Take 43 - Ongoing

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 43

Released on11 February 2019

PMTR-27655

Security Management

Values updated in resourceProfiles files to handle high CPU utilization for "Java" process (described in sk123417) are not resistant and get overridden after Jumbo Hotfix Accumulator installation or backup/restore or export/import procedures.

PMTR-28644,
PMTR-28557

Security Management

Running the fwm sic_reset command from Domain Management Server fails with "reset_objects: updateMultiple failed". Refer to sk142512.

PMTR-25816,
PMTR-25793

Security Management

Once user performs any change to his configuration, the Compliance Blade performs a partial scan and calculates the relevant Best practices. During this scan, exceptions of relevant objects for these Best practices are deleted. Meaning, if previously obj1 was excluded from applying Best practice #1, during partial scan obj1 will be relinked to Best practice #1.

PMTR-32542,
PMTR-32187

Multi-Domain Management

  • Log servers are not seen in SmartConsole Log Server tab after Advanced Upgrade to Jumbo Hotfix Accumulator Take 33.
  • After new Domain creation, logs from this Domain are not seen in SmartConsole.

PMTR-29670,
PMTR-29604

Multi-Domain Management

Upgrade of the Primary Multi-Domain Server from R80.10 fails when its Global Domain is in Standby mode. Refer to sk143892.

PMTR-27321,
PMTR-21282,
PMTR-24274,
PMTR-24249,
PMTR-22245

Multi-Domain Management

CPView is not supported on Multi-Domain Security Management environments.

PMTR-29458,
PMTR-26606

SmartConsole

"Synchronization with Check Point UserCenter" feature displays "Synchronization with Check Point UserCenter requires a valid license." warning message even though all licenses are valid.

PMTR-23395,
PMTR-29385

SmartConsole

If administrator updates his details (e.g. name, phone, email) and tries to publish the session, it fails with "Internal error" message.

  • After Jumbo HFA installation, the session cannot be published or discarded and any further update will fail. Refer to sk144214.

PMTR-25778,
PMTR-25825,
PMTR-25790

SmartConsole

When using Global VPN Community with permanent tunnel gateways list (matrix / permanent tunnel gateways), upgrade from R7x fails.

PMTR-26495,
PMTR-26474

SmartConsole

"Error: SIC initialization failed because of failure in parsing the certificate file" error when user attempts to log in with certificate to API (mgmt_cli) with password including "!".

API-512,
PMTR-25591

SmartConsole

Web API show-package fails if the package was installed on a cluster member which is already deleted. Refer to sk144132.

PMTR-25081,
PMTR-25069,
PMTR-24728

SmartConsole

Attempt to update Threat Emulation images fails with "Could not send Threat Emulation images update command, validate SIC connectivity and install policy with Threat Emulation enabled for [name]" message.

PMTR-28877,
BS-859

SmartConsole

The existing regulation is not updated and appears as "EU Data Privacy" instead of "GDPR".

PMTR-28488,
DO-902

Security Gateway

Traffic is dropped when using non-FQDN Domain object in Security policy.

PMTR-28593,
PMTR-25909

Security Gateway

Added support for NAT on payload of H323 packets when different IP addresses are used for payload and control.

PMTR-28197,
PMTR-27742

Security Gateway

No service enforcement when creating "Other services" without match expression for TCP, UDP or SCTP.

PMTR-27663,
PMTR-28320,
PMTR-24802

Threat Emulation

Added ability to update Threat Emulation file types in an offline environment.

PMTR-26022,
PMTR-25770

HTTPS Inspection

When HTTPS Inspection is enabled and "Hide X-Forwarded-For in outgoing traffic" option is selected, the XFF header is not obfuscated on HTTPS traffic.

PMTR-27702,
PMTR-20103

HTTPS Inspection

Potential memory leak due to "Out of state" HTTP response.

PMTR-30868,
PMTR-30867

HTTPS Inspection

In some scenarios, connectivity issues between Capsule Workspace and Security gateway.

PMTR-27367,
IDA-1609

Identity Awareness

In some scenarios, Identity Agent fails to authenticate using Kerberos SSO due to very large Kerberos ticket and the agent fallback to User/Password authentication.

PMTR-28368,
PMTR-28140

Anti-Malware

During upgrade, if Anti-Virus is enabled, all emails are stuck in MTA queue due to missing certificate.

PMTR-30218,
TPM-1378

IPS

The "A general error has occurred" message is displayed when trying to change the IPS protection configuration in "MySQL -> General settings".

PMTR-26141,
01967376

SSL Inspection

Added support for custom extension used by Apple.

PMTR-30550,
PMTR-29405

Logging

Exporting 100K or more logs to Excel from SmartView fails.

PMTR-30609,
PMTR-30608,
PMTR-30607,
PMTR-29589,
PMTR-29583

Logging

In rare scenarios, when the Log server miscalculates the available disk space, it may stop receiving logs from the connected gateways and cause the logs to accumulate locally on the Security gateway.
Refer to sk146152.

PMTR-27043,
PMTR-23553

Logging

After two or more upgrades of a Security gateway / Security Management server / Log server or SmartEvent server, log maintenance fails to delete logs from older version.

PMTR-26706,
PMTR-26696

Logging

After Daylight saving time change, the logs from the time of change until the end of the day are not indexed and the "Illegal instant due to time zone offset transition (daylight savings time 'gap')" error is displayed in solr.elg file.

PMTR-28160,
PMTR-23550

Logging

After upgrade from R80.x to R80.20 GA, the pre-upgrade logs data will not be deleted according to the logs retention policy.

PMTR-22357,
SL-1600

Logging

In rare scenarios, due to a connection attempt failure to the Security Management, the Security gateway starts logging locally.

PMTR-29044,
SL-1538

Logging

When Security gateway is configured to send alerts only to a specific Log server, logs may be written locally on the gateway instead to be sent to the Log server.

PMTR-26040,
PMTR-25672,
PMTR-28925

Logging

Added Threat Emulation forensic report in SmartView Log card.

PMTR-29233,
PMTR-22839,
02535956

SecureXL

Memory consumption on Security Gateway increases after enabling NetFlow v9 in Gaia OS. Refer to sk118719.

PMTR-30162,
PMTR-22869,
PMTR-30163

SecureXL

Concurrent connections monitoring can become inaccurate when "fw samp quota" rules are changed.

PMTR-27529,
MBS-4134

SecureXL

In rare scenarios, Security gateway crashes when penalty checkbox is selected.

PMTR-29118,
PMTR-17539,
PMTR-27741

SecureXL

In some scenarios, large number of incorrectly classified "simlinux_br_port: dev == NULL !!!" debug messages appear in kernel message logs.

PMTR-28120,
GAIA-3349

SecureXL

In some scenarios, HTTP requests do not pass.

PMTR-28084,
PMTR-27895

ClusterXL

In some scenarios, standby cluster member sends PIM Hello packets.

PMTR-29200,
PMTR-28139,
VSX-1928

VSX

In some scenarios, the CPD and fw_full processes unexpectedly exit when the TDERROR debug flag is enabled.

PMTR-28022,
VSX-1895

VSX

Traffic from a Virtual System in VSX Cluster to Security Management Server is dropped with "Local interface address spoofing" log.
Refer to sk110473.

PMTR-23158,
PMTR-26453,
PMTR-26095
GAIA-3010

Gaia OS

CVE-2018-15473: Username enumeration is possible due to a premature bail-out while dealing with a malformed packet. The issue exists in several authentication protocols.

PMTR-28381,
PRHF-1502,
PMTR-28899

Gaia OS

When using conv2db to recreate Gaia database from /config/active, comments are not skipped and the new database file may contain irrelevant information. Refer to sk139832.
Note: the issue is cosmetic only.

PMTR-28798,
PMTR-28822,
PMTR-12070,
01515638

Gaia OS

SNMPD process fails to send Coldstart on reboot. Coldstart is configured by threshold that can be too short comparing to the OS boot time.

PMTR-28277,
GAIA-2493

Gaia OS

Connectivity problem for 10 Gigabit fiber network interfaces (be2net driver) after upgrade from R77.30.

PMTR-28041,
PMTR-25332,
GAIA-3471

Gaia OS

Added support for "/", "(", and "*" characters as part of the system message banner.

PMTR-23058,
PMTR-24458,
01579916

Gaia OS

syslog messages forwarded to external Syslog server, do not contain the host name.
Refer to sk100727.

PMTR-28303,
02397556,
CP-41

Gaia OS

In some scenarios, snmpwalk reports false values of bond interface.

PMTR-28312,
PMTR-28338,
01906257

Gaia OS

In some scenarios, sporadic timeouts occur during snmpwalk run.

PMTR-28834,
PMTR-28836,
02489137

Gaia OS

Different LOM versions are reported in Gaia Portal and Gaia Clish.

PMTR-11377,
PMTR-25506
02100804

VPN

After Cluster failover, VPN tunnel is down and "Unknown SPI for IPsec packet" log is shown. Refer to sk112339.

PMTR-30425, PMTR-30360

VPN

VPN tunnels with 3rd party peers fail because of mismatched IDs. Refer to sk144094.

PMTR-25196,
PMTR-31887

VPN

In some scenarios, IKE fragmentation is dropped when NAT-T is enforced. Refer to sk143372.