- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Over the past few weeks i have forklifted (4) 5xxx clusters to 9100. Spoiler alert - UPPAK has been disabled everywhere.
All 9100s have nothing special added to the order, just a LOM card, no interface bonding, no vlans. All were installed with R81.20 with the latest recommended hotfix.
First cluster was a 5600 forklift. This one has the most active connections (typically between 35,000 - 50,000 during the day) but the the bandwidth usage isn't anything exorbitant. No issues with connectivity after the upgrade, but i noticed that TX-DRP were increasing at an alarming rate - a few hundred thousand per day. On the 5600 cluster, netstat counters always remained pretty clean. I found this checkmates thread, reverted to KPPAK and after a week, netstat counters are back to being clean - no other change but UPPAK -> KPPAK: https://community.checkpoint.com/t5/Security-Gateways/Packet-timeout-with-unknown-reason-in-Quantum-...
Second cluster was another 5600. This is by far our largest location from a bandwidth usage perspective. All of our sites are configured in a single vpn community and all locations are physical appliances except one cloudguard instance in azure. When this site was forklifted to a 9100, all tunnels came up except the one to azure. Tried all the normal vpn troubleshooting steps, nothing, nada, tunnel to azure remained down. I then found this phoneboy podcast with tim hall which mentioned there could be weird vpn behavior with UPPAK - reverted to KPPAK and the tunnel came up immediately and no issues since. For reference, here is the podcast i was referring to: https://community.checkpoint.com/t5/CheckMates-Go-Cyber-Security/S07E03-What-is-UPPAK/ba-p/245115
Last two sites are pretty vanilla - not much bandwidth usage, typical connections are around 8K. No issues noted since forklifting from 5400s. But considering the issues that i had with the first two sites, i changed both of these clusters to KPPAK after a few weeks.
Just wanted to provide my observations, not looking for any troubleshooting ideas as i won't be putting any of these sites back on UPPAK on R81.20. WIll see what happens when we upgrade to either r82 or r82.10.
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY