R82.20 does not replace the Threat Prevention architecture introduced in R82 — it extends its coverage in areas that are becoming increasingly relevant in modern environments. The main changes include Snort 3.x support in IoC Feeds, DNS Trap for IPv6, improved TLS block-page visibility, AI workload/agent protection, and additional gateway hardening.
From an operational perspective, the biggest gains are in custom detection and IPv6 coverage. SOC teams can bring newer Snort 3.x detection content into the Check Point prevention pipeline, while DNS Trap can now cover dual-stack environments instead of leaving IPv6 outside that workflow.
R82.20 also improves troubleshooting and emerging workload protection. TLS failures caused by revoked, expired, or untrusted certificates can provide clearer feedback to users, while new AI security capabilities expand enforcement beyond traditional malware, URL, DNS, and exploit detection.
The real question after upgrading should not be only “Is R82.20 installed?” but “Which of these new protections are actually being incorporated into the security architecture?” I published the full technical analysis on CheckMates with the R82 vs R82.20 comparison and the operational points I would review after an upgrade.
Source: r/checkpoint · by /u/WiliRGasparetto