R81 Jumbo Hotfix Take 13

 

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 13

Released on 08 February 2021

PRJ-19946,
PMTR-62429

Security Management

NEW: Added new Management HA utility to schedule automatic full syncs to peers that failed to be synchronized incrementally.

PRJ-18434,
PMTR-60665

Security Management

NEW: The upgrade process is being monitored dynamically and will be stopped if it cannot be completed, not basing on a timeout.

PRJ-19545,
ODU-73

Security Management

UPDATE: Added Update 6 of Autonomous Threat Prevention Management (ATPM). Refer to sk167109.

PRJ-20165,
ODU-76

Security Management

UPDATE: Added Update 7 of Autonomous Threat Prevention Management (ATPM). Refer to sk167109.

PRJ-19972,
PRJ-13465

Security Management

UPDATE: If a Management HA synchronization stalls (displaying "Peer is busy"), it will be released within 2 hours instead of 24 hours.

PRJ-20032,
PMTR-61770

Security Management

UPDATE: When purging revisions, task notifications will also be purged if created before the last revision to purge was published.

PRJ-20001,
PRHF-14293

Security Management

UPDATE: Added improvements in policy load process, to reduce the policy installation time when having large amount of objects.

PRJ-22105,
PRJ-21382

Security Management

In some scenarios, the installation time of Jumbo Hotfix Take 11 on the Management Server may take up to several hours.

PRJ-18253,
PRHF-12594

Security Management

When logging into SmartConsole directly to a Domain using RADIUS or TACACS, the Authentication method in the audit log may show as "Internal Password". Refer to sk168716.

PRJ-17693,
PRHF-13332

Security Management

In some scenarios, HA temporary sub-directories in $FWDIR/tmp are not deleted if sync fails. Refer to sk170972.

PRJ-18289,
PMTR-61010

Security Management

In rare scenarios, the CPU and memory usage of CPM process may be abnormally high. Refer to sk170672.

PRJ-18266,
PRHF-13607

Security Management

'Revert to Revision' tasks cannot be cleared from tasks pane in SmartConsole.

PRJ-19105,
PMTR-61908

Security Management

In some scenarios, Management HA change-over to Security Management Server Backup fails with the "Failed to communicate with the peer" message.

PRJ-20564,
PMTR-62785

Security Management

In some scenarios, policy installation on LSM Gaia cluster profile fails with "Policy installation had failed due to an internal error" message.

PRJ-17563,
PRHF-12885

Security Management

In some scenarios, reassigning a Global Policy may fail if the Global and local domains are not active on the same Multi-Domain Server.

PRJ-17729,
PRHF-13278

Security Management

Upgrade may fail if a Data Center object was last modified by an Administrator with a single quote in the name.

PRJ-19274,
PRHF-14074

Security Management

Policy installation duration may increase due to large $FWDIR/conf/invalid_object_names.C file on the Management server. Refer to sk170427.

PRJ-18476,
PRHF-13644

Security Management

In some scenarios, the first environment variable configured using sk165938 is not loaded and not used by the CPM process.

PRJ-19571,
PMTR-60842

Security Management

In rare scenarios, on a Multi-Domain Server where Domains are using a Security Management Server configured for High Availability, initial configuration of the Security Management Server may fail with "Failed to reach peer after restart" error.

PRJ-20135,
PMTR-60541

Security Management

In a rare scenario, the FWM process unexpectedly exits.

PRJ-19950,
PRHF-14394

Security Management

The Management HA window in SmartConsole may mistakenly show the "Peer is busy" warning message for a few seconds.

PRJ-19589,
PRHF-12851

Multi-Domain Management

UPDATE: With this fix, mds_backup will backup the Upgrade Tools package(s) and mds_restore will restore them on a Multi-Domain Server.

PRJ-19648,
PMTR-62201

Multi-Domain Management

In rare scenarios, a Domain is shown in the Domains view without any Domain Server or a Domain is shown with Domain Server that was deleted and does not exist anymore. Refer to sk170556.

PRJ-19278,
PRHF-13977

Multi-Domain Management

In rare scenarios, Management server becomes inaccessible after Global Policy reassign operation.

PRJ-18994,
PRHF-13874

Multi-Domain Management

The "cplic db_print -all -x" command fails when running on the MDS level.

PRJ-19321,
PMTR-61346

SmartConsole

NEW: Added support for Python 3 in Management API scripts.

PRJ-20248,
PMTR-62490

SmartConsole

UPDATE: A pop-up warning will be displayed every time a "Custom Application" object with a performance impacting URL is edited (instead of being displayed only once).

PRJ-18466,
PRHF-13551

SmartConsole

In some scenarios, Staging mode IPS protections activation in the Local Domain does not match the activation in the Global Domain after a Global Threat Prevention policy assignment. Refer to sk170322.

PRJ-18338,
PRHF-12226

SmartConsole

When using the "set simple-cluster" Management API command to update a user defined security zone, the "Specify security zone" checkbox in SmartConsole is not selected.

PRJ-19323,
PMTR-60220

SmartConsole

In some scenarios, the api.csv file may show extra empty columns.

PRJ-19203,
PRHF-13955

SmartConsole

In some scenarios, when using the "set simple-gateway" API command with "logs-settings.forward-logs-to-log-server", it fails with "Generic server error". Refer to sk170352.

PRJ-19535,
PMTR-62078

SmartConsole

In some scenarios, when adding a new user certificate of type .p12 via API command, the returned certificate may be incorrect.

PRJ-18960,
PMTR-61418

SmartConsole

In a VPN Community with MEP configuration, the OK operation may fail with the "Update operation failed" message.

PRJ-20787,
PRHF-13556

SmartConsole

When the user creates an Access Role, the AD organization tree may show duplicate branches, and some branches may be missing.

PRJ-20381,
PMTR-62935

SmartConsole

Adding Global dynamic objects to source or destination columns of access rules on the Global Domain via Management API may fail when using the Global dynamic object names.

PRJ-20911,
PMTR-63302

SmartConsole

In some scenarios, deleting a policy fails.

PRJ-18550,
PMTR-61235

SmartConsole

In a community with Cluster VSX member, the Granular encryption window may not open and show "Unable to load page".

PRJ-18309,
PRJ-18307

SmartProvisioning

NEW: Added support for Threat Emulation Blade on LSM profile of R81 SMB gateways and clusters.

  • Requires R81 SmartConsole Build 548 (or higher).

PRJ-18000,
SL-2106

Logging

NEW:

  1. Log Exporter can now schedule a recurring reconnection to the target 3rd party server periodically. This allows usage of a Load Balancer component for target servers.
  2. The target 3rd party server can be declared as a DNS name also when using UDP protocol.

PRJ-19451

Logging

UPDATE: Log Exporter read mode default was changed to Semi-unified instead of Raw mode.

PRJ-18099,
PRHF-7415

Logging

In rare scenarios, a log may display incorrect values in the Action and Rule field. Refer to sk170676.

PRJ-21078

Logging

In rare scenarios, the FWD process on the Security gateway may be blocked for several seconds due to processing of log attachments.

PRJ-18405,
PMTR-59205

Logging

The FWM and\or LOG_INDEXER processes may repeatedly stop when there are more than ~500K network objects declared. Refer to sk164452.

PRJ-19819,
SL-4358

Logging

In rare scenarios, the LOG_INDEXER process may unexpectedly exit when reading a specific log format. Refer to sk116117.

PRJ-19846,
PMTR-62010

SmartView

UPDATE: Improved the time resolutions usability (formally known as samples) of the Timeline widgets.

PRJ-20875,
PMTR-62957

SmartView

UPDATE: To improve performance, SmartView now exports data in CSV format instead of Excel.

PRJ-20795,
PRHF-13973

Security Gateway

UPDATE: Service with source port in the Access Rulebase will no longer disable accept templates for all connections.

PRJ-19066,
PRJ-18831,
PRJ-20716,
PRJ-20057,
PRJ-20738,
PRJ-20058

Security Gateway

In rare scenarios, Security Gateway memory consumption may increase.

PRJ-18982,
PMTR-61179

Security Gateway

In rare scenarios, Security Gateway may crash with USFW fwk core file.

PRJ-19802,
PMTR-62080

Security Gateway

Connectivity issues may appear due to missing proxy ARP entries on the Security Gateway.

PRJ-19813,
PMTR-62012

Security Gateway

In some scenarios, duplicate verification message is displayed when installing NAT policy on Security Gateways R80.40 and lower.

PRJ-20362,
PMTR-62876

Security Gateway

In some scenarios, DHCP traffic may be dropped after installing an accelerated policy.

PRJ-19705,
PMTR-62215

Security Gateway

In rare scenarios, a memory leak may occur in TOPOD process.

PRJ-20386,
PRHF-13431

Security Gateway

In a rare scenario, Access Control policy installation may fail after upgrade of Security Gateway from R80.10 or below to R80.20 or higher.

PRJ-20633,
PRHF-14378

Security Gateway

In rare scenarios, high memory consumption in CPD may occur due to a memory leak in authentication flow with an LDAP server.

PRJ-19586,
PMTR-61102

Security Gateway

In some scenarios, "email_unified_cmi_get_attribs: not valid caller: up_log_get_user_hash" error appears in dmesg for SMTP traffic.

PRJ-20516,
PRHF-14630

Security Gateway

In some scenarios, when using routing separation, connection to Management Plane via Data Plane is dropped.

PRJ-19852,
PRHF-14268

Security Gateway

In some scenarios, a memory leak may occur after sending a packet from the kernel.

PRJ-20937,
PMTR-62420

Security Gateway

In a rare scenario, policy installation may fail on timeout and "fw amw fetch" process is still running on the Security gateway.

PRJ-18488,
PMTR-61165

Security Gateway

In some scenarios, repeating "fwx_alloc_global_find_free_port_atomic: rtsp pending port doesn't match the same pool" errors are displayed in dmesg when using Hide NAT with VoIP.

PRJ-20656,
PMTR-63092

Security Gateway

Accept logs with reason "Connection terminated before detection: Insufficient data passed. To learn more see sk113479." may be wrongly generated when the matched action is user authentication and wrong username/password provided by user.

PRJ-20901,
PRHF-14824

Security Gateway

In some scenarios, the DNS requests from the Security gateway may fail.

PRJ-18631,
PRHF-11912

Security Gateway

Wrong memory (hmem) values may be reported by specific SNMP OID. Refer to sk168992.

PRJ-19958,
PMTR-62477

Security Gateway

Half-closed accelerated TCP connections may take too long time to expire.

PRJ-19942,
PMTR-61708

Security Gateway

In some scenarios, policy installation fails with "Error code 1-2000245".

PRJ-18316,
PRHF-12224

Security Gateway

In rare scenarios, a memory leak may occur on Security Gateway in gconn table.

PRJ-19162,
TEX-1482

Threat Extraction

UPDATE: Threat Extraction will no longer attempt to perform "Convert to PDF" if the file is corrupted, because the resulting files in these cases are usually unreadable.
To reactivate this behavior, set the "enable_alternative_scrub_method" variable in $FWDIR/conf/scrub_debug.conf file to 1 and install the Security policy.

PRJ-19194,
TEX-1906

Threat Extraction

UPDATE: Threat Extraction ( Sanitization) will be automatically disabled when Infinity Threat Prevention mode is installed while the machine does not have enough resources (RAM).

PRJ-18248,
PRJ-18124

Identity Awareness

NEW: Added Identity Sharing's performance and functionality improvements. Refer to sk170516.

PRJ-19640,
PMTR-61982

Identity Awareness

In some scenarios, when a standby cluster member receives RADIUS accounting updates, there may be high CPU on the PDP process.

PRJ-20863,
IDA-3642

Identity Awareness

In some scenarios, there may be enforcement issues for MUHv2 users due to table mismatch.

PRJ-18181,
MBS-12220

URL Filtering

In some scenarios, the WSTLSD process may unexpectedly exit and produce a core dump.

PRJ-19042,
PRHF-13886

UserCheck

In some scenarios, users cannot restore original attachment via UserCheck portal and receive the "An unexpected error has occurred" error message.

PRJ-20927,
PRHF-11733

IPS

NEW: Added ability to send connection log per application match for ATM transactions identification. The functionality is disabled by default and can be enabled by using the "up_duplicate_connection_log_on_packet_matched_app_enabled" kernel parameter.

PRJ-19198,
PRHF-10943

IPS

In some scenarios, a non-compliant IMAP traffic is dropped.

PRJ-19301,
PRHF-13560

IPS

In some scenarios, log output shows the Origin/Source as "0.0.0.0" in VSX 3rd party IPS logs.

PRJ-19601,
PRHF-14259

DLP

UPDATE: Improved the DLP scans queue for a better scan rate.

PRJ-19923,
PRHF-14156

DLP

UPDATE: Expanded DLP postfix authentication to include NTLM to allow the Security gateway to connect to a mail servers that use the NTLM authentication protocol.

PRJ-20097,
PMTR-59101

DLP

UPDATE: Added support for multi-part data to DLP.

PRJ-20935,
PRHF-14978

SSL Inspection

The AES-NI (Intel Advanced Encryption Standard New Instructions) status is not displayed and "dmesg | grep AES-NI" returns no output. Refer to sk170779.

PRJ-19435,
PRHF-13987

SSL Inspection

In rare scenarios, the DynamicID Certificate validation may fail.

PRJ-18843,
PRHF-13322

SSL Inspection

In rare scenarios, a memory leak may occur during policy installation.

PRJ-21629,
PMTR-64293

SSL Inspection

When IPv6 is enabled, the wstlsd process may consume CPU at a high level after booting in kernel mode causing HTTPS connections to fail for a few minutes until the CPU returns to normal.

PRJ-17875,
PRHF-10279

HTTPS Inspection

UPDATE: "Categorize HTTPS websites" feature enhancements when "Categorize HTTPS Sites" feature is enabled:

  • Improved enforcement of first connection when URL Filtering setting is 'Hold' mode
  • Added SNI information to connection logs when connection is matched on rule with "Extended Log"
  • Hold mode granularity

For configuration, refer to sk173633.

PRJ-19196

Threat Prevention

NEW: Improved the way Threat Prevention distinguishes between .docx, .pptx, .xlsx and .zip files.

PRJ-18119,
PRHF-12737

Anti-Malware

Exported with ioc_feeds export command indicator feeds may contain user credentials. Refer to sk169035.

PRJ-19591,
PRJ-16924

Anti-Malware

In rare scenarios, after downloading files, Anti-Virus prevent logs appear with "Strict hold is not possible failure - Write to other side occurred" error message.

PRJ-17439,
PMTR-62284

Anti-Malware

In some scenarios, users may fail to access a web site with many malicious URLs.

PRJ-20924,
PRHF-13478

Anti-Malware

In a rare scenario, Security gateway may crash when the Threat Prevention Forensics feature is enabled.

PRJ-18198,
PRHF-8315

Anti-Malware

In some scenarios, multiple files called "ckp_mutex" are created on the Security Gateway.

PRJ-19745,
PRHF-13998

Anti-Bot

Dynamic Global Network Object usage inside a Network Group object may cause an Access Policy installation failure.

PRJ-19205,
PRHF-13935

ClusterXL

UPDATE: Added the option to display only monitored interfaces to "show cluster members <option>" command:

  • In Gaia Clish, run "show cluster members monitored"
  • In Expert mode, run "cphaprob -m tablestat"

PRJ-19926,
PMTR-58748

ClusterXL

In rare scenarios, running cphastop;cphastart may cause a cluster member to stay in "Down" state.

PRJ-19393,
PRHF-14115

ClusterXL

"set router active-active-mode" settings do not survive a reboot.

PRJ-20536,
PRHF-14728

ClusterXL

In some scenarios, data connections are dropped with "First packet isn't SYN" message on ClusterXL Load Sharing.

PRJ-16568,
MBS-11708

SecureXL

NEW: Added the ability to enable monitor-only mode for penalty box independently of other DOS/Rate limiting features.

PRJ-18324,
PRHF-13474

SecureXL

UPDATE: Drop templates can be generated for connections with matched action Reject. For additional information and configuration, refer to sk171146.

PRJ-20056,
PRHF-14417

SecureXL

In rare scenarios, SecureXL may crash due to NULL handling.

PRJ-18088,
PRHF-13507

SecureXL

SNMP may show wrong values for the number of bytes and packets accepted by Security gateway. Refer to sk170132.

PRJ-20028,
PRHF-14228

SecureXL

Server may not reuse the TCP connection when the user allows out of state TCP packets.

PRJ-20051,
PRHF-14165

SecureXL

Memory leak may occur in VPN or Active Streaming configuration.

PRJ-19407,
PMTR-60870

SecureXL

In some scenarios, Rate Limiting rules for DoS do not work after reboot. Refer to sk170148.

PRJ-20105,
MBS-11960

Routing

NEW: Added support for ISP Redundancy on Scalable Platforms Appliances.

PRJ-19536,
PMTR-62075

Routing

On Scalable Platforms, SSH via MAB may disconnect.

PRJ-19630,
PRHF-14280

Routing

ip-reachability-detection ping marks a target IP address as "unreachable" if the path goes via a VPN tunnel, although pinging this IP address directly works.

PRJ-20445,
ROUT-1325

Routing

The old route may be not removed when an BGP ECMP route was changed.

PRJ-20243,
PRHF-14562

Routing

In rare scenarios, confd or routed process may restart.

PRJ-19464,
PMTR-60878

Routing

Routed logs may incorrectly state that routemaps that export to OSPF cannot set the OSPF manual tag, even though the functionality works.

PRJ-18281,
PMTR-58528

Routing

Certain types of multicast traffic may not be handled correctly in Bridge mode.

PRJ-18665,
PRJ-18664

Routing

PBR does not work with VTI/VPN.

-

Gaia OS

NEW: Added support for 1570R and 1600 / 1800 SMB appliances.

PRJ-19532,
PRJ-19531

Gaia OS

NEW: Gaia API (version 1.5) will now be deployed via Jumbo Hotfix.

PRJ-20501,
PMTR-62883

Gaia OS

UPDATE: OpenSSL was updated to version 1.1.1i to include the latest code fixes and security improvements.

PRJ-20472,
PRHF-14653

Gaia OS

In some scenarios, the Security Gateway attempts to fetch the policy from / send logs to the real IP address of the Management Server (defined in the "General Properties" section of the server object) instead of the server's NAT IP address (defined in the "NAT" section of the server object).

Refer to sk171055 to configure the required parameter FORCE_NATTED_IP.

PRJ-19518,
PRA-1520

Gaia OS

The syslog messages may be spammed when the "show asset all" command is running.

PRJ-17720,
PRHF-13075

Gaia OS

In some scenarios, one session disconnection of RADIUS users can cause another session to loose permission when one of the session terminates.

PRJ-20944,
PMTR-63343

Gaia OS

Upgrade process may fail due to corrupted sic_local_cert.p12 certificate. Refer to sk171253.

PRJ-18721,
PMTR-60804

Gaia OS

Bond interface in XOR mode or 802.3AD (LACP) mode may experience suboptimal performance, if on the Bond interface the Transmit Hash Policy is configured to "Layer 3+4" and Multi-Queue is enabled.

PRJ-18773,
PMTR-61381

VPN

NEW: Added Remote Access VPN performance improvement.

PRJ-19717,
PMTR-60976,
VPNS2S-1335

VPN

NEW: Added VPN command line mechanism stability enhancement and VPN improvements in IKEv2.

VPNS2S-1482

VPN

NEW: Added new display of vpn tu tlist command for DAIP gateway.

PRJ-19248,
PMTR-62158

VPN

NEW: Added CPDIAG (on/off) for IKE negotiations per community feature.

PRJ-21123,
PRHF-10420

VPN

Access roles do not recognize Remote Access SNX CLI clients.

PRJ-19672,
PMTR-61913

VPN

In some scenarios, Remote Access Endpoint client disconnects after roaming from Visitor Mode to NAT-T.

PRJ-20869,
PMTR-56565

VPN

In some scenarios, the VPND process keeps re-downloading the same CRL, which can cause performance issues.

PRJ-20523,
PRHF-14766

VPN

In a rare scenario, the FWM process unexpectedly exits when enrolling a certificate using the SCEP protocol.

PRJ-20276,
PRHF-14308

VPN

In a rare scenario, a memory leak may occur when RASession_util is active.

PRJ-20949,
PMTR-63287

VPN

In some scenarios, L2TP clients disconnect from the Security gateway after 10 minutes of the connection.

PRJ-20640,
PMTR-63280

VPN

In some scenarios, the VPND process may unexpectedly exit.

PRJ-19425,
PRHF-13784

VPN

In some scenarios, the VPND process unexpectedly exits with Segmentation fault.

PRJ-20334,
PMTR-62776

VPN

Security gateway may crash when you install policy on a MAB gateway and a policy file is corrupted.

PRJ-20082,
PRHF-12828

VPN

Connectivity issue may appear between Check Point Gateway and 3rd party device in MEP DPD configuration when 3rd party device is defined as Central Gateway in MEP. Relevant error message: "Failed to resolve VPN MEP gateway".

PRJ-18504,
PMTR-60820

VSX

UPDATE: Added support for VSX SecureXL tabs on CPView. Refer to sk167903.

PRJ-20567

VSX

IPv6 traffic and multicast IPv4 may not work with Virtual Switch (VSW).

PRJ-20123,
PMTR-62387

VSX

In VSX environment, Generic Data Center objects are not enforced on the VSX members.

PRJ-20284,
PRHF-14543

VSX

In some scenarios, SNMP v3 users are not recognized on VSX when SNMP is in VS mode. The "Unknown user name" error message is displayed. Refer to sk170993.

PRJ-20597,
PRHF-14400

VoIP

VoIP RTP can cause overload on global instance (CoreXL instance 0).

PRJ-18979,
PRHF-12691

VoIP

SIP parser may cause the wrong RTP dynamic connection to be opened. Refer to sk169373.

PRJ-18971,
PRJ-17805

IoT

NEW: Added IoT support to Multi-Domain Security Management.

  • Requires R81 SmartConsole Build 549 (or higher).

PRJ-20905,
PMTR-59281

Endpoint Security

NEW: Added support for new Push Operations - Host Isolation and Host Release from isolation.

PRJ-20990,
PMTR-61783

Endpoint Security

NEW: Added support for new Push Operation - Remote Uninstall for Endpoint Client.

PRJ-20394

Endpoint Security

UPDATE: Updated Endpoint Web Docker Image.

PRJ-19400,
PRHF-14139

Endpoint Security

Attempt to move members from one group to another using Endpoint Server command line operations fails.

PRJ-20778,
PMTR-63041

Endpoint Security

The "Sent to Client On" column is empty in SmartEndpoint >Reporting > Push Operations even if push operation was completed successfully.

PRJ-19772

Endpoint Security

Database size may increase exponentially because dynamic packages are packed into exported .tgz using migrate_export.

PRJ-20639,
MBS-10278

Scalable Platforms

NEW: Added full support for Gaia Backup.

PRJ-20895,
MBS-12714

Scalable Platforms

On Maestro / Scalable Platforms, users may disconnect after several attempts due to bad forwarding in TCPT flow.

PRJ-20749,
MBS-12642

Maestro

Gaia scheduled backup fails to run and the /var/log/messages file contains the error "scheduled_backup: SGM isn't SMO, skipping scheduled backup". Refer to sk170925.

PRJ-20140,
PMTR-62718

Maestro

"Packet Capture was not found" error when clicking the "View Packet Capture" link in the IPS log.