Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 

R82.20 Public EA Program

Naor_Nassi
Employee
Employee
4 13 3,384

Release notes banner_R82.20 Release_1059x177.png

Check Point's R82.20 release brings AI-era protection to on-prem and cloud firewalls, adding market-unique LLM and public AI tool security enforced directly at the firewall. Advancing unified Hybrid Mesh security, organizations can now centrally manage policy for Check Point SASE, AWS cloud-native firewalls, on-prem Firewalls, and their networks (via SD-WAN) - all from one console.

For existing customers, R82.20 also delivers major simplification improvements that reduce operational effort across upgrades, advanced configuration, remote-access VPN management, and SIEM log handling. The release adds FedRAMP-authorized threat prevention, IPv6 support, and multiple efficiency improvements.

 

Enrollment | Public EA Check Point Public EA is designed for lab and sandbox deployments only.

 

Click here to participate in the R82.20 Public EA program (SK184894)

MPORTANT NOTES: 

  • Check Point Public EA is designed for lab and sandbox deployments only.
  • Public EA version upgrade to GA is not supported

 

For more EA program you can visit our new SK here: Check Point Early Availability (EA) Programs - [sk183058]

This page provides comprehensive information about Check Point ‘Ongoing’ and ‘Upcoming’ EA programs, as well as the onboarding and support process.

 

New in this release

Bring your Firewall into the AI Era

  • Safe AI Adoption: Safely adopt generative AI tools, such as ChatGPT, Gemini, and Claude, with AI Workforce Security enforced by Check Point Firewalls and Cloud Firewalls. Automatically inspect user prompts and files uploaded to generative AI services, providing full visibility into and an audit trail of GenAI activity across your environment. Granular policies prevent data leakage, reduce risk, and ensure compliant use of AI.
  • Protect Enterprise LLM Applications: Organizations can now secure their proprietary enterprise AI applications with AI-native runtime protection against prompt injections, data exfiltration, adversarial queries, and API abuse - all directly from Check Point Firewalls, leveraging advanced AI-based detection to protect AI workloads using Check Point's AI Agent Security (previously Lakera AI).

Unify Hybrid Mesh Management

Unified management of on-prem gateways, SASE, AWS firewalls, and SD-WAN from SmartConsole, with one-click secure connectivity across your hybrid infrastructure.

  • Manage cloud-native AWS firewalls from SmartConsole: Simplify AWS firewall operations with centralized management of AWS Network Firewall. Security teams can define and enforce policies, monitor activity, and maintain compliance across cloud and on-prem environments from a single console, reducing complexity, minimizing misconfigurations, and accelerating day-to-day operations.
  • Manage SASE Internet Access Policy from SmartConsole: Single console for policy management across hybrid on-prem and SASE infrastructure. Easily set up a VPN connection between your firewall and Check Point SASE with one click.
  • Manage Your Network from SmartConsole: SD-WAN configuration, including steering policies, is now fully merged into SmartConsole. Manage internet and network connectivity alongside your firewalls. No console switching needed. New support for on-prem management now also enables network management for sensitive air-gapped environments. Multiple SD-WAN enhancements include ECMP dynamic routing, application-based QoS with bandwidth guarantees, and more.
  • New Open Garden Integrations:
    • New integrations with Nozomi Networks and Claroty enable OT/ICS device discovery, policy configuration, and enforcement at the firewall.
    • Threat Prevention Insights: Exposure Management recommendations and the ability to refine IPS protections using a false-positive engine.
  • FedRAMP-Authorized Mode:
    • New FedRAMP mode for Check Point Firewalls directs cloud-dependent security blades to use FedRAMP-hosted and authorized services.
    • IPsec tunnel setup with out-of-the-box best practices for full-mesh and hub-and-spoke topologies.

Simplify Operations

  • Background Management Upgrade: The “Prepare Upgrade” phase runs in the background while admins continue to make policy changes in SmartConsole or API. Downtime is reduced from hours to just a few minutes.
  • Higher Performance for Virtualized Environments: Improved throughput and reduced latency for VSX, GRE, and IPsec traffic with hardware acceleration on high-speed network cards.
  • Smarter Cluster Failover: Improved service continuity with automatic detection of gateway health issues, such as resource pressure or congestion, and proactive failover to a healthy cluster member.
  • Advanced Configuration Settings from Gaia Portal: Thousands of advanced settings moved from Expert mode to Gaia Portal, Clish, and the REST API. Settings are persistent across reboots and upgrades, with a full audit trail.
  • Remote Access VPN Community: A new community object enables differentiated access policies per user group, streamlined encryption settings, and intuitive management for large organizations.
  • Persistent .def Settings: .def file settings can now be configured through Web SmartConsole or the Management API instead of editing files in Expert mode. Settings persist across upgrades.
  • Sending logs to SIEM: Reduce SIEM costs and load by exporting only the first and last update per log. Improved log export throughput by scaling Log Exporter across multiple instances and leveraging multiple CPU cores. Configure log export via API and integrate directly with AWS S3.

AI Security

  • Workforce AI Security empowers organizations to safely adopt generative AI tools while protecting sensitive data and ensuring compliance. By inspecting prompts and files uploaded to AI applications, it provides full visibility into how AI is used across your environment. Granular policies help prevent data leakage, reduce risk, and promote responsible, compliant use of AI, so every user in the network can work confidently with AI tools without compromising security.
  • Introducing new Prompt Injection protection for Large Language Model (LLM) servers. Security Gateways can now detect and block prompt injection attacks targeting LLM applications, leveraging advanced AI-based detection to protect AI workloads running in your environment.

Threat Prevention

Threat Prevention Blades

  • SNORT 3.x rules syntax is now supported in IoC Feeds. This increases coverage of supported SNORT rules and enables compatibility with the latest threat detection content.
  • DNS Trap now supports IPv6 connections, enabling DNS-based threat prevention capabilities in IPv6 environments.

HTTPS Inspection

  • New TLS Inspection Block page – When HTTPS Inspection blocks a TLS connection because of server certificate issues (revoked, expired, or untrusted), a notification page explaining the reason for the block is now displayed.

Security Gateway

Identity Awareness

  • Security Gateways now support Cisco SGT (TrustSec) tagged traffic for pass-through and identity enforcement. Access Role objects can now match a specific Cisco SGT for access control directly from the network traffic.

Security Gateway Enhancements

  • Introducing the FedRAMP mode for Security Gateways. This new mode directs cloud-dependent services to use FedRAMP-hosted and authorized endpoints. The supported services are: URL Filtering, Application Control, Anti-Bot, Anti-Virus, Zero Phishing, and Threat Emulation.

    Note: Threat Extraction and IPS do not rely on cloud services and are, therefore, compliant by default.

  • Gaia Portal now allows Security Gateways to automatically establish Secure Internal Communication (SIC) to initiate a connection to the Management Servers (both on-premises and Smart-1 Cloud deployments) and fetch a predefined Security Policy. See sk184397.
  • Security Gateways can now have more than one interface with a Dynamically Assigned IP Address (DAIP).

Security Gateway Operations

  • Maestro, ElasticXL, and ClusterXL clustering health status have been refined to include critical states such as high memory, low disk space, or packet drops because of congestion. This triggers an alert that is visible in SmartConsole, CPView, and AIOps.
  • Added support for new IoT tags and enforced IoT asset attributes originating from third-party vendors.

Gaia OS

  • Gaia OS introduces Unified Configuration, expanding and streamlining advanced configuration management across the platform and related products, and deprecating the use of Expert mode. Advanced system and feature configurations, including kernel parameters and cross-feature settings, are now managed using the Gaia Portal, Gaia Clish, or the Gaia RESTful API, providing consistent access.

    A new Advanced Configuration page in Gaia Portal delivers a simplified, efficient experience for managing commonly used settings across multiple features. All configuration changes are processed through a unified API framework, ensuring configuration persistence across reboots and upgrades, with full auditability and traceability.

  • Check Point Firewall Appliances 3900 now include integrated switching capabilities. LAN ports can be segmented for switching groups, improving performance for traffic within the same segment while maintaining full firewall inspection for traffic across segments or to external networks.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Dynamic Routing

OSPFv3 enhancement:

  • OSPFv3 authentication using ESP, providing secure routing exchanges and protection against unauthorized route injection.

BGP enhancements:

  • BGP support over multiple Virtual Tunnel Interfaces (VTIs) with the same local address, enabling flexible routing across multiple tunnels.
  • AS-path prepend on import, allowing control of inbound traffic by influencing path selection.
  • BGP peer groups with auto-discovery, simplifying configuration for large-scale BGP deployments.

General routing enhancements:

  • Wildcard mask support for more flexible route matching and filtering.
  • IGMP and MLD blocked groups, preventing joins to restricted multicast groups and improving multicast security.
  • Route-map configuration via WebUI, improving usability and simplifying the configuration of the routemaps feature.
  • Monitoring of NAT Pools.
  • Monitoring of IPv4 static multicast routes (static mroutes).

Cluster and Scalability

  • ElasticXL synchronization traffic is now encrypted using Layer 2 encryption (MACsec). This protects all traffic between ElasticXL Cluster Members.
  • In VSNext mode, each Virtual Gateway now has an independent clustering state. A “Down” cluster state on a specific Virtual Gateway does not affect the entire cluster member state, so other Virtual Gateways on the affected member remain “Active” on that cluster member and does not failover.

VPN

  • Remote Access VPN now offers enhanced policy management through the new Remote Access VPN Community. This enables differentiated access policies for various user groups, streamlined configuration, and a more intuitive management experience for large and complex organizations.
  • Carrier Grade NAT (CGNAT) with auto-discovery VPN now enables direct VPN tunnels between gateways behind CGNAT, using broker-assisted discovery to create tunnels with dynamic IP addresses.
  • Introducing SmartConsole single-click IPsec tunnel setup between Security Gateway and Check Point SASE. Providing best practices for both full mesh and hub-and-spoke (star) topologies and supporting policy-based and route-based modes.

SD-WAN

  • Dynamic Routing with Equal-Cost Multi-Path (ECMP) is now supported. It allows SD-WAN to use the best path to a destination out of multiple routes with the same metric.
  • Backhaul Data Center failover for local breakout link degradation - SD-WAN can fail over to a Data Center backhaul connection upon ISP links quality degradation, and not only when the ISP links are completely unavailable.
  • Layer 2 Overlay Support - Overlay networks can now operate without requiring a next-hop configuration, enabling direct peer-to-peer VPN connections between gateways on the same local network, such as in VPLS deployments.
  • Simplified Carrier Grade NAT (CGNAT) Configuration - CGNAT no longer requires Dynamic IP object configuration when a Management Server can reach a Security Gateway directly, enabling ClusterXL support and simplified Smart-1 Cloud deployments.
  • IPv6 Local Breakout - SD-WAN can now intelligently route IPv6 traffic to the local internet breakout. IPv6 traffic through VPN overlay continues to use standard routing.
  • Link Quality Threshold now includes bandwidth. Configuring bandwidth requirements per application is now optional to ensure SD-WAN selects interfaces that meet traffic capacity needs. Set minimum bandwidth threshold alongside latency, jitter, and packet loss requirements for interface selection.
  • Symmetric Return for Gateway Traffic - Gateway-destined traffic, such as SSH sessions and policy installations, now returns through the same interface it arrived on, ensuring compatibility with ISP policies that restrict traffic with external IP addresses.
  • Application-Based Quality of Service - Define bandwidth guarantees and limits per application in SD-WAN policies. Prioritize critical applications with minimum bandwidth reservations while capping less important traffic, with automatic traffic shaping across both overlay and local breakout paths.

IPv6 Enhancements

Security Gateway

  • Suspicious Activity Monitoring (SAM) has been redesigned and integrated with the Gaia API, enabling dynamic, API-driven configuration similar to Dynamic Policy Layers. This enhancement includes full IPv6 support alongside the existing SAM commands.
  • You can now configure the Security Gateway management interface for IPv4-only, dual-stack (both IPv4 and IPv6), or IPv6-only operation during the Gaia OS installation or in the Gaia First Time Configuration Wizard, supporting single-stack IPv6 deployments from initial setup.
  • Added support for IPv6 Dead Peer Detection (DPD)-based Tunnel Monitoring for Permanent Tunnels and IPv6 DPD-based Multiple Entry Point (MEP) topology. These enhancements enable reliable VPN resilience and liveness checks over IPv6, including mixed IPv4/IPv6 tunnels in redundant and multi-entry point deployments.
  • IPv6 support for identity enforcement in Identity Awareness using Identity Agent was extended to include multiple address types, including link-local, Global Unicast Address (GUA), and Unique Local Address (ULA). It also fully supports Privacy Extension (RFC 8981), ensuring consistent identity-based policies even as IPv6 addresses change dynamically.
  • Added support for Route-based VPN over IPv6. This enables dynamic routing protocols and VTI-based VPN tunnels in IPv6 environments for improved flexibility and compatibility.

Dynamic Routing

  • Equal-Cost Multi-Path (ECMP) for static and dynamic routing protocols.
  • Policy-Based Routing (PBR) now supports IPv6. This enables administrators to define custom routing decisions for IPv6 traffic based on source, destination, or other packet attributes.
  • Static multicast routes (static mroutes).
  • Multicast Listener Discovery (MLD) group limit, protecting against DoS attacks by preventing excessive group joins.
  • MLDv1 SSM mapping, bridging legacy MLDv1 hosts to Source-Specific Multicast (SSM).
  • IPv6 PIM Embedded RP eliminating the need for external RP-mapping mechanisms and simplifying IPv6 PIM-SM multicast deployment.

VoIP

  • Added support for SIP traffic over IPv6.

Traditional VSX

  • Traditional VSX, GRE, and IPsec can now be accelerated in hardware when using the 10/25/40/100 GbE acceleration cards, supporting line-rate throughput and low latency.

Tools

  • Improved performance of FW Monitor troubleshooting utility on Check Point Firewall Appliances 19100, 19200, 29100, and 29200. The new flag provides exclusion filtering capabilities, such as exclusion expression.

Hardware Acceleration

  • Hardware Acceleration support is now available for SecureXL Penalty Box and IP Deny List features, enhancing Security Gateway resilience to DDoS attacks.

Hybrid Mesh Network Security

Management and Smart-1 Cloud

  • Introducing Unified Management of Internet Access policies for Security Gateways and Check Point SASE environments. You can now manage SASE Internet Access directly from SmartConsole, providing a single point of policy management across your hybrid infrastructure.

Smart-1

Upgrade

  • Introducing a new background upgrade capability designed to significantly minimize downtime to a few minutes during Management Server upgrades. The “Prepare Upgrade” phase runs seamlessly in the background, allowing administrators to continue working in SmartConsole, Web SmartConsole, or API without disruption. The “Complete Upgrade” phase then finalizes the changes, significantly reducing downtime compared to traditional upgrade methods.

Logging and Monitoring

  • Log Exporter can be configured to export only the first and/or the latest update per event or connection. This enables more efficient log processing by external SIEM (Security Information and Event Management) tools.
  • Log Exporter can now be configured with the Management API. This enables you to automate Log Exporter deployment and configuration within your infrastructure-as-code workflows.
  • Log Exporter can now be configured to send logs directly to AWS S3 buckets. This enables seamless integration with your existing cloud storage and log analytics workflows.
  • In the SmartConsole Gateways & Servers view, the Security Gateway status now changes to warning (yellow triangle icon) if the Security Gateway is writing logs locally for more than 5 minutes. This helps you quickly identify connectivity issues between the Security Gateway and its Log Server.

 

13 Comments
Labels