Q&A from the session:
When will Enhanced Link Selection become available for Spark appliances?
In our next release, R82.00.15, at the end of the year.
Regarding rugged appliances, will models based on the 2500 generation be launched?
We still have no ETA for new rugged firewall models. However, the next generation will have a completely new architecture rather than being a ruggedized version of the 2500.
Will Spark support AI Firewall, as Quantum R82.20 does?
Not currently. It is planned for a future release.
Is there a limit to the number of feeds that can be imported?
There is a limit of up to 20 MB per feed file, with a total limit of 100 MB. The files may be split at the user's discretion.
Can we use the 5G SIM for a site-to-site VPN?
Yes, 5G can be used for a site-to-site VPN.
In March 2027, will the 15xx rugged gateways also reach End of Sales?
No. There are currently no plans to announce an End of Sales date for them.
Is Zero Touch available for all Spark versions, including the ruggedized versions?
Yes, Zero Touch is available for all supported Spark firewalls.
Is there a plan to implement CPLC (Live Patch) on Spark appliances as well?
It is already in our plan, and we are working to apply it to Spark as well. Due to space limitations, we will first try to make it available on 2500 appliances.
For MSPs, instead of purchasing the appliance and annual subscription in advance, will you offer monthly payment options?
We already offer Pay-As-You-Go licensing for the 2500 series with the MSP-relevant SKU.
Is there a virtual environment for Spark?
No. Spark is sold only as a hardware appliance.
Is there a way to allow local VPN users to change their passwords instead of requiring changes through the administrator portal?
Only an administrator can edit Remote Access user passwords.
Can I deploy IoC files through SMP?
No, there is no option to configure IoCs through Spark Management.
Some ISPs provide a static IP address with a /32 mask. Is this supported on Spark?
Yes, it is supported.
How do I change an invalid default image on a Spark 2550?
You can find the relevant steps in this SK: https://support.checkpoint.com/results/sk/sk184995
We have a dedicated Clish command that must be run after verifying that the current image installed on the gateway is valid.
Are there plans to equip standard Spark appliances with PoE interfaces?
We are considering this for our next generation.
What is the status of the Full Gaia on Spark project?
This is still part of our long-term plan, but there is no ETA yet.
When is the GA release of R82.00.20 scheduled?
It is scheduled for Q2 2027 (subject to change).
Are there any major plans for Spark Management?
We plan to add more management options to Spark Management, including network interfaces, Wi-Fi, NAT rules, and more.
Additionally, we plan to add support for network objects and groups, including their use in access policies."\
When will Spark with Smart-1 Cloud support Entra ID for MFA?
This is not on the current roadmap.
Will the Remote Access client support IKEv2?
Yes, but only with strongSwan and the Endpoint Client.
Will it be possible to access the gateway through the Spark Management Portal if administrator access is restricted to certain IP addresses?
Administrator access restrictions also apply to Reach My Device.
What is the difference between Skyline in R81.10.17 and R82.00.11?
Skyline has been officially supported on Spark only since R82.00.11. In R81.10.17, Skyline is in the EA phase.
Are new Spark Management reports planned to replace the discontinued Extended Reports?
This is planned as part of the roadmap and will also replace the current classic reports.
Will it be possible to update a Spark gateway managed by Smart-1 Cloud through central deployment?
We currently support firmware upgrades through the repository. We plan to add firmware upgrades from the data center (Check Point Cloud) in a future release.
Is there an easy way to migrate a locally managed 15xx appliance to a new Spark appliance, including policies, objects, services, and so on?
We support backup and restore. You can take a backup from the old hardware and restore it on the new hardware.
There are some limitations, and only specific migration paths are supported. More information is available in this SK:
https://support.checkpoint.com/results/sk/sk184499
For a centrally managed cluster, do I have to upgrade SmartCenter to R82 before upgrading the Spark appliances?
Yes. For centrally managed appliances, SmartCenter should be upgraded first, followed by the Spark appliances.
Will R82 be released for non-Pro 1500-series Spark appliances?
No, non-Pro appliances do not support the R82 codebase.
Does Skyline poll the firewall inbound, or does the firewall send data outbound to Skyline?
If by Skyline you mean the Prometheus server, the firewall periodically sends data to the server.
For an MSP, we may have multiple UCs tied to a larger tenant that contains hundreds of customers. What options are available for using the new ZTP in SMP across multiple UCs?
The inventory is visible wherever the UCs are attached. We recommend placing customer gateways in the MSP UC and attaching only the MSP UC to the top-level account. This provides full visibility across all customers from the top-level account.
Can one tenant be linked to multiple UCs to use ZTP?
Yes. Link your MSP or MSSP account to all UC accounts that contain Spark appliances. You will then have full visibility and management capabilities.
Would this be done at the MSSP parent tenant rather than the child tenant underneath it?
You can do either. If you are an MSP or MSSP, we recommend doing this from the MSP or MSSP parent tenant.
We have been testing the 5G modem on Spark and found that it connects only to LTE on a regular data plan. Support said that we need a 5G RedCap plan to receive 5G service. Is that correct?
The new 2500 line has two models that support an internal 5G modem: the entry-level 2550 5G and the higher-end 2570 5G.
The 2570 5G supports both standalone (SA) and non-standalone (NSA) 5G and offers high 5G performance. The lower-cost 2550 5G supports only RedCap, with LTE as its fallback option.
In Identity Awareness, is it possible to select specific AD users instead of AD groups in access rules?
No.
Are there any plans to implement active-active clustering for SMB appliances?
There are currently no plans for this.