- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hey folks. I've got a pair of Checkpoint 6k's running in a cluster, on R82. I'm repurposing these to replace an existing EOL cluster (5k's), and was wondering what the best way was to completely reset the config's on the 6k's, without having to factory reset them. The issue is that they came with R81.10, and I'd rather not have to go through the upgrade process again. Is there an easy way to accomplish this?
To be sure you're aware, you can always wipe the box and install a new "factory default" image using a tool called ISOmorphic (sk66205). Check Point's branded boxes are pretty ordinary amd64 servers, just with weird PCIe slots. This tool takes a Check Point installation ISO image and builds a thumb drive. When you boot from the drive, it wipes the server's internal storage, sets up a new md(4) mirror (if you have two drives), sets up a new lvm(8) volume group on it, adds the "factory default" logical volume, copies the contents of the ISO image you provide to it, then reverts to that volume.
Then in the future, if you "restore to factory defaults", it will go back to R82 (for example) instead of whatever it actually shipped with.
This is the surest way to remove all existing configuration from a system you plan to repurpose.
Maybe below, though have not done it in ages...
rm -rf /config/active
reboot
Have you tested that?
Not in a long time.
Via the CPUse agent download the R82 and there you can pick 2 options, clean install and upgrade. Use the clean install option (check under major version).
So I've already got R82 take 44 installed, and there doesn't seem to be an option to do anything in CPUSE. This new version of CPUSE is garbage though, wish we had the option of going back to the old one.
Shoud be there, just checked my lab R82 take 44. It is under major versions in cpuse
Edit, i see you have no access to CP cloud that could explain it. I think via cpuse is a quick way. ISO can be a struggle and you have to be onsite.
Using the firewall Web UI, you can perform the installation via CPUSE. If the devices have Internet connectivity, they can download the required packages directly from there.
If they do not have Internet access, you will need to:
Download the R82 image/package,
Upload it to the firewall, and
Download and upload the Deployment Agent package as well.
That said, I would recommend choosing the Clean Install option. This will remove all existing firewall configuration, and you can also install the latest recommended Jumbo Hotfix during the same maintenance window. This approach helps avoid version-related bugs, improves stability, and saves you from having to schedule an additional maintenance window later.
So I've already got R82 take 44 installed, and there doesn't seem to be an option to do anything in CPUSE. This new version of CPUSE is garbage though, wish we had the option of going back to the old one.
Isomorphic
To be sure you're aware, you can always wipe the box and install a new "factory default" image using a tool called ISOmorphic (sk66205). Check Point's branded boxes are pretty ordinary amd64 servers, just with weird PCIe slots. This tool takes a Check Point installation ISO image and builds a thumb drive. When you boot from the drive, it wipes the server's internal storage, sets up a new md(4) mirror (if you have two drives), sets up a new lvm(8) volume group on it, adds the "factory default" logical volume, copies the contents of the ISO image you provide to it, then reverts to that volume.
Then in the future, if you "restore to factory defaults", it will go back to R82 (for example) instead of whatever it actually shipped with.
This is the surest way to remove all existing configuration from a system you plan to repurpose.
Excellent point, Bob. I always keep forgetting about the isomorphic tool, but definitely worth considering here.
In addition to what others already said, make sure you reset also LOM settings, if available and used. LOM settings are independent from OS and will stay configured even after you do FCD.
Thx for all the advice folks. Since I was on prem and in a bit of a hurry, I just ended up factory resetting all 3 boxes back to R81.10, and doing a clean install/upgrade from there.
Glad you got it working!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 63 | |
| 19 | |
| 13 | |
| 12 | |
| 12 | |
| 9 | |
| 8 | |
| 7 | |
| 7 | |
| 7 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY