<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Live Patch (CPLP) – TAC Clarifications and Practical Guide Offline Installation in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282852#M106916</link>
    <description>&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;I'm glad you found the post useful!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regarding your question, I couldn't find any information about how to reduce or configure this interval in the relevant SKs. I believe sk175504 is the most relevant documentation on this topic, but it doesn't provide any information about changing this interval.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would suggest opening a TAC case to clarify this point. If you get an answer, could you please share it here with us? It would be great to add this information to the post as well.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2026 13:33:47 GMT</pubDate>
    <dc:creator>israelfds95</dc:creator>
    <dc:date>2026-09-25T13:33:47Z</dc:date>
    <item>
      <title>Check Point Live Patch (CPLP) – TAC Clarifications and Practical Guide Offline Installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282800#M106902</link>
      <description>&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;Recently, I have been working with &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Check Point Live Patch (CPLP)&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; as an alternative for quickly addressing critical CVEs while allowing more time to test and plan the deployment of newer Jumbo Hotfix Accumulator Takes.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The main CPLP documentation is available in &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;sk185114&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;While discussing CPLP with customers, several practical questions came up regarding AutoUpdater, future JH upgrades, dependencies, backup/restore, network connectivity, and how future CVE protections are delivered.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P data-pm-slice="1 1 []"&gt;&lt;STRONG&gt;&lt;FONT color="#008000"&gt;Since some of this additional information is not currently available in the official documentation, I opened a TAC case to clarify these questions and decided to share the additional information and clarifications provided by TAC here, to help all of us:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P data-pm-slice="1 1 []"&gt;&lt;FONT color="#339966"&gt;&lt;STRONG&gt;In this article, I also provide a practical step-by-step procedure for enabling CPLP on offline Security Gateways, where the automatic installation and update process cannot be used.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;1. Who is responsible for new CVE updates: AutoUpdater or CPLP?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;CPLP is managed through the AutoUpdater framework&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When a new CVE is identified and a Live Patch is developed, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;AutoUpdater is responsible for checking for available updates and making them available to the system&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;By default, AutoUpdater checks for updates approximately every &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;3 hours&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;CPLP is the component responsible for &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;applying the Live Patch fixes&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In short:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;AutoUpdater → Update availability → CPLP → Live Patch application&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;2. Do we need to manually install a new CPLP Take for every new CVE?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;Normally, no.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, future supported CVE patches are generally intended to be delivered automatically through the AutoUpdater mechanism.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Manual download and installation remain available as a fallback option when needed.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;3. How is CPLP distributed?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;TAC clarified that &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;CPLP is distributed as a single package&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This differs from solutions such as IPS or Anti-Virus/Anti-Bot, which receive updates as additional content packages.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;4. Which URL does CPLP use for downloads?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;This was an important question for customers with strict outbound access policies.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After checking with the responsible team, TAC confirmed that CPLP is currently downloaded from the same location used for Jumbo Hotfix packages through the Check Point Download Center.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The destination provided by TAC was:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;&lt;A href="https://dl3.checkpoint.com" target="_blank" rel="noopener"&gt;https://dl3.checkpoint.com&lt;/A&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, allowing access to this destination should be sufficient for CPLP downloads.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TAC also recommended testing this connectivity in a lab environment before implementing the change in production.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;5. Does AutoUpdater need to be manually restarted after &lt;CODE dir="ltr"&gt;autoupdatercli stop&lt;/CODE&gt;?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;no manual restart is required&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;AutoUpdater starts again after the manual installation process.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This question came up because the&amp;nbsp;sk185114 shows on step 7 of "&lt;STRONG id="Installation"&gt;Installation Procedure for Offline Package (Single Machine)&lt;/STRONG&gt;" -&amp;nbsp; "autoupdatercli stop"&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;while an equivalent &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;start&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; option was not available in the CLI help.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-25T102413.489.png" style="width: 886px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35398i425AB2C406C63FFF/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-25T102413.489.png" alt="imagem - 2026-09-25T102413.489.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;6. What is the CPLP update workflow?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;The detailed internal workflow is not publicly available, but was possible create a simple workflow with TAC informations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;At a high level, TAC confirmed that &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;AutoUpdater periodically checks for available updates&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, approximately every 3 hours, and handles update availability for CPLP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;CPLP then handles the application of the Live Patch fixes.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Imagem do ChatGPT 24 de set. de 2026, 19_01_38.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35375i1EC75A9F865383D5/image-size/large?v=v2&amp;amp;px=999" role="button" title="Imagem do ChatGPT 24 de set. de 2026, 19_01_38.png" alt="Imagem do ChatGPT 24 de set. de 2026, 19_01_38.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;7.&lt;/STRONG&gt;&lt;STRONG&gt;&lt;SPAN&gt;Understanding AutoUpdater Status and Connectivity Validation&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;During testing, we observed &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;autoupdatercli status&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; reporting:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;Downloading&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;even when the Gateway did not have connectivity to the update service.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;After manually installing the required CPLP Take, the status changed to:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;Ready&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;We asked TAC how AutoUpdater validates connectivity and whether there is a specific command or connectivity check available.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, the internal connectivity validation mechanisms, backend checks, and detailed communication workflow are &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;not publicly documented&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Therefore, the &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;Downloading&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; state by itself should not be considered documented proof that communication with the update infrastructure has been successfully established.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;8. What should we check if an expected CVE patch does not reach &lt;CODE dir="ltr"&gt;armed&lt;/CODE&gt;?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;TAC recommended initially checking:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;AutoUpdater is operating normally.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;The Gateway has connectivity to the required update services.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;CPLP is installed and functioning correctly.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Under normal conditions, AutoUpdater periodically checks for updates automatically, so a manual synchronization should generally not be required.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TAC also indicated that they were not aware of a documented command to manually force CPLP to download a &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;specific CVE patch&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; outside of the supported AutoUpdater workflow.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If an expected patch does not appear or fails to progress to &lt;/SPAN&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;armed&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;, the recommendation is to open a support case for investigation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;9.&lt;SPAN&gt;What happens to Live Patches when upgrading to a newer Jumbo Hotfix?&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, when upgrading to a newer Jumbo Hotfix Accumulator Take, Live Patch packages addressing vulnerabilities already fixed by the newer Take are typically &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;superseded as part of the upgrade process&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;10. Does CPLP create dependencies that could affect future JH upgrades?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, Live Patch packages are designed to be &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;self-contained&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;They should not create persistent dependencies that would prevent future Jumbo Hotfix installations.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This was particularly important for customers considering CPLP as temporary protection while remaining on an already validated JHA Take.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;FONT size="5"&gt;&lt;STRONG&gt;11. Can CPLP interfere with restoring an older System Backup?&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;We specifically asked about restoring a System Backup created &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;before&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; the Live Patch installation.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;According to TAC, restoring that backup returns the system to its previous state and the Live Patch will no longer be present.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;TAC also confirmed that there are &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;no known persistent dependencies&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; that should prevent a successful restore.&lt;/SPAN&gt;&lt;/P&gt;
&lt;H2&gt;&lt;STRONG&gt;&lt;FONT size="5"&gt;12. How can a specific Live Patch be reverted?&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/H2&gt;
&lt;P&gt;&lt;SPAN&gt;TAC provided the following supported procedure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;First, identify the patch ID:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;cplp list&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Then revert the specific patch:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE dir="ltr"&gt;&lt;SPAN&gt;cplp revert --patch-id &amp;lt;patch_id&amp;gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;SPAN&gt;Enabling CPLP in offline Security Gateways&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Bellow, I will share a practical scenario I encountered with &lt;/SPAN&gt;&lt;SPAN&gt;, where automatic CPLP deployment was not possible and the required components had to be installed manually.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The principal&amp;nbsp;sk185114 describe "&lt;STRONG id="Installation"&gt;Installation Procedure for Offline Package (Single Machine)&lt;/STRONG&gt;", the first step point to&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;Manually install the latest with&amp;nbsp;sk165653&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk165653" target="_blank" rel="noopener"&gt;AutoUpdater&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;H3&gt;&lt;STRONG&gt;Offline Installation&lt;/STRONG&gt;&lt;/H3&gt;
&lt;OL start="1"&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;Verify the currently installed &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;CPupdates&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; package:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;SPAN&gt;cpinfo -y CPupdates&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;Download the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;AutoUpdater&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; package &lt;/SPAN&gt;&lt;CODE&gt;&lt;SPAN&gt;Check_Point_Deployment_Installer_Bundle_T31_AutoUpdate.tar&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; from &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;sk165653&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;Install the AutoUpdater package using:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE&gt;&lt;SPAN&gt;autoupdatercli install&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T191432.747.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35376iABD04DE86F44F589/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T191432.747.png" alt="imagem - 2026-09-24T191432.747.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;4 - Download the &lt;STRONG&gt;Self Update&lt;/STRONG&gt; package &lt;CODE&gt;Check_Point_Self_Update_Bundle_linux50_T90_AutoUpdate.tar&lt;/CODE&gt; for your respective Gaia version.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T192242.661.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35377i40D3FA4E02EFECC9/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T192242.661.png" alt="imagem - 2026-09-24T192242.661.png" /&gt;&lt;/span&gt;5 - C&lt;/SPAN&gt;&lt;SPAN&gt;onfirm that &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;AutoUpdater Take 31&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; was successfully installed and verify that the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Self Update&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; package &lt;/SPAN&gt;&lt;CODE&gt;&lt;SPAN&gt;Check_Point_Self_Update_Bundle_linux50_T90_AutoUpdate.tar&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt; is not yet installed&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;6 - Install the downloaded &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Self Update&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; package &lt;/SPAN&gt;&lt;CODE&gt;&lt;SPAN&gt;Check_Point_Self_Update_Bundle_linux50_T90_AutoUpdate.tar&lt;/SPAN&gt;&lt;/CODE&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T192553.418.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35378i86751D13D1BDB2D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T192553.418.png" alt="imagem - 2026-09-24T192553.418.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorisraelfds95_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;7 - Execute autoupdatercli stop before next step as described&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T194332.627.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35384i0B52A2EB6074C226/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T194332.627.png" alt="imagem - 2026-09-24T194332.627.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;8 - &lt;SPAN&gt;Download the latest available &lt;/SPAN&gt;&lt;CODE&gt;&lt;STRONG&gt;&lt;SPAN&gt;BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/CODE&gt;&lt;STRONG&gt;&lt;SPAN&gt; Take&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; for your version from &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;sk185114&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This is the:&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;TABLE class="footnote" border="1" cellspacing="2" cellpadding="4" data-darkreader-inline-border-top="" data-darkreader-inline-border-right="" data-darkreader-inline-border-bottom="" data-darkreader-inline-border-left=""&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD&gt;Check Point Live Patch (CPLP)&lt;/TD&gt;
&lt;TD&gt;componet name - urgent_security_updates&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T192900.479.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35379i89B08CEDF3F258CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T192900.479.png" alt="imagem - 2026-09-24T192900.479.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;9 -&amp;nbsp;&lt;SPAN&gt;Install the downloaded &lt;/SPAN&gt;&lt;CODE&gt;&lt;STRONG&gt;&lt;SPAN&gt;BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/CODE&gt;&lt;STRONG&gt;&lt;SPAN&gt; Take&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T193008.670.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35400i82435A45C82C129E/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T193008.670.png" alt="imagem - 2026-09-24T193008.670.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;10 - &lt;SPAN&gt;Verify that all required &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;Takes&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; were successfully installed.&lt;/SPAN&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T193213.193.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35381iF0484BC5173EBE10/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T193213.193.png" alt="imagem - 2026-09-24T193213.193.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;11 -&amp;nbsp;&lt;SPAN&gt;Verify the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;CPLP patch status&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; and the &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;AutoUpdater state&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; using:&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem - 2026-09-24T193600.950.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/35383i6E47A54EC9493D3C/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem - 2026-09-24T193600.950.png" alt="imagem - 2026-09-24T193600.950.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 17:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282800#M106902</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-25T17:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Live Patch (CPLP) – TAC Clarifications and Practical Guide Offline Installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282813#M106905</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thank you for this brilliant and extremely valuable summary. You write:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;By default, AutoUpdater checks for updates approximately every &lt;STRONG&gt;3 hours&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Just wanted to mention that we experienced differences of about 12 hours with different machines at different customers fixing CVEs via CPLP. Can the&amp;nbsp;&lt;EM&gt;default&lt;/EM&gt; be overridden or is that something that is hardcoded? How can we assure a prompt fix?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 06:30:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282813#M106905</guid>
      <dc:creator>Oliver_Fink</dc:creator>
      <dc:date>2026-09-25T06:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Live Patch (CPLP) – TAC Clarifications and Practical Guide Offline Installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282835#M106911</link>
      <description>&lt;P&gt;As always, excellent content for the community, my friend.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 12:21:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282835#M106911</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-09-25T12:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Live Patch (CPLP) – TAC Clarifications and Practical Guide Offline Installation</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282852#M106916</link>
      <description>&lt;P data-pm-slice="1 1 []"&gt;&lt;SPAN&gt;I'm glad you found the post useful!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regarding your question, I couldn't find any information about how to reduce or configure this interval in the relevant SKs. I believe sk175504 is the most relevant documentation on this topic, but it doesn't provide any information about changing this interval.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would suggest opening a TAC case to clarify this point. If you get an answer, could you please share it here with us? It would be great to add this information to the post as well.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2026 13:33:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Check-Point-Live-Patch-CPLP-TAC-Clarifications-and-Practical/m-p/282852#M106916</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-09-25T13:33:47Z</dc:date>
    </item>
  </channel>
</rss>

