R81.10 Jumbo Hotfix Take 152
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 152 Released on 27 June 2024 |
||
Take 152 - New Functionality
|
||
PRJ-51435, |
SSL Inspection |
NEW: Added ability to import PKCS#12 files using AES-256-CBC encryption with PBKDF2-HMAC-SHA-256. This enhancement is designed for use in multi-portal environments and HTTPS Inspection scenarios. |
PRJ-53698, |
Security Management |
NEW:
|
PRJ-48744, PMTR-94089 |
SmartConsole |
NEW: Added support for 3072 bits key size in IKE certificates. To use 3072 bits key size, refer to "HTTPS Portals (Multi-Portal) Certificate, VPN Certificate" section in sk96591. |
Take 152 - Improvements and Resolved Issues
|
||
PRJ-52403, PMTR-99617 |
Security Management |
UPDATE: Added SHA256 fingerprints to certificate objects to mitigate the risk of hash collisions and enhance trust when utilizing the fingerprint, encoded with English words, as a verification mechanism. |
PRJ-52447, |
Security Management |
UPDATE: Added an ability to configure the schedule for Compliance blade scans. This should prevent login issues during the scans. Refer to sk182033. |
PRJ-49860, PMTR-95625 |
CPView |
UPDATE: Added the "SecureXL" filter to the "cpview -m -f" command, which allows to extract to Skyline all the information related to SecureXL drops. Refer to the Skyline Metrics Repository. |
PRJ-54340, |
SSL Network Extender |
UPDATE: SSL Network Extender is updated to version 80008409. |
PRJ-51974, |
SSL Inspection |
UPDATE: If inspection logging is configured, the "Inspect" log now displays the negotiated ciphers and TLS version used for successful inspections, both between the client and the Security Gateway, and between the Security Gateway and the Server. |
PRJ-48176, |
Mobile Access |
UPDATE: jQuery UI is upgraded to version 1.13.2. |
PRJ-53525, |
Gaia OS |
UPDATE: Added Multi-Queue support for Microsoft Azure Network Adapter (MANA) accelerated network interfaces. |
PRJ-51700, |
Harmony Endpoint |
UPDATE: The audit event information when adding or removing Virtual Group members is now unified. The data includes the administrator name and device/user names for both actions. Previously:
|
PRJ-54098, PRJ-54458, PRJ-55300, PRJ-55686, ODU-1779, ODU-1755, ODU-1731, ODU-1667 |
Automatic Updates - Web SmartConsole |
UPDATE: New features and improvements are released in Take 100, Take 102, Take 104 and Take 111 via self-updatable package. Refer to sk170314. |
PRJ-54687, ODU-1707 |
Automatic Updates - CPView |
UPDATE: Added Take 93 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522. |
PRJ-54172, ODU-1683 |
Automatic Updates - CPSDC |
UPDATE: Added Take 34 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414. |
PRJ-54176, PRJ-55581, ODU-1803, ODU-1659 |
Automatic Updates - HCP |
UPDATE: Added Update 17 of HealthCheck Point (HCP) Release. Refer to sk171436. |
PRJ-50335, PMTR-96420 |
Infrastructure |
UPDATE: Added Python 3.11.4. |
PRJ-50998, |
Security Management |
Install Policy Presets may fail after purging all revisions. Refer to sk181652. |
PRJ-51542, |
Security Management |
Enabling automatic updates of Trusted CAs as described in sk173629 may fail. |
PRJ-52878, PRHF-32383, PRJ-52517, PRHF-32065 |
Security Management |
In rare scenarios, Access policy installation may fail with the "Installation failed. Reason: Failed to load Policy on Security Gateway" or "Operation failed, install/uninstall has been improperly terminated" messages. |
PRJ-52780, |
Security Management |
When using the "set simple-gateway" Management API command to edit interfaces, the operation is only performed on fifty interfaces at a time. |
PRJ-52018, |
Security Management |
Exporting a policy that contains thousands of rules may fail when the "Hit Count" column is enabled. |
PRJ-52849, |
Security Management |
Login to SmartConsole fails if the "Read_Write_All_Profile" permission profile is deleted. |
PRJ-52914, |
Security Management |
Deleting a Security Gateway object fails if there is a license attached to the Security Gateway and the Security Gateway is physically disconnected. |
PRJ-51676, |
Security Management |
Global Assignment fails with "Locked for editing by another administrator and need to be published or discarded before the operation can take place". Refer to sk181807. |
PRJ-52790, |
Security Management |
In rare scenarios, High Availability synchronization fails with "Peer is busy". |
PRJ-49361, |
Security Management |
There may be synchronization failure and, as a result, corrupted Domain policies on the Multi-Domain Security Server when a newly created local administrator on the backup Security Management Server makes changes to rules or objects, after the Active role is switched to that Security Management Server. |
PRJ-50372, |
Security Management |
When attempting to load a SNORT Rules file that contains one or more spaces, the import process fails with an ambiguous error message. |
PRJ-53348, |
Security Management |
In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit or not start, creating a core dump file. |
PRJ-51506, |
Security Management |
The on-premises Security Management Server fails to connect to Infinity Portal when this Server has a proxy configured. |
PRJ-51632, |
Security Management |
In rare scenarios, after an upgrade or a Domain migration:
|
PRJ-51695, |
Security Management |
After a global assignment, when installing policy on several installation targets at once, the log may show an incorrect rule name. |
PRJ-53730, |
Security Management |
Changes Report may allow to list certain directory contents. |
PRJ-55501, PRHF-34248 |
Security Management |
A memory leak may occur in the FWM process leading to SmartConsole connection failures. |
PRJ-54094, |
Security Management |
In rare scenarios, policy installation on R77.30 Security Gateway fails with "Operation failed, install/uninstall has been improperly terminated". Refer to sk180448. |
PRJ-53340, |
Security Management |
When a Domain object in a policy is set with a backslash in the suffix, policy installation fails with the "Unterminated string&CURRENTVERCMP" error. |
PRJ-51504, PMTR-98271 |
Security Management |
After a Multi-Domain Security Management upgrade to R81.10 version, some Infinity Portal Services may stop working. |
PRJ-49582, |
Security Management |
In some scenarios, when searching objects in SmartConsole, not all relevant results are highlighted. Refer to sk181454. |
PRJ-41780, |
Security Management |
In some scenarios, SmartConsole may close unexpectedly when clicking the "View Changes" option in the Install Policy view. |
PRJ-52345, |
Security Management |
In some scenarios, the PostgreSQL database fully utilizes disk space on the Standby Security Management Server. |
PRJ-50018, |
Security Management |
It may not be possible to add/set a Threat Prevention Exception with a protection-or-site UID. |
PRJ-51204, |
Security Management |
If all revisions were purged on the Security Management Server, the "show packages details-level full" Management API call may fail. |
PRJ-51513, |
Security Management |
The revisions purge process may get stuck due to an incomplete purge operation from a previous attempt. |
PRJ-52044, |
Security Management |
In some scenarios, the Security Management Server upgrade to R81.20 fails with "java.lang.String incompatible with com.checkpoint.infrastructure.types.CPUUID" in the upgrade report. The issue occurs during the import of the User Data Domain.
|
PRJ-48395, |
Multi-Domain Security Management |
In a Multi-Domain Security Management environment, the "show simple-gateway" and "show simple-cluster" Management API commands may fail with "Runtime error: An internal error has occurred" |
PRJ-52969, |
Multi-Domain Security Management |
The "cprlic get" command output may not provide correct information about vSEC licenses. |
PRJ-51271, |
Multi-Domain Security Management |
In Multi-Domain Security Management environments, if there are more than three hundred forty Domains, login to SmartConsole fails. |
PRJ-53226, |
SmartProvisioning |
The Management API command "set-lsm-gateway" with the "sic.ip-address" parameter may fail with "Establish SIC failed. Reset SIC on gateway and try again." when resetting SIC. |
PRJ-53274, |
SmartProvisioning |
The "show-lsm-gateways" Management API command returns LSM cluster objects besides the LSM Security Gateways. |
PRJ-51569, PMTR-90798 |
SmartConsole |
SmartConsole slowness when adding applications to rules. Refer to sk182063. |
PRJ-52601, PMTR-94461 |
CPView |
In the "cpview -m" command output on the Security Gateway which is an Active Cluster member, "metrics system.network.nat.ports" and "system.network.nat.ports.limit" may not be displayed in the list of available metrics. |
PRJ-52720, |
Logging |
Administrators without the "run script" permissions can enable or disable the option to run a script on a Security Gateway, using advanced configuration options. |
PRJ-51147, |
Logging |
When Identity Awareness blade is enabled, the "Src User Dn" and "Dst User Dn" fields in ICMP Logs are not masked for users without "Identities" permissions. Refer to sk181677. |
PRJ-49789, |
Logging |
The "cpstat -h log server ip ls -f logging" command fails when running it from Security Management. |
PRJ-53336, |
Logging |
When the "IP Options drop" tracking Global Properties setting is configured to "Log" and the policy is installed, the Security Gateway drops traffic with disallowed IPv4 options or IPv6 extension headers, but no log is shown in SmartConsole. |
PRJ-51326, |
Logging |
In rare scenarios, after an upgrade, the LOG_EXPORTER process may fail to send the log files to SIEM or to the cloud. |
PRJ-44794, |
Logging |
In rare scenarios, the FWD process on the Security Gateway may reach out of memory and produce a core dump file of around 3GB. |
PRJ-52678, |
Security Gateway |
Running GTP traffic may cause a crash on a Security Gateway without a GTP license. |
PRJ-51357, |
Security Gateway |
A highly utilized Security Gateway may crash during policy installation. |
PRJ-53627, |
Security Gateway |
A memory issue may occur in a cluster environment, when SIP inspection is enabled. |
PRJ-41753, |
Security Gateway |
Some debug messages may appear in the /var/log/messages file, although the debug mode is not activated. The issue is cosmetic only. |
PRJ-51438, |
Security Gateway |
A rare race condition may be triggered by the timing and packet patterns of VoIP traffic, and, as a result, the FWK process may restart. |
PRJ-48816, |
Security Gateway |
After deploying a new license to a Multi-Domain Log Module (MLM), all Customer Log Modules (CLMs) generate alert logs about missing license/contracts stating "No valid license was found". |
PRJ-51945, |
Security Gateway |
In some scenarios, if a rule with a security zone is installed using accelerated install policy, the traffic may stop matching the NAT Rule Base. |
PRJ-52795, |
Security Gateway |
In some scenarios, the VSX Security Gateway may not set the MAC header correctly when sending traffic back to Gaia OS directly out of an interface on a Virtual Router. |
PRJ-51527, |
Security Gateway |
Sporadic latency while uploading a file when HTTPS Inspection and ICAP client are active. Refer to sk181793. |
PRJ-52824, PMTR-100459 |
Security Gateway |
On the Security Management Server, a CPD zombie process may be created. |
PRJ-49047, |
Security Gateway |
In rare scenarios, a file downloaded via HTTP may be corrupted. |
PRJ-52470, |
Security Gateway |
CIFS traffic may cause CPU spikes in the FWK process. |
PRJ-42870, |
Threat Prevention |
After installing a hotfix in a cluster setup with a Threat Prevention policy that includes Network Objects, a member may get stuck during initialization after a reboot. Refer to sk180225. |
PRJ-53490, |
Threat Prevention |
Installation of Threat Prevention Policy fails with the error "No profile defined on GW <Name of Security Gateway Object>" in this scenario:
|
PRJ-53911, |
Threat Prevention |
SSH DPI may not work because of incorrect parsing of the client hello from a non-standard SSH client. |
PRJ-52370, |
Identity Awareness |
After an upgrade, the Security Identifier (SID) for LDAP Users or LDAP Groups that were configured prior to the upgrade may be empty. Refer to sk181946. |
PRJ-50513, |
Identity Awareness |
In a Cluster Load Sharing environment or when a single Policy Decision Point (PDP) is shared among multiple Policy Enforcement Points (PEPs), the PDP registers the PEP, but the PEP may not be aware of this registration. |
PRJ-52872, |
Identity Awareness |
User/Security Gateway identities may be revoked unexpectedly if an additional update from the AD Query identity source is rejected due to Identity session conciliation. |
PRJ-50583, |
Identity Awareness |
During policy installation, users authenticated using the Captive Portal may get disconnected. |
PRJ-52660, |
Anti-Virus |
Some URLs may be blocked by the Anti-Virus blade as malicious, even though the Threat Prevention Rule Base contains an exception rule with a Site/Application object that includes this URL. |
PRJ-53124, |
Anti-Virus |
The DLPU process may frequently exit with a core dump file. |
PRJ-53989, |
Mobile Access |
SAML authentication may fail after installation of Jumbo Hotfix Accumulator R81.10 Take 113. Refer to sk182128. See the Critical Information section. |
PRJ-52047, PRHF-31811 |
Mobile Access |
SSL Network Extender (SNX) cannot connect after installing Jumbo Hotfix Accumulator. Refer to sk181805. See the Critical Information section. |
PRJ-52895, |
ClusterXL |
In a rare scenario, after an upgrade, connections between networks may be dropped with the "First Packet isn't SYN" error. |
PRJ-42808, |
ClusterXL |
Cluster members may crash, generating vmcores in /var/log/crash. |
PRJ-50116, |
ClusterXL |
In a cluster environment, the Security Gateway may become unresponsive on the Active member, and after a failover the issue occurs on the new Active member also. |
PRJ-44519, |
SecureXL |
Multicast packets received on an interface with PIM disabled can cause multicast packet drops on other interfaces by filling up the kernel routing queue. |
PRJ-53090, |
SecureXL |
In some scenarios, when SecureXL User Mode (UPPAK) is enabled, the Security Gateway crashes during boot up. |
PRJ-53060, |
SecureXL |
During the deny list update process, there is a temporary gap where no IP addresses are blocked, allowing unwanted traffic to pass through the Security Gateway unfiltered. |
PRJ-53787, |
SecureXL |
When the Security Gateway works in SecureXL User Mode (UPPAK), a SIGPIPE signal may cause the USIM process to exit, leading to a system reboot. |
PRJ-54424, |
SecureXL |
In some scenarios, the VSX Security Gateway may fail to properly reroute traffic originating from a Virtual Switch. |
PRJ-53480, |
SecureXL |
In some scenarios, when QoS blade is enabled and SecureXL works in User Mode (UPPAK), Security Gateway may crash with the "invalid data" error. |
PRJ-51621, |
SecureXL |
In some scenarios, fragmented ICMP packets may bypass the DOS/ Rate limiting deny list. |
PRJ-53090, |
SecureXL |
In some scenarios, the Security Gateway crashes during boot up when SecureXL works in User Mode (UPPAK). |
PRJ-50854, |
SecureXL |
There may be a delay in enforcing DOS/ Rate Limiting rules to drop packets when concurrent connection limits are exceeded. |
PRJ-52805, |
SecureXL |
In some scenarios when Route based probing is configured, the VSX Security Gateway sends out encrypted traffic with a source IP address of all zeroes through a Virtual Switch interface. This traffic may be dropped by routers, the VPN peer Gateway or other Security Gateways due to the invalid source IP address. |
PRJ-53053, ROUT-2968 |
Routing |
BGP peers may experience timeouts when these conditions occur simultaneously:
|
PRJ-53056, |
Routing |
In scenarios where numerous BGP peers are configured with the "multihop" option enabled, combined with short "keepalive" settings and a large number of routes being received from each peer, the ROUTED process may experience high CPU utilization. |
PRJ-51259, |
Routing |
It may not be possible to propagate a newly added static route through OSPF. |
PRJ-53171, |
Routing |
The ROUTED process may unexpectedly exit because of an OSPF assertion failure. |
PRJ-52670, |
Routing |
Enabling rfc1583-compatibility via Clish fails with "CLINFR0329 Invalid command:'set ospf instance default rfc1583-compatibility on". |
PRJ-52723, |
Gaia OS |
The MONITORD daemon causes high CPU after 388 days of uptime. Refer to sk181922. |
PRJ-53194, |
Gaia OS |
In rare scenarios, the Gaia Portal daemon HTTPD may unexpectedly exit and create a core dump file in the /var/log/dump/usermode/ directory. |
PRJ-53487, |
Gaia OS |
Some valid interfaces may not be available with running the "set lldp interface" command. |
PRJ-52508, |
Gaia OS |
When a non-local user executes a Gaia API command, the action is incorrectly logged as performed by the "admin" user in the /var/log/messages file. |
PRJ-54179, |
Gaia OS |
Removing unused built-in user called "cp_ender" that may appear in Gaia OS after an upgrade. Refer to sk182185. |
PRJ-52948, |
VPN |
When the DAIP Gateway public IP address occasionally changes, the connected Security Gateway fails to update the new IP address and continues responding to the old IP address, causing communication issues. |
PRJ-54240, PMTR-103618 |
VPN |
In a VPN Community with a configuration involving two Security Gateways (a Center Cluster and a Satellite Security Gateway) with IPv6 external and internal interfaces, when attempting to establish a Link Selection Star community between them, the VPN process may unexpectedly exit due to repetitive IKE core crashes on one of the Security Gateways while the other Security Gateway tries to establish a tunnel, resulting in connectivity issues. |
PRJ-33776, |
VPN |
The FWK process crashes sporadically, causing impact on traffic due to an issue related to the decryption of fragmented traffic. |
PRJ-52829, |
VPN |
In a rare scenario, in a Maestro environment the first packet of the VPN tunnel is lost or has a large delay. |
PRJ-53848, |
VPN |
After an update, if in VPN if configured with Permanent Tunnels enabled, RAM utilization may increase. |
PRJ-53383, |
VPN |
IPv6 non-VPN traffic may be dropped with "Clear text packet should be encrypted". |
PRJ-50316, PMTR-89274 |
Multi-Portal |
In a rare scenario, after a VSX environment upgrade, connecting Remote Access Client to a newly created VS site using IDP authentication fails with the "This page can't be displayed" error in the embedded browse, but error logs or debugs are missing from the /opt/CPVPNPortal/logs/ directory on VSX and newly created VS. |
PRJ-50571, |
Harmony Endpoint |
In an on-premises environment, large Active Directory groups with more than 1500 members appear empty or have incomplete membership information. |
PRJ-51137, |
Harmony Endpoint |
When duplicate users with the same name and Domain exist in the database or Active Directory, FDE Pre-boot authentication on LAN may fail, not able to identify the user attempting to log in. |
PRJ-46792, |
Scalable Platforms |
An additional reboot may be performed on Maestro Security Gateway because of the database entry (otlp) which should not be pulled from SMO. This entry is updated locally on each member via self-update functionality and therefore may differ between members. |
PRJ-53621, |
Scalable Platforms |
The "reboot -b all" command in gClish may fail. The environment hangs or reboots partially (only some of the members). |
PRJ-52643, |
Scalable Platforms |
After a failover scenario, the "m site-id member-id" command requires reauthentication. |
PRJ-52884, |
Scalable Platforms |
When running the "fwaccel stat" command on a VSX Security Gateway, the output may show physical interfaces as not accelerated, although they are. |
PRJ-53082, |
Scalable Platforms |
Redundant "MHO_stateAgent[3230]: QuidAddon: System not ready yet - attempting to re-init" messages in the /var/log/messages file. |
PRJ-53831, PMTR-73771 |
Scalable Platforms |
Before enabling MDPS, CoreXL Dynamic Balancing (sk164155) must be disabled. |
PRJ-53468, PMTR-97932 |
Scalable Platforms |
In a rare scenario, when a Maestro Security Gateway is active again after a reboot, and LightSpeed is used, the LACP bond may drop incoming and outgoing packets. |
PRJ-55569, PMTR-105246 |
Scalable Platforms |
Traffic outage after policy installation on a Maestro Security Group in the VSX mode that works in the Dual Site configuration. Refer to sk182379. |
PRJ-55517, PMTR-105145 |
Scalable Platforms |
• On Quantum Maestro/Chassis or in ClusterXL, the Security Gateway may crash while processing a VPN/correction flow with a vmcore in /var/log/crash or FWK core in /var/log/dump/usermode/. • The "kernel: xxxxx: tx_timeout" error is printed in /var/log/messages. • PSL drops packets with "PSL Drop: psl_build_pslip failed” message, potentially impacting network performance and streaming capabilities. Refer to sk182463. See the Critical Information section. |