sk183754 - Microsoft Azure Network Adapter (MANA)

Microsoft Azure Network Adapter (MANA)

Product: Cloud Firewall, Multi-Domain Security Management, SmartView Monitor
Version: R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Platform: Azure
Last Modified: 2026-07-06

Solution

Microsoft Azure is deploying new network infrastructure that uses Microsoft Azure Network Adapters (MANA).

Check Point currently recommends that you opt out of MANA for all applicable deployments.

MANA uses a new driver that has limited production history. Until Check Point and Microsoft complete joint validation of driver stability and performance, the MANA driver remains disabled by default on all Check Point instances.

Check Point is working actively with Microsoft to validate the driver. Support will be enabled incrementally as validation progresses.

Why You Must Act Now

Azure places new and restarted virtual machines (VMs) on MANA-enabled hardware by default. If you do not opt out, Check Point Cloud Firewall instances placed on MANA-enabled hosts may experience performance degradation.

Applying the opt-out tag (LegacyVMNVA) keeps your instances on Mellanox-enabled infrastructure. Mellanox is the proven, validated path for Check Point deployments.

The opt-out mechanism is retired on May 30, 2027. After that date, Azure places all instances on MANA-enabled infrastructure regardless of opt-out status. Use the time before this date to complete validation and plan your migration.

How to Opt Out

Follow the official Microsoft opt-out procedure: MANA support for Network Virtual Appliances - Microsoft documentation.

Opt-out is highly recommended before any of the triggering operations described in the next section.

Note: Newer Check Point templates automatically apply the LegacyVMNVA tag to opt VMs out of Azure's new MANA networking hardware.

Operations That Trigger MANA Allocation

Azure places a VM on MANA-enabled hardware during the following operations, if you have not applied the opt-out tag beforehand:

Operation Description
New deployment Any new VM provisioned in an affected region.
Stop and start via the Azure portal Stopping and restarting a VM through the portal (not a reboot) triggers reallocation. A reboot does not trigger reallocation.
Scale-out New instances added to a Virtual Machine Scale Set (VMSS) are provisioned fresh and are subject to MANA allocation.

IMPORTANT:

Already-running VMs that are not stopped, redeployed, or scaled out are not affected — until May 30, 2027.

Affected Deployment Types

The table below shows which operations can trigger MANA allocation for each Check Point deployment type. This applies only when you have not applied the opt-out tag.

Deployment type New deployment Stop/start via portal Scale-out
Cloud Firewall Gateways and HA Clusters ✓ ✓ -
Cloud Firewall Standalone ✓ ✓ -
Cloud Firewall Virtual Machine Scale Set (VMSS) ✓ ✓ ✓
Cloud Firewall for Virtual WAN (vWAN) Automatically opted out — no action required
Security Management Server ✓ ✓ -
Multi-Domain Server ✓ ✓ -
Log Server ✓ ✓ -
SmartEvent Server ✓ ✓ -

Action required: Opt-out all deployment types listed above, except vWAN.

Azure opts out vWAN deployments automatically.

Rollout Schedule

MANA is rolling out to all VM sizes and regions starting August 1, 2026.

v5 VM Types - Rollout in Progress

(Updated May 27, 2026)

Date Region
May 26, 2026 West Central US
May 27, 2026 East Asia
May 28, 2026 Norway West
May 29, 2026 Spain Central

Microsoft will announce additional regions via Microsoft Service Health notification on May 29, 2026.

All Other Instance Types

Apply the opt-out tag before August 1, 2026. VMs created or tagged after this date may be placed on MANA-capable hardware.

Supported Releases

To enable operations with the MANA driver, the following Check Point releases are required as prerequisites:

In these versions, the MANA driver is included but disabled by default, and must be explicitly enabled to be used.

Note: For R82 Jumbo Hotfix Take 103 and higher, the MTU of MANA driver has a default value of 1500 and cannot be changed.
Important: Releases earlier than R82 do not include the MANA driver. Upgrade to R82 or later before enabling MANA.

Note: R81.20, R81.10 and earlier releases are also affected by MANA allocation - Azure may place instances running these versions on MANA-enabled hardware regardless of the Check Point release installed.

If your instances run R81.20, R81.10, or an earlier release, you have two options:

  1. Opt out of MANA (recommended immediately) - Apply the Azure opt-out tag to keep your instances on Mellanox-enabled infrastructure until May 30, 2027.
  2. Upgrade to R82 or later - This is the only path to eventual MANA support. After upgrading, make sure you are on a supported Jumbo Hotfix take before enabling the MANA driver.

How to Check Whether Your Instance Is Running on MANA-Enabled Hardware

Run this command on the instance in expert mode:

lspci | grep "Microsoft"

Look for this entry in the output:

7870:00:00.0 Ethernet controller: Microsoft Corporation Device 00ba

If this entry appears, the instance is running on MANA-enabled hardware.

Controlling MANA driver status

Prerequisite: Make sure that your Check Point release includes MANA driver (see the Supported Releases section above).

To enable MANA:

  1. Log in to the Security Management Server or Cloud Firewall Gateway/Cluster instance in expert mode.
  2. Run this command:

rm /etc/modprobe.d/disable_mana.conf 3. Reboot the instance.

To disable MANA:

  1. Log in to the Security Management Server or Cloud Firewall Gateway/Cluster instance in expert mode.
  2. Run this command:

echo "blacklist mana" > /etc/modprobe.d/disable_mana.conf 3. Reboot the instance.

FAQ

Q: What happens if the tag does not take effect?

A: VM placement is ultimately managed by Azure. Because of that, Microsoft is the best resource for understanding how these situations are handled. If you run into a case where the tag does not apply as expected, we recommend reaching out to Microsoft support - they can walk you through the specifics and help get this issue resolved.

Known Limitations

  1. MANA driver does not support MTU change