- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hello,
May be I am in the wrong section... I will see if I get any answer.
I have an old appliance 14xx still managed by our MDM (yes I know EOL....). Now I have to upgrade MDM to R82.10 and this version is no more supporting 14xx appliances.
If I remove this appliance from the database (or if the MDM/CMA is no more reachable) will the latest policy remain on the appliance ?
What if I reboot this appliance ? It will load the Initial Policy or it will keep the old policy ?
Thanks for your help.
So, there's kind of two different possible scenarios. If a gateway loses contact with the management server, it will keep on keeping on, retaining the policy on reboot as long as it starts up properly, until something else happens and it doesn't anymore. In your case though, if you delete the gateway from the management server, the gateway will try to talk to it and learn that its SIC cert is revoked. This is less charted waters, most of us won't have tried this scenario, and we don't want to tell you 'yea mate she'll be right' and leave you in the lurch should you suddenly have a with no policy on it. It won't suddenly unload the policy upon learning that its SIC is revoked, but I don't know what it will do on reboot. Hence we offer safer alternatives.
It should load the latest installed policy.
Thanks for answering.
Also think "it should" but I would prefer "it will". And since hard and soft are EOL, unable to raise a ticket.
Now system is central managed, these boxes can also be locally managed. With local mgmt, the rules and logs stay on the local box and you dont need a MDM anymore. Note: CRL check will fail towards mgmt, this is needed for site to site vpn between Check Point to Check Point. CRL check can be disabled.
During reboot it will reach out to mgmt but also during normal operations it will check if there is a new policy and will fetch it. if there is nothing to fetch box will not load a default policy.
Hi,
Probably I have not been clear enough.
Currently device is running with policy name "policy-from-cma".
Then I do not allow communication with the CMA anymore.
Then rebooting appliance. Is it going to load a local copy of "policy-from-cma" of load the default policy ?
Rgds,
It will load a local copy of "policy-from-cma"
It will work until it doesn't, at which point you won't be able to easily fix it. I think Lesley has the right idea - take the time to properly plan to reset it into Locally Managed mode and do it on your schedule, instead of waiting until it decides you need to do it.
Hi,
Happy to read everybody. But still no answer...
Question is about boot process and policy load. Not about what I should do or not.
Rgds,
So, there's kind of two different possible scenarios. If a gateway loses contact with the management server, it will keep on keeping on, retaining the policy on reboot as long as it starts up properly, until something else happens and it doesn't anymore. In your case though, if you delete the gateway from the management server, the gateway will try to talk to it and learn that its SIC cert is revoked. This is less charted waters, most of us won't have tried this scenario, and we don't want to tell you 'yea mate she'll be right' and leave you in the lurch should you suddenly have a with no policy on it. It won't suddenly unload the policy upon learning that its SIC is revoked, but I don't know what it will do on reboot. Hence we offer safer alternatives.
This is the more accurate answer I had. I will deal with it.
Even though it's not officially supported, it's quite possible that you will still be able to manage and install policy on your 1400 from R82.10 assuming the object existed prior to the upgrade.
At least that's been the case in the past when we've deprecated support for a given appliance/version as the underlying "Backward Compatibility" packages are still there.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Thu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksTue 06 Oct 2026 @ 12:00 PM (ACDT)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus APACTue 06 Oct 2026 @ 03:00 PM (CEST)
Rethinking Network Security for the AI Era : Session 2 - From User, to Branch and Campus EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY