R81 Jumbo Hotfix Take 13
List of Resolved Issues and New Features
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 13 Released on 08 February 2021 |
||
PRJ-19946, |
Security Management |
NEW: Added new Management HA utility to schedule automatic full syncs to peers that failed to be synchronized incrementally. |
PRJ-18434, |
Security Management |
NEW: The upgrade process is being monitored dynamically and will be stopped if it cannot be completed, not basing on a timeout. |
PRJ-19545, |
Security Management |
UPDATE: Added Update 6 of Autonomous Threat Prevention Management (ATPM). Refer to sk167109. |
PRJ-20165, |
Security Management |
UPDATE: Added Update 7 of Autonomous Threat Prevention Management (ATPM). Refer to sk167109. |
PRJ-19972, |
Security Management |
UPDATE: If a Management HA synchronization stalls (displaying "Peer is busy"), it will be released within 2 hours instead of 24 hours. |
PRJ-20032, |
Security Management |
UPDATE: When purging revisions, task notifications will also be purged if created before the last revision to purge was published. |
PRJ-20001, |
Security Management |
UPDATE: Added improvements in policy load process, to reduce the policy installation time when having large amount of objects. |
PRJ-22105, |
Security Management |
In some scenarios, the installation time of Jumbo Hotfix Take 11 on the Management Server may take up to several hours. |
PRJ-18253, |
Security Management |
When logging into SmartConsole directly to a Domain using RADIUS or TACACS, the Authentication method in the audit log may show as "Internal Password". Refer to sk168716. |
PRJ-17693, |
Security Management |
In some scenarios, HA temporary sub-directories in $FWDIR/tmp are not deleted if sync fails. Refer to sk170972. |
PRJ-18289, |
Security Management |
In rare scenarios, the CPU and memory usage of CPM process may be abnormally high. Refer to sk170672. |
PRJ-18266, |
Security Management |
'Revert to Revision' tasks cannot be cleared from tasks pane in SmartConsole. |
PRJ-19105, |
Security Management |
In some scenarios, Management HA change-over to Security Management Server Backup fails with the "Failed to communicate with the peer" message. |
PRJ-20564, |
Security Management |
In some scenarios, policy installation on LSM Gaia cluster profile fails with "Policy installation had failed due to an internal error" message. |
PRJ-17563, |
Security Management |
In some scenarios, reassigning a Global Policy may fail if the Global and local domains are not active on the same Multi-Domain Server. |
PRJ-17729, |
Security Management |
Upgrade may fail if a Data Center object was last modified by an Administrator with a single quote in the name. |
PRJ-19274, |
Security Management |
Policy installation duration may increase due to large $FWDIR/conf/invalid_object_names.C file on the Management server. Refer to sk170427. |
PRJ-18476, |
Security Management |
In some scenarios, the first environment variable configured using sk165938 is not loaded and not used by the CPM process. |
PRJ-19571, |
Security Management |
In rare scenarios, on a Multi-Domain Server where Domains are using a Security Management Server configured for High Availability, initial configuration of the Security Management Server may fail with "Failed to reach peer after restart" error. |
PRJ-20135, |
Security Management |
In a rare scenario, the FWM process unexpectedly exits. |
PRJ-19950, |
Security Management |
The Management HA window in SmartConsole may mistakenly show the "Peer is busy" warning message for a few seconds. |
PRJ-19589, |
Multi-Domain Management |
UPDATE: With this fix, mds_backup will backup the Upgrade Tools package(s) and mds_restore will restore them on a Multi-Domain Server. |
PRJ-19648, |
Multi-Domain Management |
In rare scenarios, a Domain is shown in the Domains view without any Domain Server or a Domain is shown with Domain Server that was deleted and does not exist anymore. Refer to sk170556. |
PRJ-19278, |
Multi-Domain Management |
In rare scenarios, Management server becomes inaccessible after Global Policy reassign operation. |
PRJ-18994, |
Multi-Domain Management |
The "cplic db_print -all -x" command fails when running on the MDS level. |
PRJ-19321, |
SmartConsole |
NEW: Added support for Python 3 in Management API scripts. |
PRJ-20248, |
SmartConsole |
UPDATE: A pop-up warning will be displayed every time a "Custom Application" object with a performance impacting URL is edited (instead of being displayed only once). |
PRJ-18466, |
SmartConsole |
In some scenarios, Staging mode IPS protections activation in the Local Domain does not match the activation in the Global Domain after a Global Threat Prevention policy assignment. Refer to sk170322. |
PRJ-18338, |
SmartConsole |
When using the "set simple-cluster" Management API command to update a user defined security zone, the "Specify security zone" checkbox in SmartConsole is not selected. |
PRJ-19323, |
SmartConsole |
In some scenarios, the api.csv file may show extra empty columns. |
PRJ-19203, |
SmartConsole |
In some scenarios, when using the "set simple-gateway" API command with "logs-settings.forward-logs-to-log-server", it fails with "Generic server error". Refer to sk170352. |
PRJ-19535, |
SmartConsole |
In some scenarios, when adding a new user certificate of type .p12 via API command, the returned certificate may be incorrect. |
PRJ-18960, |
SmartConsole |
In a VPN Community with MEP configuration, the OK operation may fail with the "Update operation failed" message. |
PRJ-20787, |
SmartConsole |
When the user creates an Access Role, the AD organization tree may show duplicate branches, and some branches may be missing. |
PRJ-20381, |
SmartConsole |
Adding Global dynamic objects to source or destination columns of access rules on the Global Domain via Management API may fail when using the Global dynamic object names. |
PRJ-20911, |
SmartConsole |
In some scenarios, deleting a policy fails. |
PRJ-18550, |
SmartConsole |
In a community with Cluster VSX member, the Granular encryption window may not open and show "Unable to load page". |
PRJ-18309, |
SmartProvisioning |
NEW: Added support for Threat Emulation Blade on LSM profile of R81 SMB gateways and clusters.
|
PRJ-18000, |
Logging |
NEW:
|
PRJ-19451 |
Logging |
UPDATE: Log Exporter read mode default was changed to Semi-unified instead of Raw mode. |
PRJ-18099, |
Logging |
In rare scenarios, a log may display incorrect values in the Action and Rule field. Refer to sk170676. |
PRJ-21078 |
Logging |
In rare scenarios, the FWD process on the Security gateway may be blocked for several seconds due to processing of log attachments. |
PRJ-18405, |
Logging |
The FWM and\or LOG_INDEXER processes may repeatedly stop when there are more than ~500K network objects declared. Refer to sk164452. |
PRJ-19819, |
Logging |
In rare scenarios, the LOG_INDEXER process may unexpectedly exit when reading a specific log format. Refer to sk116117. |
PRJ-19846, |
SmartView |
UPDATE: Improved the time resolutions usability (formally known as samples) of the Timeline widgets. |
PRJ-20875, |
SmartView |
UPDATE: To improve performance, SmartView now exports data in CSV format instead of Excel. |
PRJ-20795, |
Security Gateway |
UPDATE: Service with source port in the Access Rulebase will no longer disable accept templates for all connections. |
PRJ-19066, |
Security Gateway |
In rare scenarios, Security Gateway memory consumption may increase. |
PRJ-18982, |
Security Gateway |
In rare scenarios, Security Gateway may crash with USFW fwk core file. |
PRJ-19802, |
Security Gateway |
Connectivity issues may appear due to missing proxy ARP entries on the Security Gateway. |
PRJ-19813, |
Security Gateway |
In some scenarios, duplicate verification message is displayed when installing NAT policy on Security Gateways R80.40 and lower. |
PRJ-20362, |
Security Gateway |
In some scenarios, DHCP traffic may be dropped after installing an accelerated policy. |
PRJ-19705, |
Security Gateway |
In rare scenarios, a memory leak may occur in TOPOD process. |
PRJ-20386, |
Security Gateway |
In a rare scenario, Access Control policy installation may fail after upgrade of Security Gateway from R80.10 or below to R80.20 or higher. |
PRJ-20633, |
Security Gateway |
In rare scenarios, high memory consumption in CPD may occur due to a memory leak in authentication flow with an LDAP server. |
PRJ-19586, |
Security Gateway |
In some scenarios, "email_unified_cmi_get_attribs: not valid caller: up_log_get_user_hash" error appears in dmesg for SMTP traffic. |
PRJ-20516, |
Security Gateway |
In some scenarios, when using routing separation, connection to Management Plane via Data Plane is dropped. |
PRJ-19852, |
Security Gateway |
In some scenarios, a memory leak may occur after sending a packet from the kernel. |
PRJ-20937, |
Security Gateway |
In a rare scenario, policy installation may fail on timeout and "fw amw fetch" process is still running on the Security gateway. |
PRJ-18488, |
Security Gateway |
In some scenarios, repeating "fwx_alloc_global_find_free_port_atomic: rtsp pending port doesn't match the same pool" errors are displayed in dmesg when using Hide NAT with VoIP. |
PRJ-20656, |
Security Gateway |
Accept logs with reason "Connection terminated before detection: Insufficient data passed. To learn more see sk113479." may be wrongly generated when the matched action is user authentication and wrong username/password provided by user. |
PRJ-20901, |
Security Gateway |
In some scenarios, the DNS requests from the Security gateway may fail. |
PRJ-18631, |
Security Gateway |
Wrong memory (hmem) values may be reported by specific SNMP OID. Refer to sk168992. |
PRJ-19958, |
Security Gateway |
Half-closed accelerated TCP connections may take too long time to expire. |
PRJ-19942, |
Security Gateway |
In some scenarios, policy installation fails with "Error code 1-2000245". |
PRJ-18316, |
Security Gateway |
In rare scenarios, a memory leak may occur on Security Gateway in gconn table. |
PRJ-19162, |
Threat Extraction |
UPDATE: Threat Extraction will no longer attempt to perform "Convert to PDF" if the file is corrupted, because the resulting files in these cases are usually unreadable. |
PRJ-19194, |
Threat Extraction |
UPDATE: Threat Extraction ( Sanitization) will be automatically disabled when Infinity Threat Prevention mode is installed while the machine does not have enough resources (RAM). |
PRJ-18248, |
Identity Awareness |
NEW: Added Identity Sharing's performance and functionality improvements. Refer to sk170516. |
PRJ-19640, |
Identity Awareness |
In some scenarios, when a standby cluster member receives RADIUS accounting updates, there may be high CPU on the PDP process. |
PRJ-20863, |
Identity Awareness |
In some scenarios, there may be enforcement issues for MUHv2 users due to table mismatch. |
PRJ-18181, |
URL Filtering |
In some scenarios, the WSTLSD process may unexpectedly exit and produce a core dump. |
PRJ-19042, |
UserCheck |
In some scenarios, users cannot restore original attachment via UserCheck portal and receive the "An unexpected error has occurred" error message. |
PRJ-20927, |
IPS |
NEW: Added ability to send connection log per application match for ATM transactions identification. The functionality is disabled by default and can be enabled by using the "up_duplicate_connection_log_on_packet_matched_app_enabled" kernel parameter. |
PRJ-19198, |
IPS |
In some scenarios, a non-compliant IMAP traffic is dropped. |
PRJ-19301, |
IPS |
In some scenarios, log output shows the Origin/Source as "0.0.0.0" in VSX 3rd party IPS logs. |
PRJ-19601, |
DLP |
UPDATE: Improved the DLP scans queue for a better scan rate. |
PRJ-19923, |
DLP |
UPDATE: Expanded DLP postfix authentication to include NTLM to allow the Security gateway to connect to a mail servers that use the NTLM authentication protocol. |
PRJ-20097, |
DLP |
UPDATE: Added support for multi-part data to DLP. |
PRJ-20935, |
SSL Inspection |
The AES-NI (Intel Advanced Encryption Standard New Instructions) status is not displayed and "dmesg | grep AES-NI" returns no output. Refer to sk170779. |
PRJ-19435, |
SSL Inspection |
In rare scenarios, the DynamicID Certificate validation may fail. |
PRJ-18843, |
SSL Inspection |
In rare scenarios, a memory leak may occur during policy installation. |
PRJ-21629, |
SSL Inspection |
When IPv6 is enabled, the wstlsd process may consume CPU at a high level after booting in kernel mode causing HTTPS connections to fail for a few minutes until the CPU returns to normal. |
PRJ-17875, |
HTTPS Inspection |
UPDATE: "Categorize HTTPS websites" feature enhancements when "Categorize HTTPS Sites" feature is enabled:
For configuration, refer to sk173633. |
PRJ-19196 |
Threat Prevention |
NEW: Improved the way Threat Prevention distinguishes between .docx, .pptx, .xlsx and .zip files. |
PRJ-18119, |
Anti-Malware |
Exported with ioc_feeds export command indicator feeds may contain user credentials. Refer to sk169035. |
PRJ-19591, |
Anti-Malware |
In rare scenarios, after downloading files, Anti-Virus prevent logs appear with "Strict hold is not possible failure - Write to other side occurred" error message. |
PRJ-17439, |
Anti-Malware |
In some scenarios, users may fail to access a web site with many malicious URLs. |
PRJ-20924, |
Anti-Malware |
In a rare scenario, Security gateway may crash when the Threat Prevention Forensics feature is enabled. |
PRJ-18198, |
Anti-Malware |
In some scenarios, multiple files called "ckp_mutex" are created on the Security Gateway. |
PRJ-19745, |
Anti-Bot |
Dynamic Global Network Object usage inside a Network Group object may cause an Access Policy installation failure. |
PRJ-19205, |
ClusterXL |
UPDATE: Added the option to display only monitored interfaces to "show cluster members <option>" command:
|
PRJ-19926, |
ClusterXL |
In rare scenarios, running cphastop;cphastart may cause a cluster member to stay in "Down" state. |
PRJ-19393, |
ClusterXL |
"set router active-active-mode" settings do not survive a reboot. |
PRJ-20536, |
ClusterXL |
In some scenarios, data connections are dropped with "First packet isn't SYN" message on ClusterXL Load Sharing. |
PRJ-16568, |
SecureXL |
NEW: Added the ability to enable monitor-only mode for penalty box independently of other DOS/Rate limiting features. |
PRJ-18324, |
SecureXL |
UPDATE: Drop templates can be generated for connections with matched action Reject. For additional information and configuration, refer to sk171146. |
PRJ-20056, |
SecureXL |
In rare scenarios, SecureXL may crash due to NULL handling. |
PRJ-18088, |
SecureXL |
SNMP may show wrong values for the number of bytes and packets accepted by Security gateway. Refer to sk170132. |
PRJ-20028, |
SecureXL |
Server may not reuse the TCP connection when the user allows out of state TCP packets. |
PRJ-20051, |
SecureXL |
Memory leak may occur in VPN or Active Streaming configuration. |
PRJ-19407, |
SecureXL |
In some scenarios, Rate Limiting rules for DoS do not work after reboot. Refer to sk170148. |
PRJ-20105, |
Routing |
NEW: Added support for ISP Redundancy on Scalable Platforms Appliances. |
PRJ-19536, |
Routing |
On Scalable Platforms, SSH via MAB may disconnect. |
PRJ-19630, |
Routing |
ip-reachability-detection ping marks a target IP address as "unreachable" if the path goes via a VPN tunnel, although pinging this IP address directly works. |
PRJ-20445, |
Routing |
The old route may be not removed when an BGP ECMP route was changed. |
PRJ-20243, |
Routing |
In rare scenarios, confd or routed process may restart. |
PRJ-19464, |
Routing |
Routed logs may incorrectly state that routemaps that export to OSPF cannot set the OSPF manual tag, even though the functionality works. |
PRJ-18281, |
Routing |
Certain types of multicast traffic may not be handled correctly in Bridge mode. |
PRJ-18665, |
Routing |
PBR does not work with VTI/VPN. |
- |
Gaia OS |
NEW: Added support for 1570R and 1600 / 1800 SMB appliances. |
PRJ-19532, |
Gaia OS |
NEW: Gaia API (version 1.5) will now be deployed via Jumbo Hotfix. |
PRJ-20501, |
Gaia OS |
UPDATE: OpenSSL was updated to version 1.1.1i to include the latest code fixes and security improvements. |
PRJ-20472, |
Gaia OS |
In some scenarios, the Security Gateway attempts to fetch the policy from / send logs to the real IP address of the Management Server (defined in the "General Properties" section of the server object) instead of the server's NAT IP address (defined in the "NAT" section of the server object). Refer to sk171055 to configure the required parameter FORCE_NATTED_IP. |
PRJ-19518, |
Gaia OS |
The syslog messages may be spammed when the "show asset all" command is running. |
PRJ-17720, |
Gaia OS |
In some scenarios, one session disconnection of RADIUS users can cause another session to loose permission when one of the session terminates. |
PRJ-20944, |
Gaia OS |
Upgrade process may fail due to corrupted sic_local_cert.p12 certificate. Refer to sk171253. |
PRJ-18721, |
Gaia OS |
Bond interface in XOR mode or 802.3AD (LACP) mode may experience suboptimal performance, if on the Bond interface the Transmit Hash Policy is configured to "Layer 3+4" and Multi-Queue is enabled. |
PRJ-18773, |
VPN |
NEW: Added Remote Access VPN performance improvement. |
PRJ-19717, |
VPN |
NEW: Added VPN command line mechanism stability enhancement and VPN improvements in IKEv2. |
VPNS2S-1482 |
VPN |
NEW: Added new display of vpn tu tlist command for DAIP gateway. |
PRJ-19248, |
VPN |
NEW: Added CPDIAG (on/off) for IKE negotiations per community feature. |
PRJ-21123, |
VPN |
Access roles do not recognize Remote Access SNX CLI clients. |
PRJ-19672, |
VPN |
In some scenarios, Remote Access Endpoint client disconnects after roaming from Visitor Mode to NAT-T. |
PRJ-20869, |
VPN |
In some scenarios, the VPND process keeps re-downloading the same CRL, which can cause performance issues. |
PRJ-20523, |
VPN |
In a rare scenario, the FWM process unexpectedly exits when enrolling a certificate using the SCEP protocol. |
PRJ-20276, |
VPN |
In a rare scenario, a memory leak may occur when RASession_util is active. |
PRJ-20949, |
VPN |
In some scenarios, L2TP clients disconnect from the Security gateway after 10 minutes of the connection. |
PRJ-20640, |
VPN |
In some scenarios, the VPND process may unexpectedly exit. |
PRJ-19425, |
VPN |
In some scenarios, the VPND process unexpectedly exits with Segmentation fault. |
PRJ-20334, |
VPN |
Security gateway may crash when you install policy on a MAB gateway and a policy file is corrupted. |
PRJ-20082, |
VPN |
Connectivity issue may appear between Check Point Gateway and 3rd party device in MEP DPD configuration when 3rd party device is defined as Central Gateway in MEP. Relevant error message: "Failed to resolve VPN MEP gateway". |
PRJ-18504, |
VSX |
UPDATE: Added support for VSX SecureXL tabs on CPView. Refer to sk167903. |
PRJ-20567 |
VSX |
IPv6 traffic and multicast IPv4 may not work with Virtual Switch (VSW). |
PRJ-20123, |
VSX |
In VSX environment, Generic Data Center objects are not enforced on the VSX members. |
PRJ-20284, |
VSX |
In some scenarios, SNMP v3 users are not recognized on VSX when SNMP is in VS mode. The "Unknown user name" error message is displayed. Refer to sk170993. |
PRJ-20597, |
VoIP |
VoIP RTP can cause overload on global instance (CoreXL instance 0). |
PRJ-18979, |
VoIP |
SIP parser may cause the wrong RTP dynamic connection to be opened. Refer to sk169373. |
PRJ-18971, |
IoT |
NEW: Added IoT support to Multi-Domain Security Management.
|
PRJ-20905, |
Endpoint Security |
NEW: Added support for new Push Operations - Host Isolation and Host Release from isolation. |
PRJ-20990, |
Endpoint Security |
NEW: Added support for new Push Operation - Remote Uninstall for Endpoint Client. |
PRJ-20394 |
Endpoint Security |
UPDATE: Updated Endpoint Web Docker Image. |
PRJ-19400, |
Endpoint Security |
Attempt to move members from one group to another using Endpoint Server command line operations fails. |
PRJ-20778, |
Endpoint Security |
The "Sent to Client On" column is empty in SmartEndpoint >Reporting > Push Operations even if push operation was completed successfully. |
PRJ-19772 |
Endpoint Security |
Database size may increase exponentially because dynamic packages are packed into exported .tgz using migrate_export. |
PRJ-20639, |
Scalable Platforms |
NEW: Added full support for Gaia Backup. |
PRJ-20895, |
Scalable Platforms |
On Maestro / Scalable Platforms, users may disconnect after several attempts due to bad forwarding in TCPT flow. |
PRJ-20749, |
Maestro |
Gaia scheduled backup fails to run and the /var/log/messages file contains the error "scheduled_backup: SGM isn't SMO, skipping scheduled backup". Refer to sk170925. |
PRJ-20140, |
Maestro |
"Packet Capture was not found" error when clicking the "View Packet Capture" link in the IPS log. |