R81.10 Jumbo Hotfix Take 171

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 171

Released on 13 November 2024

Take 171 - New Functionality

 

PRJ-56703,
PMTR-102912

Security Management

NEW: Added a new Management API command which displays API usage statistics - "api stats" . It can be run on the Security Management Server or Multi-Domain Security Management Server. For detailed usage instructions, run "api -h".

PRJ-54696,

PRJ-54695,

PRJ-54244,
PRJ-54243

CloudGuard Network

NEW: CloudGuard Controller updates are now performed automatically. Refer to sk181842.

Take 171 - Improvements and Resolved Issues

 

PRJ-56247,
PMTR-106894

SmartConsole

UPDATE: Resolved CVE-2024-3596 - Blast-RADIUS attacks. Fix for Remote Access VPN and login to SmartConsole, Mobile Access and Identity Awareness Captive Portal. Refer to sk182516.

PRJ-56316,
PMTR-106774

Security Gateway

UPDATE: Apache HTTPD version was updated from 2.4.55 to 2.4.61 to fix: CVE-2023-31122, CVE-2023-43622, CVE-2024-36387, CVE-2024-38473, CVE-2024-38474, CVE-2024-38475, CVE-2024-38476, CVE-2024-38477, CVE-2024-39573.

PRJ-56881,
PMTR-106858

Security Management

UPDATE: JRE is updated from version 8.0_8.21 to version 8.0_8.26.

PRJ-55660,
PMTR-105539

Security Management

UPDATE: The "set threat-exception" Management API command now includes the "protection-or-site" parameter. When specified, this parameter adds new values to the existing list of protections or sites, instead of overwriting the current entries.

PRJ-56610,
PMTR-108410

Logging

UPDATE: Added a count of Session and Connection logs to the "cpstat" command output.

PRJ-51950,
PRHF-31203

Security Gateway

UPDATE: Added support for log rotation in the avi_del_tmp_files.elg files. Refer to sk113241.

PRJ-56015,
PRHF-36140

Threat Prevention

UPDATE: Added support for whitelisting IP addresses in external IoC feeds.

PRJ-48030,
PRHF-29471

Threat Emulation

UPDATE: The maximum size for files uploaded to Threat Emulation can now be configured using the Threat Emulation API. Set the "max_api_request_data_size" attribute to specify the new limit.

PRJ-49052,
PRHF-30097

Identity Awareness

UPDATE: Identity Collector OIDs for SNMP queries are now available in both $CPDIR/lib/snmp/chkpnt.mib and $FWDIR/conf/identity_server.cps locations.

PRJ-56482,
PMTR-107320

SecureXL

UPDATE: Improved throughput of GRE tunnels configured on the ports of the 100G Acceleration Card when SecureXL works in the KPPAK mode.

PRJ-57064,
PRHF-34509

SecureXL

UPDATE:

  • Improved debugging in the Security Gateway to identify problematic hosts when resolving their next-hop IP addresses.

  • The custom ADP queue size configuration now persists after rebooting the Security Gateway. The relevant global parameters are located in the $PPKDIR/conf/adpkern.conf file:

    • "adp_nh_total_max_arp_qents"

    • "adp_nh_local_max_arp_qents"

PRJ-57756,

PRJ-58095,

ODU-2107,

ODU-2083

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 121 and Take 123 via self-updatable package. Refer to sk170314.

PRJ-57704,
ODU-2027

Automatic Updates - CPView

UPDATE: Added Take 97 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.

PRJ-57708,
ODU-1995

Automatic Updates - CPView

UPDATE: Added Take 40 of CPviewExporter Release Updates. Refer to sk180521.

PRJ-56164,
PMTR-106542

Security Management

In some scenarios, the "set-exception-group applied-threat-rules.position" Management API command may add the exception group to an incorrect position.

PRJ-53259,
PRHF-32595

Security Management

When exporting a policy to a CSV file, the process fails silently if any rule within the policy has a name or comment in UID format. No clear error message is provided to indicate the cause of the failure.

PRJ-54719,
PRHF-33889

Security Management

In rare scenarios, when Application Control blade is enabled, cloning a policy may fail due to timeout.

PRJ-54658,
PRHF-33941

Security Management

Several Management API commands, such as "show-package" and "install-policy", may fail if running them after the deletion of a cluster member.

PRJ-56508,
PMTR-106245

Security Management

In some scenarios, the Security Management Server upgrade fails with "creating default objects and restarting services" during the import phase.

  • The fix will only be applied if the upgrade to this Jumbo Hotfix Take is done using a Blink image or via the Advanced Upgrade method.

PRJ-56613,
PRHF-35520

Security Management

An administrator whose authentication method was changed from "Check Point Password" to a different method in R77.X can still log in using their original Check Point password.

PRJ-57072,
PRHF-35818

Security Management

In rare scenarios, when exporting policy hitcounts to CSV format, the "Hitcount" column may appear blank in the exported file.

PRJ-55668,
PRHF-34447

Security Management

Adding a host object to a network group using the "set-host" Management API command may generate large redundant audit logs.

PRJ-55689,
PRHF-34236

Security Management

Searching for a Data Center asset IP address in the policy may not return results.

PRJ-56027,
PRHF-35019

Security Management

When exporting a policy to CSV with hitcount enabled, if the hitcount timeframe is set to anything other than "All", the Hitcount column in the CSV file may appear blank.

PRJ-55831,
PRHF-34199

Security Management

Global Policy Reassignment may fail with an "An internal error has occurred" message when a custom IPS package is used or was previously used in the system.

PRJ-42207,
PRHF-25950

Security Management

The Database Installation progress bar may not update during task execution.

PRJ-50035,
PRHF-30712

Security Management

The "show-domains" Management API command may return partially deleted domains among the results.

PRJ-52453,
PRHF-28597

Security Management

In some scenarios, Access Control policy verification is stuck at 40 percent.

PRJ-46462,
PRHF-28817

Security Management

In some scenarios, policy installation using Management API with the "prepare-only" parameter set to "true" may fail with an "internal error" message.

PRJ-46234,
PRHF-28814

Security Management

Changing the main URL of the UserCheck Portal using the "set simple-gateway" Management API command fails with "DNS failed to resolve the hostname: gateway name" Executed command failed. Changes are discarded".

PRJ-52756,
PMTR-99312

Security Management

Enabling IPS on Multi-Domain Security Management Server may cause Threat Prevention policy installations to fail due to legacy IPS multi-profile incompatibility.

PRJ-55704,
PRHF-34013

Multi-Domain Security Management

In rare scenarios, objects are missing from the Gateways & Servers view on the Multi-Domain Security Management level. Refer to sk182641.

PRJ-56711,
PRHF-35700

Multi-Domain Security Management

In some scenarios, cpmiquerybin core files may appear in /var/log/dump/usermode/ on the Security Management Server.

PRJ-53993,
PRHF-33263

Multi-Domain Security Management

In some scenarios, Domain deletion may fail with a "delete domain failed: null" message.

PRJ-56540,
PRHF-34752

Multi-Domain Security Management

In some scenarios, in a Multi-Domain Security Management environment, the Hit Count retention mechanism may not remove the Hit Count data from all the Domains.

PRJ-56530,
PRHF-35418

Multi-Domain Security Management

The Multi-Domain Security Management Server experiences high CPU usage when communicating with the Multi-Domain Log Server. And the cpm.elg log prints the "You have reached the maximum number of active session" error. Refer to sk182738.

PRJ-57308,
MCFG-666

SmartConsole

SmartConsole fails to connect with "Unable to connect to server. Server is initializing". Refer to sk182507.

PRJ-39673,
PRHF-24029

SmartConsole

The "show lsm-cluster" Management API command fails with a "Null Pointer exception: null" message if the "membersNetworkOverride" field is empty.

PRJ-57420,
PMTR-107206

SmartConsole

In some scenarios, opening new tab in SmartConsole Logging & Monitoring tab fails with "HTTP error 500 - problem accessing smartview/embedded. Reason: Server Error". Refer to sk182732.

PRJ-50431,
PRHF-30878

Logging

In rare scenarios, CPU consumption on the Security Management Server is high and logs are not displayed.

PRJ-51693,
PRHF-31777

Logging

In some scenarios, after removing an existing Log Exporter instance, the creation of a new instance appears successful in SmartConsole. However, the new Log Exporter object is not actually generated.

PRJ-56643,
PMTR-107570

Security Gateway

In rare scenarios, the FWK process may unexpectedly exit when the IPS / Application Control / Anti-Virus / Anti-Bot blade is active and the HyperFlow feature is enabled.

PRJ-56731,
PMTR-107546

Security Gateway

The "asg monitor" command may show the Security Gateway in the "during upgrade" state although a major downgrade is complete.

PRJ-56700,
PRHF-35624

Security Gateway

Anti-Spoofing may drop IPv6 traffic that arrives at an interface with an IPv6 address configured. Refer to sk182725.

PRJ-57352,
PRJ-57351

Security Gateway

When SecureXL User Mode (UPPAK) is enabled and using Passive/Active Streaming with QoS, the Security Gateway may incorrectly drop some traffic.

PRJ-56721,
PMTR-107648

Security Gateway

The Security Gateway may crash during large memory allocation operations in specific applications.

PRJ-53809,
PRHF-33037

Security Gateway

The Security Gateway may crash after a failure in policy installation.

PRJ-57370,
PMTR-97905

Security Gateway

When adding a new Virtual System, a CPD core dump file may be generated.

PRJ-54069,
PRHF-33254

Security Gateway

Changing the NAT settings of a host using the "set-host" Management API command succeeds but has no effect unless both the "ipv4-address" and "ipv6-address" parameters are set.

PRJ-54118,
PRHF-33299

Security Gateway

In a rare scenario, the FWK process may exit when cluster connection synchronization fails.

PRJ-57253,
PMTR-107381

Security Gateway

In some scenarios, the Security Gateway does not free some packets causing a memory leak.

PRJ-45939,
PRHF-28443

Security Gateway

Some of the "fw ctl affinity" commands may take longer than expected to display the output.

PRJ-58099,

PMTR-109857

Security Gateway

Traffic through specific interfaces is dropped when the QoS blade is active and "ISP redundancy-LS" is configured. Refer to sk182807.

See the Critical Information section.

PRJ-57128,
PRHF-31189

Threat Prevention

Threat Prevention policy installation may fail because of invalid JSON format in the IoC feed feature configuration file. Refer to sk181650.

PRJ-57748,
PMTR-100232

Threat Prevention

The Threat Prevention policy installation may fail when installing from R81.20 SmartConsole on R80.x Security Gateway.

PRJ-55376,
PRHF-33771

Threat Prevention

In some scenarios, the TPD daemon may cause high CPU usage because of a large amount of logs.

PRJ-56329,
MBS-18307

Threat Prevention

In a rare scenario, the Security Gateway may crash during traffic inspection when holding a connection.

PRJ-50242,
PMTR-83242

Threat Prevention

In a rare scenario, Anti-Bot and Anti-Virus packages may be seen as not updated in SmartConsole, even though the packages are updated.

PRJ-53589,
PRHF-32655

Identity Awareness

In Azure Active Directory, access role assignment only considers a user's first 100 group memberships. Any groups beyond this limit are disregarded when determining user access roles.

PRJ-56513,
PMTR-100177

Application Control

The fwk.elg file may be flooded with the "DNS_DATA_SOURCE failed on context 201, executing context 366 exception" messages. Refer to sk182606.

PRJ-56623,

PMTR-107215

IPS

IPS may drop an IPv6 TCP local connection.

PRJ-54430,
PRHF-33644

IPS

In a rare scenario, when IPS is enabled and logging on a rule that involves IPS is enabled, physical memory usage may rapidly increase.

PRJ-56041,
PRHF-34907

Anti-Virus

In some scenarios, the Anti-Virus Blade logs on a VSX Gateway may display an incorrect origin IP address.

PRJ-58111,

PMTR-102962

ClusterXL

VSX Cluster Members with VLAN interfaces change their cluster state to "Down" and "Active!" after installing the R81.20 Jumbo Hotfix Accumulator Take 89. Refer to sk182819.

See the Critical Information section.

PRJ-56806,
PMTR-84843

SecureXL

When the VSX Gateway is created, the parameter that determines whether VSX mode is enabled or disabled is not set in SecureXL configuration until a reboot is performed.

PRJ-56827,
PMTR-107903

SecureXL

The USIM process may occur if CPView stats are collected during the "cpstop" operation for VSX.

PRJ-57429,
PRHF-36137

SecureXL

When SecureXL User Mode (UPPAK) is enabled and running ESP traffic, packet loss may occur and the "fwconn_key_init_links failed" error is printed. Refer sk182775.

PRJ-57251,
PMTR-102529,

PRJ-57249,
PMTR-98868

SecureXL

In some scenarios, the Security Gateway crashes when SecureXL User Mode (UPPAK) is enabled.

PRJ-56944,
PRHF-35953

SecureXL

The USIM process exits when attempting to delete an IP address from an empty deny list if that IP address exists in any other deny lists (including the regular deny list or those using IoC feeds).

PRJ-57428

SecureXL

In some scenarios during low TCP traffic, there is high CPU usage when SecureXL User Mode (UPPAK) is enabled.

PRJ-57613,
PMTR-109276

SecureXL

The USIM process may unexpectedly exit when these parameters are enabled in the $PPKDIR/conf/simkern.conf file:

  • "sim_top_conns_enable" - the tracking of the top connections.

  • "sim_top_proto_enable" - the tracking of the top protocols.

PRJ-56903,
PMTR-108071

Routing

The ROUTED daemon may exit with a core dump during a BGP or OSPF restart.

PRJ-56524,
PMTR-101893

Routing

In a ClusterXL environment, a race condition may occur when BGP Graceful Restart is incorrectly configured. If the feature is enabled for some peers but not others, it may lead to permanent loss of network routes.

PRJ-55305,
PRHF-32694

Gaia OS

The "cpviewd: unable to read from gpio_nuvoton driver module. snmpd: unable to read from gpio_nuvoton driver module" messages may be printed in /var/log/messages.

PRJ-52907,
PRHF-32420

Gaia OS

In some scenarios when MDPS is enabled, the "Loading kernel module for a network device with CAP_SYS_MODULE (deprecated). Use CAP_NET_ADMIN and alias netdev-eth7 instead" message appears in /var/log/messages.

PRJ-56120,
PRHF-35200

Gaia OS

The "Unable to connect to the server, Press OK to reconnect" error is displayed when opening the Network Interfaces tab in the Gaia Portal. Refer to sk182560.

PRJ-56053,
PRHF-35042

Gaia OS

Adding multiple VPN tunnels via Clish in Transaction Mode fails, while adding them individually succeeds.

PRJ-57596,
PRHF-36233

VPN

IKEv2 VPN tunnels experience multiple Child SA timeouts after an upgrade. Refer to sk182735.

PRJ-51350,
PRHF-31438

VPN

Remote Access VPN connections in Maestro environments may be dropped with the "out-of-state" reason.

PRJ-50156,

PMTR-93643

VPN

When working with iOS devices, after establishing a VPN connection and subsequently disconnecting devices, the "vpn tu tlist" command may display an incorrect device connection status, indicating that a device is still connected.

PRJ-55886,
PMTR-106172

VSX

Deleting a Virtual System ID (VSID) that does not exist may trigger the "cpstop" command. Stopping all Check Point services on VS0 can disrupt the entire VSX environment.

PRJ-56479,

PMTR-107271

VSX

In some scenarios, the VSX cluster can take extra time to boot up and activate the Virtual Systems.

PRJ-37243,
PMTR-73814

Scalable Platforms

The gClish scheduled backup retention command is applied to SMO member only and not on all Security Group members as it should.

PRJ-31708,
PMTR-73815

Scalable Platforms

After a scheduled backup is performed, redundant backup files may be generated on Security Group members.

PRJ-44696,
PRHF-27834

Scalable Platforms

When running the "asg resource" command, the SSD overall health check is displayed as "PASSED" with the "Unknown_Attribute on Member X_XX is below/getting towards low threshold (val: 0/ thresh: 0)" warning. The issue is cosmetic only.

PRJ-56568,
PRJ-31526

Scalable Platforms

A backup or snapshot operation may fail with the "Another backup is currently in execution" error when the backup file does not exist on any of the members in the Security Group.

PRJ-56313,
MBS-18304

Scalable Platforms

The VSX Gateway may cause traffic interruption when SecureXL User Mode (UPPAK) is enabled on systems with multiple physical interfaces.

PRJ-56968,
PRJ-56967

Scalable Platforms

After upgrade on Quantum Maestro and Scalable Chassis, when working in SecureXL User Mode (UPPAK), policy installation may fail.

PRJ-48866,
PMTR-87890

Scalable Platforms

Using Image Cloning when the same VMAC feature is enabled may cause a boot loop.

PRJ-46193,
PRHF-28141

Scalable Platforms

In a Maestro environment, when MDPS is enabled, the "asg if --diag" command reports the "no files matched glob pattern "/sys/class/net/BPEth*/operstate" error.

PRJ-55683,
PRHF-34515

Smart-1 Cloud

When creating multiple Interoperable Devices with dynamic IP addresses, the duplicate IP addresses may be assigned to Interoperable Devices. Refer to sk181834.