sk183754 - Microsoft Azure Network Adapter (MANA)
Microsoft Azure Network Adapter (MANA)
Product: Cloud Firewall, Multi-Domain Security Management, SmartView Monitor
Version: R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Platform: Azure
Last Modified: 2026-07-06
Solution
Microsoft Azure is deploying new network infrastructure that uses Microsoft Azure Network Adapters (MANA).
Check Point currently recommends that you opt out of MANA for all applicable deployments.
MANA uses a new driver that has limited production history. Until Check Point and Microsoft complete joint validation of driver stability and performance, the MANA driver remains disabled by default on all Check Point instances.
Check Point is working actively with Microsoft to validate the driver. Support will be enabled incrementally as validation progresses.
Why You Must Act Now
Azure places new and restarted virtual machines (VMs) on MANA-enabled hardware by default. If you do not opt out, Check Point Cloud Firewall instances placed on MANA-enabled hosts may experience performance degradation.
Applying the opt-out tag (LegacyVMNVA) keeps your instances on Mellanox-enabled infrastructure. Mellanox is the proven, validated path for Check Point deployments.
The opt-out mechanism is retired on May 30, 2027. After that date, Azure places all instances on MANA-enabled infrastructure regardless of opt-out status. Use the time before this date to complete validation and plan your migration.
How to Opt Out
Follow the official Microsoft opt-out procedure: MANA support for Network Virtual Appliances - Microsoft documentation.
Opt-out is highly recommended before any of the triggering operations described in the next section.
Note: Newer Check Point templates automatically apply the LegacyVMNVA tag to opt VMs out of Azure's new MANA networking hardware.
Operations That Trigger MANA Allocation
Azure places a VM on MANA-enabled hardware during the following operations, if you have not applied the opt-out tag beforehand:
| Operation | Description |
| New deployment | Any new VM provisioned in an affected region. |
| Stop and start via the Azure portal | Stopping and restarting a VM through the portal (not a reboot) triggers reallocation. A reboot does not trigger reallocation. |
| Scale-out | New instances added to a Virtual Machine Scale Set (VMSS) are provisioned fresh and are subject to MANA allocation. |
IMPORTANT:
Already-running VMs that are not stopped, redeployed, or scaled out are not affected — until May 30, 2027.
Affected Deployment Types
The table below shows which operations can trigger MANA allocation for each Check Point deployment type. This applies only when you have not applied the opt-out tag.
| Deployment type | New deployment | Stop/start via portal | Scale-out |
| Cloud Firewall Gateways and HA Clusters | ✓ | ✓ | - |
| Cloud Firewall Standalone | ✓ | ✓ | - |
| Cloud Firewall Virtual Machine Scale Set (VMSS) | ✓ | ✓ | ✓ |
| Cloud Firewall for Virtual WAN (vWAN) | Automatically opted out — no action required | ||
| Security Management Server | ✓ | ✓ | - |
| Multi-Domain Server | ✓ | ✓ | - |
| Log Server | ✓ | ✓ | - |
| SmartEvent Server | ✓ | ✓ | - |
Action required: Opt-out all deployment types listed above, except vWAN.
Azure opts out vWAN deployments automatically.
Rollout Schedule
MANA is rolling out to all VM sizes and regions starting August 1, 2026.
v5 VM Types - Rollout in Progress
(Updated May 27, 2026)
| Date | Region |
| May 26, 2026 | West Central US |
| May 27, 2026 | East Asia |
| May 28, 2026 | Norway West |
| May 29, 2026 | Spain Central |
Microsoft will announce additional regions via Microsoft Service Health notification on May 29, 2026.
All Other Instance Types
Apply the opt-out tag before August 1, 2026. VMs created or tagged after this date may be placed on MANA-capable hardware.
Supported Releases
To enable operations with the MANA driver, the following Check Point releases are required as prerequisites:
In these versions, the MANA driver is included but disabled by default, and must be explicitly enabled to be used.
Note: For R82 Jumbo Hotfix Take 103 and higher, the MTU of MANA driver has a default value of 1500 and cannot be changed.
Important: Releases earlier than R82 do not include the MANA driver. Upgrade to R82 or later before enabling MANA.
Note: R81.20, R81.10 and earlier releases are also affected by MANA allocation - Azure may place instances running these versions on MANA-enabled hardware regardless of the Check Point release installed.
If your instances run R81.20, R81.10, or an earlier release, you have two options:
- Opt out of MANA (recommended immediately) - Apply the Azure opt-out tag to keep your instances on Mellanox-enabled infrastructure until May 30, 2027.
- Upgrade to R82 or later - This is the only path to eventual MANA support. After upgrading, make sure you are on a supported Jumbo Hotfix take before enabling the MANA driver.
How to Check Whether Your Instance Is Running on MANA-Enabled Hardware
Run this command on the instance in expert mode:
lspci | grep "Microsoft"
Look for this entry in the output:
7870:00:00.0 Ethernet controller: Microsoft Corporation Device 00ba
If this entry appears, the instance is running on MANA-enabled hardware.
Controlling MANA driver status
Prerequisite: Make sure that your Check Point release includes MANA driver (see the Supported Releases section above).
To enable MANA:
- Log in to the Security Management Server or Cloud Firewall Gateway/Cluster instance in expert mode.
- Run this command:
rm /etc/modprobe.d/disable_mana.conf
3. Reboot the instance.
To disable MANA:
- Log in to the Security Management Server or Cloud Firewall Gateway/Cluster instance in expert mode.
- Run this command:
echo "blacklist mana" > /etc/modprobe.d/disable_mana.conf
3. Reboot the instance.
FAQ
Q: What happens if the tag does not take effect?
A: VM placement is ultimately managed by Azure. Because of that, Microsoft is the best resource for understanding how these situations are handled. If you run into a case where the tag does not apply as expected, we recommend reaching out to Microsoft support - they can walk you through the specifics and help get this issue resolved.
Known Limitations
- MANA driver does not support MTU change