Take 33 - General Availability

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 33

Released on 8 January 2019 and declared as General Availability on 4 February 2019

PMTR-25005,
PMTR-23377

Security Management

In some scenarios, purge operation fails with "Task was interrupted because of server restart" message and the CPM process unexpectedly exits, producing core dump file.

PMTR-28037,
PRHF-1977

Security Management

Policy installation fails due to a memory allocation failure.

PMTR-26802

Security Management

When creating a Security Gateway object and click OK, SmartConsole terminates with "The connection with the server was lost...." error.

PMTR-25488,
PMTR-25218

Security Management

When Database is more than 100 objects and searching for the objects in the Objects Explorer and scrolling down, list of items disappears and the results in the bottom-left show "No items found". Refer to sk139793.

PMTR-26386,
PRHF-1656,
PMTR-25184

Security Management

Cannot export logs to Excel from SmartView connected to Multi-Domain Log Server.
Refer to sk140433.

PMTR-24555,
PMTR-26219

Security Management

In some scenarios, migrate_export fails when exporting R77.30 database from Windows machine in order to import it to R80.20 on Gaia.

PMTR-26457,
PMTR-17608

Multi-Domain Management

When Domain has policies that are in use in some policy installation preset, the attempt to delete this Domain fails with "Error: Unspecified error".

PMTR-23217,
PMTR-22277

Multi-Domain Management

Log in to the primary Multi-Domain Management GUI fails due to HA and logging objects synchronization generating high load.

PMTR-21125

SmartEvent

In large-scale environments, LOG_INDEXER process may unexpectedly exit producing 3.5GB core file.

PMTR-23080,
PMTR-26637

SmartConsole

HTTPS Inspection rule with mixed Access Role and network object cannot be enforced.

PMTR-25913

SmartView

Added consolidated Threat Prevention dashboard, providing full threat visibility across Networks, Mobile and Endpoints.
Refer to sk134634.

PMTR-23063,
PMTR-22415

SmartUpdate

SmartUpdate hangs on launch due to over 4000+ unattached licenses.
Refer to sk136512.

PMTR-21902,
PMTR-21183

Security Gateway

Memory leak in FWD process.

PMTR-29099

Security Gateway

Security gateway drops multicast or broadcast packets when working in bridge mode.

PMTR-26564,
PMTR-25323

ClusterXL

  • 3rd party cluster Full-Sync does not run on startup and caused the cluster to be in down state.
  • Dynamic Routing packets are dropped on the cluster member with the lower priority.

PMTR-25290,
PRHF-1556

Threat Prevention

In some scenarios, Advanced Upgrade fails with different errors due to NULL pointer exception check.

PMTR-25286,
PMTR-25287,
PMTR-25106

Identity Awareness

User's access to a network resource may fail in the following scenario:

  • Access to a network resource is through an Identity Awareness Gateway (configured as PEP)
  • In SmartConsole, the Identity Awareness Gateway object is configured with "Identity Awareness -> Identity Sharing -> Get identities from other gateways -> All sharing gateways"
  • The sharing Identity Awareness Gateway (configured as PDP) that shares identities with the affected Identity Awareness Gateway (configured as PEP), opens an identity sharing connection not from its main IP address

Refer to Scenario 1 in sk156953.

PMTR-24536,
PRHF-1462

Identity Awareness

Identity sharing does not work for non-HTTP traffic when XFF is enabled only on the layer and not on the Security gateway.

PMTR-25193,
IDA-1396

Identity Awareness

Identity sharing fails when XFF is enabled and remote PDP does not respond.

PMTR-26589,
IDA-1604

Identity Awareness

In some scenarios, Terminal Servers Identity Agent (MUH Agent) session Access Role is missing on PDP but exists on PEP, causing next PEP to PDP sync to be removed from PEP and thus the accessibility loss.

PMTR-25100,
IDA-1226

Identity Awareness

Improved error handing when Identity Sharing is used and remote PDP server does not respond due to prolong outage.
Refer to sk141152.

PMTR-22758,
PMTR-22632

Identity Awareness

In rare scenarios, PDP crashes after generating traffic for a long time.

PMTR-26173,
PMTR-26171

SSL Inspection

Change SSL Network Extender on MacOS to 64-bit architecture to support 32 bit apps depreciation in OSX.

PMTR-24797

SSL Inspection

HTTPS traffic is inspected when it is configured to be bypassed: when HTTPS Inspection is enabled and probe bypass is 0.
Refer to sk132913.

PMTR-23567,
PMTR-23317

Logging

A Domain administrator connected to a specific Domain in Multi-Domain environment cannot see suggestions when typing in logs search box.

PMTR-29010,
SL-1878

Logging

After configuring mail alerts to be sent using "internal_sendmail" script, emails from Check Point server arrive with blank email body. Refer to sk142492.

PMTR-23288,
PMTR-19838

Gaia OS

After adding the RBA roles Gaia commands (add rba role TACP-0 virtual-system-access all), the lines are missing from the "show configuration" command output, but the values can be seen in Expert mode (/config/active). Refer to sk119394.

PMTR-24810,
PMTR-24803

Gaia OS

Security Management / Multi-Domain Management server OS backup fails due to package compression errors. Refer to sk121212.

PMTR-24293,
VSECC-785

CloudGuard

Attempt to install central license on CloudGuard gateway fails with "not vSec product" error.

PMTR-24166,
PMTR-23917

SecureXL

The Anti-Spoofing policy is not unloaded by running the "fw unloadlocal" command.

PMTR-25207

SecureXL

"sume_from_fw_forward: dropping packet of for vsid=0 due to loop prevention" dmesg errors during policy installation failure.