- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi all,
This is a very good development by Check Point. Keep up the good work!
sk185114 - Check Point Live Patch (CPLP)
Does anyone know if environments not connected to the internet but using a Private Threat Cloud appliance can benefit from this feature?
Regards,
Martijn
Well ... very interesting.
Hi Martijn
Have asked the question internally at a minimum so that the limitations can be updated...
Cheers.
My guess is it that the current PTC offering doesn't include this.
Hi,
I have a TAC case open for the PTC question and it is a internal discussion at the moment.
I have checked the customer's environment and CPLP does not seems to be enabled on the gateway's using the PTC. The command #cplp is not recognized.
Checking the software repository on the PTC, the 'BUNDLE_URGENT_SECURITY_UPDATE_R8X' is not found on the hard disk of the PTC.
So it looks CPLP is not supported when using a PTC appliance. Let's see what the official statement will be.
Keep you posted.
Martijn
FWIW, I've run the cplp commands listed in the sk on my internet connected gateways and management, and in both cases it returns "cplp: command not found". I do have this listed in cpinfo output:
"BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE Take: 17"
Anyone successfully run the cplp commands?
Dave
Hi David,
I have the same in an environment where the gateways get their updates via a PTC appliance.
The BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE is installed, but I also cannot run the cplp commands.
Did you manage to get this solved?
Martijn
Unrelated to the PTC discussion, there is a cosmetic issue in which the cplp command may not appear in the shell $PATH, resulting in situations where the urgent security bundle is successfully installed, but the cplp command is not visible when invoked directly. An upcoming bundle update will address this element.
The currently deployed packages are R81.20 Take 18 / R82 Take 17 / and R82.10 Take 18. These bundles contain a known issue in which the CPLP command-line utility may not appear in the shell PATH ("cplp: Command not found." issue), due to another Gaia issue where "/usr/local/bin" is missing from PATH environment variable.
This is a cosmetic issue only and does not affect the patching process or the operation of applied patches, running cplp through its full path works: /usr/local/bin/cplp
Upgrading to the latest bundles: R81.20 Take 19 / R82 Take 18 / R82.10 Take 19, resolves this issue without impacting any patches currently installed in the environment.
cc: @Martijn
Hi all,
I got the following answer from the TAC engineer:
"According to the information shared and discussed with the relevant teams, the deployment method should be transparent to the PTC. Gateways located behind the PTC are expected to receive the Urgent Security Bundle, which includes both the required live patches and the corresponding CPLP updates."
I will keep monitoring the customer's environment to see if this is the case.
Martijn
CPLP has been incredibly well received by our customers. We checked a bunch here in our small European market and between circa 15:00 and midnight they all got the live patch. It's the kind of security-minded approach which really resonated with customers who needs to go through hoops to get updates or simply operate in high-intensity operations.
Times are challenging and teams are certainly under a lot of pressure, so this is a thoughtful development which really helps us integrators to keep up and reassure our customers.
Hello,
I have monitored the customer's system the last couple of weeks and CPLP doesn't work when not connected to the internet and a PTC appliance is installed. TAC is investigating internally to verify my findings.
In a webinar I attended this week, we where told a manual installation will be available soon. Let's hope this is the case.
Martijn
Manual installation is actually a lot easier than I expected. You just copy the 'urgent_security_updates_R82_Bundle_T24_AutoUpdate.tar' file to the firewall or management, and run
autoupdatercli install /full/path/here/urgent_security_updates_R82_Bundle_T24_AutoUpdate.tar
I'm not yet 100% sure whether this is safe on aarch64 (3900 series). Those boxes typically have a separate package for updates, and I don't see one here.
If you expand the tar and its contents, you eventually get to a scripts/cplp directory which contains an RPM for CPLP itself and one for each process it's meant to patch.
Here's what it says on ARM.
no arm patch for ike (module=vpn1, branch=R82_10_jumbo_hf_main, build=999000012) under /opt/cplp/patches: prefix 'libvpn1_R82_10_jumbo_hf_main' matched 1 arm build file(s). Below-earliest fallback (GA branch jess_main) not taken: build is newer than every jumbo patch, or no jumbo patch exists to anchor a range. Either the build is outside the range the patches cover, no matching file is installed, or no arm variant exists (patches are x86 by default; ARM needs an '_arm' .so).
I applied the offline Take 24 CPLP to our 3920s without issue.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 7 | |
| 7 | |
| 6 | |
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Tue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall Architectures - AWS, Azure & GCPThu 17 Sep 2026 @ 05:00 PM (CEST)
Under the Hood: Unified Hybrid Mesh Management across AWS Firewalls, SASE and SD-WANThu 17 Sep 2026 @ 03:00 PM (EDT)
Americas Deep Dive: Troubleshooting 101 for Check Point FirewallsTue 15 Sep 2026 @ 12:00 PM (MDT)
Lone Tree, CO: Workspace Security and Exposure ManagementWed 23 Sep 2026 @ 06:00 PM (EDT)
Santo Domingo: Workspace Security and SASE Live: Protección Total del Usuario Email, Endpoint y SASEAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY