- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
The only time I _ever_ need to update CPUSE / CPDA is to install hotfixes.
Is there any reason the agent is not included and installed as part of the hotfix, to mitigate the dependency?
That's not exactly foolproof as you sometimes need the latest deployment agent to install the latest JHF, one not made available in a previous JHF.
In any case, you can always download the Deployment Agent and install it offline here: https://support.checkpoint.com/results/sk/sk92449
I believe we plan to start adding AutoUpdater content to the JHF for offline gateways.
Don't believe CPUSE is currently part of this.
Notice that when using central deployment from Smart Console or central deployment tool (CDT) it's enough to have the latest DA on the management machine and it will be pushed automatically to the gateways.
It should routinely self-update avoiding the dependency.
Is this on a machine that has internet access and a valid license or is isolated?
Isolated. Practically all the environments I touch are. Except for maybe management IPS updates via proxy...
I agree with Chris, I never have to do this manually, its always auto-updated. I mean, periodically (maybe once a month, if that), I click on "check for update" in web UI, but usually does not return any new versions of CPUSE agent.
That's not exactly foolproof as you sometimes need the latest deployment agent to install the latest JHF, one not made available in a previous JHF.
In any case, you can always download the Deployment Agent and install it offline here: https://support.checkpoint.com/results/sk/sk92449
I believe we plan to start adding AutoUpdater content to the JHF for offline gateways.
Don't believe CPUSE is currently part of this.
Wouldn't it be smarter to include the dependent DA in the JHF itself, and install it as part of the HFA if required?
Not really, considering you may need an updated DA to install a hotfix. As mentioned above, it is a separate type of software update.
Of course, that is how it works today and likely a result of the packaging, process and architecture. And I understand it may not be simple to change the process to include the latest DA at the time the HFA is released to hopefully make the offline installation process a tiny bit simpler. It may not sound like much but anything we can do to reduce the amount of maintenance required adds value.
KISS
I think last part of you statement, I agree with 100%...anything to make upgrade process easier would help.
Notice that when using central deployment from Smart Console or central deployment tool (CDT) it's enough to have the latest DA on the management machine and it will be pushed automatically to the gateways.
I found that out in the most annoying way possible when a new CPUSE version was in the "gradual deployment" stage. One of the members of the cluster I was trying to upgrade knew about it, but the other member and the management server did not yet. Not particularly hard to deal with. We just check for a new CPUSE build before using CDT and install it if there is one. It's ultimately just a little snag made more noticeable because of how smooth the process is otherwise.
Agreed that if CDT is usable in the environment, it's a great way to address this problem. My environment has a separate firewall between the management and the firewalls, and we had to allow CPRID through it. Now that we have it working, my team doesn't do any manual jumbo installations on firewalls anymore.
CDT is great, but often we are building new gateways that are not yet managed.
At the very least, it would be great if a link to the latest DA was provided with the HFA download, and as accessible as the HFA itself (no login is required to download the HFA, yet one is to download the DA?).
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
9 | |
6 | |
5 | |
4 | |
4 | |
3 | |
2 | |
2 | |
2 |
Wed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksWed 03 Sep 2025 @ 11:00 AM (SGT)
Deep Dive APAC: Troubleshooting 101 for Quantum Security GatewaysThu 04 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: External Risk Management for DummiesWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY