R81.20 Jumbo Hotfix Take 158

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 158

Released on 22 July 2026

Take 158 - New Functionality

 

PRJ-67020,
PMTR-124959

Security Management

NEW: Added a new Management API command to retrieve an entire Access Control Layer (including inline layers) - "export-access-rulebase".

PRJ-69423,
PRHF-45847

Scalable Platforms

NEW: Added a configuration option for Maestro Orchestrator to forward Spanning Tree Protocol (STP) BPDUs to Maestro Security Group Members. Refer to sk185110.

Take 158 - Improvements and Resolved Issues

 

PRJ-70599,

PMTR-129991

Gaia OS

UPDATE: Resolved CVE-2026-62145 - Local privilege escalation in Gaia Portal. Refer to sk185153.

PRJ-70486,

PMTR-129956

Security Management

UPDATE: Resolved CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation. Refer to sk185152.

PRJ-70934,

PMTR-130686

Security Management

UPDATE: Resolved CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token. Refer to sk185169.

-

-

This Jumbo Hotfix Accumulator Take provides additional Management and Gateway hardening fixes, including VPN Site to Site and Remote Access.

PRJ-69641,
ODU-4190

Automatic Updates - Security Management

UPDATE: Added Take 89 and Take 90 of the AutoUpdater Utility. Refer to sk165653.

PRJ-69417,
ODU-4204,

PRJ-70010,
ODU-4253,

PRJ-70565,

ODU-4316

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 171, Take 173, and Take 176 of Web SmartConsole. Refer to sk170314.

PRJ-69644,
ODU-4086,

PRJ-70602,

ODU-4337

Automatic Updates - Log Exporter

UPDATE: Added Take 65 and Take 70 of Log Exporter Auto Update Deployment. Refer to sk182866.

PRJ-69638,
ODU-4225,

PRJ-66381,
ODU-3435,

PRJ-70663,

ODU-4330

Automatic Updates - Policy Insights

UPDATE: Added Take 80, Take 82, Take 87, Take 94, and Take 96 of Policy Insights Release Updates. Refer to sk183421

PRJ-69587,
ODU-4093

Automatic Updates - Smart-1 Cloud

UPDATE: Added Take 13 and Take 75 of Smart-1 Cloud MaaS Tunnel. Refer to sk166056.

PRJ-69572,
ODU-4218

Automatic Updates - HCP

UPDATE: Added Update 28 of HealthCheck Point (HCP) Release. Refer to sk171436

PRJ-70143,
ODU-4232,

PRJ-69583,
ODU-4169

Automatic Updates - CPView

UPDATE: Added Take 57 and Take 59 of CPquid (QUID) Release Updates. Refer to sk181458.

PRJ-65594,
HEC-1347

Automatic Updates - HCP

UPDATE: Added a new HCP test that analyzes load balancing and NAT utilization, and suggests optimal distribution adjustments accordingly. Refer to sk171436.

PRJ-70685,

ODU-4351

Automatic Updates - HCP

UPDATE: Added Take 94 of HealthCheck Point (HCP) Release. Refer to sk171436

PRJ-68746,
ODU-4030

Automatic Updates - Threat Prevention

UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109.

PRJ-67356,
PRHF-43660

Security Management

UPDATE: JRE is updated from version 8.0_8.50 to version 8.0_8.60.

PRJ-62060,
PMTR-111171

Security Management

UPDATE: In environments with hundreds of Updatable Objects, policy installation time has been significantly improved.

PRJ-57222,
PRHF-36163

CPView

UPDATE: On the Exporter Rates tab in CPView, the Log Exporter configuration name length limit is now increased from 15 characters to 25 characters. This resolves the issue when the configuration name may appear blank if it exceeds the length limit.

PRJ-65492,
PMTR-122413

Logging

UPDATE: SmartEvent now supports the "system alert" log type for URL Filtering and Application Control Software Blades.

PRJ-68501,
PMTR-127051

Logging

UPDATE: In the Logs view, search performance is improved when the search term includes a Cluster.

PRJ-65349,
PMTR-118923

Security Gateway

UPDATE: Added the ability to automatically stop kernel debugging after a specified number of seconds. See the R81.20 Quantum Security Gateway Administration Guide. Refer to the command "fw ctl debug -T <Number of Seconds>".

PRJ-67792,
PRHF-44615

Security Gateway

UPDATE: Optimized Mobile Access policy installation to improve performance in environments with a large Mobile Access Rule Base (more than 500 rules).

PRJ-65588,
PRHF-42963

Security Gateway

UPDATE: In environments with thousands of Domain objects or External User Groups, the policy installation duration has been significantly improved.

PRJ-66948,
PRHF-44085

Security Gateway

UPDATE: Added the "tap_mode" parameter to a dispatcher (fwmultik_dispatcher_in_tap_mode). This parameter puts the multi-core dispatcher into the Tap Mode for inbound traffic. Refer to sk184455.

PRJ-60907,
PRHF-39442

SSL Inspection

UPDATE: Added support for the X.509v3 Subject Key Identifier (SKI) and Authority Key Identifier (AKI) extensions in the HTTPS outbound inspection Certificate Authority (CA). Refer to sk184273.

PRJ-67381,
PMTR-125446

Mobile Access

UPDATE: Resolved the Mobile Access Portal XSS vulnerability in the PHP file.

PRJ-66694,
PMTR-124314

Mobile Access

UPDATE: The Magnific Popup JavaScript library is upgraded from the 1.1.0 version to 1.2.0.

PRJ-68782,
PMTR-127386

Gaia OS

UPDATE: Gaia API updates are now included in the Jumbo Hotfix Accumulator (previously were installed by AutoUpdater). See sk143612.

PRJ-63808,
PRJ-65094

Cloud Firewall

UPDATE: Azure VM sizes v2 and v3 are no longer supported. During installation of Jumbo Hotfix Accumulator or in-place upgrade, this message is now displayed: "The Azure VM size {VMsize} is deprecated for upgrade. Refer to sk183693 for details"

PRJ-67527,
PMTR-125744

Scalable Platforms

UPDATE: Old SVMAC feature is now deprecated ("toggle_same_vmac" parameter is blocked). Only use the new SVMAC feature ("toggle_same_vmac_os"). Refer to sk165674.

PRJ-64981,
PMTR-121665

Scalable Platforms

UPDATE: Improved warning message, user confirmation prompt, and audit logging when running the "set fcd revert" command in gClish on a Scalable Platform Security Group.

PRJ-62352,

PRHF-37359

Scalable Platforms

UPDATE Global parameter "fwha_grade_should_consider_lacp" is now disabled by default.

PRJ-66879,
PMTR-117271

Scalable Platforms

UPDATE: Change in "asg monitor" and "ast stat -v" commands: when there is a grade difference between sites, manual site failover is now blocked, and a warning is displayed.

PRJ-60553,
PRHF-30495

Scalable Platforms

UPDATE: "asg_route" tests is now removed from the "asg_diag" command options.

PRJ-61156,
PRHF-39669

Diagnostics

When the "Same VMAC" feature is enabled, concurrent connections are not updated during site failover.

PRJ-60389,
PRHF-39002

CPView

In the VLAN interface, CPView shows the speed of the parent.

PRJ-67371,
PRHF-44242

CPView

CPU information may not be displayed in the CPU tab in CPView for an environment with Virtual Systems.

PRJ-68532,
PRHF-45122

Security Management

In rare scenarios, the FWM process on the Multi-Domain Security Management Server may not stop after running mdsstop.

PRJ-66178,
PRHF-43671

Security Management

In some scenarios, accumulated open sessions can cause the Security Management Server to become unavailable.

PRJ-55499,

PRHF-34095

Security Management

The delay may be observed during the "compiling policy" and "generating policy files" stages in SmartConsole.

PRJ-65206,
PRHF-42646

Security Management

API login to the Security Management Server may fail with a "Null Pointer Exception" error when the session name, comment, or description is specified.

PRJ-61548,
PRJ-62108

Security Management

In some scenarios, the automatic update of Data Center assets fails. Refer to sk184316

PRJ-60902,
PRHF-39412

Security Management

In some scenarios, when attempting to view a revision in SmartConsole, it unexpectedly crashes after several minutes with the error message: “SmartConsole has experienced a serious problem and needs to relaunch.”

PRJ-67190,
PMTR-124870

Security Management

In some scenarios, after the FWM process crashes and generates a core dump, High Availability synchronization may fail, and the Security Management Servers may appear as disconnected.

PRJ-68292,
PRHF-45027

Security Management

SmartTasks may fail to send email notifications with a "send mail to <email address> failed" error when the Cc field is populated

PRJ-64521,
PRHF-42149,

PRJ-64524,
PRHF-42412

Security Management

In some scenarios, opening a Security Gateway object in SmartConsole fails with "Smart Dashboard component failed to connect to a server".

PRJ-63496,
PRHF-41612

Security Management

Policy installation may fail with "failed to get tls rulebases from policy id".

PRJ-63493,
PRHF-41691

Security Management

If the "Revert to Revision" operation fails:

  • Login to the Security Management Server may fail with timeout.

  • Publish operations may take a long time.

PRJ-66976,
PRHF-44315

Security Management

The FWM process may exit because of memory exhaustion and generate large core files (up to 4GB).

PRJ-66030,
PRHF-43621

Security Management

In some scenarios, the Security Management Server may generate excessive log messages, causing the cpm.elg log file to reach its size limit quickly.

PRJ-66224,
PRHF-43824

Security Management

Packet mode search does not return results for Inline Layer rules in SmartConsole and Management API. Refer to sk184638.

PRJ-65777,
PRHF-43423

Security Management

In rare scenarios, some Management API commands may fail with "Management server failed to execute command" error. 

PRJ-63909,
PRHF-41943

Security Management

In some scenarios, the "show-tasks" Management API command displays incorrect results when the "from-date" and "to-date" parameters are used. Refer to sk184072.

PRJ-64044,
PRHF-42109

Security Management

In some scenarios, running the "api stats" command with the "-calc_avg_duration" flag on the Security Management Server fails with the "IndexError: list index out of range" error. Refer to sk184144.

PRJ-64100,
PRHF-42074,

PRJ-66378,
PRHF-43925

Security Management

In rare scenarios, the Security Management Server fails to start after performing a "Revert to Revision" operation.

PRJ-65161,
PRHF-42879

Security Management

In SmartTask-generated emails, the Sender field displays the username instead of the user's email address.

PRJ-63532,
PRHF-41677

Security Management

Rulebase search for a specific user may fail to return rules that include user groups in which the user is a member.

PRJ-69130,
PMTR-127809

Security Management

In some scenarios, the FWM process on the Security Management Server may unexpectedly exit when performing the "Fetch branches" action in the LDAP Account Unit properties window of SmartConsole.

PRJ-66973,
PRHF-44216

Security Management

A SmartTask configured to send an email after policy installation may fail when the target gateway is a VSX object.

PRJ-66867,
PRHF-44037

Security Management

SmartConsole may display the error "the user already exists" when attempting to create a new administrator with the same name as a previously deleted SAML (Identity Provider) administrator.

PRJ-66324,
PRHF-43883

Security Management

In some scenarios, an API key may become invalid after editing an administrator account.

PRJ-66605,
PMTR-124200

Security Management

If the MGMTCOMP-DIFF-REPORT-CLIENT process becomes suspended on the Security Management Server, the Server-side Change Report Generator fails to generate and send reports when processing a large number of changes.

PRJ-65007,
PRHF-42618

Security Management

In some scenarios, the submit-time field in emails generated by SmartTask displays an incorrect value.

PRJ-65035,
PRHF-42720

Security Management

In some scenarios, the status of a Security Gateway is incorrectly displayed in the Gateways & Servers View.

PRJ-65046,
PRJ-65041

Security Management

When connecting a Domain to the Check Point Portal, Dedicated Log Servers in the Domain may not be automatically connected.

PRJ-63570,
PRHF-41727

Security Management

The Security Management Server upgrade may fail during the export phase with the "Object not found - Entities can not be found" message.

PRJ-65446,
PRHF-43029

Security Management

In some scenarios, Global Domain assignment may fail with the "Failed to save the access policy assignment properties" error.

PRJ-66945,
PRHF-44222

Security Management

SmartWorkflow may incorrectly show zero changes for a session, preventing the change report from being displayed. Refer to sk184779.

PRJ-65669,
PRHF-43067

Security Management

In some scenarios, the Domain Log Management Server fails to connect to the Check Point Portal.

PRJ-61278,
PRHF-39745

Security Management

In some scenarios, the "show-simple-clusters" Management API command with details-level set to "full" may fail with the error message "Configuration Sharing Failed to update Infinity Portal".

PRJ-61280,
PRHF-38623

Security Management

In rare scenarios, the /var/tmp directory may be filled up with redundant tmpUserDefineCmd_OS0*.sh files, created during Compliance Software Blade scans.

PRJ-61771,
PRHF-40047

Security Management

Security Gateway license information may not be visible in SmartConsole when using Demo mode or when connecting with a read‑only user.

PRJ-59613,
PRHF-38392

Security Management

Upon creation of a new Domain on a Multi-Domain Security Management Server, the Domain Server's virtual IP address is not added to the Gaia database, making it inaccessible via Clish commands. Refer to sk183941.

PRJ-68994,
PMTR-127578

AIOps

A temporary fix related to the QUID identity database (used by CPDiag and AIOps) caused issues in Maestro environments and led to degradation and occasional agent resets in AIOps, as it relies on this component as its IdentityDB. The fix has therefore been removed.

PRJ-56715,
PRHF-35509

Logging

In the Connection logs, the Source Country and Destination Country fields may contain missing or incorrect values.

PRJ-59832,
PRHF-38494

Logging

In HTTPS Inspection logs, some log entries may incorrectly display "Log Update" in the Software Blade field.

PRJ-64073,
SL-9462

Logging

In some scenarios, incorrect values are shown in the "Total Bytes" field in the logs. Refer to sk184237.

PRJ-66841,
PRHF-44182

Logging

In some scenarios, non-ASCII characters may appear garbled in SmartEvent Automatic Reaction emails.

PRJ-66530,
PRHF-44001

Logging

CPView may display "N/A" values for logging-related metrics when there is insufficient free disk space in the log partition.

PRJ-63013,
PRHF-41211

Logging

In some scenarios, the SmartLog Server process may unexpectedly exit and generate a core dump.

PRJ-66903,
PRHF-44038

Logging

High load on the LOG_INDEXER process may impact system performance.

PRJ-66321,
PMTR-123346

Logging

In some scenarios, the LOG_INDEXER process unexpectedly exits and generates a core dump.

PRJ-66656,
PRHF-41752

Logging

In SmartConsole, when exporting logs from the Logs tab to a CSV file, the "Rule" column may display only the parent rule number instead of the specific inline rule number.

PRJ-65331,
PRHF-42927

Logging

In SmartView Monitor, opened from the Logs & Events > Tunnel & User Monitoring view, the "SmartEvent Correlation Unit" status may be displayed as "Not running" although the CPSEMD process is running.

PRJ-63440,
PRHF-39816

Logging

In a Management High Availability environment, configuring threshold settings in SmartView Monitor, fails with the "Couldn't load threshold settings for the selected gateway" error.

PRJ-65905,
PMTR-121592

Logging

In the "HTTPS Inspection Statistics" in SmartView, filtering by the "bypass_reason" field returns no results.

PRJ-60250,
PRHF-36152

Logging

SmartEvent processes may unexpectedly exit in environments containing over 1 million network objects.

PRJ-68593,
PRHF-45113

Security Gateway

In a rare scenario, the FWK process crashes when the Mirror and Decrypt feature handles large MTU frames.

PRJ-62434,
PRHF-40579

Security Gateway

FTP traffic does not pass through Security Gateway when using the FTP Extended Passive Mode. Refer to sk183853.

PRJ-64833,
PRHF-42537

Security Gateway

Legitimate files may be incorrectly flagged as malicious when scanned with ICAP. Refer to sk184628.

PRJ-57232,
PRHF-29611

Security Gateway

In a rare scenario, the CPD process may crash because of a race condition.

PRJ-62968,

PRHF-41301

Security Gateway

In rare scenarios, when deleting a subordinate interface from a bonding group, the FWK process may exit. Refer to sk183736.

PRJ-65663,
PRHF-43354

Security Gateway

There may be high CPU usage by the CMID process when the ICAP Client is enabled on Security Gateway. Refer to sk184524.

PRJ-66747,
PRHF-44002

Security Gateway

When ISP Redundancy is enabled, and the administrator changes the priority, the primary ISP may not be updated in the Security Gateway (the route is updated, but the Security Gateway continues to consider the old ISP as the primary/standby). Refer to sk184923.

PRJ-68165,
PMTR-113101

Security Gateway

Policy installation may fail because of empty settings in Suspicious Activity Monitoring (SAM) rules.

PRJ-60595,
FMW-2291

Security Gateway

In cluster configurations, synchronization between members was optimized to reduce CPU overhead.

PRJ-62366,
PMTR-116380

Security Gateway

On 9400, 9700, and 9800 Check Point Firewall Appliances, the throughput is blocked up to ~2.5G for IPv6 tests.

PRJ-64518,
PRHF-41790

Security Gateway

First packet may be delayed for around 10 seconds because of pending WSDNSD DNS lookup over TCP. Refer to sk184096.

PRJ-64161,
PRHF-42100

Security Gateway

In rare scenarios, ElasticXL VSX Cluster Members fail over several times per day because of HTTP/2 explicit proxy process termination. Refer to sk184932.

PRJ-65228,
PRHF-42920

Security Gateway

Active Streaming Layer connections become stuck, resulting in increased memory consumption over time on the Security Gateway. 

PRJ-65267,
PMTR-121815

Security Gateway

In some scenarios, non-accelerated traffic from a Standby VSX Cluster member may not be routed to the correct virtual instance on the current Active member when SecureXL User Mode (UPPAK) is enabled.

PRJ-63998,
PRHF-42068

Security Gateway

Suspicious Activity Monitoring (SAM) rules may not function properly on a standalone device. Refer to sk184330.

PRJ-67079,
PRHF-44360

Security Gateway

On ClusterXL and in Maestro Security Groups, after performing a rolling upgrade that includes a change in the CoreXL instance count, newly created firewall instances may remain in local-sync-only mode. As a result, these instances do not receive state updates from their peers, leading to intermittent connection failures and "First packet isn't SYN" drops. Refer to sk184786.

PRJ-67745,
PMTR-125710

Security Gateway

In a rare scenario, the FWD daemon may restart because of the Application Control Dynamic URL List version file.

PRJ-67646,
PRHF-44347

Security Gateway

In some scenarios, internal memory mishandling in global connections may cause unexpected behavior or connectivity issues.

PRJ-67155,
PRHF-44365

Security Gateway

In some scenarios related to Check Point Active Streaming (CPAS), the Security Gateway may unexpectedly crash.

PRJ-66358,
PRHF-43916

Security Gateway

The BMAC/VMAC verification for a VSX Maestro Security Group member incorrectly reports a failure on warp interfaces.

PRJ-65756,
PRHF-42940

Security Gateway

Some service ports may be missing in some instances, resulting in unexpected behavior for some services.

PRJ-65726,
PRHF-43228

Security Gateway

In some scenarios, when the Mirror and Decrypt feature is enabled, there may be traffic disruption.

PRJ-64087,
PRHF-40610

Security Gateway

The RAD daemon may unexpectedly exit when customizing RAD internal parameters ("max_flows" and "queu_max_capacity"). Refer to sk182136

PRJ-64077,
PRHF-41256

Security Gateway

In scenarios where a network connection is closed before the Anti-Virus ThreatCloud emulation or scanning response is received, the affected session may experience connectivity instability.

PRJ-64055,
PRHF-42098

Security Gateway

In rare scenarios, the FWK process may unexpectedly restart when an HTTP/2 connection containing specific stream characteristics is released.

PRJ-66620,
PRHF-44062

Security Gateway

In rare cases, the FWK process may restart unexpectedly while the Security Gateway is processing a URL Filtering categorization response and a policy installation is running simultaneously.

PRJ-66488,
PRHF-43994

Security Gateway

In a rare HTTP/2 traffic scenario, a valid connection may fail.

PRJ-65441,
PRHF-42991

Security Gateway

The SD-WAN NAT rule may not be applied when no NAT is defined in the Access Control policy.

PRJ-63681,
PRA-5002

Security Gateway

In a rare scenario, the FWD process may crash during Policy Installation because of memory corruption related to licensing.

PRJ-63658,
PRHF-41793

Security Gateway

FTP transfers of files smaller than 1KB fail and result in empty files on the destination server. Refer to sk184200.

PRJ-65521,
PRHF-42914

Security Gateway

RSH connections fail when Destination NAT is configured for the RSH server. Refer to sk184768.

PRJ-66803,
PRHF-44149

Security Gateway

In rare scenarios, the FWK process may unexpectedly exit when the Anti-Bot Software Blade inspects a specific malformed domain.

PRJ-66419,
PRHF-43935

Security Gateway

In a rare scenario, a memory leak may occur due to a race condition between policy installation and Application Control/IPS signature updates, and persists until the next policy installation.

PRJ-66431,
PRHF-43910

Security Gateway

The memory usage may increase over time when using the Mirror and Decrypt feature.

PRJ-66003,
PRHF-43522

Security Gateway

In a rare scenario, an incorrect zone assignment occurs when NAT Rule Base returns HOLD. Refer to sk184530.

PRJ-65977,
PRHF-43452

Security Gateway

After an upgrade, the "show configuration" command output for MDPS may be missing bond configuration.

PRJ-64913,
PRA-4998

Security Gateway

When ESP traffic is present in the environment, and the fwmultik_dispatcher_in_tap_mode parameter is enabled, the Security Gateway may drop ESP traffic.

PRJ-64755,
PRHF-38664

Security Gateway

The ICAP client does not work correctly, impacts the allowed number of characters for the ":service" field in the $FWDIR/conf/icap_client_blade_configuration.C ICAP configuration file.

PRJ-62611,
PRHF-41063

Security Gateway

In some rare scenarios, when HyperFlow is enabled, HTTPS traffic fails when processed in the accelerated pipelined path. Websites going through SSL Inspection may take a long time to load or parts of the website may not load.

PRJ-61384,
PMTR-113498

Security Gateway

In a VSX setup, when Dynamic Balancing is enabled, and an Elephant Flow is running, only one firewall instance may remain active to handle the rest of the traffic.

PRJ-64845,
PMTR-120708

Security Gateway

HTTPS inspection causes connections to fail when using a custom service with a non-standard HTTPS port (for example, TCP/9400), and the custom service object is configured with "Protocol: None". Refer to sk184294.

PRJ-63599,
PMTR-117005

Security Gateway

In some scenarios, DOS/Rate Limiting causes blocking errors during boot.

PRJ-63725,
PMTR-94556

Security Gateway

Connections handled by CPAS may stop forwarding data upon receiving a FIN from one side. As a result, a file download fails.

PRJ-60247,
PMTR-113336

Security Gateway

In some scenarios, active connections using HyperFlow are closed following a crash of the dmd_run process, and the FWK process may also crash. This error appears in the dmd.elg file: "mux_dmd_handle_errors_from_dmd: Handling errors from DMD. error SESSION_COLLISION".

PRJ-58537,
PRHF-37274

Threat Prevention

SSH connections may fail after enabling SSH Deep Packet Inspection (DPI).

PRJ-69301,
PMTR-124700

Threat Prevention

In some scenarios, Zero Phishing becomes inactive during traffic inspection when Anti-Virus performs a Deep Scan on HTML or JavaScript files.

PRJ-68771,
PMTR-127315

Threat Prevention

IoC feed observables may continue to be enforced even after Anti-Virus and Anti-Bot are disabled.

PRJ-66295,
PMTR-123479

Threat Prevention

In a rare scenario, the Threat Prevention rule base may fail to match traffic to any rule.

PRJ-65306,
PRHF-42982

Threat Prevention

In rare scenarios, the Anti-Virus fails to inspect HTTP file downloads.

PRJ-63419,
PMTR-114692

Threat Prevention

In certain scenarios, IP Range observables using CIDR notation within an IoC feed may not be enforced by the Gateway. Refer to sk184031.

PRJ-57712,
PRHF-36392

Identity Awareness

The Microsoft Graph API access token does not renew if an authorization error occurs while working in on-demand fetch mode.

PRJ-65631,
PRHF-42181

Identity Awareness

Identity Awareness AD user authentication takes a long time. Refer to sk183748.

PRJ-69141,
PMTR-127848

Identity Awareness

The default role in Aruba Networks ClearPass CPPM does not match the identity sessions.

PRJ-64693,
PRHF-42522

Identity Awareness

When the Packet Tagging feature is enabled on the Full Identity Agent, new user and machine identity sessions reported to the Identity Awareness Gateway may not be assigned the correct access roles. As a result, traffic from these sessions may not match Access Control Policy rules that use access roles with Packet Tagging enabled.

PRJ-64119,
PRHF-41176

Identity Awareness

In a rare scenario, there may be no access to resources for identities received from the Remote Access identity source.

PRJ-64919,
PRHF-42534

Identity Awareness

In a rare scenario, a Policy Decision Point (PDP) Security Gateway that acts as both an Identity Broker Subscriber and a sharing identity with a Policy Enforcement Point (PEP) may become unresponsive.

PRJ-59798,
PRHF-38576

Identity Awareness

SNMP queries to the Security Gateway may return unexpected results: specific IP addresses or Identity Collector objects may continue to appear in SNMP outputs even after being removed from the topology configuration. Additionally, polling OIDs such as 1.3.6.1.4.1.2620.1.38.55 or 1.3.6.1.4.1.2620.1.38.53 may result in the message "No Such Instance currently exists at this OID"

PRJ-64785,
PRHF-42302

Identity Awareness

In some scenarios, the PDPD process stops responding and users cannot authenticate through the Identity Awareness. Refer to sk184407.

PRJ-65959,
PMTR-123099

Application Control

Updating two or more Dynamic URL Lists may result in partial updates.

PRJ-66560,
PRHF-43834

Application Control

When using custom applications and SD-WAN, HTTPS traffic may be blocked with "Reason: Application Control - Internal system error" in SmartConsole log.

PRJ-65875,
PMTR-123004

Application Control

In a rare scenario, when using Dynamic URL List, updating the version file may result in a FWK process restart.

PRJ-67578,
PRHF-44375

URL Filtering

RAD request drop may occur in rare case header includes unsupported characters.

PRJ-67374,
PMTR-125272

IPS

In some scenarios, the Custom Threat Prevention policy fails to enforce IPS protection overrides on rules configured with a network group in the "Install On" column.

PRJ-59837,
PRHF-38433

DLP

In some scenarios, changes to the kernel parameter "dlpk_drv_default_queue_sz" may not take effect.

PRJ-65023,
PRHF-42722

Anti-Virus

In rare scenarios, the RAD process may exit generating a core dump.

PRJ-65578,
AAD-8717

SSL Inspection

A memory leak may occur in the parsers_is TLS module when HTTPS Inspection is enabled and used to inspect non-standard TLS traffic transmitted over a proxy.

PRJ-66593,
PRHF-44051

Mobile Access

When Mobile Access is working in Path Translation (PT) Link Translation mode, the Citrix application may not load after an upgrade to Citrix version LTSR 2507

PRJ-70252,
PMTR-129404

Mobile Access

After hardening non-RFC-compliant HTTP requests, some Mobile VPN connections fail. Since multiple clients send bare LF requests (a specific type of non-RFC-compliant traffic), bare LF errors are now disabled by default. This behavior can be enabled using the kernel parameter "ws_block_bare_lf".

PRJ-64364,
PRHF-40663

ClusterXL

Connections with fragmented packets drop on Scalable Platform/Maestro when there are multiple active Security Group Members (SGMs) on the site. Refer to sk182559.

PRJ-64089,
PRA-5003

ClusterXL

When MDPS is enabled, cluster members may remain in INIT or DOWN state after reboot.

PRJ-66292,
PRA-5197

ClusterXL

In rare scenarios, CPHASTART, CPHACONF, and CPHAMCSET processes may intermittently unexpectedly exit.

PRJ-66147,
PMTR-123186

ClusterXL

After rebooting specific Security Group Members (SGMs) in a dual-site Maestro environment, PDP (Policy Decision Point) to PEP (Policy Enforcement Point) connections are not always corrected to the SMO (Single Management Object) as expected. This results in connection restarts and additional CPU load.

PRJ-65991,
PRHF-43213

ClusterXL

In some scenarios, the USIM process may unexpectedly exit.

PRJ-59710,
PRHF-37976

ClusterXL

The "cphaconf failover_bond <bond_name>" command fails with Management Data Plane Separation (MDPS). Refer to sk183935.

PRJ-66066,
PMTR-121465

SecureXL

In a Cloud Firewall environment with Kernel Performance Pack (KPPAK) enabled by default, when modifying the TX queue size parameter for supported network interfaces to 2048 (2K) or 4096 (4K), reverting the setting back to the default value of 1024 (1K) is not possible.

The issue is observed with these synthetic network drivers: virtio (used in GCP and KVM environments), vmxnet3 (used in VMware ESXi), and ena (used in AWS).

PRJ-66601,
PMTR-117662

SecureXL

In some scenarios, a crash occurs when many concurrent nexthop lookups are performed.

PRJ-57244,
PMTR-103508

SecureXL

Added logic to forbid IP forwarding at startup if the deny list/rate limit policy installation fails.

PRJ-64487,
PMTR-120867

SecureXL

In rare scenarios, instability of the User Space Firewall during system boot may cause failures in SecureXL User Mode (UPPAK).

PRJ-64173,
PRHF-42253

SecureXL

The "arping" command on the Security Gateway returns this output "Sent 4 probes Received 0 response" in SecureXL User Mode (UPPAK). Refer to sk184292.

PRJ-64146,
PMTR-120207

SecureXL

The Security Gateway with SecureXL User Mode (UPPAK) enabled may not properly update routes when bond interfaces are configured.

PRJ-63505,
PMTR-119083

SecureXL

When VLAN interfaces are created on top of bond interfaces configured for Load Sharing, connections may not be hardware accelerated if the bond uses multiple ports from the same physical NIC. Refer to sk184291.

PRJ-67244,
PRHF-44550

SecureXL

Maestro backplane interfaces may appear in the SYN Defender interface list. This is a cosmetic issue.

PRJ-67765,
PMTR-119508

SecureXL

When using DoS Deny List and running "cpstop", an error message may be displayed, and a memory leak may occur.

PRJ-67065,
PMTR-124718

SecureXL

The FWK process may exit during an upgrade if DOS/Rate limiting is active.

PRJ-68392,
PMTR-106768

SecureXL

In some scenarios, VPN clients establish the tunnel in Visitor Mode instead of NAT-T.

PRJ-68720,
PMTR-126262

SecureXL

After rebooting the Security Gateway, the Allow List entry is present when viewing the list, but it is not enforced. The Deny List takes precedence, and traffic from the IP is blocked, even though it should be allowed according to the configuration

PRJ-66506,
PMTR-122586

SecureXL

In some scenarios in a VSX Maestro Security Group, when SecureXL User Mode (UPPAK) is enabled, a cluster member may incorrectly forward traffic through a Warp interface to the incorrect Virtual System. This results in traffic not being processed by the intended Virtual System, potentially causing "Out of State" drops.

PRJ-66211,
PMTR-123304

SecureXL

A reference count issue in the UPPAK module can cause a USIM process core dump, particularly on busy systems with long uptime.

PRJ-66170,
PRHF-43757

SecureXL

In some scenarios, when installing a policy fails, the Sand Blast Security Gateway becomes unresponsive and reboots automatically. The "Installation failed. Reason: Due to a timeout value of 600000 (millisecond) (port) (IP), Security Management Server aborted the connection with the peer" error is displayed in SmartConsole.

PRJ-65913,
PMTR-122248

SecureXL

When SecureXL User Mode (UPPAK) is enabled on a VSX Security Gateway, taking down a warp interface on any Virtual System may cause all Virtual Systems connected to the same Virtual Router or Switch to lose network connectivity.

PRJ-65450,
PMTR-121744

SecureXL

Permanently disabling the "cphwd_enable_ecmp" global parameter on a VSX Gateway using the "-f" option of the "fwl ctl set" command may fail.

PRJ-65600,
PMTR-122439

SecureXL

When SecureXL works in User Mode (UPPAK) on Security Gateways with CPAC-4-10F-C interface modules, invalid Ethernet frames permanently shut down the port's transmit queue, causing complete connectivity loss.

PRJ-65885,
PRHF-43515

SecureXL

PPTP/GRE traffic fails when Hide NAT is used and SecureXL runs in UPPAK mode and the "fw_pptp_enforce_protocol" parameter is enabled. Refer to sk184641.

PRJ-54515,
PMTR-103535

SecureXL

The USIM process may crash because of memory allocation failures.

PRJ-61885,
PRJ-61014

SecureXL

In some scenarios, an error occurs in UPPAK mode when packets are cloned. This can lead to random crashes in the USIM process, causing instability during interface changes or high traffic.

PRJ-69885,
PRJ-69330

SecureXL

In some scenarios, the VSX Security Gateway passes traffic without performing proper NAT from a Virtual Router or Switch's external interface when SecureXL User Mode is enabled.

PRJ-64012,
PMTR-119496

SecureXL

In some scenarios in UPPAK mode, the nexthops may be incorrectly indexed, which leads to packet drops.

PRJ-67172,
PRHF-44146

Routing

A ROUTED daemon may exit with a dump file during an OSPF route lookup on a route being redistributed between BGP and OSPF.

PRJ-66228,
PRHF-43674

Routing

The ROUTED daemon may exit when running the "show bgp paths" command.

PRJ-67017,
PRHF-44174

Routing

The ROUTED daemon may exit with a pnote on Security Group Members after the Orchestrator daemon (ORCHD) stops. Refer to sk184771.

PRJ-65916,
PMTR-122434

Routing

A VSX Security Gateway may drop traffic with IPv4 options or IPv6 extension headers arriving from a Virtual Switch (VSW) interface.

PRJ-67624,
PRHF-44844

VSX

When using VSX SmartProvisioning on Maestro, the operation fails if the VSX Gateway name includes the substring "wrp0".

PRJ-67113,
PMTR-123775

VSX

When adding or deleting static routes in the huge VSX environment (more than 50 Virtual Systems and hundreds of static routes), VS creation fails with "Unable to watch directory /etc/routed-mc-enable: init: Too many open files". Refer to sk181317.

PRJ-58507,
PRHF-44304

VSX

When configuring DNS addresses per-VS (different servers for different VSs), the DNS may fail.

PRJ-62321,
PMTR-116925

VSX

In some scenarios, the CPView utility causes high CPU usage or becomes stuck while calculating disk space.

PRJ-67929,

PRHF-45114

Multi-Portal

In a rare scenario, a security hardening change related to Multi-Portal connections may cause an unexpected Security Gateway restart when such a connection is terminated.

PRJ-53498,
PRHF-32832

Gaia OS

A snapshot created via the Gaia Portal is deleted immediately upon creation. Once this occurs, the operation cannot be retried. Orphaned lock files block all subsequent attempts. The error "Snapshot: Failed to take snapshot. Another backup / snapshot is currently in execution. Please try again in a few moments" is printed in the logs. Manual deletion of the lock files is required to restore functionality. Applying the workaround from sk100403 does not provide a permanent resolution, and the issue recurs.

PRJ-59153,
PRHF-37998

Gaia OS

When the nstat utility (in the iproute2 package) encounters a corrupted state file (for example, if /tmp/.nstat.u0 contains invalid data), it aborts with a core dump instead of providing an error message.

PRJ-59063,
PMTR-110978

Gaia OS

The "config_verify" command or the HCP configuration sync validation incorrectly fails because of a fwkern.conf file mismatch between the Security Group members.

PRJ-50670,
PRHF-30690

Gaia OS

Custom log rotation configured using Gaia OS does not apply to SAML-related log files, so these logs are not rotated automatically. Refer to sk113241

PRJ-56024,
PRHF-34965

Gaia OS

Custom log rotation configured using Gaia OS does not apply to UserCheck Portal log files, so these logs are not rotated automatically. Refer to sk113241.

PRJ-64588,
PRHF-41203

Gaia OS

CPU spikes may occur in a cluster when SNMP is enabled.

PRJ-67501,
PRHF-44333

Gaia OS

After an upgrade, in some scenarios, two-factor authentication (2FA) may not be enforced for SSH access. This results in users are able to authenticate via SSH without the required 2FA.

PRJ-69111,
PRHF-44815

Gaia OS

After disabling Two-factor authentication (2FA) in Gaia OS, the user still requires a 2FA code on login attempts.

PRJ-64556,
PRHF-42434

Gaia OS

Unable to enter Virtual System with "virtual-system-access all" configured. Refer to sk184282.

PRJ-66750,
PRHF-44108

Gaia OS

Cloning groups may fail during configuration updates. Refer to sk184701.

PRJ-65946,
PRHF-43616

Gaia OS

Remote and local backup operations fail after installation of Jumbo Hotfix Accumulator with the "Cannot complete the backup process: not enough space in /var/log/CPbackup/backups" error. Refer to sk183767.

PRJ-65648,
PRHF-43017

Gaia OS

Excessive log entries for RADIUS users logging into Gaia Portal. Refer to sk184534.

PRJ-66614,
PRHF-43985

Gaia OS

Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000. Refer to sk184653.

PRJ-66407,
PRHF-43907

Gaia OS

The SNMPD daemon fails to restart when an interface configured with an IPv6 address is set as the SNMP agent interface.

PRJ-65925,
PRHF-43620

Gaia OS

Clish may restart unexpectedly when running the set snapshot-onetime command.

PRJ-65698,
PRHF-42970

Gaia OS

Chassis parameters "fwha_mbs_blade_state_events" and "fwha_mbs_interface_state_events" will not be written in the fwkern.conf file if the values are not set, and the value is 0.

PRJ-65525,
PRHF-43016

Gaia OS

Upon logging in to the Gaia Portal, the login page accepts the credentials, briefly displays the homepage, and then automatically redirects back to the login screen.

PRJ-64773,
PRHF-42632

Gaia OS

Configuring an IPv6 NTP server (via CLI or WebUI) may cause the NTP service to ignore the server and repeatedly log errors.

PRJ-62670,
PRHF-40983

Gaia OS

Multiple "login_notifier_server: before force_2fa_generation, params: 2fa-check" messages appear in the /var/log/messages file. The issue is cosmetic. Refer to sk183690.

PRJ-69002,
PRHF-45517

Gaia OS

In Gaia Portal, bond member interfaces can be edited when they should be disabled.

PRJ-68249,
PMTR-126527

Gaia OS

For IDNS-Resolver, when the DNS server returns "TC=1", and communication should be moved to TCP instead of UDP, TCP communication does not block DNS requests.

PRJ-66883,
PRHF-43932

Gaia OS

In rare scenarios, the CORE_UPLOADER process on Security Gateways may unexpectedly generate a core dump when the number of detected CPU cores exceeds a specific threshold.

PRJ-67602,
PRHF-44603

Gaia OS

In some scenarios, SNMP monitoring may incorrectly report 100% CPU usage. 

PRJ-70033,

PMTR-129280

VPN

Improved certificate validation during IKEv2 VPN negotiations to ensure VPN connections are established only after successful certificate-based authentication.

PRJ-62054,
PRHF-40518

VPN

IKE daemons may fail to start on Cluster members without generating dump files.

PRJ-64805,
PRHF-42566

VPN

Traffic passing through a route-based VPN tunnel may cause high CPU usage if the traffic is fragmented.

PRJ-68989,
PMTR-116331

VPN

Added the ability to import additional .p12 certificate types as inbound and outbound certificates.

PRJ-67351,
PMTR-125245

VPN

In VPN Site-to-Site environments, a memory leak in VPN-related processes may occur after a VPN driver restart, or during prolonged system runtime.

PRJ-69426,
PMTR-128278

VPN

Improved input validation in the VPN L2TP PPP packet parser to handle malformed configuration options correctly.

PRJ-69525,
PMTR-128338

VPN

Improved address validation in the VPN Remote Access proxy to correctly restrict outbound connections to internal and link-local destinations.

PRJ-66364,
PMTR-123613

VPN

In some scenarios, over time, prolonged VPN traffic may lead to gradual memory growth.

PRJ-70098,

PRHF-45664

VPN

In ElasticXL environments, a stale NAT-T port in the cluster sync overwrites the correct port.

PRJ-66683,
PMTR-123507

VPN

During VPN IKEv2 negotiations with third-party peers that offer multiple combined encryption algorithms (both AES-GCM-128 and AES-GCM-256), the Security Gateway may not properly match the proposal, resulting in IKE failure logs and the tunnel establishment failure.

PRJ-65825,
PRHF-43529

VPN

A customized Per-gateway Secure Configuration Verification (SCV) policy is not enforced for Remote Access VPN clients. Refer to sk184863.

PRJ-65325,
PRHF-42932

VPN

When using Capsule VPN or Endpoint Security VPN (Connect) clients in IPsec mode with IKED enabled, users can successfully authenticate and establish a VPN tunnel. However, group information received from the RADIUS server is not passed to the IKED process. As a result, security policies and access roles that rely on RADIUS group membership do not apply, and users are unable to access internal resources through the VPN.

PRJ-65320,
PRHF-42883

VPN

The VPND or IKED daemon may crash during IKEv2 negotiation.

PRJ-63828,
PRHF-41901

VPN

When generating a CPInfo file using the CPInfo utility, major CPU spikes may occur on the Security Gateway or Security Management Server.

PRJ-65666,
PMTR-119883

VPN

When Hub Mode is not enabled, traffic destined for dynamic objects included in the Remote Access VPN Split Tunneling Inclusion group may be incorrectly dropped. As a result, remote users may be unable to access resources defined by these dynamic objects, even though they are specified for inclusion in the split tunnel.

PRJ-61161,
PMTR-92656

VPN

A VPN tunnel may fail to establish in ClusterXL Load Sharing Mode during cluster member failover (pivot recovery).

PRJ-60956,
PRHF-38401

VPN

High CPU utilization on single core because of excessive VPN probing and SEP correction in ClusterXL HA Mode. Refer to sk183814.

PRJ-63551,
PRHF-41687

VPN

CRL files may not be synchronized as expected in Management High Availability and Multi-Domain Security Management environments.

PRJ-57365,
PRHF-36014

VPN

Certificate validity period not applied after using the "set_cert_validity" command. Refer to sk184230.

PRJ-62439,
PMTR-116975

VPN

Improved SSL Network Extender (SNX) certificate-based authentication stability and session reliability.

PRJ-64734,
SDWANGW-5773

SD-WAN

A VPN IPv6 traffic outage may occur when a host/network object is defined with the Security Gateway's main IPv6 address.

PRJ-68332,
AAD-9724

SD-WAN

On the Scalable Platform Cluster, LS fragmented packets may be dropped on the receiving member with an error "handle_sim_inbound_frag: error (2): frag freed, ret_val (11): FRAG_ERROR_MSG_DUPLICATE in fragment" on a loaded environment with a lot of corrected fragmented packets.

This may also occur with Cluster HA; however, correcting packets is negligible in such environments.

PRJ-64472,
PMTR-120815

SD-WAN

In some scenarios, SD-WAN ISP link status may fluctuate between UP and DOWN states. Reduced SD-WAN ARP probing default sensitivity to packet drops.

PRJ-67305,
AAD-9373,

PRJ-66600,
AAD-9375

SD-WAN

VPN traffic outage may occur in ClusterXL environments after a Cluster failover.

PRJ-66776,
PRHF-43782

SD-WAN

In some scenarios, enabling SD-WAN Symmetric Return may lead to elevated CPU utilization on Secure Network Distributor (SND) cores.

PRJ-64870,
PRHF-42485

SD-WAN

In rare scenarios, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) may be incomplete, causing SD-WAN rules to match traffic incorrectly.

PRJ-66384,
PRHF-43223

Cloud Firewall

The FWM may unexpectedly exit when attaching a license to a Security Gateway using vSEC license distribution (vsec_lic_cli).

PRJ-67513,
PMTR-125729

Cloud Firewall

Moving Cloud licenses from one pool to another triggers license alignment: If adding a new license to CK fails, license removal will not be initiated on the Security Gateways.

PRJ-69050,
PMTR-127703

Cloud Firewall

When a Cloud license's support contract expires, the system now keeps all gateways licensed and alerts the administrator with remediation steps, instead of silently removing their licenses.

PRJ-68795,
PMTR-127298

Cloud Firewall

Deleting a license pool while Cloud Firewall Gateways are still associated with it causes all licensing operations (add, distribute, remove) to continuously fail until the orphaned reference is manually cleared from the database.
The fix allows licensing operations to complete normally without administrator intervention.

PRJ-65799,
PRHF-42758

VoIP

Security Gateway may drop legitimate H323 traffic with "Illegal H.225(Q931) No Q.931 User-user IE found". Refer to sk184591.

PRJ-44176,
PRHF-25992

Scalable Platforms

Gaia Portal and Gaia gClish of a Maestro Security Group do not show newly created Loopback interfaces.

PRJ-50825,
PMTR-97166

Scalable Platforms

Added the ability to send ping requests (ICMP) from the management interface of a standby site member when using Hide mode or Same VMAC mode.

PRJ-58702,
PMTR-97177

Scalable Platforms

The command "set backup restore ftp" executed in gClish is applied only to the SMO member and not to all Security Group members.

PRJ-64156,
PMTR-120199

Scalable Platforms

In some scenarios, when proxy ARP is used, unloading and reloading the policy causes members to enter a down state with a configuration pnote.

PRJ-60808,
PMTR-109844

Scalable Platforms

The HCP configuration sync verifier ("config_verify") incorrectly reports a failure because the asg_diag_file.dat file is not synced between members.

PRJ-67645,
PRHF-44577

Scalable Platforms

When adding or removing VS, if the freeze timeout ended before the VS was fully stable, the VS might still have a Critical Device (pnote), which will cause the member to go down. Refer to sk185115.

PRJ-67458,
PMTR-109489

Scalable Platforms

When performing a SIC reset after Anti-Malware (AMW) has been installed, some members may enter a "cluster-down" state with an AMW Critical Device.

PRJ-64975,
PMTR-121215

Scalable Platforms

When "g_ClusterXL admin up" is triggered from a non-VS0 member (for example, VS1), the command fails and the upgraded site remains down with a pnote.

PRJ-64753,
PMTR-110923

Scalable Platforms

When running the "show asset all" command on setups with ElasticXL enabled, Disk Model, Serial, and Capacity outputs are not displayed.

PRJ-63907,
PRHF-41940

Scalable Platforms

Policy installation on one Virtual System (VS) fails without a visible error message. Refer to sk184194.

PRJ-63816,
PRHF-41860

Scalable Platforms

On Maestro appliances, /var/log/messages may be flooded with "asg_copy_capture" error messages when the system attempts to retrieve packet capture files that do not exist on remote Security Group members.

PRJ-67348,
PMTR-123997

Scalable Platforms

A Security Group Member may enter a continuous boot loop after the other members were upgraded. An incorrect image file (with an invalid or mismatched MD5 checksum) is presented on the Single Management Object (SMO). As a result, the problematic member fails to complete the autoclone and repeatedly reboots.

PRJ-67184,
PRHF-44401

Scalable Platforms

The SGM400 chassis member uses an incorrect backplane Ethernet (BPEth) drive, causing backplane traffic not to be processed on that member.

PRJ-68807,
PMTR-126879

Scalable Platforms

When a Security Group member transitions from a down state to an active state, the synchronization process with other members in the Security Group may not complete before the recovered member becomes active. This can result in traffic drops because of incomplete state synchronization.

PRJ-66520,
SPC-3384

Scalable Platforms

Rebooting an Active member in the Single Management Object (SMO) role may trigger a brief connectivity loss.

PRJ-66510,
PMTR-121748

Scalable Platforms

When MDPS Resource Separation is enabled, pushing policy under load may cause Single Management Object (SMO) to become unresponsive.

PRJ-65968,
PMTR-92125

Scalable Platforms

After creating a bridge interface using Gaia Portal and rebooting, the Security Gateway state is Down.

PRJ-65962,
PRHF-43121

Scalable Platforms

In a rare scenario, when a VPN-corrected packet is dropped, the packet truncation warning "14 bytes missing" may be seen in the "tcpdump" output.

PRJ-65540,
PMTR-108818

Scalable Platforms

In Maestro or ElasticXL environments with VPN enabled, traffic may be dropped with the log message "fwha_select_should_drop_vmac".

PRJ-65563,
PMTR-101420

Scalable Platforms

Identity Collector connections may be handled incorrectly by a non-SMO Security Group Member after an SMO failover. Refer to sk184461.

PRJ-65597,
PMTR-122629

Scalable Platforms

Intermittent VS failover when both Maestro Hyperscale Orchestrators (MHOs) have the interface link state set to Down. Refer to sk184568.

PRJ-66119,
PRHF-41852

Scalable Platforms

BGP Sessions may fail to re-establish after SMO failover because of physical link failure. Refer to sk184371.

PRJ-69876,
PMTR-127622

Scalable Platforms

In VSLS clusters with multiple members, when a member rejoins the cluster after a reboot, an Interface Active Check (IAC) problem notification may incorrectly appear on the rejoining member, showing it in ACTIVE state. This occurs even though all interfaces are physically UP and the cluster is fully functional.

PRJ-65700,
PMTR-122627

Scalable Platforms

"TCP packet out of state" or "connection dropped due to state mismatch" messages may be seen in SmartLog or SmartView Tracker. These drops specifically occur on the sync interface, which is used for internal communication and synchronization between Security Group members.

PRJ-67165,
PRHF-43859

Scalable Platforms

  • When a large number of bond interfaces are configured, the synchronization of link states may fail.

  • In rare scenarios, a cluster member may become stuck in the "active (sync)" state. When this occurs, the affected member does not handle network traffic as expected.

  • There may be inconsistencies in the reported link state across Security Group Members (SGMs), as observed with the "asg stat -v" command.

PRJ-69163,
CST-492

Carrier Security

In a rare scenario, a processed malformed GTP packet may cause the Security Gateway to crash.

PRJ-66713,
CST-439

Carrier Security

A "Tunnel established" message may be printed for rejected sessions. The issue is cosmetic.

PRJ-66710,
CST-437

Carrier Security

A GTPv0 tunnel fails to establish under certain conditions.

PRJ-65686,
CST-423

Carrier Security

GTP-U intra-tunnel packets may be dropped with "Packet too short" and "Invalid IP packet" errors in Bridge Mode, preventing proper inspection of encapsulated traffic.

PRJ-65683,
PRHF-42942

Carrier Security

The FWK process may exit when GTP Intra Tunnel Inspection is enabled.

PRJ-65231,
PMTR-121783

Hardware

After upgrading the firmware, the interface on one of the VSX cluster members may go down.