<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One or two thoughts on Live Patching in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282242#M47012</link>
    <description>&lt;DIV&gt;I agree with the concern that there should be some form of notification or alert before a live patch is applied. This would provide administrators with greater visibility into patching activities, help with change tracking, and allow teams to assess any potential impact in advance. Such a notification mechanism would improve operational awareness and make the live patching process more transparent.&lt;/DIV&gt;</description>
    <pubDate>Fri, 11 Sep 2026 13:03:56 GMT</pubDate>
    <dc:creator>Gaurav_Pandya</dc:creator>
    <dc:date>2026-09-11T13:03:56Z</dc:date>
    <item>
      <title>One or two thoughts on Live Patching</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282216#M46999</link>
      <description>&lt;P&gt;Good morning,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;great to have CPLP there and running! Saves lots of people on doing panic-update sessions on several customers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One or two thoughts i have on this:&lt;/P&gt;&lt;P&gt;- the option to enable this (enabled by default) is a bit hidden or not naming it by its name&lt;/P&gt;&lt;P&gt;&amp;nbsp; - please give it a more prominent place, as that is a very good and important feature; you should promote it like that (i.e. as Option at the General Properties of devices)&lt;/P&gt;&lt;P&gt;- given that this is a Global Property&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - would it be possible to en-/disable CPLP by machine&amp;nbsp;&amp;nbsp;(i.e. as Option at the General Properties of devices)&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; - some might have issues with having software (or parts) installed automatically or might want to stage or manually approve the application of automated software changes, because of processes&lt;/P&gt;&lt;P&gt;&amp;nbsp;- I am not sure on that, but looking at regulated customers,&amp;nbsp; externally changing software can be an issue or at least something that has to be specifically looked at, defined, approved and documented.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Perhaps setting the whole CPLP thin to devices General Properties and let the admin decide, if this is fully automated or downloaded and applied after an approval would be good. But thats only my opinion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Again, great that CPLP is there and thanks for that!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 07:13:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282216#M46999</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2026-09-11T07:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: One or two thoughts on Live Patching</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282217#M47000</link>
      <description>&lt;P&gt;We are too really happy with Check Points Live Patch feature. Saved us a lot of time regarding the last new CVEs. All of our gateways are patched live without any interaction and without problems (ClusterXL, single gateways, Maestro, VSX). Isolated environments or gateways with more restriction have to be patched manually.&lt;/P&gt;
&lt;P&gt;!!! GREAT FEATURE&amp;nbsp; !!!&lt;/P&gt;
&lt;P&gt;I recommend&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1663"&gt;@Nüüül&lt;/a&gt;&amp;nbsp;thoughts.&lt;/P&gt;
&lt;P&gt;- enabling/disabling by gateway&lt;/P&gt;
&lt;P&gt;- information in SmartConsole that something changed automatically (like the security issues or maybe as installed patch). patch is installed but we have to dig through Audit-Logs to see this&lt;/P&gt;
&lt;P&gt;- possibility for an installation with approval only&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 07:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282217#M47000</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2026-09-11T07:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: One or two thoughts on Live Patching</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282233#M47007</link>
      <description>&lt;P&gt;CPLP reports ro SC in the Audit Logs.&lt;/P&gt;
&lt;P&gt;Edit: Thats what you wrote. We export the logs and use filtering for events.&lt;/P&gt;
&lt;P&gt;Maybe Playblocks can help there.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 09:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282233#M47007</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2026-09-11T09:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: One or two thoughts on Live Patching</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282238#M47010</link>
      <description>&lt;P&gt;We found that live update was not in place on all of our firewalls unfortunately, and so the protection was only applied to about half the firewalls, despite them all being on the same version.&lt;/P&gt;&lt;P&gt;We see now on our perimeter that the download and install parameters for auto update were set to false for some reason:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;nbsp;autoupdatercli show auto_updater&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;product-name: deployment_products&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;component-name: auto_updater&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;component-branch: Infra_AutoUpdate&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;GA-Version: 0&lt;/EM&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;download-scheduler-active: false&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;install-scheduler-active: false&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;download-action: idle&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I think a feature to alert us that live update was not enabled so that we could have sorted this on the gateways, ensuring that they are ready for these situations would have been helpful.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 10:25:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282238#M47010</guid>
      <dc:creator>Parabol</dc:creator>
      <dc:date>2026-09-11T10:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: One or two thoughts on Live Patching</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282242#M47012</link>
      <description>&lt;DIV&gt;I agree with the concern that there should be some form of notification or alert before a live patch is applied. This would provide administrators with greater visibility into patching activities, help with change tracking, and allow teams to assess any potential impact in advance. Such a notification mechanism would improve operational awareness and make the live patching process more transparent.&lt;/DIV&gt;</description>
      <pubDate>Fri, 11 Sep 2026 13:03:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282242#M47012</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2026-09-11T13:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: One or two thoughts on Live Patching</title>
      <link>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282245#M47014</link>
      <description>&lt;P&gt;I found a silly issue with cplp.&lt;/P&gt;
&lt;P&gt;We login with TACACAS accounts and get to clish mode. We then escalate with the `expert`command to get a bash prompt. But that way the splp command isn't working as expected.&amp;nbsp; because in that case it's not the PATH variable. A directlogin with a user with bash shell allows it to work.&lt;/P&gt;
&lt;P&gt;Alternative in expert mode yu can run `/usr/local/bin/cplp`and that takes care of things as well.&lt;/P&gt;
&lt;P&gt;Not a big issue but rather silly if a less experience collegue volunteers to validate CPLP status on a number of machines and fails.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Sep 2026 13:11:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/One-or-two-thoughts-on-Live-Patching/m-p/282245#M47014</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2026-09-11T13:11:04Z</dc:date>
    </item>
  </channel>
</rss>

