Take 237 - General Availability

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 237

Released on 11 July 2021 and declared as General Availability on 31 August 2021

PRJ-26241,
PRJ-26233

Diagnostics

NEW: Added the Check Point Performance Sizing Utility (CPSizeMe) v5.2.

PRJ-24232,
PRJ-24233,
PMTR-64142

Licensing

UPDATE: If there is no license installed, the error message will be printed when running the cpstart command.

PRJ-24203,
PMTR-67200

Security Management

NEW: Trusted CAs updates for HTTPS Inspection can be configured to be installed automatically upon update. Refer to sk173629.

PRJ-25034,
SMCUPG-1653

Security Management

UPDATE: If there is no license on the Security Management Server, a new verification blocks an attempt to migrate a Domain.

PRJ-31072,
PRHF-19320

Security Management

UPDATE: Added an environmental variable to control the sduu command timeout in the FWM process: SDUU_UPDATE_TIMEOUT.

PRJ-24609,
PRJ-24610,
PMTR-63454

Security Management

Incorrect Mobile Access license status upon a license change.

PRJ-22383,
PRJ-26134,
PRHF-15325

Security Management

User may fail to connect to SmartConsole after the administrator changed the RADIUS server host IP address. Refer to sk172065.

PRJ-19633,
PRHF-14000

Security Management

The Management API command "get-attachment" may fail with an error. Refer to sk170894.

PRJ-26505,
PMTR-69683

Security Management

Policy verification may incorrectly fail with a NAT verification error "The range size of Original and Translated columns must be the same".

PRJ-26192,
PMTR-69529

Security Management

In a rare scenario, the FWM process may unexpectedly unexpectedly exit.

PRJ-21917,
PRHF-15491

Security Management

In some scenarios, the Desktop policy fails with "Policy installation had failed due to an internal error. If the problem persists please contact Check Point support". Refer to sk171970.

PRJ-21398,
PRHF-15001

Security Management

In rare scenarios, deleting an object fails with "Can't reach source object, maybe it already deleted" error. Refer to sk172828.

PRJ-25685,
PRHF-17286

Security Management

In some scenarios, a policy installation failure message may show "ReferenceObject" instead of the actual object's name.

PRJ-24050,
PMTR-66980

Security Management

If the Management Server is up for many days, the CPM process's memory consumption and CPU usage may increase consistently.

PRJ-23883,
PMTR-66708

Security Management

In some scenarios, when updating Check Point Host object to be a Network Policy Management and in addition configuring it as a Secondary Server, "Publish" fails with "Action Failed due to an internal error".

PRJ-22074,
PRHF-15725

Security Management

In rare scenarios, the Management Server may fail to start because Solr fails to initialize.

PRJ-26182,
PRHF-17487

Security Management

When running the "fwm logexport" command multiple times, the FWM process may unexpectedly exit, producing a core file.

PRJ-21966,
PRHF-15471

Security Management

Packet Mode search in rule base ignores matching of inline layer parent rules. In some scenarios, this may retrieve inline layer rules that should not be matched.

PRJ-26192,
PMTR-69529

Security Management

In a rare scenario, the FWM process may unexpectedly unexpectedly exit.

PRJ-24485,
PRHF-16631

Security Management

In very large Management environments, Policy verification and installation may fail with core dump. Refer to sk173722.

PRJ-23937,
CPM-3316

Multi-Domain Management

NEW: Once a day, Multi-Domain Management Servers will check for peers that are not synchronized. If such are identified, HA full sync will be automatically initiated at the MDS level.

PRJ-25890,
PMTR-69154

Multi-Domain Management

NEW: Added ability to create Domain Management Servers with a netmask different than the one of the Multi-Domain Server. Refer to sk173934.

PRJ-25516,
PRJ-25517

Multi-Domain Management

In rare scenarios, in a Multi-Domain environment with active Domains on multiple Multi-Domain Servers, when performing manual HA sync in one Domain, objects from another Domain are not shown in SmartConsole.

PRJ-22637,
PRHF-15727

Multi-Domain Management

In rare scenarios, the Multi-Domain Management Server may fail to start if Domains were previously deleted.

PRJ-24758,
PRHF-16660

Multi-Domain Management

Global Policy Assignments may be missing in Multi-Domain environment after upgrade from R77.x.

PRJ-23696,
PRHF-16119

Multi-Domain Management

Global Policy Reassignment may take a long time to complete after an IPS Update in the Global Domain.

PRJ-25408,
CPM-2542

Multi-Domain Management

In some scenarios, HA synchronization may fail on the MDS level with the "Failed to synchronize this peer due to purged revisions in the database." message.

PRJ-15876,
PRHF-11539

Multi-Domain Management

OS information for Domain Servers may not be shown correctly at the MDS level.

PRJ-26870,
PRHF-17640

SmartConsole

In some scenarios, the gateway hardware change in SmartConsole fails with "Changing the hardware to <New_Selected_Check_Point_Appliance> Appliances is blocked." warning.

PRJ-27299,
PMTR-70643

SmartView

After upgrade, SmartView scheduled export to Excel of Reports and Views stop running and users are unable to edit the scheduled tasks. Refer to sk174047.

PRJ-27070,
PMTR-70430

Compliance

In some scenarios on Multi-Domain environments, Compliance data is not synchronized between primary and secondary Domains.

PRJ-20256,
PMTR-57895

Logging

NEW: Log exporter allows the re-export of logs based on starting and end positions provided by the user, to close possible gaps. Refer to sk122323.

PRJ-21420,
PMTR-61503

Logging

NEW: The Log exporter now supports formatting for RSA SIEM application.

PRJ-25135,
PRHF-17079

Logging

NEW: Added support for JSON format in Log Exporter.

PRJ-25593,
SL-5164

Logging

UPDATE: The Log Server now supports up to 2700 Gateways (previously was 1024). Refer to sk163413.

PRJ-12425,
PRJ-12426,
PRHF-10612

Logging

In some scenarios, exported FireWall logs from a Security Gateway to an external syslog server (sk87560) contain a redundant new line character.

PRJ-16646,
PMTR-58979

Logging

In the SmartConsole Logs tab, the "IKE IDs" field cannot be added to column profiles.

PRJ-23819,
PRHF-12659

Logging

In rare scenarios, when querying logs with a timeframe larger than 1 day, only 50 logs from each day will be shown.

PRJ-24893,
PRJ-24892

Logging

Starting from Jumbo Take 216, logs exported in LogRhythm format via the Log Exporter, appear in an incorrect format.

PRJ-23578,
PMTR-65203

Logging

In some scenarios following a Multi-Domain Management Server upgrade, logs queries may not retrieve results from some CMAs\CLMs.

PRJ-24214,
PMTR-65200

Logging

In Multi-Domain environment, the same Domain may appear twice in the Domains view of the SmartEvent application.

PRJ-23762,
PRHF-16328

Logging

In rare scenarios, SmartConsole may unexpectedly close if the pre-defined VPN columns profile in the Logs view was modified and saved.

PRJ-22965,
PMTR-64536

Logging

In some scenarios, when exporting logs using the Log exporter tool and filtering on all Threat Prevention Blades, logs of the "Anti Spam" Blade are not exported.

PRJ-15230,
PRHF-12075

Logging

In SmartView, when creating a statistical table and grouping by Time, the query may fail.

PRJ-20618,
PRHF-14608

Logging

In SmartView, when filtering with specific time filters, the result may include more logs than was requested.

PRJ-25452,
PMTR-68670

Logging

In rare scenarios, logs generated at the same second, with the same ID, may not show up in SmartConsole's Logs tab.

PRJ-24481,
SL-5577

Logging

When a Management Server manages more than 1024 Gateways, the connectivity status may show "N/A" for several Gateways.

PRJ-25270,
PMTR-68358

Internal CA, VPN, Multi-Portal

UPDATE: The IKE certificate's validity period is set to 1 year by default. Refer to sk176527.

PRJ-26137,
PMTR-69466

Internal CA

UPDATE: Added automatic extension for Internal CA database to support more than 100,000 certificates.

PRJ-26700

Internal CA

Expired certificates cannot be deleted via the ICA Management Tool.

PRJ-21126,
PRJ-21127,
PRHF-13973

Security Gateway

UPDATE: Service with source port in the Access rulebase will no longer disable accept templates for all connections.

PRJ-24375,
PRJ-24376,
SMB-10515

Security Gateway

A memory leak in a DNS resolving I/S may occur.

PRJ-20980,
PRHF-14104

Security Gateway

In rare scenarios, the CPD process unexpectedly exits when the VPN is enabled, and statuses are not sent to the Management Server.

PRJ-23076,
PRJ-23077,
PMTR-65799

Security Gateway

Enhancement: Early drop optimization will work even if the UserCheck is not relevant for this connection.

PRJ-24007,
PRJ-24008,
PRHF-16196

Security Gateway

In rare scenarios, when the "sd_global_monitor_only" property is set to "true", there is no HTTP inspection.

PRJ-23271,
PRHF-15932

Security Gateway

In some scenarios, the "fw ctl affinity" command on MPDS Dplane does not show the Mplane Multi-Queue interfaces.

  • Fix is relevant for Gaia 3.10 only.

PRJ-22622,
PRJ-22623,
PRHF-15835

Security Gateway

In some scenarios, the VSX Cluster switch may cause a core dump.

PRJ-23425,
PRJ-23426,
PMTR-65909

Security Gateway

The VPND process may consume high CPU because of ECDHE use, which affects multi-portal functionality. Refer to sk173145.

PRJ-26374,
PRJ-26375,
PRJ-26257

Security Gateway

In a rare scenario, incorrect error messages regarding the ICAP client flow appear in dmesg.

PRJ-16919,
PRJ-16920,
PRHF-12897

Security Gateway

In rare scenarios, SmartView Monitor shows the "Error code: 2147483647" message when viewing data from a VSX Gateway. Refer to sk174206.

PRJ-24527,
PRJ-24528,
PRHF-16667

Security Gateway

In a rare scenario, the FWK process unexpectedly exits on the Security Gateway.

PRJ-25814,
PRJ-25815,
PRHF-16364

Security Gateway

Added Dynamic Anti-Spoofing stability enhancements.

PRJ-22736,
PRJ-22737,
PRHF-15578

Security Gateway

When Strict Hold is enabled in the fail-open configuration, some HTTPS connections may stuck.

PRJ-23946,
PRJ-23947,
PMTR-66474

Security Gateway

In a rare scenario, Security Gateway may crash when running in USFW (User-Space Firewall) mode.

PRJ-23340,
PRHF-16111

Security Gateway

Boot may take a long time on machines with many VLANs or secondary IP addresses.

  • Fix is relevant for Gaia 3.10 only.

PRJ-25735,
PRJ-25736,
PRHF-16886

Security Gateway

In some scenarios, Security Gateway may crash when ICAP client is enabled.

PRJ-25617,
PRJ-25618,
PRHF-15688

Security Gateway

In a rare scenario, Security Gateway may crash when handling some DNS packets.

PRJ-25907,
PMTR-69241

Security Gateway

In a rare scenario, machine hangs and user is unable to run any command. Refer to sk173405.

PRJ-24124,
PRJ-24125,
PRHF-15896

Security Gateway

RADIUS authentication failure messages are written to SmartConsole logs but not presented to a user. Refer to sk173927.

PRJ-21268,
PRJ-21269,
PMTR-56012

Security Gateway

In some scenarios, emails may be stuck in the MTA queue.

PRJ-24518,
PRJ-24556

Gaia OS

In some scenarios, when adding a "#" in the login banner, the banner becomes corrupted.

PRJ-25390,
PRJ-25391,
PRHF-17173

Security Gateway

In some scenarios, there is no match on URL Filtering rules.

PRJ-25599,
PRJ-25600,
PRHF-12228

Security Gateway

In some scenarios, packets are dropped due to incorrect SACK translation when SACK and sequence translation are being used together.

PRJ-24416,
PRHF-16452

Security Gateway

In a rare scenario, Security Gateway may crash under heavy load during cluster failover.

  • Fix is relevant for Gaia 3.10 only.

PRJ-23846,
PRJ-23847,
PRHF-15781

Security Gateway

In some non-VPN scenarios, MSS Adjustment (Clamping) does not work.

PRJ-26149,
PRJ-26150,
PMTR-69312

Security Gateway

In a rare scenario, a memory leak may occur when IPS / Anti-Bot / Anti-Virus Blade is enabled.

PRJ-25550,
PRJ-25551,
PMTR-67991

Security Gateway

In some scenarios, connections are dropped with the "Virtual defragmentation error: fragment table is full" message. Refer to sk180404.

PRJ-25154,
PRJ-25155,
PMTR-67534

Security Gateway

When running the "fwaccel stats -r" command to reset the SXL statistics, the statistics may become corrupted.

PRJ-27039,
PRJ-27038,
PMTR-67834

Security Gateway

VSX provisioning may fail to commit changes to the VSX database. Refer to sk173683.

PRJ-22945,
PRJ-22946,
PMTR-55080

Security Gateway

In rare scenarios, policy installation fails with "gen_rpc_service_inspect_func: <service name> mismatch in service_arr" error message. Refer to sk174165.

PRJ-23456,
PMTR-66212

Security Gateway

In some scenarios, values set in fwkern.conf file may not be applied correctly.

PRJ-14275,
PRHF-7150

Security Gateway

In some scenarios, SCCP traffic may be dropped by the Security Gateway. Refer to sk108124.

  • Fix is relevant for Gaia 3.10 only.

PRJ-24835,
PRJ-24836,
PRHF-15080

Security Gateway

In some scenarios, when moving Mobile Access from Legacy to Unified Policy, previously configured native application may unexpectedly exit. Refer to sk172935.

PRJ-23063,
PRJ-23064,
PMTR-63142

Security Gateway

Improved displayed drop log messages on the Security Gateway:

  1. To see drops since the last reboot, use the fw ctl drop command.
  2. To see drops in real time, use the CPView tool.

Refer to sk172232.

PRJ-18865,
PRJ-18866,
PRHF-13722

Security Gateway

In rare scenarios, DynamicID authentication fails with "server_code 403 log_msg General HTTP error" message in vpnd.elg. Refer to sk170303.

PRJ-27160,
PRJ-27161,
PRHF-16851

Security Gateway

In rare scenarios, running "fw1 + misp" debug on cluster may cause Security Gateway to crash.

PRJ-26616,
PRJ-26617,
PRHF-17663

Security Gateway

In some scenarios, "[INFO] encode resource in base64 failed" messages generated by the RAD process are shown in /var/log/messages file.

PRJ-26593,
PRJ-26594,
PMTR-70023

Security Gateway

Configuring the "Virtual Activation Timeout" option above 65535 may lead to an incorrect timeout definition.

PRJ-23265,
PMTR-49906

Threat Prevention

In rare scenarios, the "fw load_sigs" command fails to exit appropriately after completing.

PRJ-23775,
PRJ-23927,
PMTR-66261

Anti-Bot

UPDATE: Anti-Bot URL cache was enhanced to support further requests.

PRJ-25746,
PRJ-25747,
PMTR-67597

Identity Awareness

NEW: Added a new Auto-Tune feature for Nested Groups to select the optimal nested state for maximum performance.
The feature is disabled by default. To enable it, refer to sk128212.

PRJ-25388,
PRHF-10292

Identity Awareness

In Identity Awareness Captive portal, the default Check Point logo is displayed even if the user-defined logo is configured. Refer to sk133492.

  • Fix is relevant for Gaia 3.10 only.

PRJ-25923,
PRJ-25924,
PMTR-68088

Identity Awareness

Optimized the PDP expired timers mechanism performance.

PRJ-26229,
PRJ-26231,
IDA-4019

Identity Awareness

When the PDP gateway is connected to multiple pre-R81 PEP gateways, the CPU consumption may be high. Refer to sk173709.

PRJ-26201,
PRJ-25544

Anti-Virus

In a rare scenario, the Security Gateway may crash when working with Anti-Virus.

  • Fix is relevant for Gaia 3.10 only.

PRJ-21769,
PRJ-21770,
PMTR-58795

Application Control

A failure log may be generated when inspecting connections to servers with certificates without a common name (CN) field.

PRJ-24630,
PRJ-24631,
TEX-2201

UserCheck

In rare scenarios, when clicking the "Send Original Mail to me" button (sk140214) in the UserCheck portal for Threat Extraction, action fails with "An unexpected error has occured..." error message.

PRJ-23979,
PRJ-23981,
PRHF-16392

UserCheck

Sensitive file push.js may be visible on the Security gateway.

PRJ-23034,
PRJ-23035,
PMTR-65728

Anti-Malware

In rare scenarios, Security Gateway may crash if event app debug is enabled.

PRJ-23039,
PRJ-23040,
PMTR-65729

Anti-Malware

In a rare scenario, Security Gateway may crash during the Application Control / IPS / Anti-Bot package update.

PRJ-24779,
PRJ-24780,
PRHF-16849

Anti-Malware

In a rare scenario, the Security gateway may crash with the "Problem with the Commit Function" error during policy installation. Refer to sk173248.

PRJ-23297,
PRJ-23299,
PRJ-23295

IPS

UPDATE: Added support for PM statistics when IPS is disabled.

PRJ-25198,
PRJ-25199,
IPS-352

IPS

In some scenarios, the DNS response message with record type 0 may be dropped by "Non compliant DNS" protection.

PRJ-24982,
PRJ-24982,
PRJ-24932

IPS

In a rare scenario, Security Gateway crashes when Threat Prevention Forensic Log feature is enabled.

PRJ-24344,
PRJ-24381,
PRHF-16288

IPS

Improved the HTTP protocol handling.

PRJ-20711,
PRHF-13454

IPS

In rare scenarios, policy installation fails due to duplicate id in IPS Snort protections.

PRJ-19938,
PRJ-19939,
PMTR-58379

SSL Inspection

UPDATE: Avoid sending the TLS probe during inbound inspection when it is not necessary for the SNI-based categorization.

PRJ-21689,
PRJ-21691,
PMTR-63310

SSL Inspection

UPDATE: Avoid sending the TLS probe during the inbound inspection when a rule is matched according to the IP address.

PRJ-20678,
PRJ-20679,
PRHF-14540

SSL Inspection

A table hash size may be too small for some environments and cause an increased CPU usage.

PRJ-26742,
PRJ-26743,
PRHF-4657

SSL Inspection

Added an option to bypass Name Constraints extension on certificates using a registry flag. Refer to sk159692.

PRJ-19854,
PRJ-19855,
PMTR-61029

SSL Inspection

TLS probing failures generate logs with a general description in SmartLog: "Internal system error in HTTPS Inspection (Error Code: 2)". With this fix, more descriptive logs will be generated.

PRJ-24460,
PRJ-24470,
PMTR-65718

SSL Inspection

In some scenarios, memory leaks may occur after policy installation.

PRJ-24467,
PRJ-24469,
PMTR-66181

SSL Inspection

In rare scenarios, the WSTLSD daemon may unexpectedly exit during TLS probing.

PRJ-25177,
PRJ-25192,
PRHF-14178

SSL Inspection

In some scenarios, when HTTPS Inspection is enabled, overall memory consumption may gradually increase. Refer to sk171280.

PRJ-24666,
PRJ-24204

ClusterXL

The Gaia Clish command "set snmp traps trap clusterXLFailover enable" fails with "Bad Command Unknown Trap name." Refer to sk173810.

  • Fix is relevant for Gaia 3.10 only.

PRJ-24143,
PRJ-24144,
PMTR-67140

SecureXL

UPDATE: Firewall debug drop template message now indicates the rule ID the template was created from.

PRJ-24650,
PRJ-24651,
PMTR-67738

SecureXL

In some scenarios, the "reached the limit of maximum enqueued packets!" log is printed in the /var/log/messages file.

PRJ-17459,
PRJ-17460,
PRHF-13183

SecureXL

SecureXL keeps forwarding packets in VSX bridge mode when the member is down. Refer to sk169495.

PRJ-23458,
PRJ-23459,
PRHF-16084

SecureXL

A race condition in the DOS/Rate limiting policy's install logic may cause incorrect counter values for "concurrent-conns".

PRJ-22788,
PRJ-22789,
PMTR-65162

SecureXL

In a rare scenario, Security Gateway may crash after running the "fwaccel tab -t connections" command.

PRJ-25509,
PRHF-16656

SecureXL

In a rare scenario, Security Gateway may crash when generating CPInfo in VSX mode.

  • Fix is relevant for Gaia 3.10 only.

PRJ-27222,
PRJ-27223,
PRHF-17921

SecureXL

In some scenarios, SYN Defender log messages in SmartConsole show "*** MISSING ***" instead of the real log.

PRJ-24539,
PRJ-24540,
PMTR-67556

SecureXL

In a VSX environment, the SYN Defender configuration may not be applied correctly.

PRJ-27224,
PRHF-17734

SecureXL

Invalid VLAN traffic may cause repeated "deliver_list is empty!!!" error messages in the /var/log/messages file.

  • Fix is relevant for Gaia 3.10 only.

PRJ-24475,
PRJ-24476,
PRHF-16658

Routing

UPDATE: Allow "set bgp internal peer <value> send-route-refresh" commands.

PRJ-16532,
PMTR-54703

Routing

UPDATE: User does not have to enable logging/accounting in SmartConsole to generate the Netflow records. New "NetFlow Firewall rule" option was added to configure NetFlow to report per Firewall rule by turning it on and enabling Log/Accounting per rule.

PRJ-23247

Routing

VRRP member freezes when deleting a VLAN interface. Refer to sk106226.

PRJ-24789,
PMTR-48384

Routing

In some scenarios, OSPF configured with unnumbered VTI on cluster frequently moves between "Full" and "EXSTART" status.

PRJ-24714,
PRJ-24715,
PRHF-16801

Routing

In OSPF environment, the ROUTED process may unexpectedly exit when a VPN tunnel is flapped leading to a temporary connectivity loss.

PRJ-24968,
PRJ-24969,
PMTR-48361

Routing

Graceful restart has been enhanced to tolerate a non-standard behavior by peers of closing BGP connection before getting established.

PRJ-25040,
PRJ-25043,
PRHF-16981

Routing

In a rare scenario, the ROUTED process unexpectedly exits when creating an MFC (S,G) entry. Refer to sk176685.

PRJ-25993,
PRJ-25994,
PMTR-69290

Routing

In some scenarios, the monitored IP option "force-if-symmetry" does not detect the asymmetric ping properly.

PRJ-24386,
PRJ-24387,
MBS-12759

Routing

In rare scenarios, a Load Sharing cluster can experience DHCP relay drops with the "dropped by fw_post_vm_chain_handler Reason: Handler 'dhcp_reply_code' drop" message.

PRJ-25316,
PRJ-25317,
PMTR-68232

Routing

In some scenarios, CPView displays incorrect values of RIP statistics.

PRJ-27043,
PRJ-27045,
PMTR-57379

Routing

The ROUTED process with Ping enabled always gets reset during Clish reconfiguration.

PRJ-26967,
PRJ-26968,
PMTR-66574

Routing

In some scenarios, the ROUTED process may produce a core dump when it receives IGMPv3 Membership Reports over a long period of time.

PRJ-27057,
PRJ-27058,
PRHF-17925

Routing

In some scenarios, the ROUTED process may unexpectedly exit when there is a static route and a kernel route to the same destination.

PRJ-25914,
ROUT-1502

Routing

NetFlow packets are sent from the individual VS IP address instead of VS0.

  • Fix is relevant for Gaia 3.10 only.

PRJ-23090,
PRJ-23091,
PRHF-12121

Mobile Access

In some scenarios, FWK process unexpectedly exits due to SNX authorization timeout in MAB's Unified Policy mode. Refer to sk173125.

PRJ-22330,
PRJ-22331,
PMTR-21454

Mobile Access

In some scenarios, the VPND process unexpectedly exits in SNX Application Mode.

PRJ-23722,
PMTR-60065

Mobile Access

Remote Access session may not be synced on the standby member VS.

  • Fix is relevant for Gaia 3.10 only.

PRJ-23729,
PRJ-23730,
PRHF-16302

Mobile Access

In some scenarios, when configuring the "X-Forwarded-For" header to MAB reverse proxy, the header is passed in reverse order.

PRJ-22804,
PRJ-22805,
SNX-61

Mobile Access

When the administrator adds more than 30 native applications, users may fail to connect via SSL Network Extender Application mode.

PRJ-25219,
PRJ-25220,
PRHF-17088

Mobile Access

Improved the Portal Rendering performance in Unified Policy mode.

PRJ-24685,
PRHF-16135

Mobile Access

In some scenarios, the HTTPD process consumes a high CPU causing slowness in access to web applications.

PRJ-24815,
PRJ-24814,
VPNS2S-2313

VPN

UPDATE: Added VPN improvements in IKEv2:

  • Added support for IKEv2 authentication when using multiple certificates.
  • Added support for "Matching info" authentication.

PRJ-24917,

PRJ-24933,

VPNS2S-2235

VPN

UPDATE:

  • Improved Site to Site VPN stability when it is configured with NAT.

  • Enabled the global parameter "offer_nat_t_initator" by default. Refer to sk32664.

 

VPNS2S-2313

VPN

"Invalid ID information" message may be displayed when peer is 3rd party and Link selection is overridden.

VPNS2S-2313

VPN

IKEv2 may cause the VPND process to unexpectedly exit when IKEv2 rekey uses certificates.

VPNS2S-2313

VPN

  • Stability improvement of IKEv2 rekey when using Pre-shared-key
  • Stability improvement of cluster synchronization mechanism

PRJ-25051,
PRJ-25052,
PRHF-16121

VPN

In some scenarios, user may not be able to connect because the VPND process unexpectedly exits.

PRJ-25131,
PRJ-25132,
PMTR-68208

VPN

In some scenarios, the VPN Remote Access client cannot reconnect after changing the authentication method.

PRJ-21940,
PRJ-21941,
PRHF-15509

VPN

In some scenarios, VPN Remote Access users are disconnected after policy installation. Refer to sk171966.

PRJ-24250,
PRJ-24251,
PRHF-15984

VPN

In some scenarios, the TTM (Transform Template) file is not loaded when there are no TTM groups for the user.

PRJ-14270,
PRJ-14271,
PRHF-9691

VPN

Added IKE improvement for DAIP peer with ID_DER_ASN1_DN ID type.

PRJ-24400,
PRJ-24401,
PRHF-16421

VPN

In some scenarios, DAIP gateways may be identified as Remote Access, causing the connection to fail. Refer to sk173417.

PRJ-25487,
PRJ-25488,
PMTR-68687

VPN

In VSX environments, Anti-Spoofing in SecureXL may cause Remote Access VPN drops. Refer to sk173266.

PRJ-24858,
PRJ-24859,
PRHF-16883

VPN

The VPND process may unexpectedly exit when cipher priority configuration is invalid. Refer to sk173083.

PRJ-23972,
PRJ-23973,
PMTR-65986

VPN

In some scenarios, the IKED process unexpectedly exits producing a core dump.

PRJ-22526,
PRJ-22527,
PMTR-64500

VPN

When Multiple Factor Authentication is configured with DynamicID , VPN clients may receive four password prompts. Refer to sk144932.

PRJ-26202,
PRJ-26203,
PMTR-68557

VPN

MEP failover with 3rd party vendors may not work correctly.

PRJ-26339,
PRJ-26340,
PMTR-69135

VPN

In some scenarios, Phase 2 NULL encryption in IKEv2 fails with "Received notification from peer: No proposal chosen" message in the log.

PRJ-25334,
PRJ-26237,
VPNS2S-2335

VPN

In some scenarios, the "Illegal sequence number" error may be printed in Dead Peer Detection (DPD) debug.

PRJ-26265,
PRJ-26266,
PMTR-68840

VPN

In some scenarios in MEP configuration, failover to available MEP members may fail.

PRJ-26933,
PRJ-26932,
PMTR-70367

VPN

In some scenarios, the VPND process unexpectedly exits after installing the policy.

PRJ-27738

VPN

In some scenarios, NAT-T traffic is sent to the wrong next-hop MAC address.

  • Fix is relevant for Gaia 3.10 only.

PRJ-26621,
PRJ-26622,
PRHF-17733

VPN

Added VPN stability improvement in IKEv2.

PRJ-25983,
PRJ-25984,
PMTR-65599

VPN

In rare scenarios, IKE negotiation fails when using IPv6 addresses.

PRJ-25310,
PRJ-25311,
PRHF-17101

VPN

In rare scenarios, all traffic is dropped with "Rulebase Internal Error" in SmartLog.

PRJ-24804,
PRJ-24806,
PRHF-16698

VPN

Site to Site VPN connectivity issue when NAT is enabled.

PRJ-26440,
PRJ-26441,
PMTR-69836

VPN

In rare scenarios, a memory leak related to gateway authentication may occur.

PRJ-26438,
PRJ-26437,
PRHF-2715

VPN

In a rare scenario, a memory leak may occur when RASession_util is active.

PRJ-26431,
PRJ-26432,
PMTR-69479

VPN

In a rare scenario, the IKED process stops with core dump when using Office Mode IP allocation for clients and users cannot connect.

PRJ-21428,
PRJ-21429,
PRJ-21430,
PRJ-21424

Gaia OS

NEW: Added support for hardware (sensors/NICs) data auto-update.

PRJ-25670,
PRHF-16999

Gaia OS

In some scenarios, the driver's (i40e) response time for MQ settings takes a too long time.

  • Fix is relevant for Gaia 3.10 only.

PRJ-26111,
PRJ-24594,
PRJ-24595,
PRHF-16780

Gaia OS

When the RADIUS server uses a multi-pool "Access Challenge", the system sends many authentication requests without waiting

PRJ-24492,
PRHF-16665

Gaia OS

In a rare scenario, the Security Gateway may become unresponsive. Refer to sk172827.

  • Fix is relevant for Gaia 3.10 only.

PRJ-24508

Gaia OS

In some scenarios, when adding a "#" in the login banner, the banner becomes corrupted.

  • Fix is relevant for Gaia 3.10 only.

PRJ-24371,
PRJ-25003,
PRJ-24372,
PMTR-49877

Gaia OS

In some scenarios, the force-password-change option does not work.

PRJ-23965,
PRHF-16338

VSX

UPDATE: Added ability to change the Management and Sunc interfaces via vsx_util change_interfaces.

PRJ-25022,
PRJ-25023,
PRHF-14371

VSX

In some scenarios, the "cpstat vsx" command does not show the correct output. Refer to sk170793.

PRJ-5187,
PMTR-32931

VSX

In some scenarios during shutdown, the FWK process may unexpectedly exit producing a core dump when VSX gateway is upgraded to R80.30.

PRJ-25726,
PRJ-25727,
PMTR-68887

QoS

A memory leak may occur when using domain names in QoS policy rules. Refer to sk174904.

PRJ-24289,
ODU-83

Smart-1 Cloud

Added Update #1 of Quantum Smart-1 Cloud. Refer to sk166056.

PRJ-25384,
PRHF-17170

CloudGuard IaaS

CloudGuard Controller with Cisco ACI Data Center sends updates without IP addresses to Security Gateways.

PRJ-23351,
PRHF-13883

CloudGuard IaaS

The SNMP response may show incomplete values.

PRJ-21719,
PMTR-64430

CloudGuard Azure

Improved performance consistency (with Multi-Queue) after the Microsoft Azure Maintenance event.