- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
AI Security Masters
LGTM: Bypassing an LLM Build Gate
When Prompt Injection Fails
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
CheckMates Go:
Half is Not Enough
Hello.
We have deployed the Check point in Virtual Wan managed application in Azure. This has deployed 2 NVAs with version R2. There is no way to configure the SKU, just the scale set number. So no way to configure the disk size.
By default the partition layout provides 49gb and these are split between logs and root with 16gb unallocated. The logs partition is 10gb and 85% used.
So how do we install hot fixes or patch upgrades on a system with not enough space out of a the box?
Do we need to deploy new Managed application with side by side on a newer version and change routing intent to use it?
Microsoft have no access to the Managed Application. I have no access to see the NVAs in Azure so can't add disk space and boot into maintenance mode etc to increase the disk size.
A bit stuck. Please help.
Thanks in advance
Understood — so just to confirm, it was Microsoft who approved the deployment of the Check Point image as a Managed Application in vWAN, despite the small disk size and the fact that neither the customer, Check Point, nor Microsoft has the ability to modify it to increase the disk size?
@Shay_Levin can you please advise?
I believe you need to trigger a scale out, then it will automatically scale in a new firewall with the latest version.
I believe its not recommended to do jhf upgrades on scalesets like you do on physical appliances or other deployment types.
Hi,
Thanks for you reply.
So I have a few questions then please
1. How do we trigger a scale out, there doesn't seem to be a setting within Azure to perform this?
2. Even if we scale out how will the image be any different to what we have, we are already on R82
3. There is a reimage button in Azure Portal but I how do we know which image it will use, I presume it will be the same as what is already configured.
Our issue here is not so much the Major releases but the version upgrades. We can't operate our firewalls in BAU without performing these hotfixes on a regular basis and with the current image provided by the Azure Marketplace we are unable to do this.
Any further information how this is meant to work would be appreciated.
Hi,
You need to perform side by side upgrade:
Thanks Amir for your response.
I have read that link before and yes I understand that to roll out a major release we would need to do it side by side and change routing intent however does the same apply to Hot fixes?
We are currently on R82 so there is no need to upgrade the version but we need a Jumbo Hotfix to comply with our security team and there is no space in /var/log to do this.
These hotfixes come out every few months so how can we remain compliant on these patch versions?
At the moment this is due to limitations from Microsoft.
Once this will be solved we'll be working on it. I believe we'll have this in the future.
Hi Amir,
Sorry but how is it a Microsoft limitation? The issue is the Image which is too small, or am I missing something?
If the image was big enough out of the gate, we would have enough space to deploy hotfixes.
Thanks,
Hi @Cortez009 , I am checking with RnD on this.
thanks Jeff
Unlike other solution, this is managed by Azure. If this was solely by CP I would say that you can use SK for adding more storage.
Understood — so just to confirm, it was Microsoft who approved the deployment of the Check Point image as a Managed Application in vWAN, despite the small disk size and the fact that neither the customer, Check Point, nor Microsoft has the ability to modify it to increase the disk size?
Thu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEATue 06 Oct 2026 @ 02:00 PM (EDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY