R80.40 Jumbo Hotfix Take 100

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 100

Released on 17 March 2021

PRJ-21006,
PRHF-14969

Security Management

NEW: Improved FWM process performance during Security policy or database installation.

PRJ-20072,
MCFG-229

Security Management

NEW: Optimized the Solr build time to improve performance in the following operations:

  • Restore of the entire MDS/MLM from backup
  • Upgrade from R80.10
  • Solr Cure

PRJ-20031,
PMTR-61770

Security Management

UPDATE: When purging revisions, task notifications will also be purged if created before the last revision to purge was published.

PRJ-20450,
SMCUPG-1563

Security Management

UPDATE: Added validation to block migration of a Domain to a Security Management if the Domain is assigned to the Global Domain.

PRJ-21872,
ODU-82

Security Management

UPDATE: Added Update 8 of Autonomous Threat Prevention Management (ATPM). Refer to sk167109.

PRJ-20855,
SMCUPG-1316

Security Management

Management Server upgrade from R80.20 to R80.40 may fail if a Network Interface object refers to a Gateway object that does not exist.

PRJ-20842,
SMCUPG-1454

Security Management

When migrating a Domain Management Server to a Security Management Server:

  • SmartEvent Blade cannot be activated on the migrated domain.
  • If the Domain had standby Domain Servers, it may cause inconsistencies in the database, that may result in different failures. For example, policy installation may fail.

PRJ-20304,
PRHF-14634

Security Management

In some scenarios, deleting a Domain Server may fail with "Got at least one duplicate UID in requested list" error.

PRJ-21586,
PRHF-15222

Security Management

In rare cases, the CPM Solr process may not be stopped when running cpstop or mdsstop.

PRJ-16926,
PMTR-58592

Security Management

Migrate of Security Management to a Domain on a Multi-Domain Server may fail if a previous migration attempt of the same Security Management already failed and a different Domain name was used for the second attempt.

PRJ-20765,
PRHF-14399

Security Management

High load may occur on the Management Server when searching for a prefix of IP address that has more than 10 thousand matches.

PRJ-20995

Security Management

In rare scenarios, the initiation of the Management server may take a long time.

PRJ-21359,
PRHF-14606

Security Management

In some scenarios, the Purge Revisions task may stop and show 0% for hours or fail with the "An error has occurred while performing revision purge operation" message in SmartConsole.

PRJ-21591,
PRHF-15244

Security Management

Although the Access Settings of the Management API is set to "All IP addresses", the API server does not accept requests from any IP address unless the IP is defined explicitly as a Trusted Client.

PRJ-17789,
PRHF-13382

Security Management

In some scenarios, policy verification for static NAT rules succeeds even though the source subnet NAT is bigger than the destination subnet NAT.

PRJ-20887,
PRHF-14946

Security Management

In some scenarios, when connecting to an existing session in SmartConsole from a different IP address, a wrong "Client IP" is shown in Audit Logs view.

PRJ-20804,
PRHF-14691

Security Management

In some scenarios, delete partial domain with createDomainRecovery.sh script fails when there are several RadiusGroup objects with the same name in different domains.

PRJ-15744

Multi-Domain Management

UPDATE: When running Reassign Global Domain for a Domain that is active on another Multi-Domain Server, the task is immediately relayed to the remote Multi-Domain Server without waiting in queue of the local server due to other tasks that are running.

PRJ-21275,
SMCUPG-1625

Multi-Domain Management

In some scenarios, HA Full Sync on the System Domain fails after upgrade on a Multi-Site environment with multiple Multi-Domain Servers. Refer to sk171059.

PRJ-19995,
PRHF-14349

Multi-Domain Management

After importing two (or more) Security Management servers into a Multi-Domain Server, the Gateway objects may not be functional:

  • The editor may not show configuration correctly
  • Security Gateway update may fail.

PRJ-16910,
PRJ-21342

Multi-Domain Management

When running many Reassign Global Domain operations for Domains that are not active on the current Multi-Domain Server, the load on the Server may increase and result in slowness of user and automation work.

PRJ-21213,
PMTR-60619

Multi-Domain Management

Migration of a Domain assigned to a Global Domain may fail with the "Dynamic object: not found" error.

PRJ-22276,
PMTR-65110

Multi-Domain Management

In some scenarios, updating a Domain Server may fail with the "<IP> already in use" message. Refer to sk171916.

PRJ-19721,
PMTR-62272

Multi-Domain Management

The Multi-Domain session APIs "view sessions" and "show last-published-session" results may include sessions that were not filtered according to the administrator's permissions profile.

  • A Domain manager running the API will be notified when the results will be filtered and will be asked to run the command again with the "ignore-warnings" flag.

PRJ-20786,
PRHF-13556

SmartConsole

When the user creates an Access Role, the AD organization tree may show duplicate branches, and some branches may be missing.

PRJ-20951,
PMTR-62383

SmartConsole

After a network interface is removed by cluster API, a network group assigned to that interface remains as used by cluster members and cannot be deleted.

PRJ-20910,
PMTR-63302

SmartConsole

In some scenarios, deleting a policy fails.

PRJ-21389,
PMTR-63149

SmartConsole

Slowness may be observed in some SmartProvisioning operations (like open SmartProvisioning GUI, create a new LSM object, open an LSM object editor, etc.).

PRJ-20240,
PRHF-14533

SmartConsole

When there are no search results, search in Access Control Policy displays "An error occurred while searching" instead of "No Items Found".

PRJ-20315,
PRHF-14637

SmartConsole

In some scenarios, the "show gateways-and-servers" Management API command fails when running it with details-level full and when connected to the Global Domain. Refer to sk170895.

PRJ-19141,
PRHF-14010

SmartConsole

In some scenarios, the "add-user" API command with authentication method TACACS+ or RADIUS Server fails with "object not found" message. Refer to sk170325.

PRJ-19931,
PRHF-14278

SmartConsole

In rare scenarios, the "Show Policy Package" tool and some Management API commands with details-level "full" may fail when UTM cluster is part of the policy targets.

PRJ-21525

SmartConsole

In a rare scenario, Automatic NAT rules are not visible in SmartConsole.

PRJ-18922,
PRHF-13879

SmartConsole

In some scenarios, the "show-access-rulebase" Management API command fails when running it with details-level "full" and there is a network group with more than 50000 objects on one of the rules. Refer to sk170435.

PRJ-21159,
PMTR-63555

SmartConsole

If there is an HTTPS Inspection layer that is not used in the policy, policy installation may fail with the "Internal error" message.

PRJ-20874,
PMTR-62957

SmartView

UPDATE: To improve performance, SmartView now exports data in CSV format instead of Excel.

PRJ-18860,
SL-4613

Logging

NEW: Added support for Endpoint Forensics reports to get-attachment API.

PRJ-12202,
PRHF-10306

Logging

In some scenarios, the "Failed to fetch the file" error is displayed when trying to open Threat Emulation summary reports generated by VSX Gateways.

PRJ-20563,
PMTR-58714

Logging

In rare scenarios, the Log Exporter fails to connect to external destination when using the TLS protocol.

PRJ-17356,
PMTR-59205

Logging

FWM and\or log_indexer processes may repeatedly stop when there are more than ~500K network objects declared. Refer to sk164452.

PRJ-21155,
PRJ-21078

Logging

In rare scenarios, the FWD process on the Security gateway may be blocked for several seconds due to processing of log attachments.

PRJ-10292,
PRHF-7415

Logging

In rare scenarios, a log may display incorrect values in the Action and Rule field. Refer to sk170676.

PRJ-19010,
PRHF-13936

Logging

In a rare scenario, CPD process may use a random port for AMON communication instead of port 18196.

PRJ-20091,
PRHF-13973

Security Gateway

UPDATE: Service with source port in the Access rulebase will no longer disable accept templates for all connections.

PRJ-18487,
PMTR-61165

Security Gateway

In some scenarios, repeating "fwx_alloc_global_find_free_port_atomic: rtsp pending port doesn't match the same pool" errors are displayed in dmesg when using Hide NAT with VoIP.

PRJ-19585,
PMTR-61102

Security Gateway

In some scenarios, "email_unified_cmi_get_attribs: not valid caller: up_log_get_user_hash" error appears in dmesg for SMTP traffic.

PRJ-19704,
PMTR-62215

Security Gateway

In rare scenarios, a memory leak may occur in TOPOD process.

PRJ-19851,
PRHF-14268

Security Gateway

In some scenarios, a memory leak may appear after sending a packet from the kernel.

PRJ-20900,
PRHF-14824

Security Gateway

In some scenarios, the DNS requests from the Security gateway may fail.

PRJ-20632,
PRHF-14378

Security Gateway

In rare scenarios, high memory consumption in CPD may occur due to a memory leak in authentication flow with an LDAP server.

PRJ-20655,
PMTR-63092

Security Gateway

Accept logs with reason "Connection terminated before detection: Insufficient data passed. To learn more see sk113479." may be wrongly generated when the matched action is user authentication and wrong username/password provided by user.

PRJ-20955,
PRJ-20953

Security Gateway

In some scenarios, logs with incorrect action are generated by ICAP server.

PRJ-20385,
PRHF-13431

Security Gateway

In a rare scenario, Access Control policy installation may fail after upgrade of Security Gateway from R80.10 or below to R80.20 or higher.

PRJ-21111,
PRHF-14953

Security Gateway

Authentication may fail when LDAP branch name contains "\".

PRJ-11205,
PRHF-9029

Security Gateway

In some scenarios, traffic that is matched on implied rule is dropped while it should not.

PRJ-21021,
PRHF-12746

Security Gateway

In rare scenarios, proxy ARP entries may be deleted when installing a policy.

PRJ-21361,
PMTR-52835

Security Gateway

Traffic may be dropped when the Hide NAT is configured on IPv6 host.

PRJ-20340,
PRHF-14616

Security Gateway

In rare scenarios, passive FTP packets may be dropped.

PRJ-19307,
TEX-1906

Threat Extraction

UPDATE: Threat Extraction (Sanitization) will be automatically disabled when Infinity Threat Prevention mode is installed while the machine does not have enough resources (RAM).

PRJ-17874,
PRHF-10279

HTTPS Inspection

UPDATE: "Categorize HTTPS websites" feature enhancements when "Categorize HTTPS Sites" feature is enabled:

  • Improved enforcement of first connection when URL Filtering setting is 'Hold' mode
  • Added SNI information to connection logs when connection is matched on rule with "Extended Log"
  • Hold mode granularity

For configuration, refer to sk173633.

PRJ-20407,
PMTR-52421

Identity Awareness

NEW: Added the Identity Awareness performance and memory consumption improvements. Refer to sk170516.

PRJ-20862,
IDA-3642

Identity Awareness

In some scenarios, there may be enforcement issues for MUHv2 users due to table mismatch.

PRJ-23655,
PRHF-10292

Identity Awareness

In Identity Awareness Captive portal, the default Check Point logo is displayed even if the user-defined logo is configured. Refer to sk133492.

PRJ-20847,
PRHF-14347

Identity Awareness

In some scenarios, running pdpd commands results in "daemon did not respond or not running!" error. Refer to sk171136.

PRJ-20348,
PRHF-14266

IPS

In a rare scenario, the SmartConsole shows the "IPS is not responding" message even though IPS is functioning normally.

PRJ-20096,
PMTR-59101

DLP

UPDATE: Added support for multi-part data to DLP.

PRJ-20838,
PRHF-14744

DLP

Improved DLP scanning for POST request to some Web sites.

PRJ-18842,
PRHF-13322

SSL Inspection

In rare scenarios, a memory leak may occur during policy installation.

PRJ-20936,
PRHF-14978

SSL Inspection

The AES-NI (Intel Advanced Encryption Standard New Instructions) status is not displayed and "dmesg | grep AES-NI" returns no output. Refer to sk170779.

PRJ-18596,
PRHF-13478

Anti-Malware

In a rare scenario, Security gateway may crash when the Threat Prevention Forensics feature is enabled.

PRJ-20976,
PRHF-14820

Anti-Malware

In rare scenarios, the Threat Prevention policy installation fails due to IoC parsing errors. Refer to sk171316.

PRJ-19041,
PRHF-13886

UserCheck

In some scenarios, users cannot restore original attachment via UserCheck portal and receive the "An unexpected error has occurred" error message.

PRJ-19204,
PRHF-13935

ClusterXL

UPDATE: Added the option to display only monitored interfaces to "show cluster members <option>" command>:

  • In Gaia Clish, run "show cluster members monitored"
  • In Expert mode, run "cphaprob -m tablestat"

PRJ-20535,
PRHF-14728

ClusterXL

In some scenarios, data connections are dropped with "First packet isn't SYN" message on ClusterXL Load Sharing.

PRJ-19392,
PRHF-14115

ClusterXL

"set router active-active-mode" settings do not survive a reboot.

PRJ-19925,
PMTR-58748

ClusterXL

In rare scenarios, running cphastop;cphastart may cause a cluster member to stay in "Down" state.

PRJ-16516,
MBS-11708

SecureXL

NEW: Added the ability to enable monitor-only mode for penalty box independently of other DOS/Rate limiting features.

PRJ-18323,
PRHF-13474

SecureXL

UPDATE: Drop templates can be generated for connections with matched action Reject. For additional information and configuration, refer to sk171146.

PRJ-19664,
PRHF-13929

SecureXL

In some scenarios, connections are dropped when SYN Defender and ISN Defender are both enabled on the same interface.

PRJ-17404,
PRHF-13153

SecureXL

In some scenarios, PPTP or GRE traffic may be dropped. Refer to sk170293.

PRJ-19406,
PMTR-60870

SecureXL

In some scenarios, Rate Limiting rules for DoS do not work after reboot. Refer to sk170148.

PRJ-15662,
PMTR-57216

Routing

UPDATE: Display of routing CPview results is limited to 30 lines.

PRJ-18662,
PRJ-18663

Routing

UPDATE: Added support for Check Point Active Streaming (CPAS), Policy-Based Routing (PBR), and Application-Based Routing (ABR) on the Security Gateway. Refer to sk167135.

PRJ-19629,
PRHF-14280

Routing

ip-reachability-detection ping marks a target IP address as "unreachable" if the path goes via a VPN tunnel, although pinging this IP address directly works.

PRJ-20964,
VSX-2519

VSX

After running "vsx_util vsls" and selecting option #6, the operation may fail with the "Internal Error: got empty reply set" error. Refer to sk171352.

PRJ-20149,
PRHF-14537

VSX

In rare scenarios, some interfaces remain in "Down" state after reboot.

PRJ-15447,
PMTR-55887

VSX

In some scenarios, there may be high CPU utilization in a VSX environment with several instances.

PRJ-15550,
PRHF-11629

VPN

UPDATE: Added the TTM-per-group feature improvement that allows it to work with more client types (for example Nemo client).

PRJ-17494,
PRHF-13007

VPN

In IKEv2 renegotiation scenario, IPSec SAs may be deleted on a standby cluster member during post sync causing a VPN traffic outage. Refer to sk172926.

PRJ-19424,
PRHF-13784

VPN

In some scenarios, the vpnd process unexpectedly exits with Segmentation fault.

PRJ-18271,
PRHF-13543

VPN

The VPND process on a standby cluster member may unexpectedly exit when VPN peer has a probing link selection configured. Refer to sk170136.

PRJ-20414,
PRHF-14429

VPN

In some scenarios, the IKE QM negotiating issue with Windows Server 2008 R2 peer may occur.

PRJ-20522,
PRHF-14766

VPN

In a rare scenario, the FWM process unexpectedly exits when enrolling a certificate using the SCEP protocol.

PRJ-13821,
PRHF-10420

VPN

Access roles do not recognize Remote Access SNX CLI clients.

PRJ-20868,
PMTR-56565

VPN

In some scenarios, the VPND process keeps re-downloading the same CRL, which can cause performance issues.

PRJ-12242,
PRHF-10370

VPN

When clicking "View" in Trusted CA object's OPSEC PKI tab, this may show the "Failed to get a certificate of <object name> from keyset" error. Refer to sk166496.

PRJ-20948,
PMTR-63287

VPN

In some scenarios, L2TP clients disconnect from the Security gateway after 10 minutes of the connection.

PRJ-20644,
PMTR-63280

VPN

In some scenarios, the VPND process may unexpectedly exit.

PRJ-19216,
PRHF-13685

VPN

Site to Site VPN fails to establish with IKEv2 on GCP when NAT-t is enabled.

PRJ-20542,
PMTR-62883

Gaia OS

UPDATE: OpenSSL was updated to version 1.1.1i to include the latest code fixes and security improvements.

PRJ-19146,
PMTR-55383

Gaia OS

UPDATE: Added the option to bind IP addresses to sockets using the udp_connect API. Refer to sk171019.

PRJ-20958,
GAIA-6704

Gaia OS

UPDATE: Added support for multiple commands definition in Dynamic CLI feature.

PRJ-11114,
PMTR-50378

Gaia OS

UPDATE: Updated the arp table limit to 131072 in:

  • "set arp table" maximum entries through WebUI
  • Help description of "set arp table cache-size" in CLI

PRJ-18091,
PRHF-13475

Gaia OS

Messages log level in /var/log/messages file for ERR level was changed to INFO level when fetching proxy configuration from Clish/WebUI/Gaia API.

Example: [DATE TIME] <daemon.err> ... xpand[25958]: proxy_live_get_proc: Started...

PRJ-20045,
PMTR-55456

Gaia OS

Potential command injection in Clish when using the "show file" command.

PRJ-17319,
PRA-1520

Gaia OS

The syslog messages may be spammed when the "show asset all" command is running.

PRJ-19624,
PMTR-58288

Gaia OS

Extended commands are missing after adding Dynamic CLI.

PRJ-20741,
PMTR-63201

Gaia OS

CVE-2020-25705: ICMP reply rate.

PRJ-16259,
PRHF-5016

Gaia OS

A Timestamp in Unix/Epoch time may not be updated when the user changes a password using hash.

PRJ-20916,
PMTR-58250

Gaia OS

In some scenarios, like defected LOM card, or when LOM port exists, but no LOM is connected, the confd process may unexpectedly exit.

PRJ-19236,
PRHF-14046

Mobile Access

There may be a delay when connecting to HTTPS based SMS portal over a non-standard proxy port. Refer to sk170497.

PRJ-20090,
PRJ-19772

Endpoint Security

Database size may increase exponentially because dynamic packages are packed into exported .tgz using migrate_export.

PRJ-21749,
PMTR-60418

Endpoint Security

On the SmartEndpoint Reporting page, the "Endpoint Connectivity" report that is filtered by a virtual group returns an empty list.

PRJ-21914,
PMTR-50113

Endpoint Security

In some scenarios, the "Endpoint Security Client Version" report shows "N/A" in DAT Date column for all devices on the SmartEndpoint Reporting page.

PRJ-19312,
PRHF-13909

CloudGuard Network

When creating a GCP Data Center, Test Connection may fail on large GCP accounts.