Take 235 - Ongoing

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 235

Released on 26 Apr 2021

PRJ-24911,
PMTR-67937

Security Management

"Unauthorized client" error on login failure from an IP address that is not explicitly defined in the Trusted Clients list. Refer to sk173026.

PRJ-9515,
PRHF-8550

Security Management

The Rule UID is hidden in Audit logs. Refer to sk165016.

PRJ-23921,
PMTR-64482

Security Management

SmartConsole Extensions fail to load with "Error: unable to retrieve read-only session" if login with SmartConsole is performed with an IP address that is not defined as the primary IP of the Management Server.

PRJ-22609,
SMCUPG-1375

Security Management

In some scenarios, a Domain migration may fail during the Access Policy import with the "Object not found" error in cpm.elg file.

PRJ-22440,
PRHF-15754

Security Management

Upgrade or migration from R80.10 and lower to R80.20 and higher may fail with "Scheme adjustment had failed" error in logs. Refer to sk172003.

PRJ-22122,
PMTR-61785

Security Management

Running override_server_setting.sh may not update settings correctly when updating a setting multiple times.

PRJ-15904,
PRHF-12367

Security Management

Security policy compilation fails if the Domain network object name (FDQN name) contains space.

PRJ-17232,
PRHF-12911

Security Management

In some scenarios, Apache does not start and shows a "No space left on device" message if the user runs "cprestart" frequently.

PRJ-23772,
PMTR-66072

Security Management

"Query failed" error is displayed in Security Gateway Device & License Information view in SmartConsole when canceling the "Export to PDF/CSV" operation.

PRJ-22871,
PRHF-15786

Security Management

In some scenarios, policy installation fails with "Error code 0-2000077" message.

PRJ-20808,
PRJ-20809,
PMTR-62949

Security Management

On Security Management with connected Endpoint Security Server, the SICTUNNEL process may unexpectedly exit and start again every few minutes with core file ~4gb in size. Refer to sk173704.

PRJ-22210,
PMTR-61168

Security Management

In rare scenarios, concurrent update operations performed by several administrators on the Management Server may fail.

PRJ-22129,
PMTR-61861

Security Management

In a rare scenario, Management HA synchronization fails after the Purge Revisions operation.

PRJ-13069,
PRHF-11089

Security Management

In rare scenarios, during a Global Policy Reassignment, the Management Server may unexpectedly exit and fail to start again.

PRJ-22631,
PMTR-62650

Multi-Domain Management

UPDATE: Improved the Domain Management Server and Domain Log Server creation and deletion operations.

PRJ-23158,
PMTR-64136

Multi-Domain Management

UPDATE: Added stabilization improvement for Assign and Reassign Global Policy operations.

PRJ-22579,
SMCUPG-1625

Multi-Domain Management

In some scenarios, HA Full Sync on the System Domain fails after upgrade on a Multi-Site environment with multiple Multi-Domain Servers. Refer to sk171059.

PRJ-22595,
PRHF-15856

Multi-Domain Management

Create Domain action may fail with a "License violation detected" error even though CPSM-DOMAINS-1 license is applied on the Management Server.

PRJ-24019,
PMTR-66953

Multi-Domain Management

In some scenarios, after upgrade of Multi-Domain environment that has active Domains on multiple Multi-Domain servers, some objects may not be visible in the System Domain.

PRJ-21911,
PMTR-64572

Multi-Domain Management

In some scenarios, installation of Jumbo Hotfix on Multi-Domain Server may fail after running restore from backup.

PRJ-22521,
PMTR-65290

Multi-Domain Management

In some scenarios, Reassign Global Domain for a Domain that is active on another Multi-Domain Server may fail with "An internal error has occurred" message. Refer to sk172704.

PRJ-22137,
PMTR-64481

Multi-Domain Managemen

A Multi-Domain Server with dozens of Domains may take a long time to start.

PRJ-23542,
PMTR-66182

Multi-Domain Managemen

In some scenarios, HA sync in a Multi-Domain environment may fail with the "Failed to import data" error message after the user creates new Permission Roles.

PRJ-13189,
PRHF-11482

Multi-Domain Management

In a rare scenario, Advanced upgrade from R80.10 may fail.

PRJ-19498,
PMTR-61526

SmartConsole

"The object specified in 'Always send alerts to' field, has no active 'Logging & Status' Blade" error may be displayed after running the "add-simple-gateway" command in Management HA environments where one of the Security Management servers has the "Logging & Status" Blade disabled. Refer to sk172226.

PRJ-21622,
PRHF-15156

SmartConsole

In some scenarios, FWM process logs show Provisioning/LSM activity even though LSM is not in use. Refer to sk171905.

PRJ-22217,
PMTR-32568

SmartConsole

In some scenarios, a validation warning may appear on an updatable object with the following message: "Object is no longer supported. Enforcing security for this object is not possible." However, the object is still available in the updatable objects picker.

PRJ-17275,
PMTR-59746

SmartConsole

The "Recent Tasks" view allows only Super Users to view other administrators' tasks.

PRJ-21182,
PMTR-61750

Logging

NEW: Resource pools for log queries and report generation have been separated to ensure query responsiveness while multiple reports are generated.

PRJ-18558,
PRHF-13614

Logging

In the "Logs" view in SmartConsole, when the query filter contains "time:yesterday" as a literal, the query fails with a "Query resolution failed" error. The pre-defined time filter "Yesterday" shows results from today. Refer to sk170999.

PRJ-23154,
PMTR-62454

Logging

When viewing an Access log card that was matched on both a Network layer (firewall) rule and an Application layer rule, and both actions are "Accept", the application layer rule will be presented in the card instead of the network layer rule. Refer to sk172763.

PRJ-23203,
PMTR-65244

Logging

In rare scenarios, when creating a Log server object and establishing SIC, log queries from the newly created Log server object may fail.

PRJ-23007,
PRHF-15886

Logging

In rare scenarios, when the user exports logs to Excel using SmartView web, the action fails when the exported logs contain special characters, like emojis.

PRJ-21113,
PRJ-24227

Logging

In some scenarios, when declaring a filter in Log Exporter, logs may not be exported. Refer to sk173025.

PRJ-23414,
PMTR-60082

Logging

In SmartView's "Cyber Attack View - Endpoint", the widgets Active/Dormant Attacks and Cleaned/Blocked Attacks show clean hosts as infected (false positive results).

PRJ-17118,
PMTR-59484

Logging

In SmartView, chart and timeline widgets may show a "Query Failed" error.

PRJ-21305,
PMTR-62117

Logging

  • In environments with more than 500K network objects, the log_indexer process may lead to a memory leak.
  • In some scenarios, when there are offline logs to index, queries are slower than expected.

PRJ-15783,
PRHF-11889

Logging

In SmartView, when the user exports a container widget with charts to PDF, some data may be missing, and the charts may be shown in a distorted manner.

PRJ-22183,
PMTR-58496

Logging

In SmartView, when the user exports multiple PDF/CSV/Templates of the same view/report at the exact same time, the second export to complete may overwrite the first one.

PRJ-22247,
PMTR-65133

Logging

In some scenarios, in the "Views and Reports" of SmartView, it is not possible to use the field "Roles".

PRJ-21144,
PMTR-51637

Logging

In SmartView, when opening a log card popup in lower resolutions, the text in the header may be cut off.

PRJ-21372,
PMTR-63927

Logging

In some scenarios, in Multi-Domain servers with many domains, the Solr process for logs may unexpectedly unexpectedly exit.

PRJ-15325,
PMTR-52927

Logging

In some scenarios in SmartView, exporting a report or view to PDF duplicates the item and displays it twice in the Catalog until the export is done.

PRJ-23139,
PMTR-65727

Internal CA

The output of the "lscert" command has duplicate lines for all certificates that are not in "pending" status.

PRJ-16050,
PRHF-11884

Compliance

Deactivated Compliance Best Practices appear in the Compliance report.

PRJ-21900,
PRJ-21901,
PMTR-64675

Security Gateway

NEW: Added new troubleshooting tool to cplic command for Entitlement manager.

PRJ-23384,
PRJ-23385,
PMTR-66195

Security Gateway

NEW: Implemented new Fast-Accel producer.

The following Fast-Accel statistics are added to CPView:

  • Status: current status of Fast-Accel feature (enabled/disabled).
  • Configured rules: number of rules were added by the user. These rules determines whether a connection should be accelerated or not.
  • Accelerated connections amount: number of accelerated connections.
  • Total connections amount: total connections opened in PPAK.
  • Accelerated connections percentage: percentage of accelerated connections as part of the overall traffic.
  • Services distribution: number of times each service was used by the accelerated connections.

PRJ-22678,
PRJ-22679,
PRHF-14534

Security Gateway

UPDATE: Security Gateway performance optimizations for specific scenarios. Refer to sk174607.

PRJ-10988,
PRJ-15441,
PRHF-8504

Security Gateway

UPDATE: Added L3 routing support for bridge interface assigned with IP address. To enable it, set fw_bridge_with_ip_routing=1 in the $FWDIR/fwkern.conf file. Refer to sk165560.

PRJ-19572,
PRJ-22934,
PRHF-13912

Security Gateway

When using "User Alert 3" in the code alert, cosmetic error "FW-1: fwdrv_get_string_id_from_code: illegal parameters for code 8" appears in the /var/log/messages file.

PRJ-20568,
MBS-12769

Security Gateway

In some scenarios, the "fwauthd_init: got known service port XXX ... choosing another one" message appears repeatedly in the $FWDIR/log/fwd.elg file.

PRJ-22453,
PRJ-22454,
PMTR-64448

Security Gateway

In a rare scenario, Security gateway may crash with fwk and fwk_wd core dump files.

PRJ-19410,
PRJ-19411,
PMTR-60877

Security Gateway

The "new-conn-rate" DOS/Rate limiting rules may not be enforced in usermode when enforcement for internal interfaces is disabled.

PRJ-22371,
PRJ-22372,
PRHF-15705

Security Gateway

In some scenarios, the Security Gateway attempts to access the Management Server through the server's NAT IP address (defined in the "NAT" section of the server object), while the server is reachable only through the main IP address (defined in the "General Properties" section of the server object).

Refer to sk171665 to configure the required parameter SKIP_NATTED_IP.

PRJ-20902,
PRHF-5313

Security Gateway

In a rare scenario, the FWK process unexpectedly exits during debug.

  • Fix is relevant for Gaia 3.10 only.

PRJ-21110,
PRHF-14953

Security Gateway

Authentication may fail when LDAP branch name contains "\".

  • Fix is relevant for Gaia 3.10 only.

PRJ-21053,
PRJ-21054,
PRHF-15024

Security Gateway

In a rare scenario, Fast Accel logs are sent although they are disabled on the matched rule. Refer to sk171336.

PRJ-23519,
PRJ-23520,
PRJ-23502

Security Gateway

Security Gateway may freeze on boot when enable IPv6 and IPv4 with 40 instances in Kernel mode. Refer to sk172364.

PRJ-21470,
PRJ-21471,
PRHF-14963

Security Gateway

When the Security Gateway is configured as a proxy, some network objects may not be matched correctly.

PRJ-23396,
PRJ-23395,
PRHF-15802

Security Gateway

Added support for "Other" services configured with IP protocol, but without advanced "Match" expression.

PRJ-23099,
PRJ-23100,
PRHF-13417

Security Gateway

The connection may not exist in SecureXL connection table when configuring Smart Connection Reuse kernel parameters and allow out of state TCP packets.

PRJ-21310,
PRJ-21311,
PMTR-63867

Security Gateway

Allow automatic configuration of Identity Awareness nested group state 4 for Security Gateways with a previously installed fix for IDA-754.

PRJ-24297,
PRJ-24298,
PMTR-67184

Security Gateway

In a rare scenario, the FWK process unexpectedly exits on the Security Gateway.

PRJ-22079,
PRJ-22080,
PMTR-64650

Internal CA

In a rare scenario, "This operation is not supported on STANDBY members" message is displayed and the cpca_client process unexpectedly exits when trying to renew a certificate on a standby Domain.

PRJ-19450,
PRJ-21495,
IDA-3194

Identity Awareness

Added optimization for PDP when handling Terminal servers Multi-User Host Agent (MUH).

PRJ-24583,
PRJ-24584,
PMTR-56794

Identity Awareness

In some scenarios, a Security gateway may crash after Take 232 installation due to Identity Awareness specific flow.

PRJ-21455,
PRJ-21456,
PRHF-14980

Identity Awareness

In some scenarios, VPN Remote Access client fails to connect if a certificate contains a DN with an asterisk (*).

PRJ-22357,
PRJ-22358,
IDA-3759

Identity Awareness

In some scenarios, output of "pdp conn pep" command may show wrong PEP names.

PRJ-21237,
PRJ-14541,
PMTR-52079

IPS

UPDATE: Exceptions are now enforced for these IPS protections:

  • ASCII Request Response
  • ASCII Response Response
  • HTTP Header Patterns
  • HTTP URL Patterns
  • CIFS File Patterns

Refer to sk166222.

PRJ-22516,
PRJ-22517,
PMTR-65461

IPS

Proxy source IP address is not printed in the IPS logs.

PRJ-19491,
PRJ-23516,
PMTR-20344

Application Control

The fw_full (fwd daemon) unexpectedly exits producing a core dump fila and causing a cluster failover.

PRJ-21294,
PRJ-21295,
PMTR-63495

URL Filtering

UPDATE: Improved RAD event output to provide additional information on events, such as detailed timing. This update also activates the retry mechanism by default.

PRJ-21708,
PRJ-21709,
PMTR-64263

SSL Inspection

In rare scenarios, a memory leak may occur in a crypto module.

PRJ-19776,
PRJ-19777,
PMTR-57233

SSL Inspection

In some scenarios, the wstlsd process may unexpectedly exit when browsing to certain websites.

PRJ-19780,
PRJ-19781,
PMTR-58480

SSL Inspection

A memory leak may occur during policy installation.

PRJ-22532,
PMTR-41488

Anti-Malware

UPDATE: Improved behavior of Intelligence Feed failure.

  • Fix is relevant for Gaia 3.10 only.

PRJ-22019,
PRJ-22020,
PMTR-63963

Anti-Malware

In rare scenarios, the Threat Prevention Blade Exception used for performance optimization does not work as expected.

PRJ-20267,
PRJ-20268,
PRHF-14501

Anti-Malware

Packet capture may not be generated for certain IPS protections.

PRJ-18701,
PRHF-12299

UserCheck

When using the UserCheck agent, the original URL attribute variable $orig_url$ may appear on URL field of log details.

  • Fix is relevant for Gaia 3.10 only.

PRJ-14601,
PRJ-14602,
PMTR-56744

Mobile Access

In some scenarios, pinger (MAB process that handles the ActiveSync traffic) may unexpectedly exit.

PRJ-21641,
PRJ-21642,
PMTR-60226

Mobile Access

Mobile Access may overwrite the /etc/hosts file on Security Gateway.

PRJ-21697,
PRJ-21698,
PMTR-64360

ClusterXL

UPDATE: Added the fwha_disable_ccp_on_monitor global kernel parameter. The parameter turns on/off the sending of CCP packets on link monitor interfaces.

PRJ-21347,
PRJ-21348,
CLUS-1804

ClusterXL

In some scenarios, a large quantity of logs is generated on cluster VIP API.

PRJ-19516,
PRHF-14206

ClusterXL

In some scenarios, the required interface value is higher than it should be when adding a VLAN interface.

  • Fix is relevant for Gaia 3.10 only.

PRJ-22149,
PMTR-63571

ClusterXL

During active-active-bridge mode, the "show routed cluster-state" command may display some members as subordinate instead of master.

  • Fix is relevant for Gaia 3.10 only.

PRJ-18060,
PRJ-18061,
PMTR-60766

SecureXL

UPDATE: Changed the "accept out of state" global parameter usage and added support to change it for specific VS. Refer to sk147093.

PRJ-22287,
PRJ-22288,
PMTR-62849

SecureXL

TCP reset packets may be dropped with an invalid sequence.

PRJ-22166,
PRJ-22167,
PRHF-15607

SecureXL

Rate limiting rules using concurrent-connection counters may cause connections to be blocked.

PRJ-22434,
PRJ-22435,
PRHF-15755

SecureXL

In some scenarios, the concurrent-conns rate limiting count may be inaccurate for FTP data connections.

PRJ-19370,
PRJ-19371,
PRHF-14133

SecureXL

Security Gateway may crash when the user runs "fwaccel tab -t" to view certain rate limiting tables that have a large number of entries.

PRJ-20683,
PRJ-20682

SecureXL

In some scenarios, not all IP addresses listed in Deny List file $FWDIR/conf/deny_lists are loaded.

PRJ-22914,
PRJ-22915,
PRHF-15478

SecureXL

Improved the Smart Connection Reuse feature to be consistent with the user configuration. Refer to sk24960.

PRJ-19663,
PRHF-13929

SecureXL

In some scenarios, connections are dropped when SYN Defender and ISN Defender are both enabled on the same interface.

  • Fix is relevant for Gaia 3.10 only.

PRJ-22901,
PMTR-48384

Routing

In some scenarios, OSPF configured with unnumbered VTI on cluster frequently moves between "Full" and "EXSTART" status.

  • Fix is relevant for Gaia 3.10 only.

PRJ-17586,
PRJ-17587

Gaia OS

UPDATE: SNMP USM user names limitation was increased from 8 characters to 31.

PRJ-22920,
PRJ-22921,
PMTR-62465

Gaia OS

"kernel: [SIM4];resume_from_error: failed to get ci_or_corr" error message may be printed numerous times in /var/log/messages file while running UDP Traffic Load. Refer to sk172543.

PRJ-21997,
PRJ-21998,
PRJ-21999,
PMTR-56379

Gaia OS

In rare scenarios, SNMP user details may be visible in /var/log/messages file.

PRJ-21925,
PRJ-21924,
PRJ-17304

Gaia OS

Unable to set MTU on Igb cards.

PRJ-443

Gaia OS

Non-English characters in Expert password may cause Clish to crash.

PRJ-24153,
PRHF-15900

Gaia OS

In rare scenarios, "show asset network" command may lead to memory leak. Refer to sk174823.

PRJ-24049,
PRJ-24062,
DP-7201

Gaia OS

Captive Portal / SAML portal may not work after installation with Blink image.

PRJ-21664,
PRHF-15328

Gaia OS

In some scenarios, policy installation on a Check Point Gateway in Azure causes the Gateway to crash and load a default policy. Refer to sk171553.

  • Fix is relevant for Gaia 3.10 only.

PRJ-20743,
PMTR-63201

Gaia OS

CVE-2020-25705: ICMP reply rate.

  • Fix is relevant for Gaia 3.10 only.

PRJ-22214,
PRHF-15159

Gaia OS

"show configuration on" may not expose bond members.

  • Fix is relevant for Gaia 3.10 only.

PRJ-13301,
PMTR-63247

VPN

NEW: Added 3 new views to SmartView for Remote Access, providing visibility for Remote Access users, users login summary, failed login attempts, used clients, top login options, number of users, operating systems, authentication methods and login activity.

PRJ-15567

VPN

In some scenarios, NAT-T traffic is sent to the wrong next-hop MAC address.

PRJ-19902,
PRJ-19903,
PRHF-14090

VPN

Mobile Access SNX may fail to connect to the Security gateway when the realm used by the client is different for the SSL VPN realm.

PRJ-18413,
PRJ-16099,
PMTR-62229

VPN

Remote Access VPN policy installation optimization. Refer to sk173947.

PRJ-21762,
PRJ-22178,
PMTR-34300

VPN

In a rare scenario, there may be an incorrect IKE ID in an ID payload with 3rd party peers in IKEv1 and IKEv2.

PRJ-17493,
PRHF-13007

VPN

In IKEv2 renegotiation scenario, IPSec SAs may be deleted on a standby cluster member during post sync causing a VPN traffic outage. Refer to sk172926.

  • Fix is relevant for Gaia 3.10 only.

PRJ-22424,
PRJ-22608,
PRHF-11938

VPN

Tunnel Test packets may be dropped by Secure Configuration Verification (SCV) check when implied rules are disabled. Refer to sk168033.

PRJ-21649,
PRJ-22302,
PRHF-15006

VPN

When static NAT is configured on a destination, the SCV may fail to access the internal resources and "No scv status from client..." drops appear in SmartConsole. Refer to sk171550.

PRJ-19215,
PRHF-13685

VPN

Site to Site VPN fails to establish with IKEv2 on GCP when NAT-t is enabled.

  • Fix is relevant for Gaia 3.10 only.

PRJ-22411,
PRJ-22412,
PMTR-60014

VPN

In some scenarios, L2TP tunnel is not deleted completely upon disconnection.

PRJ-23940,
PRJ-23939,
PRHF-14819

VPN

When the Remote Access is configured to use DHCP for the Office Mode allocation, disconnection of SNX/L2TP clients may cause the IP address not be removed from the table.

PRJ-23301,
PRJ-23302,
PMTR-66146

VPN

In rare scenarios, the vpnd process may unexpectedly exit in an L2TP-related flow.

PRJ-22541,
PRJ-22542,
PRHF-14102

VPN

Added stability fix in validation checks for ECDSA certificates.

PRJ-21259,
VSX-2520

VSX

Allow the addition of routes with specific group of type "Group with Exclusion" when using VSX Provisioning tool.

PRJ-15568

VPN

In some scenarios, NAT-T traffic is sent to the wrong next-hop MAC address.

  • Fix is relevant for Gaia 3.10 only.

PRJ-23827,
PRHF-16241

VSX

In rare scenarios, the Wrp interface may not come up. Refer to sk171753.

  • Fix is relevant for Gaia 3.10 only.

PRJ-20919,
PRJ-20920,
PRHF-14900

QoS

Security Gateway may crash in QoS flow when interface goes down and up during packet processing.