down/Lost state while USIM core files are generated. |
| PRJ-61989,<br>PRJ-61915 | SecureXL | The USIM process may crash during route updates when the Hardware Acceleration offloading connection is active. |
| PRJ-61828,<br>PMTR-115846 | Routing | Traffic routing may fail between the host and PPPoE / DNS Server through the Security Gateway, even though host-to-gateway and gateway-to-DNS connections work as expected. |
| PRJ-62662,<br>PMTR-117551 | Routing | DHCP broadcast packets are not visible on the intended VLAN when working in SecureXL User Mode (UPPAK). Refer to [sk183675](https://support.checkpoint.com/results/sk/sk183675). |
| PRJ-62538,<br>PRHF-40540 | Routing | A memory leak occurs in the ROUTED daemon when CoreXL is running OSPF and handling large numbers of LSAs combined with frequent route flaps. |
| PRJ-61241,<br>PMTR-115436 | Gaia OS | On the 3900 appliances, the synchronization of Gaia Cloning Groups never completes (in Gaia Portal > the "System Management" section > the "Cloning Group" page > in the "Cloning Group" section, the "Member Status" field constantly shows "Synchronizing"). |
| PRJ-61144,<br>PRHF-38271 | SD-WAN | SD-WAN policy installation may fail during the configuration of MDPS on the Security Gateway. |

## Installation Instructions

**Procedure:**

- **Show / Hide instructions for installation in Gaia Clish**

1. Download the TAR package from the Availability section of this SK article and place it to the `/tmp` directory on the 3900 Security Gateway.
2. Install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What%27s%20New).
3. Connect to command line on target Security Gateway.
4. Log in to Gaia Clish.
5. Obtain the lock over the Gaia configuration database:

`HostName:0> lock database override`
6. Import the package from the hard disk:

`HostName:0> installer import local /<Full_Path>/<Package_File_Name>.TAR`
7. Show the imported packages:

`HostName:0> show installer packages imported`
8. Verify that this Hotfix package can be installed without conflicts:

`HostName:0> installer verify <Package_Number>`
9. Install the imported package:

`HostName:0> installer install <Package_Number>`

## Uninstall Instructions

**Important Note:** This Hotfix removes all its packages during uninstall.

**Procedure:**

- **Show / Hide instructions for uninstall in Gaia Clish**

1. [CPUSE Software Updates Policy](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE%20-%20Additional%20How%20To) should be configured to allow self-update of CPUSE Agent.

Otherwise (and if this machine is offline), users should manually install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What%27s%20New).
2. Connect to command line on Gaia OS.
3. Log in to Gaia Clish.
4. Obtain the lock over the Gaia configuration database:

`HostName:0> lock database override`
5. Uninstall the package:

`HostName:0> installer uninstall <Package_Number>`

Note: The progress in percentage appears in Gaia Clish.
6. **Server reboots automatically.**

## Revision History

Show / Hide revision history

|     |     |
| --- | --- |
| Date | Description |
| 29 Dec 2025 | Updated the Introduction section |
| 14 Sep 2025 | First release of Hotfix for Check Point Firewall 3900 Appliances - Take 22 |
