- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hello Team,
This might be a silly question but after installing HFA, we saw less traffic hitting the GWs.
We did a "Install Policy" then more traffic seems to be hitting our GWs.
Do we need to Install Policy after installing HFA?
Thank you very much.
The answer is “it depends.”
Generally installing a JHF on a gateway requires a reboot (usually not on management).
When you’re doing a version upgrade on the gateway (going from say R80.30 to R80.40), that most definitely requires a policy install afterwords.
If the JHF has content that impacts policy compilation (obviously on management), which changing gateway version does, then you may need to reinstall policy for the relevant changes to take effect.
However, I would expect the need for this to be documented in the JHF notes.
Were you installing the HFA on Security Management or Gateway?
Actually I would like the answer for both.
The answer is “it depends.”
Generally installing a JHF on a gateway requires a reboot (usually not on management).
When you’re doing a version upgrade on the gateway (going from say R80.30 to R80.40), that most definitely requires a policy install afterwords.
If the JHF has content that impacts policy compilation (obviously on management), which changing gateway version does, then you may need to reinstall policy for the relevant changes to take effect.
However, I would expect the need for this to be documented in the JHF notes.
hello @PhoneBoy
Does a backup restore requires a policy installation ? Last time when i restore the backup on Security Gateway it worked only after installing the policy.
Thank you
Again, it depends.
If management is on the same version as when you took the backup, it may not be required, but if management has changed version at all, it is required.
But I'm with @HristoGrigorov on this, it's a good idea to do a policy install afterwords just to make sure everything is working.
I always install policy as part of validation procedure that upgrade went well and things are working as they should.
Historically no, policy install on a JHF wasn't necessary...
However CP changed something in JHF 196+ that seems to require an policy install for GW connections to function post JHF install.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 24 | |
| 19 | |
| 10 | |
| 9 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY