R81.20 Jumbo Hotfix Take 99

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 99

Released on 20 March 2025

Take 99 - New Functionality

 

PRJ-52612,
PRHF-31058

SSL Inspection

NEW: This Take introduces a fail-open mechanism for HTTPS Inspection with Hardware Security Module (HSM) integration. If the HSM becomes unavailable, TLS connections now automatically bypass HTTPS Inspection, ensuring continuous network connectivity.

PRJ-58467,
ROUT-3004

Routing

NEW: Added a new Gaia Clish parameter to ignore the Autonomous System (AS) Path when aggregating routes: "set aggregate <IP Address>/<IP Mask> aspath-ignore {on | off}". Note, enabling "aspath-ignore" will disable "aspath-truncate" if configured.

Take 99 - Improvements and Resolved Issues

 

PRJ-56535,
PRHF-34745

Security Management

UPDATE: The Management API logs outbound payloads to api.elg only for non-"200" response codes. It is now possible to enable the "WRITE_FULL_OUT_PAYLOAD" environment variable to force comprehensive logging of all API call payloads, regardless of the response status. Refer to sk182786.

PRJ-55606,
PRHF-34346

Multi-Domain Security Management

UPDATE: Added a log print to warn about unsupported SIC reset configurations on Multi-Domain Security Management Server / Multi-Domain Log Management Server and to alert when a Domain lacks an ObjectStoreDomain, which prevents CPM from starting. Refer to sk182533.

PRJ-57847,
PMTR-109621

Logging

UPDATE: Enhanced the CLI "cp_log_export" command with additional examples and expanded help documentation.

PRJ-58668,

PMTR-110592

Security Gateway

UPDATE: Added multi-interface packet fragment reassembly support to prevent drops in Equal Cost Multipath (ECMP) environments.

PRJ-53148,
PRHF-32539

Security Gateway

UPDATE: Reduced memory usage of LDAP keepalives and improved connection error handling, resulting in improved performance.

PRJ-55618,
PRHF-34380

Security Gateway

UPDATE: Added information about VSX context to the mem.report. files.

PRJ-58814,
PRHF-37100

Security Gateway

UPDATE: Added a kernel parameter "domo_reverse_lookup_disabled" to disable reverse DNS lookups to avoid rare incorrect matches in scenarios involving non-Fully Qualified Domain Name (non-FQDN) Domains.

  • "domo_reverse_lookup_disabled 1" to disable reverse DNS lookups.

  • "domo_reverse_lookup_disabled 0" to enable reverse DNS lookups (the default value).

PRJ-57147,
PMTR-108406

Security Gateway

UPDATE: Optimized handling of gzip encoded HTTP traffic to enhance performance under high load conditions.

PRJ-54141,
PRHF-31274

SSL Inspection

UPDATE: HTTPS Inspection statistics are now available through SNMP requests.

PRJ-57527,
PMTR-109151

SecureXL

UPDATE: Improved throughput of GRE tunnels configured on the ports of the 100G Acceleration Card when SecureXL works in UPPAK mode.

PRJ-58465,
PRHF-33825

Routing

UPDATE: IP Reachability Detection now supports simultaneous BFD and ping monitoring to the same remote address, where previously only one method was functional at a time. When both are configured, each monitoring protocol operates independently, allowing features to track their preferred detection method while maintaining existing configuration syntax.

PRJ-56896,
PMTR-107995

Gaia OS

UPDATE: Added validation rules to ensure file names meet the required format when restoring backups using Clish.

PRJ-54385,
PRHF-33678

Gaia OS

UPDATE: Added vertical scroll bar functionality to the Gaia Portal login page to enable viewing of long banner messages.

PRJ-49363,
PRJ-49367

CloudGuard Network

UPDATE: NSX-T in-place upgrade is now supported. Refer to CloudGuard Network for NSX-T Security Gateway Deployment Guide.

PRJ-57804,
PRJ-57795

CloudGuard Network

UPDATE: CloudGuard Network for AWS Gateway Load Balancer Auto Scaling Group now supports inspection of IPv6 traffic encapsulated with GENEVE IPv4 headers.

PRJ-57220,

PMTR-110740

CloudGuard Network

UPDATE: Traffic between an external network host and an internal network host is now accelerated when a static NAT is configured to translate a cluster member's IP address or specific high port to an internal host IP address or specific service port. This scenario is relevant in Check Point CloudGuard Network Security Azure High Availability deployments, where traffic passes through a Load Balancer.

  • To enable acceleration, add the following kernel parameter to the $FWDIR/boot/modules/fwkern.conf file - "accel_dnat_to_cluster=1".

  • The change can also be applied immediately to the running FW1 process without requiring a reboot: "fw ctl set int accel_dnat_to_cluster 1".

PRJ-57903,
PMTR-109685

Scalable Platforms

UPDATE: It is possible to add up to 28 members per site in a Single Site topology.

PRJ-58878,

ODU-2219,

PRJ-59438,

ODU-2323,

PRJ-60329,

ODU-2403

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 125, Take 128 and Take 134 via self-updatable package. Refer to sk170314.

PRJ-58989,
ODU-2195

Automatic Updates - CPView

UPDATE: Added Take 141 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.

PRJ-58995,
ODU-2203

Automatic Updates - CPView

UPDATE: Added Take 44 of CPviewExporter Release Updates. Refer to sk180521.

PRJ-59280,

ODU-1579

Automatic Updates - Threat Prevention

UPDATE: Added Update 25 of Autonomous Threat Prevention Management integration Release. Refer to sk167109.

PRJ-59322,

ODU-2259

Automatic Updates - HCP

UPDATE: Added Update 21 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-59996,

ODU-2227

Automatic Updates - Smart-1 Cloud

UPDATE: Added Update 8 of Quantum Smart-1 Cloud. Refer to sk166056.

PRJ-58273,
PRHF-37209

Security Management

In rare scenarios:

  • Login to the Security Management Server may fail with timeout.

  • Publish operations may take a long time.

PRJ-57068,
PRHF-36058

Security Management

After an upgrade, when browsing to SmartConsole > Manage & Settings > Permissions & Administrator > Administrators, the page may display "Error retrieving results".

PRJ-56973,
PRHF-36032

Security Management

Using the "set simple-cluster" command without the "members.add" option to add cluster members may result in recreating existing cluster members and potential loss of SIC.

PRJ-57781,
PRHF-36576

Security Management

In rare scenarios, publishing Multi-Domain Security Management level changes such as Administrator configuration changes fails. The "Action Failed due to an Internal Error" error is displayed.

PRJ-54488,
PRHF-33773

Security Management

Scheduled Snapshot Issues:

  • Gaia may not recognize the Remote Server as a known host during scheduled backup creation, even after following sk164234 instructions.

  • The "Remote server identity is not known by Gaia" error is displayed despite proper HBA configuration.

  • The "set snapshot-scheduled recurrence monthly" command fails when using the "all" option.

Refer to sk182665.

PRJ-46671,
PMTR-63558

Security Management

In the Management API, when setting "scan-malicious-links.max-bytes" to a value greater than 10,000 bytes, the API returns a "generic_error".

PRJ-58717,
PRHF-37561

Security Management

Changes to a SmartConsole administrator's Authentication Server (RADIUS or TACACS) may occasionally fail to take effect.

PRJ-58850,
PRHF-37388

Security Management

In rare scenarios, a core file of the CPRLIC process is generated.

PRJ-57035,
PRHF-35374

Security Management

In some scenarios, deleting a Security Gateway object fails if the Security Gateway is a participant in Global VPN Community.

PRJ-58471,
PRHF-37430

Security Management

Creating a Threat Prevention Exception from a log fails with the "Failed to add exception" error when the "File Name" field in the log contains a Windows directory separator ("\").

PRJ-58447,
PRHF-37393

Security Management

In rare scenarios, Revert to Database Revision is stuck at 10%.

PRJ-58900,
PRHF-37631

Security Management

After an IPS update, reassigning global policies may take a long time.

PRJ-57538,
PRHF-36475

Security Management

In some scenarios, the "show packages" Management API command with "details-level full", fails with "Null Pointer exception: null".

PRJ-57916,

PMTR-43993

Security Management

In rare scenarios, the CPD process may unexpectedly exit and create a core dump file. Refer to sk182787.

PRJ-48282,
PRHF-29640

Security Management

Execution of the "set access-rule" and "add access-rule" API commands takes a long time to complete. Refer to sk181349.

PRJ-58523,
PRHF-37446

Security Management

In rare scenarios, login to SmartConsole may fail with the timeout.

PRJ-57396,
PRHF-36340

Security Management

In rare scenarios, when more than one Security Blade is enabled on the Security Gateway, Install Policy Presets may fail after purging all revisions.

PRJ-58340,
PRHF-37251

Security Management

In rare scenarios, login to SmartConsole using LDAP, TACACS or RADIUS authentication fails with a timeout.

PRJ-57817,
PMTR-107227

Security Management

In some scenarios, Web SmartConsole session gets disconnected after several minutes.

PRJ-59058,
PRHF-37185

Security Management

When using SmartWorkflow on a Security Management Server with more than 200 administrators, requests may stall or cause SmartConsole crashes during submission.

PRJ-58573,
PRHF-37436

Security Management

Global Policy Reassignment fails with the "org.postgresql.util.PSQLException: ERROR: more than one row returned by a subquery used as an expression" error printed in the cpm.elg file.

PRJ-57657,
PRHF-36501

Security Management

In some scenarios, High Availability synchronization fails with "NGM failed to export data" because of invalid Global Domain Assignments.

PRJ-60043,

FMW-4330,

PMTR-113639

Security Management

In cloud environments, in a rare scenario, when using updatable objects in security policies, policy installation fails when the updatable objects package is missing.

PRJ-58846,
PRHF-34721

Multi-Domain Security Management

In a Multi-Domain Security Management environment with a VSX Security Gateway, such operations as login to SmartConsole, Global Domain Assignment, Domain creation or deletion may take longer than expected or fail with a timeout message "Task failed".

PRJ-57981,
PRHF-36890

Multi-Domain Security Management

In rare scenarios, an upgrade of Multi-Domain Security Management Server, handling Domain Log Server certificates, may get stuck.

  • The fix will only be applied if the upgrade to R81.20 Jumbo Hotfix Accumulator Take 99 or higher is done using a Blink image or the Advanced Upgrade method.

PRJ-58029,
PRHF-36922

Multi-Domain Security Management

In rare scenarios, in Multi-Domain Security Management environments, domain creation fails with "Failed to create Domain server "Domain name" Permission calculation failed."

PRJ-57784,
PRHF-36479

Multi-Domain Security Management

In environments where not all Domains are Active on the same Server (for example, in a multi-site environment), and there is no Domain Management Server for a specific Domain, logs from that Domain are not forwarded to the Infinity Portal.

PRJ-45340,
PRHF-23903

Multi-Domain Security Management

In a Multi-Domain Security Management environment, RADIUS authentication may be sent with an incorrect IP address. Refer to sk180723.

PRJ-58264,
PRHF-37258

Multi-Domain Security Management

In rare scenarios, the "mdsstat" command shows that the CPD process is down even though it is up and running.

PRJ-59347,
PMTR-111094

Logging

In the cloud environments (Smart-1 Cloud and EPMaaS), logs query may fail because of the AWS certificate change.

PRJ-59585,

PRHF-38427

Logging

In rare scenarios, after an upgrade, SmartConsole does not display logs in the Logs & Monitor tab, and the page remains blank. Refer to sk183086.

PRJ-59397,

PRJ-59397

Logging

After an upgrade, Log Sharing feature does not function as expected, "Encountered an internal error" is printed in the Infinity Services view, under Log Sharing status, and LOG_EXPORTER core dumps are generated.

See the Critical Information section.

PRJ-55407,
PRHF-34152

Logging

In rare scenarios, the description of IPS Logs in the Logs view may be unclear. Refer to sk182386.

PRJ-57675,
PRHF-36647

Security Gateway

A stability issue where the ICAP Server may unexpectedly restart when processing traffic from a Security Gateway with Threat Emulation enabled.

PRJ-56296,
PMTR-106906

Security Gateway

The FWK process on the Security Gateway may exit when processing the HTTP traffic.

PRJ-47910,
PRHF-29290

Security Gateway

Intermittent drops of transmission packets for "Streaming Engine: TCP Invalid Retransmission" causing HTTP loading issues. Refer to sk181282.

PRJ-53185,
PMTR-111974

Security Gateway

High CPU usage on SND cores related to processing network traffic and distributing it to the appropriate firewall instances.

PRJ-59118,
PMTR-110235

Security Gateway

In a rare scenario, the RAD daemon may crash during large memory allocation operations.

PRJ-57828,
PRHF-36779

Security Gateway

In some scenarios, an HTTP format size protection exception is not applied to the HTTP/2 flow.

PRJ-50630,
PRHF-29467

Security Gateway

GTP-U traffic may be dropped because of incorrect message type handling.

PRJ-50698,
PRHF-30983

Security Gateway

Running the "g_tcpdump mcap" with "-C" flag fails with the file matching or captured packets merging error.

PRJ-58188,
PRHF-35819

Security Gateway

After an upgrade, Dynamic Balancing does not start. The "dynamic_balancing -p" command returns "Dynamic Balancing is currently Initializing". Refer to sk182615.

PRJ-58151,
PRHF-37032

Security Gateway

In a rare scenario, the FWK process may exit when HTTPS Inspection is enabled and TLS connections are inspected on non-standard ports (ports other than 443 or 8080).

PRJ-58090,
PMTR-109845

Security Gateway

When the autodebug feature is enabled, the RAD service may consume high CPU and trigger "RAD service not available" alert logs.

PRJ-56910,
PRHF-35918

Security Gateway

The FWK process may unexpectedly exit after policy installation failure.

PRJ-58205,
PRHF-36513

Security Gateway

Incorrect Rule Base parameters synchronization logic may lead to the FWK process exit.

PRJ-57598,
FMW-2980

Security Gateway

In some scenarios, the FWK process may exit when traffic is inspected by Content Awareness.

PRJ-57961,
PRHF-36794

Security Gateway

In some specific HTTP/2 traffic scenarios, a valid connection may fail.

PRJ-58560,
PRHF-37532

Security Gateway

Enabling the CoreXL Dynamic Split feature causes high CPU load on Maestro Security Group Members because of multiple "mq_mng -u" processes. Refer to sk183251.

PRJ-56199,
FMW-795

Security Gateway

Large NAT Rule Base (more than 2,000 rules), may lead to high CPU usage during packet processing.

PRJ-54402,
PRHF-33615

Security Gateway

In rare scenarios, after an upgrade, the FWK process may unexpectedly exit because of memory corruption.

PRJ-58419,
PRHF-37014

Security Gateway

Android devices' HTTP HEAD requests to Google services are blocked by Security Gateway proxy, generating excessive logs that impact Security Gateway performance through high CPU usage. Refer to sk182990.

PRJ-47275,
PMTR-92832

Security Gateway

When Dynamic Split is enabled, SND synchronization fails between members on Active site and Standby site, although it should occur automatically, when one of the members receives an additional SND.

PRJ-58392,
PRHF-36652

Security Gateway

In some scenarios, a memory leak may occur in the FWK process.

PRJ-56941,
PRHF-32506

Security Gateway

VoIP H.323 calls are dropped with reason "Handler 'h323_h245_code' reject". Refer to sk182835.

PRJ-49694,
PRHF-30506

Security Gateway

High CPU utilization on the new Active cluster member after a failover. Refer to sk182040.

PRJ-53323,
PRHF-32698

Security Gateway

PPPoE interface fails to restart when it is disconnected from the Server side. Refer to sk182154.

PRJ-58860,
PMTR-110741,

PRJ-56437,
PRHF-35363

Security Gateway

In rare scenarios, the FWK process may unexpectedly exit.

PRJ-56403,
PRHF-35372

Internal CA

The "cpca_dbutil print" command may delete the provided output file content if the input file does not exist.

PRJ-57045,
PRHF-36045

Identity Awareness

In a rare scenario, the PDPD process may unexpectedly exit during policy Installation.

PRJ-57644,
PRHF-36542

Identity Awareness

In a rare scenario, when fetch_by_SID is enabled, the PDPD process repeatedly exits. Refer to sk182745.

PRJ-58130,
PRHF-36964

Identity Awareness

In a rare scenario, the PDPD process may unexpectedly exit during PDP sharing flow.

PRJ-55652,
PRHF-34020

Application Control

In some scenarios, a custom application does not match a URL Filtering rule.

PRJ-56812,
SDWANGW-712

Application Control

An application may not be matched to an Application Control rule.

PRJ-58459,
PRHF-37149

Application Control

Web protections may not properly block HTTP requests without a Host header.

PRJ-57505,

PMTR-108132

URL Filtering

IPv6 address ranges defined in IoC feeds may fail to be enforced, not allowing proper filtering of IPv6 traffic.

PRJ-55515,

PRHF-34270

URL Filtering

In a rare scenario, an IoC feed containing a long URL type observable may not be enforced.

PRJ-54399,
PRHF-33607

IPS

In a rare scenario, the FWK may unexpectedly exit because of a memory allocation issue.

PRJ-57764,
PRHF-33315

IPS

In some scenarios, the DNS Tunneling IPS protection does not function as expected. Refer to sk178487.

PRJ-57968,
PRHF-36711

DLP

The DLP blade may not block the password-protected files of a specific type, although it should.

PRJ-56281,
PRHF-35095

DLP

The DLPU process may exit with a core dump file.

PRJ-56516,
PRHF-35504

DLP

DLP policies may not correctly block password-protected and unprotected files during Google Drive uploads, despite Content Awareness blade configuration.

PRJ-58169,
PRHF-37164

Anti-Virus

In a specific scenario involving a long-lived SMTP connection, the memory usage allocated by the Anti-Virus blade steadily increases over time.

PRJ-58286,
PMTR-109114

Anti-Virus

In a rare scenario, when the Anti-Virus blade is enabled, the Security Gateway may crash during traffic inspection.

PRJ-53157,
PRHF-32596

Anti-Virus

In specific scenarios, the Anti-Virus file type classification engine incorrectly identifies Microsoft Office documents as zip archives, leading to improper handling of these files.

PRJ-58737,
PRJ-58810

Mobile Access

After an upgrade, the Mobile Access Blade's CVPND daemon fails to load and the Mobile Access Portal becomes inaccessible when adding new Virtual Systems or converting to a VSX Gateway, because of improper updates to the gateway-side configuration file cvpnd.C.

PRJ-57390,
PRHF-36150

Mobile Access

A "No matching appID candidates found for 'push'" message appears when modifying push notification settings on Capsule Workspace. Refer to sk182974.

PRJ-54055,
PRHF-33345

Mobile Access

The debug output file for Mobile Access, named "exchangeRegistration_portal_error_log" is increasing in size.

PRJ-59583

ClusterXL

The FWK process may exit after enabling or disabling the "Same VMAC" feature. Refer to sk165674.

PRJ-52524,

PRHF-32026

ClusterXL

When attempting to configure the minimum number of required subordinate interfaces for Bond Load Sharing, the settings are not applied.

PRJ-56635,

PMTR-107128

ClusterXL

In a cluster environment, proxy flow error may cause repeated log messages in the fwk.elg file: "de_allocate_port: fwx_alloc_global_del failed (second try)".

PRJ-58891,
HAAN-883

SecureXL

The "tcpdump -i <cx7_interface>" command may not capture traffic passing through an interface with 100G Acceleration Card on Quantum Force appliances.

PRJ-58080,
PMTR-68784

SecureXL

Packet drops may occur if the same multicast packet is received on multiple interfaces.

PRJ-53631,
PRHF-32840

SecureXL

High volumes of RST packets may cause CPU spikes, resulting in incoming network packet drops on SND instances.

PRJ-58275,
PMTR-110096

SecureXL

SecureXL User Mode crashes if an acceleration card interface has an MTU above 9000 and receives frames larger than 9234 bytes.

PRJ-60159,

PRHF-38880

SecureXL

Routing related connectivity and stability issues may occur when SecureXL operates in User Mode (UPPAK). Refer to sk183181.

See the Critical Information section.

PRJ-60103,

PMTR-106961

SecureXL

Security Gateway may crash with a vmcore during next hop routing table lookups.

PRJ-57986,
ROUT-3189

Routing

Static routes may get permanently deleted from the kernel during rapid interface configuration changes when there is a large number of routes.

PRJ-57990,
PRHF-36805

Routing

The "iphelper" (IP Broadcast Helper) service may trigger high CPU utilization because of a recursive packet broadcasting loop between network interfaces.

PRJ-59287,

PMTR-111756

Routing

SecureXL may drop traffic with "cphwd_send_packet Reason: F2P outbound processing failed (CPAS)". Refer to sk183194.

PRJ-54133,
PRHF-33418

VPN

Two or more Endpoint Security VPN (Remote Access VPN) users may get the same Office Mode IP address. Refer to sk182537.

PRJ-54558,
PRHF-33826

VPN

Policy installation in large scale VPN environments may take a long time.

PRJ-56804,
PRHF-34632

VPN

SSL Network Extender (SNX) traffic on Maestro may be dropped with "vpnk_tcpt invalid negative tunnel id". Refer to sk182806.

PRJ-57942,
PMTR-108894

VPN

When configuring machine authentication without an LDAP server, the computer is authenticated during the connection with the RA VPN. However, the logs in SmartConsole do not display the "Authenticated machine ..." message as expected.

PRJ-56527,
PRHF-34034

VPN

Multi-Portal Certificates are not updated through policy installation but only after terminating the VPND process or performing a reboot or "cpstop;cpstart". Refer to sk182583.

PRJ-55554,
PRHF-34063

VPN

Policy installation fails with "ERROR: Duplicate keys <0000001b, ac130265, ac130265> in table vpn_routing_correction" when duplicating keys in a VPN table and "Encryption domain per community" is configured. Refer to sk182353.

PRJ-58000,
PRHF-36849

VPN

Capsule VPN connectivity failures may occur after a configuration change of the VPND daemon table parameters.

PRJ-59690,

SMBGWY-7704

VPN

Repeatedly lost connection to resources located behind a Remote Access VPN Gateway. Refer to sk183147.

See the Critical Information section.

PRJ-58248,
PRHF-37106

VSX

SNMP counters may return incorrect data on VSX.

PRJ-54638,
PRHF-33880

VSX

The "vsx_util convert_cluster" command may fail and cause the FWM process to exit with a core file.

PRJ-57745,
PRHF-36734

VSX

In a rare scenario, the FWM process may exit when running the VSX creation wizard.

PRJ-57394,
PRHF-29543

VSX

Newly pushed VSX configuration on Maestro may not be synchronized on all Security Group Members, causing DOWN state.

PRJ-54254,
PRJ-54255

Gaia OS

When Gaia's backup retention policy is configured with a maximum of one backup or a disk space allocation smaller than the backup file size, the backup process hangs and requires a device reboot. This also may cause the CONFD daemon to exit.

PRJ-54155,
PRHF-33439

Gaia OS

When querying VLAN interfaces, instead of returning the ifType specifically for the VLAN interface itself, the SNMP walk returns the ifType of the underlying physical interface that the VLAN is associated with.

PRJ-58164,
PRHF-37102

Gaia OS

The ROUTED daemon fails to start when a VTI is configured with a local IP address that matches the next-hop address used in the static route configuration. Refer to sk182848.

PRJ-53604,
PRHF-32577

Gaia OS

Capturing with Check Point Traffic Capture Tool (cppcap) from all devices may lead to high CPU usage and potential performance issues.

PRJ-56419,
PMTR-107014

Gaia OS

Miscalculation of disk space may cause snapshot to fail.

PRJ-57914,
PMTR-86473

Gaia OS

In Gaia Job Scheduler, when running a user-defined command, it may be replaced with "dummyCommand".

PRJ-58699,

PRHF-37362

Gaia OS

In a Maestro environment with RADIUS users, accessing Maestro Hyperscale Orchestrator (MHO) through Gaia Portal generates the "ERR_EMPTY_RESPONSE" error and triggers a segmentation fault in the httpd2_error_log file, causing the Gaia Portal to go down and prevent users from managing the system through the WebUI.

PRJ-58935,
PMTR-102731

Gaia OS

The "show interface" command fails to display loopback interface configurations, and the "CliError( ) called without module or error code" error is printed when attempting to view or modify loopback interfaces on the Security Gateway.

PRJ-48288,
PRHF-29918

QoS

Security Gateway may have an unexpected behavior when receiving VPN connection QoS outbound flows without assigned interfaces.

PRJ-59310,
PRHF-27173

VoIP

High volumes of VoIP/ SIP traffic may trigger a Security Gateway crash.

PRJ-58109,
PRJ-57641

Scalable Platforms

Activation of downgraded Security Group members may fail, preventing the rollback process performed using the "sp_upgrade --revert" command.

PRJ-56276,
PRHF-35335

Scalable Platforms

In CPView and in the output of Clish commands, unused PMIC-1 1.2V sensor in the MHO-175 appliance shows an incorrect reading value. This is a cosmetic issue.

PRJ-58436,
PRJ-57507

Scalable Platforms

When running the "enabled_blades" command multiple times simultaneously, the command output may be incorrect. Refer to sk181024.

PRJ-56907,
PRJ-57105

Scalable Platforms

Configuring a Unique IP Address for Each Standby Chassis (UIPC) may fail.

PRJ-58735,
PRJ-58323

Scalable Platforms

In a Maestro environment, a Security Gateway may enter a reboot loop because of sync issues of the settings.fwset file.

PRJ-58345,
PRHF-37291

Scalable Platforms

In rare scenarios, the "asg perf" command fails because of the incorrect (negative) value of the number of connections per second (CPS) that are forwarded from SecureXL to the Firewall kernel in the slow path.

PRJ-57472,
PRHF-36424

Scalable Platforms

In rare scenarios, Interface Active check may cause a Security Gateway crash when probing a local network.

PRJ-57388,
MBS-14520

Scalable Platforms

Using the "#" character in the Message of the Day (MOTD) banner message causes SGMs to fail during boot.

PRJ-48696,
PMTR-94043

Scalable Platforms

After upgrade:

  • Output of the "asg diag verify" command shows in the "System Components" section that the status of the "Software Provision" test is "Failed".

  • Output of the "asg diag print <ID of "Software Provision">" command shows a shell script code.

  • Output of the "asg_provision" command shows a shell script code.

PRJ-46078,
PMTR-90934

Scalable Platforms

After a Jumbo Hotfix upgrade a single site is displayed as active, but the assigned load value is 0%. Refer to sk182454.

PRJ-57765,
PMTR-106842

Scalable Platforms

Changing the bond mode on Scalable Platform Security Group members may cause a MAC address mismatch on the bond interface due to a reordering of bond subordinate that does not match the database. Refer to sk182488.

PRJ-58960,
PRJ-57191

Scalable Platforms

Import an R82 upgrade package may fail with "[ERROR] Failed to transfer package to several members, Import was aborted" because of timeout which occurs while copying the package to all Security Group members.

PRJ-59372,

PRHF-38206

Scalable Platforms

VPN tunnels may be disconnected due to an error in processing IKE (Internet Key Exchange) packet flow.

PRJ-56443,
PRHF-31476

Carrier Security

When Carrier Security is enabled, GTP-U packets are incorrectly matched against GTP rules instead of a non-GTP UDP rule, causing drops with the "Unestablished tunnel" error.

PRJ-58369

IoT Protect

Removing a member from an IoT-enabled Security Group leaves residual files that prevent IoT processes from starting when this member joins a new Security Group.