- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello.
We have deployed the Check point in Virtual Wan managed application in Azure. This has deployed 2 NVAs with version R2. There is no way to configure the SKU, just the scale set number. So no way to configure the disk size.
By default the partition layout provides 49gb and these are split between logs and root with 16gb unallocated. The logs partition is 10gb and 85% used.
So how do we install hot fixes or patch upgrades on a system with not enough space out of a the box?
Do we need to deploy new Managed application with side by side on a newer version and change routing intent to use it?
Microsoft have no access to the Managed Application. I have no access to see the NVAs in Azure so can't add disk space and boot into maintenance mode etc to increase the disk size.
A bit stuck. Please help.
Thanks in advance
Understood — so just to confirm, it was Microsoft who approved the deployment of the Check Point image as a Managed Application in vWAN, despite the small disk size and the fact that neither the customer, Check Point, nor Microsoft has the ability to modify it to increase the disk size?
@Shay_Levin can you please advise?
I believe you need to trigger a scale out, then it will automatically scale in a new firewall with the latest version.
I believe its not recommended to do jhf upgrades on scalesets like you do on physical appliances or other deployment types.
Hi,
Thanks for you reply.
So I have a few questions then please
1. How do we trigger a scale out, there doesn't seem to be a setting within Azure to perform this?
2. Even if we scale out how will the image be any different to what we have, we are already on R82
3. There is a reimage button in Azure Portal but I how do we know which image it will use, I presume it will be the same as what is already configured.
Our issue here is not so much the Major releases but the version upgrades. We can't operate our firewalls in BAU without performing these hotfixes on a regular basis and with the current image provided by the Azure Marketplace we are unable to do this.
Any further information how this is meant to work would be appreciated.
Hi,
You need to perform side by side upgrade:
Thanks Amir for your response.
I have read that link before and yes I understand that to roll out a major release we would need to do it side by side and change routing intent however does the same apply to Hot fixes?
We are currently on R82 so there is no need to upgrade the version but we need a Jumbo Hotfix to comply with our security team and there is no space in /var/log to do this.
These hotfixes come out every few months so how can we remain compliant on these patch versions?
At the moment this is due to limitations from Microsoft.
Once this will be solved we'll be working on it. I believe we'll have this in the future.
Hi Amir,
Sorry but how is it a Microsoft limitation? The issue is the Image which is too small, or am I missing something?
If the image was big enough out of the gate, we would have enough space to deploy hotfixes.
Thanks,
Hi @Cortez009 , I am checking with RnD on this.
thanks Jeff
Unlike other solution, this is managed by Azure. If this was solely by CP I would say that you can use SK for adding more storage.
Understood — so just to confirm, it was Microsoft who approved the deployment of the Check Point image as a Managed Application in vWAN, despite the small disk size and the fact that neither the customer, Check Point, nor Microsoft has the ability to modify it to increase the disk size?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 7 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY