R81.20 Jumbo Hotfix Take 8

 

ID

Product

Description

Take 8

Released on 7 March 2023

PRJ-42694,
PMTR-88560

Security Management

NEW: Added ability to run the "verify-policy" Management API command on a private session with unpublished changes.

PRJ-40017

Security Management

NEW: Central Deployment of Hotfixes and Version Upgrades in SmartConsole will now support clusters of Centrally Managed Quantum Spark Appliances that run R81.10.XX firmware versions.

PRJ-41769,
PMTR-86000

CPView

NEW: Integrated Skyline, a solution that provides an OpenTelemetry CPView Agent service to monitor your Check Point Servers and export health metrics from the CPView tool to an external location. Refer to sk178566.

PRJ-43896,
PMTR-89750

Security Gateway

NEW: We have extended the grace period of Compliance Blade to support you for 90 days following contract expiration to continue providing the best security value during the renewal process.

PRJ-43808,
PMTR-89699

Application Control,

URL Filtering

NEW: We have extended the grace period of Application Control and URL Filtering Blade to support you for 90 days following contract expiration to continue providing the best security value during the renewal process.

PRJ-43911,
PMTR-89774

SmartView

NEW: We have extended the grace period of SmartEvent Blade to support you for 90 days following contract expiration to continue providing the best security value during the renewal process.

PRJ-44256,
PMTR-90165

Threat Extraction

NEW: We have extended the grace period of Threat Extraction Blade to support you for 90 days following contract expiration to continue providing the best security value during the renewal process.

PRJ-42165,
PMTR-87948

IPS

NEW: Added ability to block "HTTP 206 partial content" responses from resources with malicious content.

PRJ-41947,
PMTR-87634

Security Management

UPDATE: Connecting a Quantum Security Management Server to Infinity Portal is now supported in the Full High Availability Cluster (when each cluster member has a Security Management Server and a Security Gateway).

PRJ-42028,
PMTR-87761

Security Management

UPDATE: When adding R81.10 or lower Security Gateways to a Threat Prevention policy with Zero Phishing Blade, a verification error will be shown.

PRJ-42563,

PRJ-42564

Security Management

UPDATE: It is now possible use multiple values when filtering in these views:

  • Global Assignments (MDS)

  • Permissions (MDS)

  • Sessions (MDS)

  • IPS (Domain level)

PRJ-42554,
PRHF-22345

Security Management

UPDATE: Added an option to configure the maximum number of IPS SNORT rules.

These lines should be added at the end (or their value should be changed if they already exist) in the file $FWDIR/conf/malware_config

(for MDS - additionally in the $MDS_FWDIR/conf/malware_config file):

"[IPS]

snort_convertor_max_rules_per_update=<value>

snort_convertor_total_rules_num_limit=<value>".

Refer to sk136515.

PRJ-42034,
PMTR-87522

Security Management

UPDATE: Added a new Management API "mgmt_cli verify-management-license". It allows to check how many Security Gateway objects the Management Server license supports. Note that this API does not support Quantum Maestro and VSX. Refer to Management API Reference.

PRJ-42307,
PRHF-25869

Security Management

UPDATE: Improved the "Purge revisions" operation to reduce the size of the database.

PRJ-42982,
ODU-747

Web SmartConsole

UPDATE: Released Take 76 with new features and improvements. Refer to sk170314.

PRJ-44560,
PMTR-90438

Security Gateway

UPDATE: Apache HTTPD version was updated from 2.4.53 to 2.4.55 to fix CVE-2022-37436.

PRJ-42373,
PRHF-21182

Security Gateway

UPDATE: The "fw unloadlocal" command can now be used on a Virtual System only with the "-f" flag added. Otherwise, a warning message is displayed, indicating that unloading policy on a Virtual System will cause traffic issues with any Virtual System connected to a Virtual Switch or a Virtual System in Bridge mode.

PRJ-42659,
TPP-2280

IPS

UPDATE: In several IPS protections, improved performance for traffic that contains repeated sections.

PRJ-42704,
ODU-494

Threat Prevention

UPDATE: Added Update 16 of Autonomous Threat Prevention Management integration Release. Refer to sk167109.

PRJ-42260,
PRJ-42201

Threat Prevention

UPDATE: Reduced loading time of big external Custom Intelligence Feeds.

PRJ-41381,
PRHF-24483

VPN, Multi-Portal

UPDATE: Added a new Registry parameter "use_crl_for_revocation_method" that enables the CRL revocation method when the Security Gateway does not get a response from an OCSP Server. Refer to sk179434.

PRJ-44248,
PRHF-27306

VPN

UPDATE: When the VTI MTU is different from the physical MTU, the physical MTU is used for sending packets by default.

  • To modify the default behavior (the change does not survive reboot), run the CLI command "fw ctl set int sim_vpn_use_physical_mtu 0 -a". This allows using configured VTI MTU as the default.

  • To make the change permanently, open the $PPKDIR/conf/simkern.conf file for editing and add the entry "sim_vpn_use_physical_mtu=0".

Refer to sk98074.

PRJ-42405,
PMTR-87600

VSX

UPDATE: Added more logs related to Pushing VSX Configuration.

  • On the Security Gateway side: in the last_vsx_push_configuration.elg. The log file will now be circular.

  • On the Security Management side: in the vsx_util log. Also, commands are added to the name of log files (for example, vsx_util_reconfigure_xxxxx_xx_xx.elg).

  • VSX Provisioning tool is now logged in the vpt_history.elg.

.

PRJ-42875,

ODU-611

Gaia OS

UPDATE: Gaia API updates will now be automatically installed through AutoUpdater. Refer to sk165653.

PRJ-43614,
PRHF-26959

Gaia OS

UPDATE: Gaia Cloning Groups will now use the highest TLS version available.

PRJ-43048

CloudGuard Network

UPDATE: Added support for Data Centers in AWS eu-central-2 (Zurich) and eu-south-2 (Spain) and ap-south-2 (Hyderabad) regions.

PRJ-43028,
PRJ-43025

CloudGuard Network

UPDATE: Added support for connecting to VMware NSX-T 4.0.0.x and higher.

PRJ-41847,
PRHF-25754

CloudGuard Network

UPDATE: Improved handling of NSX-T API responses.

PRJ-42015,
PRJ-42149

CloudGuard Network

UPDATE: Improved performance of pushing Data Center Objects changes to Security Gateways.

PRJ-41649,
MBS-16088

Scalable Platforms

UPDATE: Upon member state change to Active, there may be minor packet drops. Added an option to not forward traffic to a new Active member until all connections are synchronized to it:

• To enable this option:

  • on the fly, run g_fw -a ctl set int fwha_force_present_state_over_active 1

  • to be boot persistent, run g_update_conf_file fwkern.conf fwha_force_present_state_over_active =1

• To disable this option:

  • on the fly, run g_fw -a ctl set int fwha_force_present_state_over_active 0

  • to be boot persistent, run g_update_conf_file fwkern.conf fwha_force_present_state_over_active =0

PRJ-43405,
PMTR-89295

Diagnostics

Skyline may not show any information. Refer to sk180748.

PRJ-42111,
PRHF-25747

Security Management

The date of a policy configured with "accelerated installation" may not be updated in logs.

PRJ-43902,
SMB-19002

Security Management

On R77.20 Quantum Spark appliances with some IPS packages, policy installation fails with the "Operation failed, install/uninstall has been improperly terminated" error. Refer to sk180448.

PRJ-41763,
PRHF-25381

Security Management

In some scenarios, the CME process fails to start.

PRJ-43341,
PMTR-89193

Security Management

In some scenarios, Audit logs may not be created when running remote API commands from Infinity Portal.

PRJ-42411,
PRHF-26108

Security Management

Login to the Security Management Server or Multi-Domain Security Management Server may fail with the "Connection timeout" error.

PRJ-44564,
PRHF-27782

Security Management

In a rare scenario, OCSP response cash located in $CPDIR/tmp/curl_crl_ocsp may take a lot of memory.

PRJ-35072,
PMTR-89310

Security Management

High Availability synchronization fails when one Management Server is installed on an appliance of 6000 series and the other one is an Open Server, a Virtual Machine, or installed on an appliance of different series.

PRJ-43095,
PRHF-25895

Security Management

After configuring an IoC feed on the Global Domain and assigning a Global Policy, Threat Prevention policy installation in the local Domain fails.

PRJ-43364,
PMTR-87860

Security Management

Editing a Global Assignment object using Ansible may fail.

PRJ-43318,
PMTR-87565

Security Management

In SmartConsole, when editing a tagged Security Gateway object, the tags may get removed.

PRJ-43315,
PMTR-88093

Security Management

Running API commands with the "dereference-max-depth" parameter with "0" value may fail when there is the "groups" field in the reply.

PRJ-44023,
PRHF-27405

Security Management

When using Custom Application/Site Group objects in an Access policy, policy installation may fail with an "Internal error" message.

PRJ-42244,
SMB-19124

Security Management

Installing a large Access Control policy on Quantum Spark Security Gateways may fail due to high memory consumption on the Security Management Server caused by FW_LOADER.

PRJ-42798,
PRHF-24308

Security Management

The FWM process may frequently exit. This causes SmartConsole authentication to fail and dashboards that were opened before to get closed.

PRJ-44485,
PRHF-27877

Security Management

The "show simple-gateways" Management API command may fail with the "Null Pointer Exception" error and cause the CME failure. Refer to sk180944.

PRJ-41977,
PRHF-25682

Security Management

The /var/log/dump/usermode/ directory on the Management Server may contain core dump files for the FWM process. Refer to sk180119.

PRJ-43688,
PMTR-89520

Security Management

When running the "update-provisioned-satellites" Management API command on a cluster, it may fail with the "The operation does not support this object type" error.

PRJ-41557,
PRHF-25556

Security Management

After an Application Control update, policy installation may fail.

PRJ-42061,
PRHF-25730

Security Management

The "show objects" command returns all objects in Global Domain with any filter when "ip-only" flag is set to "true".

PRJ-44630,

PMTR-90519

Security Management

There may be many duplicates of OCSP response in the $CPDIR/tmp/curl_crl_ocsp folder.

PRJ-42860,
PRHF-26649

Security Management

After performing the "Revert to Revision" operation, new Audit logs cannot be seen in the Logging&Monitoring View in SmartConsole.

PRJ-42510,
PRHF-26349

Security Management

Access policy verification may fail when dynamic objects exist in the NAT policy.

PRJ-41672,
PRHF-25452

Security Management

When using CME (Cloud Management Extension), the FWM process may unexpectedly exit because of a memory issue.

PRJ-41929,
PRHF-25575

Security Management

After an upgrade, while installing a policy, SmartConsole may unexpectedly close with a "The connection with the server was lost. Any unsaved changes will be preserved" message. Refer to sk180294.

PRJ-41893,
PRHF-25534

Security Management

High Availability synchronization fails if automatic purge is configured to run on the Standby Management Server.

PRJ-42043,
PRHF-25899

Security Management

In a rare scenario, the Show Package tool and some Management API commands with details-level "full" fail.

PRJ-43313,
PMTR-88097

Security Management

The API command "show-nat-rulebase" may not show the name of each rule in the Rule Base.

PRJ-41921,
PRHF-25795

Multi-Domain Security Management

In rare scenarios, in a Multi-Domain Security Management Server environment, a memory leak may occur in the FWM process. This may cause the process to exit.

PRJ-42850,
PRHF-26378

Multi-Domain Security Management

In a Multi-Domain Security Management environment, traffic may not match rules with custom applications.

PRJ-42106,
PRHF-25807

Multi-Domain Security Management

In a Multi-Domain Security Management environment, the HitCount retention mechanism may prematurely remove the HitCount data.

PRJ-42050,
PRHF-25759

Multi-Domain Security Management

In rare scenarios in a Multi-Domain Security Management environment:

  • Login to the Management Server may timeout and fail.

  • Publish operation may take a long time.

PRJ-42303,
PRHF-25848

Multi-Domain Security Management

Reassigning a Global Domain to a local Active Domain from one MDS to another may result in the local domain not reflecting recent changes. The issue occurs in Multi-Site environments if two Multi-Domain Security Management Servers (MDS) have a Standby Global Domain.

PRJ-43176,
PMTR-88159

SmartConsole

SmartConsole installation folder contains screenshots of legacy demo documents.

PRJ-41610,
PMTR-86559

SmartProvisioning

Deleting an LSM Gateway via REST API does not revoke the device's VPN certificate.

PRJ-42085,
PRHF-25916

CPView

A typo in "Dropped fragmentation violation" under CPView > Advanced > SecureXL > Drops.

PRJ-43590,
PMTR-89477

CPView

In a Multi-Domain Security Management environment, Skyline is down after mdsstop/mdsstart.

PRJ-43672,
PMTR-89535

CPView

The Network-per-CPU tab under CPVIEW > Advanced > SecureXL does not show traffic distribution for all CPUs. Refer to sk180540.

PRJ-42415,
PRHF-26316

Logging

When LEA spawning is turned off (sk91343), the FWD process may run out of memory.

PRJ-41853,
PRHF-23629

Logging

After an upgrade and change of the Security Management Server name, logs created before the upgrade are unavailable.

PRJ-43394,
PRHF-26905

Logging

When working with Multi-Domain Security Management, Virtual Systems (VS's) may be unable to send logs to the management because the Log Server constantly disconnects.

PRJ-42818,
PMTR-88623

Security Gateway

The Security Gateway may crash when running a memory leak detection procedure.

PRJ-43134,
PRHF-24896

Security Gateway

When using the SMTP service with resource objects in a rule and NAT is configured for the destination IP address, the traffic may match the Cleanup rule instead.

PRJ-43012,
PRHF-26600

Security Gateway

When adding a new RADIUS Server to Gaia, its IP address is automatically added to MDPS tasks, but when deleting this Server, the MDPS task is not deleted.

PRJ-42297,
PRHF-26094

Security Gateway

When MDPS is configured, mdps_tun interface is shown when running the "cpstat ha -f all" command.

PRJ-42945,
PRHF-26610

Security Gateway

When Anti-Spoofing is enabled, the Security Gateway may crash.

PRJ-43840,
PRHF-27097

Security Gateway

The Security Gateway may receive duplicated traffic (such as non-IP protocol connections) for IPS inspection. This can trigger high CPU usage and result in failures to connect over SSH or policy installation.

PRJ-42708,
PRHF-26247

Security Gateway

DNS parser incorrectly handles additional records, which results in appearing additional DNS IP addresses in the FQDn objects list.

PRJ-43619,
PRHF-21529

Security Gateway

The Security Gateway may frequently crash with vmcore files, recording invalid context.

PRJ-43887,
PRHF-26861

Security Gateway

In some scenarios, the FWD process is stuck during policy installation.

PRJ-43706,
PRHF-27184

Security Gateway

The Security Gateway may crash during policy installation if the Rule Base has multiple layers and many interfaces on the Security Gateway (VLANs).

PRJ-43555,
PRHF-26844

Security Gateway

Security Gateway may drop traffic when Dynamic Anti-Spoofing is enabled.

PRJ-41635,
PRHF-25363

Security Gateway

Dynamic Dispatcher may send fragments of the same packet to different Firewall instances during a high load of fragmented traffic. This may cause some packets to drop.

PRJ-43529,
PMTR-89421

Security Gateway

In rare scenarios when ISP Redundancy feature is enabled, default route disappears after policy installation.

PRJ-42805,
PRHF-23758

Security Gateway

Stability issues when ICAP client is active.

PRJ-41496,
PRHF-24787

Security Gateway

Stability issues when ICAP client is active.

PRJ-41092,
PRJ-34903

Security Gateway

A kernel crash may occur during system shutdown when PIM is enabled.

PRJ-43344,
PMTR-88981

Security Gateway

A connection may be closed with the "ws_mux_handle_poll: ERROR: Poll flag still set after unsetting" error in the fwk.elg file, when HTTP parser does not receive requested data.

PRJ-41791,
PRJ-41721

Security Gateway

The Security Gateway with enabled Anti-Virus may experience a memory allocation issue.

PRJ-42973,
MBS-16324

Security Gateway

The Security Gateway on a LightSpeed appliance may crash when a Bond interface is configured on the LightSpeed 10/25/40/100G QSFP28 Ports, and the state of this Bond interface changes between on / off, or off / on.

PRJ-41796,
PRJ-41720

Security Gateway

The Security Gateway with enabled Anti-Virus Blade may experience a memory allocation issue.

PRJ-43143,
PRJ-43197

Security Gateway

Policy installation from R81/R81.10 Security Management Server on R81.20 Security Gateway fails if Autonomous Threat Prevention mode is enabled.

PRJ-43801,
PMTR-89661

Security Gateway

When handling some RTSP connections and the Hyperflow feature is enabled the Security Gateway may crash.

PRJ-43128,
PMTR-89008

Security Gateway

Some TCP connections may be stuck in "Both-Fin" state in the SecureXL connection table and cause high memory consumption.

PRJ-41865,
PRHF-25769

Security Gateway

After an upgrade, it is not possible to monitor Security Gateways with enabled Management Data Plane Separation (MDPS).

PRJ-43534,
PRHF-26097

Security Gateway

In some scenarios, the Security Gateway may frequently crash, causing outages.

PRJ-41422,
PRHF-24690

Security Gateway

The Security Gateway may send multiple "Failed to fetch Check Point resources. Timeout was reached" logs.

PRJ-41791,
PRJ-41721

Security Gateway

The Security Gateway with enabled Anti-Virus Blade may experience a memory allocation issue.

PRJ-43779,
PMTR-89539

Security Gateway

When working in VSX Load Sharing (VSLS) mode, the FWK process may unexpectedly exit.

PRJ-43671,
PMTR-89323

Multi-Portal

In a rare scenario, the MPDAEMON process may fail to start on one of the cluster members.

PRJ-41472,
PRHF-25382

Internal CA

When managing cloud Gateways, the FWM process memory usage may increase.

PRJ-42904,
PRHF-26659

Internal CA

The certificate in SmartConsole is shown as valid, although it is expired.

PRJ-41599,
PRHF-25439

Threat Prevention

Anti-Virus Blade fails to parse external IoC feeds that contain commas in the CSV column field value.

PRJ-42022,
PMTR-88108

Threat Prevention

Some logs with IP observables from custom intelligence feeds may be suppressed, although they contain different IP addresses.

PRJ-41483,
PMTR-88110

Threat Prevention

Custom intelligence feeds load may fail because of a parsing issue.

PRJ-42287,
PRHF-26079

Threat Prevention

The "ioc_feeds set interval -r" command may fail.

PRJ-42196,
PMTR-88923

Threat Prevention

Files related to IoC may not be entirely removed from the disk after the feed removal.

PRJ-42365,
PRJ-41688

Threat Prevention

In some scenarios, a "malware_res_rep_rad_query: rad_kernel_malware_request_prepare() failed" message may appear in the /var/log/messages file.

PRJ-42586,
PMTR-88424

Threat Prevention

When using a host with automatic static NAT in a Threat Prevention policy object, the object will not be enforced.

PRJ-41637,
PRA-3254

Threat Prevention

The Security Gateway becomes unresponsive when loading external IoC feeds on a Security Gateway with EXT3 filesystem.

PRJ-43367,
PRJ-43360

Threat Extraction

In some scenarios, Mail Transfer Agent (MTA) does not scan files with an unsupported extension if they were renamed to ".exe".

PRJ-43504,
PRHF-26475

Application Control

Policy installation may fail with an "Error 0-200184" message because of memory allocation issues.

PRJ-42507,
PRHF-26186

Application Control

In a rare scenario, when Application Control is enabled, the Security Gateway in AWS Cloud may crash. The issue does not occur if Application Control database on the Security Gateway is updated with Release 141122_1 and higher.

PRJ-43000,
PRHF-24890

Identity Awareness

In a rare scenario, disconnection between the Identity Server (PDP) and Identity Gateway (PEP) leads to missing identities on the PEP side.

PRJ-42340

Identity Awareness

In a VSX High Availability cluster, a member in the Backup state should remain idle, but it opens connections for identity sharing.

PRJ-42934,
PMTR-88806

Identity Awareness

The PDPD process may cause CPU spikes during cluster failover.

PRJ-42996,
PRHF-23473

Identity Awareness

There may be connectivity issues and high CPU spikes on PDP when installing policy.

PRJ-43731,
PRHF-25083

Identity Awareness

Connectivity issue may occur during Azure AD Group fetch, and the "get_http_error_msg - http code is 401" error response is shown in Identity Awareness logs.

PRJ-42592,
PMTR-88426

IPS

The Security Gateway may crash during policy installation because of a memory allocation problem.

PRJ-41656,
PRHF-25585

IPS

Running the "ips stats" command in CLI may cause the IPS process to unexpectedly exit with core dumps.

PRJ-41464,
PRHF-25330

IPS

When Anti-Virus is enabled, the Mail Transfer Agent (MTA) log files may get blocked because of fail-close operation.

PRJ-43584,
PRHF-27076

DLP

A memory leak may occur in the DLPU process.

PRJ-43829,
PMTR-89510

Anti-Virus

When the RAD process exits with a timeout, the Blade name shown in the SmartConsole log card is incorrect.

PRJ-44010,
PMTR-89738

Anti-Virus

The fwk.elg file may be flooded with the "match_cb for CMI APP 11 - CI AV failed on context 144, executing context 366 and adding the app to apps in exception" messages because of improper parsing of HTTP headers by Anti-Virus Blade.

PRJ-43414,
PMTR-87254

SSL Inspection

In a rare scenario, the WSTLSD process may unexpectedly exit and produce a core dump file during certificate chain verification.

PRJ-43182,
PRHF-26878

SSL Inspection

The WSTLSD process may unexpectedly exit and create core dump files.

PRJ-43892,
PRHF-26317

SSL Inspection

In rare scenarios, the FWK and/or WSTLSD processes may unexpectedly exit and create a core dump during certificate validation. Refer to sk180473.

PRJ-43359,
PRJ-43681

SSL Inspection

In some scenarios, Inbound HTTPS Inspection may fail when working in USFW (User-Space Firewall) mode.

PRJ-42152,
PRJ-41973

Mobile Access

After an upgrade, it may not be possible to connect to SNX, it gets stuck when initializing.

PRJ-44292,
PRHF-27598

Mobile Access

Some web applications which use PT or UT link translation methods may have issues after a browser upgrade.

PRJ-42469,
PRHF-26292

Mobile Access

When Mobile Device Management (MDM) cooperative enforcement feature is enabled, establishing a VPN connection fails while the HTTPD log incorrectly indicates a compliance issue.

PRJ-43226,
PRHF-25249

Mobile Access

Web applications may not work correctly when Mobile Access Blade is configured in Hostname Translation (HT) mode while the "obscure_destination_hostname" management attribute is disabled.

PRJ-43618,
PRHF-25371

Mobile Access

Access to a web application that uses WebSocket protocol may not be possible.

PRJ-41728,
PRHF-24710

ClusterXL

The cphaprob show_bond command does not show newly added subordinates from Virtual Systems (VSs).

PRJ-43117,
PMTR-87809

ClusterXL

The "cphaprob tablestat" command may fail on the Security Gateway with many interfaces.

PRJ-43004,
PRHF-26722

ClusterXL

Traffic does not pass through the GRE tunnel when Virtual MAC (VMAC) is enabled. Refer to sk180292.

PRJ-44169,
PRHF-27330

ClusterXL

When handling HTTP/2 traffic, cluster members may crash, generating vmcores.

PRJ-42929,
PMTR-88804

ClusterXL

A Hide NAT port may be allocated twice causing the "out of state" drops.

PRJ-42465,
PRHF-26264

ClusterXL

Stability issues may occur in a Multi-Version Cluster (MVC) when VPN is enabled.

PRJ-42576,
PRHF-25865

SecureXL

Multicast traffic may get dropped, and no logs are generated.

PRJ-44132,
PMTR-89935

SecureXL

IPv6 template is not created when the connection is NATed.

PRJ-43980,
PMTR-89372

SecureXL

In a rare scenario, a CPAQ message sent during policy push does not have critical priority, and can be dropped when the Security Gateway is busy.

PRJ-42897,
PRHF-26517

SecureXL

SecureXL may drop traffic when HTTPS Inspection is enabled on a VSX Security Gateway with a Virtual Router.

PRJ-42446,
PRHF-26215

SecureXL

The Security Gateway may prematurely expire half-closed TCP connections and drop VoIP and HTTPS packets with "First packet isn't SYN".

PRJ-42074,
PRHF-25880

SecureXL

In some scenarios, the change of the cphwd_enable_ecmp global parameter value on a VSX Gateway does not survive a reboot.

PRJ-43923,
ROUT-2460

Routing

Failover may take longer than expected and traffic does not pass for several seconds because dynamic routes are lost.

PRJ-41709,
PRHF-25613

Routing

The ROUTED process may unexpectedly exit when the route does not have a next hop.

PRJ-43411,
PRHF-6347

Routing

The ROUTED daemon may repeatedly exit when using PIM in Sparse mode (SM).

PRJ-41725,
PRHF-25460

Routing

The "asg diag verify" command reports inconsistent OSPFv3 routes for Security Gateway Modules in Quantum Maestro. Refer to sk179931.

PRJ-44373,
PMTR-88972

Routing

OSPF routes may not be redistributed after reboot.

PRJ-44260,
PRHF-27407

Routing

The ROUTED daemon may unexpectedly exit when using PIM and source IP address is set "0.0.0.0".

PRJ-42381,
PMTR-87326

VPN

The IKED process unexpectedly exits when the "Aggressive SLP" (Simultaneous Login Prevention) feature is enabled.

PRJ-44945,
PRHF-28050

VPN

When many users in nested groups login using Remote Access Client \ connect to VPN, and the LDAP topology is large, there may be a spike of CPU usage and performance impact. Refer to sk180664.

PRJ-42176,
PRHF-24166,

PRJ-43714,
PRHF-27256,

PRJ-42654,
PRHF-26482

VPN

  • NAT-T traffic may stop matching the implied rule after policy installation and is dropped with "IKE_NAT_TRAVERSAL Traffic Dropped from x.x.x.x to y.y.y.y" message in SmartLog.

  • VPND and IKED stability issues occur when loading newly created LDAP group objects.

Refer to sk180530.

PRJ-42730,
PRHF-26453

VPN

In a rare scenario, when IPv6 is configured, and VPN is enabled, policy installation may cause a stability issue.

PRJ-43387,
PRHF-27010

VPN

After an upgrade, an incorrect IPSec users counter may be displayed in SmartView Monitor or when running the "cpstat vpn -f ipsec" command for a cluster. The issue is cosmetic only.

PRJ-43551,
SDWANGW-1205

VPN

VPN stability issues.

PRJ-43300,
PRHF-26853

VPN

Stability issues for Data connections (RDP / RTP / FTP / ETC). Refer to sk179651.

PRJ-42562,
PRHF-26325

VPN

When the user connects with RADIUS authentication method, the "Authentication method" value in Mobile Access logs is shown as empty.

PRJ-43348,
PRHF-25367

VPN

StrongSWAN Remote Access client can connect but fails to access internal resources.

PRJ-42880,
PRHF-26241

VPN

When initiating IKEv2 tunnel from Check Point to a third party, creating Child SA fails. Refer to sk180281.

PRJ-41561,
PRHF-25552

VPN

After an upgrade, the community name may not be visible from SmartView Monitor, and the "snmpwalk" command returns an empty value for this entry.

PRJ-42763,
PRHF-26567

VPN

Despite the Secure Configuration Verification (SCV) exceptions being configured to not apply for connections, the strongSWAN client's traffic is dropped with the "Client's configuration is not verified" error.

PRJ-41698,
VSX-2670

VSX

The "vsx_util change_mgmt_subnet" command may fail if a VSX object is not correctly saved in the database.

PRJ-40976,
PRHF-23107

VSX

SecureXL may not let HTTPS traffic pass through a Virtual Router (VR).

PRJ-43005

VSX

Some connections inspected by Threat Prevention Blade may not be closed successfully, which leads to connectivity issues.

PRJ-43357,
PMTR-89245

VSX

The SNMPD process may consume a high CPU in a VSX environment and there may be slowness when using the "fw vsx stat" command. Refer to sk180324.

PRJ-43652,
PRHF-27195

Gaia OS

When setting password hash on cloning group members, some members may not get updated.

PRJ-42527,
PRHF-26323

Gaia OS

Gaia backup fails with "Cannot complete the backup process: not enough space in /var/log/CPbackup/backups" although there is enough free disk space in the /var/log/ partition. Refer to sk180181.

PRJ-42646,
PRJ-43428

Gaia OS

In some scenarios, the "nslookup" command can cause the NSLOOKUP process to exit.

PRJ-42963,
PRHF-26713

Gaia OS

IPv6 address may be removed from bond VLAN interface when changing bond xmit-hash-policy configuration. Refer to sk180309.

PRJ-42221,
PRHF-25947

Gaia OS

Incorrect logs are printed in the /var/log/httpd2_error_log file when logging into the WebUI.

PRJ-42625,
PRHF-26432

Gaia OS

SNMP trap may not be sent after a cluster failover if it occurred by running the "clusterXL_admin down" command.

PRJ-44162,

PRJ-43959

Gaia OS

When uninstalling a Jumbo Hotfix, some of the Management APIs may not work. The "gaia_api status" command returns an error and requests may fail.

PRJ-43564,
PRHF-27096

Gaia OS

When restoring a backup with VSX objects, the objects database may not be restored on the newly installed Security Management Server.

PRJ-42930,
PRHF-24249

Gaia OS

When running the "ifconfig -a" command on a Virtual System (VS) with more than 250 interfaces, the "/bin/cp-ifconfig.sh: line 179: /bin/echo: Argument list too long" error is printed.

PRJ-44239,
PRHF-27526

Gaia OS

The System Backup page in the Cloning Group view may be empty, although a scheduled backup was added.

PRJ-43987,
PRHF-27222

Gaia OS

The "lldpneighbors" Clish command may have a corrupted output. Refer to sk182065.

PRJ-42195,
PRHF-25359

Gaia OS

When configuring Gaia Cloning Group mode on the cluster, members with "off" state appear without an IP address and the "adding notification Member mvc is down" error is displayed.

PRJ-42255,
PRHF-26113

Gaia OS

Running the "save configuration" command the second time in the same Clish session may fail with the "free(): invalid pointer" error.

PRJ-41687,
PRHF-25430

Gaia OS

In a cloning group cluster, when allowed hosts are changed from "Any" host to a specific host, communication between members is blocked, and the group cannot function.

PRJ-43263,
PRJ-43140

Gaia OS

After an upgrade, the RADIUS Server is unavailable and authentication fails.

PRJ-41614,
PMTR-87176

Gaia OS

Information about scheduled backup failure is now displayed in Clish, WebUI, and in the error message inside the log file.

PRJ-43133,
PMTR-88415

Harmony Endpoint

Endpoint Web Management service may fail to delete old logs.

PRJ-42954,
PMTR-88744

Harmony Endpoint

In an environment with the Endpoint Security Server, Jumbo Hotfix Accumulator installation may take a long time.

PRJ-43069,
PRHF-26666

CloudGuard Network

Importing objects from VMware vCenter may fail with a "Failed to fetch objects from the Data Center." message because of a rare communication issue between CloudGuard Network Security controller and VMware vCenter Data.

PRJ-43579,
PMTR-89444

CloudGuard Network

When enabling debug mode with the "$MDS_FWDIR/scripts/cpm_debug.sh -c ObjectCrudSvcImpl" command, it may impact the work of CloudGuard Central License utility. And adding license fails.

PRJ-43074,
PRHF-26286

CloudGuard Network

A Kernel-based Virtual Machine (KVM) or a Virtual Machine using SRIOV with the i40evf/ixgbevf network driver, may boot with non-optimized performance settings.

PRJ-43260,
PRHF-26750

CloudGuard Network

Disabling or removing all network interfaces from a vCenter object is not dynamically reflected on the CloudGuard Controller Data Center object.

PRJ-42011,
PRHF-25644

CloudGuard Network

When mapping of some Azure Subscriptions fails, assets of these Subscriptions are revoked from the Security Gateway.

PRJ-42116,
PRHF-25910

CloudGuard Network

AWS Data Center mapping fails when a Subnet with only IPv6 addresses is added to Virtual Private Cloud (VPC).

PRJ-43648,

PMTR-88995

CloudGuard Network

Connectivity issues may occur between the Security Gateway and cluster on Alibaba cloud.

PRJ-41535,
PRHF-11703

VoIP

In some scenarios, when using early media with NAT, the first data connections specified in the SDP get closed, although they should not. And the new data connection does not open, resulting in one-way audio. Refer to sk179651.

PRJ-42700,
PRJ-42696

VoIP

In some scenarios, when using static NAT, VoIP traffic may be affected.

PRJ-43078,
PRHF-26401

VoIP

While handling a multi-INVITE scenario (where a user registers with multiple devices), and the VoIP SIP MultiCore feature is enabled, each SIP INVITE maybe be handled simultaneously on different FW instances and cause memory corruption.

PRJ-41836,
PRHF-25720

Scalable Platforms

SNMP threshold events traps may be missing "Chassis ID" and "Blade ID" fields. Refer to sk179926.

PRJ-42014,
PRHF-24199

Scalable Platforms

In a rare scenario, the FWK process may unexpectedly exit and bring down the Security Gateway Module (SGM).

PRJ-42948,
MBS-11024

Scalable Platforms

Optimized the SNMP communication between Security Gateway Module (SGM) and Security Switch Module (SSM) to prevent timeouts.

PRJ-43420,
PRJ-43361

Scalable Platforms

The "set expert-password-hash" command may fail to update the password hash on all cluster members.

PRJ-43490,
PRJ-43488

Scalable Platforms

Running the "show" or "set" commands for SSH in gClish fails.

PRJ-44778,

PRJ-44600

Scalable Platforms

Uninstalling a Jumbo Hotfix from Maestro Orchestrator may cause the REST Server initialization to fail and lead to connectivity issues.

PRJ-42754,
PRHF-26604

Scalable Platforms

When using asg alert, the domain name is changed to "BladedCenter.com" instead of the configured name.

PRJ-42193,
PMTR-87997

Scalable Platforms

Upgrade rollback may not be performed successfully on a Security Group if Security Gateways were upgraded via CPUSE to a new major version more than once.

PRJ-43601,
PRJ-43213

Scalable Platforms

The task in "cpd_sched_config" is not correctly added and performed because of predefined NTP Servers.

PRJ-42515,
PMTR-88150

Scalable Platforms

Upon failover/failback, multicast packets are sent to Active members only. The member that changed state from Down to Active starts receiving the multicast packets before the route is resolved. This may impact traffic.

PRJ-43309,
PRJ-43307

Scalable Platforms

Minor packet drop may occur during Maestro Orchestrator graceful reboot.