R80.40 Jumbo Hotfix Take 100
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 100 Released on 17 March 2021 |
||
PRJ-21006, |
Security Management |
NEW: Improved FWM process performance during Security policy or database installation. |
PRJ-20072, |
Security Management |
NEW: Optimized the Solr build time to improve performance in the following operations:
|
PRJ-20031, |
Security Management |
UPDATE: When purging revisions, task notifications will also be purged if created before the last revision to purge was published. |
PRJ-20450, |
Security Management |
UPDATE: Added validation to block migration of a Domain to a Security Management if the Domain is assigned to the Global Domain. |
PRJ-21872, |
Security Management |
UPDATE: Added Update 8 of Autonomous Threat Prevention Management (ATPM). Refer to sk167109. |
PRJ-20855, |
Security Management |
Management Server upgrade from R80.20 to R80.40 may fail if a Network Interface object refers to a Gateway object that does not exist. |
PRJ-20842, |
Security Management |
When migrating a Domain Management Server to a Security Management Server:
|
PRJ-20304, |
Security Management |
In some scenarios, deleting a Domain Server may fail with "Got at least one duplicate UID in requested list" error. |
PRJ-21586, |
Security Management |
In rare cases, the CPM Solr process may not be stopped when running cpstop or mdsstop. |
PRJ-16926, |
Security Management |
Migrate of Security Management to a Domain on a Multi-Domain Server may fail if a previous migration attempt of the same Security Management already failed and a different Domain name was used for the second attempt. |
PRJ-20765, |
Security Management |
High load may occur on the Management Server when searching for a prefix of IP address that has more than 10 thousand matches. |
PRJ-20995 |
Security Management |
In rare scenarios, the initiation of the Management server may take a long time. |
PRJ-21359, |
Security Management |
In some scenarios, the Purge Revisions task may stop and show 0% for hours or fail with the "An error has occurred while performing revision purge operation" message in SmartConsole. |
PRJ-21591, |
Security Management |
Although the Access Settings of the Management API is set to "All IP addresses", the API server does not accept requests from any IP address unless the IP is defined explicitly as a Trusted Client. |
PRJ-17789, |
Security Management |
In some scenarios, policy verification for static NAT rules succeeds even though the source subnet NAT is bigger than the destination subnet NAT. |
PRJ-20887, |
Security Management |
In some scenarios, when connecting to an existing session in SmartConsole from a different IP address, a wrong "Client IP" is shown in Audit Logs view. |
PRJ-20804, |
Security Management |
In some scenarios, delete partial domain with createDomainRecovery.sh script fails when there are several RadiusGroup objects with the same name in different domains. |
PRJ-15744 |
Multi-Domain Management |
UPDATE: When running Reassign Global Domain for a Domain that is active on another Multi-Domain Server, the task is immediately relayed to the remote Multi-Domain Server without waiting in queue of the local server due to other tasks that are running. |
PRJ-21275, |
Multi-Domain Management |
In some scenarios, HA Full Sync on the System Domain fails after upgrade on a Multi-Site environment with multiple Multi-Domain Servers. Refer to sk171059. |
PRJ-19995, |
Multi-Domain Management |
After importing two (or more) Security Management servers into a Multi-Domain Server, the Gateway objects may not be functional:
|
PRJ-16910, |
Multi-Domain Management |
When running many Reassign Global Domain operations for Domains that are not active on the current Multi-Domain Server, the load on the Server may increase and result in slowness of user and automation work. |
PRJ-21213, |
Multi-Domain Management |
Migration of a Domain assigned to a Global Domain may fail with the "Dynamic object: |
PRJ-22276, |
Multi-Domain Management |
In some scenarios, updating a Domain Server may fail with the "<IP> already in use" message. Refer to sk171916. |
PRJ-19721, |
Multi-Domain Management |
The Multi-Domain session APIs "view sessions" and "show last-published-session" results may include sessions that were not filtered according to the administrator's permissions profile.
|
PRJ-20786, |
SmartConsole |
When the user creates an Access Role, the AD organization tree may show duplicate branches, and some branches may be missing. |
PRJ-20951, |
SmartConsole |
After a network interface is removed by cluster API, a network group assigned to that interface remains as used by cluster members and cannot be deleted. |
PRJ-20910, |
SmartConsole |
In some scenarios, deleting a policy fails. |
PRJ-21389, |
SmartConsole |
Slowness may be observed in some SmartProvisioning operations (like open SmartProvisioning GUI, create a new LSM object, open an LSM object editor, etc.). |
PRJ-20240, |
SmartConsole |
When there are no search results, search in Access Control Policy displays "An error occurred while searching" instead of "No Items Found". |
PRJ-20315, |
SmartConsole |
In some scenarios, the "show gateways-and-servers" Management API command fails when running it with details-level full and when connected to the Global Domain. Refer to sk170895. |
PRJ-19141, |
SmartConsole |
In some scenarios, the "add-user" API command with authentication method TACACS+ or RADIUS Server fails with "object not found" message. Refer to sk170325. |
PRJ-19931, |
SmartConsole |
In rare scenarios, the "Show Policy Package" tool and some Management API commands with details-level "full" may fail when UTM cluster is part of the policy targets. |
PRJ-21525 |
SmartConsole |
In a rare scenario, Automatic NAT rules are not visible in SmartConsole. |
PRJ-18922, |
SmartConsole |
In some scenarios, the "show-access-rulebase" Management API command fails when running it with details-level "full" and there is a network group with more than 50000 objects on one of the rules. Refer to sk170435. |
PRJ-21159, |
SmartConsole |
If there is an HTTPS Inspection layer that is not used in the policy, policy installation may fail with the "Internal error" message. |
PRJ-20874, |
SmartView |
UPDATE: To improve performance, SmartView now exports data in CSV format instead of Excel. |
PRJ-18860, |
Logging |
NEW: Added support for Endpoint Forensics reports to get-attachment API. |
PRJ-12202, |
Logging |
In some scenarios, the "Failed to fetch the file" error is displayed when trying to open Threat Emulation summary reports generated by VSX Gateways. |
PRJ-20563, |
Logging |
In rare scenarios, the Log Exporter fails to connect to external destination when using the TLS protocol. |
PRJ-17356, |
Logging |
FWM and\or log_indexer processes may repeatedly stop when there are more than ~500K network objects declared. Refer to sk164452. |
PRJ-21155, |
Logging |
In rare scenarios, the FWD process on the Security gateway may be blocked for several seconds due to processing of log attachments. |
PRJ-10292, |
Logging |
In rare scenarios, a log may display incorrect values in the Action and Rule field. Refer to sk170676. |
PRJ-19010, |
Logging |
In a rare scenario, CPD process may use a random port for AMON communication instead of port 18196. |
PRJ-20091, |
Security Gateway |
UPDATE: Service with source port in the Access rulebase will no longer disable accept templates for all connections. |
PRJ-18487, |
Security Gateway |
In some scenarios, repeating "fwx_alloc_global_find_free_port_atomic: rtsp pending port doesn't match the same pool" errors are displayed in dmesg when using Hide NAT with VoIP. |
PRJ-19585, |
Security Gateway |
In some scenarios, "email_unified_cmi_get_attribs: not valid caller: up_log_get_user_hash" error appears in dmesg for SMTP traffic. |
PRJ-19704, |
Security Gateway |
In rare scenarios, a memory leak may occur in TOPOD process. |
PRJ-19851, |
Security Gateway |
In some scenarios, a memory leak may appear after sending a packet from the kernel. |
PRJ-20900, |
Security Gateway |
In some scenarios, the DNS requests from the Security gateway may fail. |
PRJ-20632, |
Security Gateway |
In rare scenarios, high memory consumption in CPD may occur due to a memory leak in authentication flow with an LDAP server. |
PRJ-20655, |
Security Gateway |
Accept logs with reason "Connection terminated before detection: Insufficient data passed. To learn more see sk113479." may be wrongly generated when the matched action is user authentication and wrong username/password provided by user. |
PRJ-20955, |
Security Gateway |
In some scenarios, logs with incorrect action are generated by ICAP server. |
PRJ-20385, |
Security Gateway |
In a rare scenario, Access Control policy installation may fail after upgrade of Security Gateway from R80.10 or below to R80.20 or higher. |
PRJ-21111, |
Security Gateway |
Authentication may fail when LDAP branch name contains "\". |
PRJ-11205, |
Security Gateway |
In some scenarios, traffic that is matched on implied rule is dropped while it should not. |
PRJ-21021, |
Security Gateway |
In rare scenarios, proxy ARP entries may be deleted when installing a policy. |
PRJ-21361, |
Security Gateway |
Traffic may be dropped when the Hide NAT is configured on IPv6 host. |
PRJ-20340, |
Security Gateway |
In rare scenarios, passive FTP packets may be dropped. |
PRJ-19307, |
Threat Extraction |
UPDATE: Threat Extraction (Sanitization) will be automatically disabled when Infinity Threat Prevention mode is installed while the machine does not have enough resources (RAM). |
PRJ-17874, |
HTTPS Inspection |
UPDATE: "Categorize HTTPS websites" feature enhancements when "Categorize HTTPS Sites" feature is enabled:
For configuration, refer to sk173633. |
PRJ-20407, |
Identity Awareness |
NEW: Added the Identity Awareness performance and memory consumption improvements. Refer to sk170516. |
PRJ-20862, |
Identity Awareness |
In some scenarios, there may be enforcement issues for MUHv2 users due to table mismatch. |
PRJ-23655, |
Identity Awareness |
In Identity Awareness Captive portal, the default Check Point logo is displayed even if the user-defined logo is configured. Refer to sk133492. |
PRJ-20847, |
Identity Awareness |
In some scenarios, running pdpd commands results in "daemon did not respond or not running!" error. Refer to sk171136. |
PRJ-20348, |
IPS |
In a rare scenario, the SmartConsole shows the "IPS is not responding" message even though IPS is functioning normally. |
PRJ-20096, |
DLP |
UPDATE: Added support for multi-part data to DLP. |
PRJ-20838, |
DLP |
Improved DLP scanning for POST request to some Web sites. |
PRJ-18842, |
SSL Inspection |
In rare scenarios, a memory leak may occur during policy installation. |
PRJ-20936, |
SSL Inspection |
The AES-NI (Intel Advanced Encryption Standard New Instructions) status is not displayed and "dmesg | grep AES-NI" returns no output. Refer to sk170779. |
PRJ-18596, |
Anti-Malware |
In a rare scenario, Security gateway may crash when the Threat Prevention Forensics feature is enabled. |
PRJ-20976, |
Anti-Malware |
In rare scenarios, the Threat Prevention policy installation fails due to IOC parsing errors. Refer to sk171316. |
PRJ-19041, |
UserCheck |
In some scenarios, users cannot restore original attachment via UserCheck portal and receive the "An unexpected error has occurred" error message. |
PRJ-19204, |
ClusterXL |
UPDATE: Added the option to display only monitored interfaces to "show cluster members <option>" command>:
|
PRJ-20535, |
ClusterXL |
In some scenarios, data connections are dropped with "First packet isn't SYN" message on ClusterXL Load Sharing. |
PRJ-19392, |
ClusterXL |
"set router active-active-mode" settings do not survive a reboot. |
PRJ-19925, |
ClusterXL |
In rare scenarios, running cphastop;cphastart may cause a cluster member to stay in "Down" state. |
PRJ-16516, |
SecureXL |
NEW: Added the ability to enable monitor-only mode for penalty box independently of other DOS/Rate limiting features. |
PRJ-18323, |
SecureXL |
UPDATE: Drop templates can be generated for connections with matched action Reject. For additional information and configuration, refer to sk171146. |
PRJ-19664, |
SecureXL |
In some scenarios, connections are dropped when SYN Defender and ISN Defender are both enabled on the same interface. |
PRJ-17404, |
SecureXL |
In some scenarios, PPTP or GRE traffic may be dropped. Refer to sk170293. |
PRJ-19406, |
SecureXL |
In some scenarios, Rate Limiting rules for DoS do not work after reboot. Refer to sk170148. |
PRJ-15662, |
Routing |
UPDATE: Display of routing CPview results is limited to 30 lines. |
PRJ-18662, |
Routing |
UPDATE: Added support for Check Point Active Streaming (CPAS), Policy-Based Routing (PBR), and Application-Based Routing (ABR) on the Security Gateway. Refer to sk167135. |
PRJ-19629, |
Routing |
ip-reachability-detection ping marks a target IP address as "unreachable" if the path goes via a VPN tunnel, although pinging this IP address directly works. |
PRJ-20964, |
VSX |
After running "vsx_util vsls" and selecting option #6, the operation may fail with the "Internal Error: got empty reply set" error. Refer to sk171352. |
PRJ-20149, |
VSX |
In rare scenarios, some interfaces remain in "Down" state after reboot. |
PRJ-15447, |
VSX |
In some scenarios, there may be high CPU utilization in a VSX environment with several instances. |
PRJ-15550, |
VPN |
UPDATE: Added the TTM-per-group feature improvement that allows it to work with more client types (for example Nemo client). |
PRJ-17494, |
VPN |
In IKEv2 renegotiation scenario, IPSec SAs may be deleted on a standby cluster member during post sync causing a VPN traffic outage. Refer to sk172926. |
PRJ-19424, |
VPN |
In some scenarios, the vpnd process unexpectedly exits with Segmentation fault. |
PRJ-18271, |
VPN |
The VPND process on a standby cluster member may unexpectedly exit when VPN peer has a probing link selection configured. Refer to sk170136. |
PRJ-20414, |
VPN |
In some scenarios, the IKE QM negotiating issue with Windows Server 2008 R2 peer may occur. |
PRJ-20522, |
VPN |
In a rare scenario, the FWM process unexpectedly exits when enrolling a certificate using the SCEP protocol. |
PRJ-13821, |
VPN |
Access roles do not recognize Remote Access SNX CLI clients. |
PRJ-20868, |
VPN |
In some scenarios, the VPND process keeps re-downloading the same CRL, which can cause performance issues. |
PRJ-12242, |
VPN |
When clicking "View" in Trusted CA object's OPSEC PKI tab, this may show the "Failed to get a certificate of <object name> from keyset" error. Refer to sk166496. |
PRJ-20948, |
VPN |
In some scenarios, L2TP clients disconnect from the Security gateway after 10 minutes of the connection. |
PRJ-20644, |
VPN |
In some scenarios, the VPND process may unexpectedly exit. |
PRJ-19216, |
VPN |
Site to Site VPN fails to establish with IKEv2 on GCP when NAT-t is enabled. |
PRJ-20542, |
Gaia OS |
UPDATE: OpenSSL was updated to version 1.1.1i to include the latest code fixes and security improvements. |
PRJ-19146, |
Gaia OS |
UPDATE: Added the option to bind IP addresses to sockets using the udp_connect API. Refer to sk171019. |
PRJ-20958, |
Gaia OS |
UPDATE: Added support for multiple commands definition in Dynamic CLI feature. |
PRJ-11114, |
Gaia OS |
UPDATE: Updated the arp table limit to 131072 in:
|
PRJ-18091, |
Gaia OS |
Messages log level in /var/log/messages file for ERR level was changed to INFO level when fetching proxy configuration from Clish/WebUI/Gaia API. Example: [DATE TIME] <daemon.err> ... xpand[25958]: proxy_live_get_proc: Started... |
PRJ-20045, |
Gaia OS |
Potential command injection in Clish when using the "show file" command. |
PRJ-17319, |
Gaia OS |
The syslog messages may be spammed when the "show asset all" command is running. |
PRJ-19624, |
Gaia OS |
Extended commands are missing after adding Dynamic CLI. |
PRJ-20741, |
Gaia OS |
CVE-2020-25705: ICMP reply rate. |
PRJ-16259, |
Gaia OS |
A Timestamp in Unix/Epoch time may not be updated when the user changes a password using hash. |
PRJ-20916, |
Gaia OS |
In some scenarios, like defected LOM card, or when LOM port exists, but no LOM is connected, the confd process may unexpectedly exit. |
PRJ-19236, |
Mobile Access |
There may be a delay when connecting to HTTPS based SMS portal over a non-standard proxy port. Refer to sk170497. |
PRJ-20090, |
Endpoint Security |
Database size may increase exponentially because dynamic packages are packed into exported .tgz using migrate_export. |
PRJ-21749, |
Endpoint Security |
On the SmartEndpoint Reporting page, the "Endpoint Connectivity" report that is filtered by a virtual group returns an empty list. |
PRJ-21914, |
Endpoint Security |
In some scenarios, the "Endpoint Security Client Version" report shows "N/A" in DAT Date column for all devices on the SmartEndpoint Reporting page. |
PRJ-19312, |
CloudGuard Network |
When creating a GCP Data Center, Test Connection may fail on large GCP accounts. |