R80.40 Jumbo Hotfix Take 91
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 91 Released on 16 December 2020 and declared as Recommended on 26 January 2021 |
||
PRJ-19279, |
Security Management |
NEW: The upgrade process is being monitored dynamically and will be stopped if it cannot be completed, not basing on a timeout. |
PRJ-13934 |
Security Management |
Login with SmartConsole may be blocked while purge revisions action is running. |
PRJ-19084, |
Security Management |
In some scenarios, HA synchronization may fill up the disk space of a standby Management Server. Refer to sk168492. |
PRJ-18379, |
Security Management |
In some scenarios, SecurID configuration files on the Security Gateway are overridden upon policy installation. |
PRJ-18817, |
Security Management |
Management HA synchronization between Multi-Domain Management Servers may fail with "Failed to import data" error due to manual or automatic updates of contracts. |
PRJ-18030, |
Security Management |
In some scenarios, export of EndPoint package may fail due to FWM process that utilize 100% CPU. |
PRJ-19021, |
Security Management |
In rare scenarios, FWM process may unexpectedly exit after a login attempt to the Management server. |
PRJ-18492, |
Security Management |
In rare scenarios, a policy installation task may never complete. |
PRJ-13476, |
Security Management |
Domain Servers may disappear from Multi-Domain view after running the Solr Cure utility. |
PRJ-15906, |
Security Management |
Security policy compilation fails if the Domain network object name (FDQN name) contains space. |
PRJ-17692, |
Security Management |
In some scenarios, HA temporary sub-directories under $FWDIR/tmp are not deleted if sync fails. Refer to sk170972. |
PRJ-19131, |
Security Management |
Advanced Upgrade from R80.10 to R80.40 with Jumbo Hotfix Take 83 may fail. Refer to sk170313. |
PRJ-18288, |
Security Management |
In rare scenarios, the CPU and memory usage of CPM process may be abnormally high. Refer to sk170672. |
PRJ-18954, |
Security Management |
Policy verification may fail with error "For security gateways R80.40 and higher, rules that use Access Roles can only have "Any Traffic" or "RemoteAccess" in the VPN column". |
PRJ-16724, |
Security Management |
For more information, refer to sk170632. |
PRJ-18265, |
Security Management |
'Revert to Revision' tasks cannot be cleared from tasks pane in SmartConsole. |
PRJ-16369, |
Security Management |
When logging into SmartConsole directly to a Domain using RADIUS or TACACS, the Authentication method in the audit log may show as "Internal Password". Refer to sk168716. |
PRJ-17763, |
Security Management |
When migrating a Security Management Server that was created as a standby and then set to active, into a Domain Management Server, the new Domain is created without an active Domain Server. |
PRJ-18690, |
Security Management |
Database installation to the newly created Domain Log Server may fail. |
PRJ-18907, |
Multi-Domain Management |
In some scenarios, size of MDS backup file increases after each policy installation. |
PRJ-18251, |
Multi-Domain Management |
Migration of Domain Server between different Multi-Domain Servers may fail due to incorrect internal values of default objects. |
PRJ-18970, |
Multi-Domain Management |
The "cplic db_print -all -x" command fails when running on the MDS level. |
PRJ-19647, |
Multi-Domain Management |
In rare scenarios, a Domain is shown in the Domains view without any Domain Server or a Domain is shown with Domain Server that was deleted and does not exist anymore. Refer to sk170556. |
PRJ-12845, |
Multi-Domain Management |
Global Domain Assignment may fail with the "An internal error has occurred" message after deleting a Global VPN Community object. |
PRJ-19320, |
SmartConsole |
NEW: Added support for Python 3 in Management API scripts. |
PRJ-18317, |
SmartConsole |
NEW: Added 1600, 1800, and 1570R appliances to SmartConsole Hardware list. |
PRJ-19202, |
SmartConsole |
In some scenarios, when using the "set simple-gateway" API command with "logs-settings.forward-logs-to-log-server", it fails with "Generic server error". Refer to sk170352. |
PRJ-19322, |
SmartConsole |
In some scenarios, the api.csv file may show extra empty columns. |
PRJ-19376 |
SmartConsole |
In a rare scenario, when user clicks on Mail Transfer Agent (MTA) options in the Security gateway settings or on 'Next hop' column inside MTA settings, SmartConsole shows "Not Responding" and freezes. Refer to sk161232.
|
PRJ-20163, |
SmartConsole |
Duplicate central licenses may be added to the management database. In some rare scenarios, this may lead to heavy load on the FWM process and prevent login. |
PRJ-18382, |
SmartConsole |
In some scenarios, running an action on a ROBO Gateway behind NAT does not work during sync on SMB appliances. |
PRJ-17414, |
SmartConsole |
When removing an object from a group using the "groups" field of the object"s module in the Ansible collection, the group will not be changed and Ansible will show that no changes are needed. |
PRJ-18041, |
SmartConsole |
In some scenarios, after a successful IPS update, the new IPS version does not appear under 'switch version' window. |
PRJ-17643, |
SmartConsole |
When creating a user with Check Point password authentication through the Management API, log in to Mobile Access portal may fail. Refer to sk170412. |
PRJ-18592, |
SmartConsole |
After enabling the Endpoint Policy Management blade on the Security Management Server, some views on SmartConsole may not load properly and SmartClient may disconnect. |
PRJ-15743, |
SmartConsole |
When using the "set simple-cluster" Management API command to update a user defined security zone, the "Specify security zone" checkbox in SmartConsole is not selected. |
PRJ-18465, |
SmartConsole |
In some scenarios, Staging mode IPS protections activation in the Local domain does not match the activation in the Global domain after a Global Threat Prevention policy assignment. Refer to sk170322. |
PRJ-19057, |
SmartConsole |
Upgrade may fail due to IPS protections comment that is exceeding the comment length limit. |
PRJ-16706, |
SmartConsole |
Enabling Threat Prevention policy may fail with validation errors when the policy's targets include cluster members running a version lower than R80.10. |
PRJ-16979, |
SmartConsole |
In some scenarios, some Web APIs fail with "Script stopped running due to severe error!" message when SMB gateway is defined as a policy target. Refer to sk169557. |
PRJ-14107, |
SmartConsole |
Search in Threat Prevention Exceptions in Protection/Site/File/Blade column may not return all expected results. |
PRJ-15818, |
SmartConsole |
In some scenarios, Management API does not start automatically after restart, although automatic start is enabled. Refer to sk168332. |
PRJ-18327, |
SmartConsole |
Exception group may be incorrectly deleted in the following scenarios:
|
PRJ-18307 |
SmartProvisioning |
NEW: Added support for Threat Emulation blade on LSM profile of R80.20 SMB gateways and clusters.
|
PRJ-17482, |
SmartProvisioning |
In some scenarios, when recreating a ROBO object with the same name, the new object receives the previous status. |
PRJ-14511, |
CPView |
In some scenarios, CPView may unexpectedly exit after upgrade from R80.20 GA. |
PRJ-17209, |
Compliance |
UPDATE: Added ability to select 'Any' in the Service column when creating a custom firewall Best practice.
|
PRJ-17805 |
IoT |
NEW: Added IoT support to Multi-Domain Security Management.
|
PRJ-18781, |
SmartView |
In rare scenarios, "Critical attacks allowed by policy widgets" in "General Overview" view may show no results while actual data exists. Refer to sk171001. |
PRJ-18339, |
SmartView |
In some scenarios, SmartView fails to load with a "permission denied" error. |
PRJ-19815, |
Logging |
In rare scenarios, the log_indexer process may unexpectedly exit when reading a specific log format. Refer to sk116117. |
PRJ-11343, |
Security Gateway |
NEW: Added support for authentication with a RADIUS server that expects to receive an empty password on the first message. VPN client will receive 2 dialogs instead of 3. |
PRJ-17730, |
Security Gateway |
UPDATE: Added a message informing that to enable Dynamic Balancing on models with less than 8 cores, GNAT must be enabled. |
PRJ-16668, |
Security Gateway |
UPDATE: You cannot manually configure Multi-Queue while Dynamic Balancing is active. |
PRJ-17300, |
Security Gateway |
Connections distribution may get unbalanced on VSX environment. Refer to sk169352. |
PRJ-18833, |
Security Gateway |
In rare scenarios, Security Gateway memory consumption may increase. |
PRJ-19957, |
Security Gateway |
Half-closed accelerated TCP connections may take too long time to expire. |
PRJ-19195, |
Security Gateway |
In some scenarios, when using routing separation, connection from data plane to management plane is dropped. |
PRJ-10573, |
Security Gateway |
The SSH Deep Packet Inspection (SSH DPI) configuration may be lost after upgrade. |
PRJ-17704, |
Security Gateway |
After enabling USFW mode (User-Space Firewall) and rebooting, system boots in KFW (Kernel mode Firewall) instead. Refer to sk169956. |
PRJ-17960, |
Security Gateway |
In some scenarios, policy installation fails with "Error code 0-2000077". |
PRJ-19179, |
Security Gateway |
Connections may be wrongly matched on Domain or Updatable objects used in Security policy. |
PRJ-13377, |
Security Gateway |
The TCP State Logging feature may not work as expected. Refer to sk101221. |
PRJ-16089, |
Security Gateway |
In rare scenarios, a memory leak may appear on Security Gateway in gconn table. |
PRJ-16172, |
Security Gateway |
After changing 'pdp nested_groups __set_state 2', flat groups are fetched correctly, but nested groups are not fetched. Refer to sk166199. |
PRJ-18981, |
Security Gateway |
In rare scenarios, Security Gateway may crash with USFW fwk core file. |
PRJ-18247, |
Identity Awareness |
NEW: Added Identity Sharing performance and functionality improvements. Refer to sk170516. |
PRJ-19106, |
Identity Awareness |
NEW: Performance optimization for Identity broker. |
PRJ-18345, |
IPS |
NEW: Added ability to send connection log per application match for ATM transactions identification. The functionality is disabled by default and can be enabled by using the "up_duplicate_connection_log_on_packet_matched_app_enabled" kernel parameter. |
PRJ-13970, |
IPS |
UPDATE: The "ips stat" command now shows all active Threat Prevention profiles with IPS enabled on the Security gateway. |
PRJ-16446, |
IPS |
The get_ips_statistics.sh script on VSX may fail with "/bin/cat: /proc/self/vrf: No such file or directory" error. |
PRJ-18825, |
HTTPS Inspection |
The user may not be able to browse with Chrome when using mixed chain with ECDSA subordinate CA in HTTPS Inspection. Refer to sk170332. |
PRJ-17594, |
HTTPS Inspection |
Connectivity issue may appear for inbound HTTPS Inspection when HTTP/2 is proposed by the client. Refer to sk169375. |
PRJ-19465, |
HTTPS Inspection |
In some scenarios, the HTTPS Inspection CA bundle is not created on the Security Gateway. |
PRJ-17168, |
Anti-Malware |
In a rare scenario, Security gateway may crash while processing SMB3 multi-channel when Anti-Virus blade is enabled. |
PRJ-16563, |
Anti-Malware |
Security Gateway may crash when certain traffic is handled during policy installation and the Anti-Virus Deep Scanning is enabled. |
PRJ-19579, |
Anti-Virus |
In rare scenarios, after downloading files, Anti-Virus prevent logs appear with "Strict hold is not possible failure - Write to other side occurred" error message. |
PRJ-15944, |
Anti-Bot |
In a rare scenario, Security gateway may crash after a match of the Anti-Bot blade. |
PRJ-17640, |
UserCheck |
In some scenarios, UserCheck agent notifications may be blocked. |
PRJ-18699, |
UserCheck |
When using the UserCheck agent, the original URL attribute variable $orig_url$ may appear on URL field of log details. |
PRJ-19434, |
SSL Inspection |
In rare scenarios, the DynamicID Certificate validation may fail. |
PRJ-18957, |
ClusterXL |
When MDPS is configured, the output of "cphaprob syncstat" may show unreadable characters for the speed of the sync interface. |
PRJ-12589, |
SecureXL |
NEW: Added support for Cluster AA/LS. |
PRJ-16583, |
SecureXL |
In some scenarios, traffic with the destination IP address as the broadcast address configured according to sk98810 is dropped. |
- |
Gaia OS |
NEW: Added support for 1570R and 1600 / 1800 SMB appliances. |
PRJ-16672, |
Gaia OS |
UPDATE: CPView Network -> Top-Protocols and Network -> Top-Protocols tabs was added back. Refer to sk167903. |
PRJ-17921, |
Gaia OS |
"cphaprob -h" shows wrong explanation for "cphaprob show_bond [<bond_name>]" command. |
PRJ-19330, |
Gaia OS |
In some scenarios, login from data plane context fails (no connectivity to server). |
PRJ-17714, |
Routing |
Security Gateway may stop forwarding the Multicast stream when PIM is configured on it. Refer to sk169774. |
PRJ-17856, |
Routing |
In rare scenarios involving large AS paths, there may be a loss of BGP adjacency. Refer to sk170876. |
PRJ-18026, |
Routing |
SNMP queries for bgpPeerFsmEstablishedTime return an incorrect constant value. Refer to sk170074. |
PRJ-18069, |
VPN |
NEW: Added Remote Access VPN performance improvements. |
PRJ-18667, |
VPN |
NEW: Added Remote Access VPN performance improvement for USFW mode (User-Space Firewall). |
PRJ-16432 |
VPN |
UPDATE: Added ability to fetch CRL with proxy in Site-to-Site VPN. |
PRJ-17369, |
VPN |
DynamicID via SMTP does no work when an HTTP proxy server is defined. |
PRJ-15742, |
VPN |
In some scenarios, findSAByPeer does not validate the peer IP address for DAIP peer behind NAT. |
PRJ-18764, |
VPN |
In some scenarios, userspace cores may appear on Security gateways with enabled AES-GCM-256 and AES-256 VPN encryption. Refer to sk169417. |
PRJ-20283, |
VSX |
In some scenarios, SNMP v3 users are not recognized on VSX when SNMP is in VS mode. The 'Unknown user name' error message is displayed. Refer to sk170993. |
PRJ-15859, |
Endpoint Security |
An exception may be displayed in SmartEndpoint when uploading an offline group software deployment package. Refer to sk165852. |
PRJ-16465, |
Endpoint Security |
In some scenarios, content of the "User Name" tab in SmartEndpoint is displayed in wrong format. |
PRJ-16317, |
Endpoint Security |
Client may not be added automatically to a Virtual Group that was configured in the SmartEndpoint export package policy when deployment is done using dynamic package. |