- Products
- Learn
- Local User Groups
- Partners
- More
The Great Exposure Reset
24 February 2026 @ 5pm CET / 11am EST
AI Security Masters E4:
Introducing Cyata - Securing the Agenic AI Era
AI Security Masters E3:
AI-Generated Malware
CheckMates Go:
CheckMates Fest
Hi everyone,
We’re seeing an unexpected and concerning behavior with Generic Data Center Objects (GDCO) in SmartConsole. In short: when the GDCO JSON file is updated, SmartConsole does not reflect those changes, even though enforcement on gateways works perfectly.
For firewall admins and operations teams, visibility is critical. SmartConsole becomes an unreliable source of truth — admins cannot see which IPs are actually part of a GDCO, nor which ones were added or removed. This creates a real risk of human error when managing policy.
Using CloudGuard, Check Point correctly detects GDCO JSON changes and applies them to all gateways within the configured 60-second update window — no Publish or Install required (as expected). We also receive clear syslogs showing exactly which IPs changed. These logs are also visible in SmartConsole (blade:"CloudGuard").
This part is fantastic!!!!
Despite successful detection, logging, and enforcement:
So an admin opening the GDCO object in SmartConsole only sees the originally imported GDCO IPs — even when they’re no longer in policy. This is dangerous and misleading, as SmartConsole offers no visual way (other than logs) to validate the current GDCO state.
To reiterate, even with fixes claimed in R81.20 JH Take 115, (we applied this and the latest JH, as noted above) SmartConsole still does not reflect GDCO updates.
Thanks SO MUCH in advance for any help, guidance, or insight on this — it’s a critical visibility issue for day-to-day firewall operations!!! 🙏
.
We are aware of this issue and are working on delivering a hotfix as soon as possible. I’ll update this thread once the hotfix is available.
Eli
Check Point R&D
Hey PJ,
First, welcome to the community!
Excellent explanation, appreciated. Let me do some testing with this in my R82 lab and see the results. I will update you Saturday.
Did some tests this morning...maybe someone else can confirm this, but I cant seem to find anywhere where it shows date when specific updatable object was update, though in smart console, they all show its dynamically updated, so maybe thats why. Let me see if there might be a file that would show that information.
Just did some more testing...I see what you are saying, I have exact same issue.
We are aware of this issue and are working on delivering a hotfix as soon as possible. I’ll update this thread once the hotfix is available.
Eli
Check Point R&D
Thanks Eli!
Hi @Eliba thank you very much for this news. Also thanks @the_rock for validating the issue on your side.
Curious if there is a rough timeframe when this hotfix might be expected.
Also wondering why this thread was marked as "Resolved" when in-fact a patch is still being worked. Thanks again for your consideration.
pj
Hey PJ,
Usually people would mark an answer as solution in case like this where fix will be developed to correct the problem.
Solution refers to a (mostly) definitive answer to the original poster's question(s).
While this often is a workable solution, it also can refer to "not supported" and "known issue" type of answers.
Also note "Solutions" can be marked by anyone on the community, including the person who posted the post.
Admins will sometimes adjust these marks.
Hi @Eliba hope all is well, just circling back to ask if there might be an SK number or Ticket number we can reference - not just to try to escalate via our rep, but also to provide our management some confidence that this is being addressed. If you happen to have any idea on a rough timeline for the release of a potential hotfix I'd also appreciate that. Thanks so much!
Hi @Paul_SecDevOps, please follow ticket TM-91614.
Eli
Check Point R&D
Hey Eli,
Is that info available publicly?
That looks like a CFG task opened through TAC.
They're internal.
Makes sense.
Hi Eli, hope you're well. Any idea by when TM-91614 might be addressed in a HF or other update? Thanks as always.
pj
Hey PJ,
I tested this in R82.10 and worked well, so must be fixed in newest version.
Hi Andy! Would you mind sharing what full version you're testing, CP version and SmartConsole version if you dont mind. I'd like to test on the same if possible, Thanks and happy Sunday!!! 🙂
Happy Sunday 🙂
Here you go:
https://support.checkpoint.com/results/download/135254
https://support.checkpoint.com/results/download/140673
Hi Andy, sorry but those versions are not the ones being reported w/ the issue. We're running R81.20 and R82 firewalls, not R82.10 which is what your link/versions are pointing to. My original problem report is specifically for the two versions mentioned, not R82.10. Looking for a fix for R81.20 and R82 which does not yet look available - LMK if im misunderstanding, however. Thanks!!
pj
I know exactly versions you mentioned : - )
What I said was that it worked for me in R82.10, thats all. In your case, maybe keep checking when fix will be ready.
Got it. Thanks and that's good to know! However too many firewalls on R81.20 and R82 showing this critical issue - and none of those will be upgraded anytime soon. Thanks for the useful observation/possible workaround, however!!!!! All the best!!! 🙂
Totally understood. I get the situation and no arguments there. I know R82.10 is brand new, so would be very difficult to get approvals to upgrade to that version, it may take some time until its officially recommended code.
Anywho, I hope fix for R82 and below will be ready soon.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 3 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 24 Feb 2026 @ 10:00 AM (CET)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - EMEATue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANTue 24 Feb 2026 @ 10:00 AM (CET)
Latest updates on Quantum Spark including R82 features and Spark Management zero touch - EMEATue 24 Feb 2026 @ 11:00 AM (EST)
Under The Hood: CloudGuard Network Security for Azure Virtual WANThu 26 Feb 2026 @ 05:00 PM (CET)
AI Security Masters Session 4: Introducing Cyata, Securing the Agentic AI EraTue 03 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Introduction to Maestro Hyperscale FirewallsFri 06 Mar 2026 @ 08:00 AM (COT)
Check Point R82 Hands‑On Bootcamp – Comunidad DOJO PanamáAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY