R81 Jumbo Hotfix Take 51
List of Resolved Issues and New Features
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 51 Released on 29 December 2021 |
||
PRJ-27433, |
Security Management |
NEW: Added support for CloudGuard Edge appliances in LSM and SmartConsole.
|
PRJ-31537, |
Security Management |
UPDATE: The Management API "show-logs" command timeout increased from 2.5 minutes to 5 minutes. |
PRJ-29237, |
Security Management |
UPDATE: Added a new flag to the Threat Prevention "show-protections" API command ("show-capture-packets-and-track") that allows not to return capture-packets and track information. |
PRJ-30365, |
Security Management |
UPDATE: Added new flags for Management API commands "add/set simple-gateway" and "add/set simple-cluster":
|
PRJ-27424, |
Security Management |
UPDATE: The "show application-sites" Management API command now returns additional fields for UIDs of primary category and additional categories. |
PRJ-31057, |
Security Management |
In rare scenarios, Security Management upgrade or migration may fail due to missing temporary files. |
PRJ-29188, |
Security Management |
In a rare scenario, High Availability full synchronization may fail due to a large number of records. |
PRJ-29305, |
Security Management |
In environments with a large number of objects, licenses for cluster members in the Licenses tab may not be displayed. |
PRJ-28901, |
Security Management |
When searching IP addresses using logical operators (AND / OR), the results may be incorrect:
Some matched objects may be missing, while some unmatched objects may be present. |
PRJ-28649, |
Security Management |
In some scenarios, when using a VPN community, the status of the Global Domain Assignment may change to "not up to date", although no changes were made in the Global Domain. |
PRJ-28536, |
Security Management |
In rare scenarios, Global Policy Assignment may fail with the "class name not found for object" error. |
PRJ-27921, |
Security Management |
In rare scenarios, more than one IP address may be shown in SmartConsole's Sessions view under the "Connected From" column. |
PRJ-28896, |
Security Management |
If there are no explicit rules in one or more policy layers, policy verification may fail with the "No active rules found in the Security Policy" error. |
PRJ-28001, |
Security Management |
If Brute Force Password Guessing Protection is set to the value of more than 25 seconds, login to SmartConsole fails.
|
PRJ-20287, |
Security Management |
In rare scenarios, the second attempt of a Secondary Management Server upgrade may fail with "Task was interrupted because server restart". |
PRJ-26522, |
Security Management |
In a rare scenario, policy installation may fail with a "Policy installation had failed due to an internal error" message. |
PRJ-24634, |
Security Management |
In rare scenarios, policy installation may fail with an internal error due to missing permissions. Refer to sk17384. |
PRJ-26522, |
Security Management |
In a rare scenario, policy installation may fail with a message: "Policy installation had failed due to an internal error". |
PRJ-25629, |
Security Management |
In rare scenarios, a Management Server upgrade may fail with an "Object not found - [UID]" error message in the cpm.elg log file. |
PRJ-25566, |
Security Management |
In rare scenarios, an upgrade may fail when there is an OPSEC Server object configured. |
PRJ-23433, |
Security Management |
Upgrade to R81 may fail if one of the objects does not have a creator. |
PRJ-28785, |
Security Management |
In some scenarios, "show-mdss" and "show-domains" Management API commands take a significant amount of time to complete or time out after 5 minutes. |
PRJ-28570, |
Security Management |
In some scenarios, the Purge Revisions operation fails with the "An error has occurred while performing revisions purge operation, Incident ID - xxxxx-xxxxxxx-xxxxx-xxxxx" error message. Refer to sk174645. |
PRJ-28423, |
Security Management |
Virtual session timeout for a TCP service cannot exceed 86400 seconds. Refer to sk168872. |
PRJ-28293, |
Security Management |
In rare scenarios, High Availability incremental synchronization may fail with a wrong status message. |
PRJ-28299, |
Security Management |
In rare scenarios, High Availability on the Global Domain may fail to synchronize the Multi-Domain Log Server if IPS protection was added or removed in the Threat Prevention rulebase. |
PRJ-28064, |
Security Management |
In rare scenarios:
|
PRJ-28088, |
Security Management |
In some scenarios, the Administrators view may not filter Domain names according to the permission profile of the connected administrator. |
PRJ-13161, |
Security Management |
The "show-global-assignment" command returns the default limit when the limit request is greater than the default limit. |
PRJ-26736, |
Security Management |
In a rare scenario, the "show hosts" Management API command with "details-level full" fails with a "Java.util.InputMismatchException: got at least one duplicate UID in requested list, duplicates UIDs:" message. |
PRJ-26677, |
Security Management |
The "show gateways and servers" Management API command does not show policy information for cluster members. |
PRJ-27486, |
Security Management |
Global Policy reassignment may fail with "An internal error has occurred" due to duplicated Access Policy Assignment object. Refer to sk174183. |
PRJ-27480, |
Security Management |
If there is an Administrator is named "Endpoint", an upgrade of Endpoint Security Server from R77.30 fails. |
PRJ-21788, |
Security Management |
In some scenarios, the output of the "cpmistat" command may contain partial information. |
PRJ-29898, |
Security Management |
In some scenarios, login to a Domain from the System Domain dashboard may fail with "Failed to connect to server". |
PRJ-28157, |
Security Management |
In rare scenarios, if Domain migration fails, the operation may not revert fully and leave some remnants in the database of the Management Server. |
PRJ-29517, |
Security Management |
In rare scenarios, when installing a policy immediately after publishing a session, the installation is not accelerated. |
PRJ-29158, |
Security Management |
Scheduled IPS updates data may not be shown in the IPS update report. |
PRJ-30048, |
Security Management |
The Management API command "show-sessions" may return sessions that were purged and no longer exist in the Management database. |
PRJ-29968, |
Security Management |
In some scenarios, simultaneous policy installation on multiple Gateways may fail if there is at least one Gateway on R77.X and one Gateway on R80.X. |
PRJ-25197, |
Security Management |
The "Packet capture is not supported on this platform" warning appears after policy installation on SMB Gateways, although no packet capture is used. |
PRJ-30622, |
Security Management |
In rare scenarios, after the Security Management Server starts up, when connecting to SmartConsole, some objects appear more than once. |
PRJ-30054, |
Security Management |
In rare scenarios, the FWM process unexpectedly exits and fails to start, creating core dumps in the /var/log/dump/usermode directory. Refer to sk175007. |
PRJ-29469, |
Security Management |
In some scenarios, an API query to VRRP cluster for "show simple-cluster name <name>" returns an incorrect cluster type. Refer to sk174866. |
PRJ-21877, |
Security Management |
In some scenarios, applying the "Where used" action may show incorrect data when an object exists more than once in an Inline Layer. |
PRJ-21831, |
Multi-Domain Management |
In rare scenarios, after an upgrade, the CPD process in a Multi-Domain environment may unexpectedly exit, creating a core dump file. |
PRJ-23852, |
Security Management |
Management Server upgrade may fail, if there is a large amount of customized column profiles in the Logs view. |
PRJ-30019, |
Security Management |
In rare scenarios, the "set-group" API command may return the "generic_err_invalid_parameter" error. |
PRJ-27764, |
Security Management |
The Management API commands "import-smart-task" and "export-smart-task" are enabled at the System Domain level, although Smart Tasks are only supported at the Local Domain level. |
PRJ-29199, |
Security Management |
After an upgrade from R77.x. in a multi-site environment, High Availability full synchronization may fail with an "NGM failed to load data" message. |
PRJ-25280, |
Security Management |
In rare scenarios, login to Multi-Domain Management fails with the "No Valid Domains were found for [username]" error. Refer to sk175005. |
PRJ-28816, |
Security Management |
In some scenarios, the "show gateways-and-servers" Management API command fails with "generic_error" when running it with "details-level full". |
PRJ-21778, |
Licensing |
In some scenarios, the total number of "sr" licenses may be counted incorrectly. |
PRJ-27346, |
Licensing |
In a rare scenario, the licensing status in SmartConsole is displayed incorrectly. |
PRJ-29804 |
Web SmartConsole |
Added enhancements for Task Manager and policy installation. Refer to Take 48 in sk170314. |
PRJ-30384, |
CPInfo |
UPDATE: Added CPInfo build 914000219. Refer to sk92739. |
PRJ-20498, |
CPUSE |
The "Recommended" Package value is not changed from true to false in SmartConsole while installing Jumbo Hotfix. Refer to sk174508. |
PRJ-22893, |
CPView |
In some scenarios, SNMP statistics per VS may not be displayed in CPView. |
PRJ-29825, |
SmartView |
UPDATE: In SmartView, new MITRE ATT&CK techniques were added to the heatmap view. |
PRJ-22159, |
Logging |
NEW:
|
PRJ-26809, |
Logging |
NEW: In SmartEvent GUI, added the "referrer" field for filtering correlation unit events. |
PRJ-25888, |
Logging |
UPDATE: During Management and Log Servers upgrade from R80.X to R81, indexes, stored in external storage (sk66003), can now be upgraded as part of the flow. |
PRJ-25897, |
Logging |
UPDATE: Improved the time of search that require scanning logs for several days. |
PRJ-29117, |
Logging |
In some scenarios, emails of DLP Blade may be sent with obfuscated information, with no option to present the full data. Refer to sk106430. |
PRJ-29221, |
Logging |
In a rare scenario, Application Control events may not be displayed in SmartEvent. |
PRJ-24979, |
Logging |
When AES authentication is configured, the "thresold_config" command does not send traps for SNMP v.3. Refer to sk173045. |
PRJ-23868, |
Logging |
In SmartView reports, the "Show only icon" option for table widgets does not work as expected. |
PRJ-26695, |
Logging |
When adding the "UC Block" action, log queries may not show UserCheck logs. Refer to sk174543. |
PRJ-25833, |
Logging |
The LOG_INDEXER process on the SmartEvent Server may consume a high CPU when the Mobile Access Blade is enabled on the Security Gateway. |
PRJ-25974, |
Logging |
In a rare scenario, logs that are created exactly at midnight, are shown in the SmartConsole Logs view tab but not shown in SmartView web. |
PRJ-24524, |
Logging |
In a low log rate, there may be a delay in exporting logs using the Log Exporter. |
PRJ-26116, |
Logging |
In a multi-site MDM environment, Log queries may fail to retrieve results from a CMA or CLM, if there is another CMA or CLM with the same sic_name. |
PRJ-22346, |
Logging |
In SmartView, the "Duration" field is missing from Reports and Views. |
PRJ-28301, |
Logging |
When using the LEEF format in the Log Exporter tool, product names miss the last letter. |
PRJ-26726, |
Logging |
In some scenarios, the FWD process on Security Gateway may cause high memory consumption when Log Forwarding is configured or when running the "fw fetchlogs" command. |
PRJ-27619, |
Logging |
The CPSEMD process on SmartEvent Server may unexpectedly exit when trying to send two automatic reactions simultaneously for the same event. |
PRJ-27050, |
Logging |
In rare scenarios, Management object changes may not be reflected in the Logs view. When the issue occurs, the CPM process may also consume a high CPU. |
PRJ-21313, |
Logging |
|
PRJ-28341, |
Logging |
In some scenarios, Log Exporter configured to export in TLS, cannot authenticate a certificate from an external certificate authority. |
PRJ-25442, |
Logging |
On a Management Server, with SmartEvent enabled and many Networks configured in the database, login to SmartConsole may fail with an "Error: the operation timeout" message, and the FWM process is running with a high CPU. Refer to sk167239. |
PRJ-29030, |
Logging |
In rare scenarios, SmartEvent may show no results or partial results in the Audit Log report. |
PRJ-25623, |
Logging |
In environments with more than 500K network objects, the LOG_INDEXER process on SmartEvent and Correlation Unit Server may unexpectedly close with the "Out of memory" error and a dump core file, although limited resolving is enabled (according to sk164452). |
PRJ-23681, |
Logging |
In rare scenarios, in environments with many network objects, when typing a query in the Logs tab Search bar, SmartConsole may close unexpectedly. |
PRJ-30228 |
Logging |
When traffic is dropped due to a Threat Prevention rule, fetching a packet capture from a security Blade violation log may not work. |
PRJ-31210, |
Logging |
In a rare scenario, logs export from SmartView web view to CSV may fail. Refer to sk175545. |
PRJ-29576, |
Security Gateway |
NEW: Added a new kernel parameter "up_disable_early_drop_optimization_for_reject" to disable "Early Drop Optimization" for reject rules. The parameter is enabled by default. |
PRJ-28853, |
Security Gateway |
UPDATE: Added DNS Passive Learning support for DNS responses containing the Domain name in uppercase letters. |
PRJ-29443, |
Security Gateway |
UPDATE: The default value for the kiss_kthread_allow_resched kernel parameter is changed to 1. Refer to sk170560. |
PRJ-32157, |
Security Gateway |
UPDATE: Apache HTTPD version was updated from 2.4.41 to 2.4.51. |
PRJ-30982, |
Security Gateway |
UPDATE: Added L3 routing support for bridge interface assigned with IP address. To enable it, set _fw_bridge_with_ip_routing=1_ in the _$FWDIR/fwkern.conf_ file. Refer to sk165560. |
PRJ-29505, |
Security Gateway |
In some scenarios, using automatic Network Static NAT/Address range objects may cause connectivity issues. |
PRJ-29088, |
Security Gateway |
In some scenarios, the CPD process may consume high CPU because of the memory leak in File Download Tool (FDT). |
PRJ-28830, |
Security Gateway |
Improved the ICAP Server internal memory allocation logic. |
PRJ-26036, |
Security Gateway |
A "fw_xlate_rule_count_dec: refcount is negative" message may be displayed in dmesg when IP pool NAT is used on a cluster environment. |
PRJ-19771, |
Security Gateway |
Security Gateway may crash after policy installation. |
PRJ-24692, |
Security Gateway |
In rare scenarios, creating a new SAM rule on a Management machine may fail. |
PRJ-25294, |
Security Gateway |
In rare scenarios, a re-matched connection has 2 logs in SmartConsole. |
PRJ-26077, |
Security Gateway |
After policy installation, Security Gateway may stop responding due to memory leaks. |
PRJ-26393, |
Security Gateway |
In some scenarios, the WSDNSD process may unexpectedly exit and create a core file. Refer to sk173627. |
PRJ-28810, |
Security Gateway |
Added cosmetic fixes of the "cpwd_admin list" command output. |
PRJ-27560, |
Security Gateway |
In some scenarios, configuring an un-numbered virtual interface may cause ARP requests to stay not answered by the interface. Refer to sk174188. |
PRJ-28104, |
Security Gateway |
In a rare scenario, a memory leak may occur on the Security Gateway. |
PRJ-27872, |
Security Gateway |
After a reboot or policy installation, the Cluster Under Load(CUL) messages in the fwk.ekg show CPU usage higher than 100%. |
PRJ-26824, |
Security Gateway |
In rare scenarios, a duplicate entry may appear in the /etc/cpshell/log_rotation.conf file. This issue is only cosmetic. |
PRJ-27077, |
Security Gateway |
In rare scenarios, using IP Pool NAT with only IPv4/IPv6 addresses configured may cause Security Gateway to crash. |
PRJ-27127, |
Security Gateway |
In some scenarios, the ROUTED process may unexpectedly exit. |
PRJ-28873, |
Security Gateway |
In a rare scenario, when using ICAP client, Security Gateway may crash. |
PRJ-26931, |
Security Gateway |
SNMP lowDiskSpace trap with MDPS does not work with SNMP versions v1/v2 . Refer to sk173811. |
PRJ-26584, |
Security Gateway |
In a rare scenario, CPView may show incorrect SecureXL statistics per VS. |
PRJ-27651, |
Security Gateway |
Negative values may appear in the output of the "fw tab -t connections -s" command and under the NAT section. |
PRJ-29130, |
Security Gateway |
In rare scenarios, policy installation may fail with an "Operation failed, install/uninstall has been improperly terminated" message. |
PRJ-30215, |
Security Gateway |
In some scenarios, policy installation may take longer or fail when GEO Updatable Objects are used in the policy. |
PRJ-30204, |
Security Gateway |
In some scenarios, NATed VPN traffic may be routed out through the wrong interface. Refer to sk176785. |
PRJ-29743, |
Security Gateway |
In a rare scenario, due to TCP connection reuse, a TCP connection may not be initiated Refer to sk11088. |
PRJ-29543, |
Security Gateway |
There is no option to enable hyperthreading via cpconfig. |
PRJ-29527, |
Security Gateway |
In a very rare scenario, the ICAP Server may crash with a core dump file generated. |
PRJ-29420, |
Security Gateway |
In a rare scenario, policy installation on the Security Gateway may fail with an "Error code: 0-2000108" message. Refer to sk170673. |
PRJ-29139, |
Security Gateway |
The cpsicdemux process may unexpectedly exit, causing the Secure Internal Communication (SIC) connection to fail. |
PRJ-28554, |
Security Gateway |
Capsule Workspace end users may fail to authenticate to their Exchange Mail Server via Mobile Access SSO when authenticated with Kerberos, and the end users belong to many user groups or user groups with very long names. |
PRJ-29588, |
Security Gateway |
In a rare scenario, Security Gateway may crash. |
PRJ-26671, |
Security Gateway |
In a rare scenario, traffic outage may occur. It is caused by a memory leak related to delayed logs. |
PRJ-30251, |
Security Gateway |
Added a translation of the error exit code of cprid_util in $CPDIR/log/cprid_util.elg debug log. |
PRJ-31370, |
Security Gateway |
Improved the handling of a large number of sessions per single HTTP/S connection. |
PRJ-31031, |
Security Gateway |
In a rare scenario, the Security Gateway may crash when disabling or enabling Threat Prevention Blade. |
PRJ-28680, |
Threat Prevention |
UPDATE: Added the option to remove proxy usage in ioc_feeds tool. |
PRJ-28520, |
Threat Prevention |
In rare scenarios, the Security Gateway may crash when the TCP connection is unexpectedly closed. |
PRJ-26543, |
Threat Prevention |
In some scenarios, the IPS update status in SmartConsole is incorrect after the automatic update fails with the "Update failed. Failed to load database" error. |
PRJ-26007, |
Threat Prevention |
SSH Deep Packet Inspection (SSH DPI) may fail after upgrade to R81. |
PRJ-25778, |
Threat Prevention |
In a rare scenario, the FWD process may unexpectedly exit after an upgrade. |
PRJ-28607, |
Threat Prevention |
Large file transfer in connections inspected by SSH Deep Packet Inspection (SSH DPI) may fail if SSH renegotiation is performed during the transfer. |
PRJ-28764, |
Threat Prevention |
In some scenarios, when using OpenSSH 8.2 Server, file download fails after starting the transfer. |
PRJ-28939, |
Threat Prevention |
Improved telemetry for Infinity Vision SOC. |
PRJ-29616, |
Threat Prevention |
After an upgrade from R80.30, if Custom Intelligence Feeds (IoC) feature is enabled, Threat Prevention policy on VSX cluster may fail with "failed to handle indicators". |
PRJ-29926, |
Threat Prevention |
Threat Prevention policy installation may fail when loading 2 IoC feeds that contain the same signature name for one of the observables. |
PRJ-28135, |
Threat Extraction |
In some scenarios, the "fw_send_kmsg: No buffer for tsid 44" error is printed in dmesg. |
PRJ-29488, |
Identity Awareness |
UPDATE:
|
PRJ-32355, |
Identity Awareness |
UPDATE: The default threshold value for Identity Collector Service Accounts exclusion was changed from 10 to 100. Refer to sk174266. |
PRJ-29397, |
Identity Awareness |
Improved the Identity Server (PDP) performance for publishing new network on Identity Sharing with SmartPull. |
PRJ-27476, |
Identity Awareness |
When using sk167118, the user may fail to authenticate if the "Ask user for password" checkbox is enabled. |
PRJ-26804, |
Identity Awareness |
In a rare scenario, the Security Gateway may crash. |
PRJ-27943, |
Identity Awareness |
In some scenarios, users may not be able to reach Identity Gateway (PEP). Refer to sk174105. |
PRJ-29614, |
Identity Awareness |
In a rare scenario, some IPv6 sessions may get deleted due to an incorrect update of Identity Gateway (PEP) kernel tables. |
PRJ-27193, |
Application Control |
UPDATE: Improved matching of URLs for custom applications. |
PRJ-27260, |
IPS |
Proxy source IP address is not printed in the IPS logs. |
PRJ-27959, |
IPS |
In some scenarios for HTTP, Gateway closes a connection from the Server side, but the user side may remain open. |
PRJ-26463, |
IPS |
An HTTP download of a large file may unexpectedly stop with an error message. |
PRJ-28245, |
IPS |
In some scenarios, HTTP Parser in the CPView statistics may show incorrect values for connections with more than 50 sessions. |
PRJ-29941, |
IPS |
In rare scenarios, if IPS Geolocation is enabled, the Security Gateway may crash. |
PRJ-32499, |
IPS |
In some scenarios, when IPS Automatic update is enabled, a memory leak may occur in the FWD process. |
PRJ-31694, |
IPS |
Improved the handling of decoded HTTP/S traffic. |
PRJ-29192, |
Anti-Bot |
UPDATE: Improved performance of Anti-Bot URL Reputation. |
PRJ-29476, |
SSL Inspection |
In some scenarios, a memory leak may occur when creating ECDHE keys. |
PRJ-30460, |
SSL Inspection |
In rare scenarios, HTTPS connections may hang indefinitely during the TLS handshake, causing timeout. |
PRJ-30701, |
SSL Inspection, |
A memory leak in HTTPS Inspection and HTTPS portals may occur when using ECDHE ciphers. |
PRJ-29269, |
Mobile Access |
In a rare scenario, a memory leak may occur in the CVPND process. |
PRJ-28258, |
Mobile Access |
In a rare scenario, the VPND process may unexpectedly exit causing user disconnections from Checkpoint Mobile client. |
PRJ-27297, |
Mobile Access |
In rare scenarios, when SNX client is used with Application mode on the Mobile Access Blade, the VPND process may unexpectedly exit. |
PRJ-27453, |
ClusterXL |
In a very rare scenario, after adding a member to a cluster, the FWK process may unexpectedly exit, creating core dumps. |
PRJ-28283, |
SecureXL |
In a rare scenario, DoS/Rate Limiting when using rules with country codes (CC) or autonomous system numbers (ASN) may not update Geo IP files correctly. |
PRJ-26953, |
SecureXL |
TCP packets may be dropped as "TCP out of state" although following sk11088. |
PRJ-32940, |
SecureXL |
In some scenarios, when configuring internal/external enforcement for DOS/Rate limiting, a syslog error message may be displayed. |
PRJ-30030, |
Routing |
In some scenarios, when BootP is configured, during policy installation, the Security Gateway may become unresponsive and the ROUTED process may crash. |
PRJ-27820, |
Routing |
If the interface cable is unplugged, after a failover, Border Gateway Protocol (BGP) stops receiving routes from Primary member to Secondary and back to Primary. |
PRJ-23816, |
Routing |
During the boot process "pbrroute-conf" messages may appear. Refer to sk173514. |
PRJ-26754, |
Routing |
In some scenarios, the NetFlow Packet may report a wrong source IP Address. |
PRJ-29497, |
Routing |
BGP sessions may unexpectedly close because of unrecognized AFI/SAFI pairs in multiprotocol capability advertisements from a peer. |
PRJ-28958, |
Routing |
The ROUTED process may unexpectedly exit. |
PRJ-29320, |
Routing |
AS path loops may occur, although BGP multihop is configured. |
PRJ-28840, |
Routing |
In some scenarios, an outage may occur because of premature graceful-restart exit. |
PRJ-31127, |
Routing |
In rare cases, if Graceful Restart is not configured on the BGP peer, BGP routes may be lost near the Graceful Restart ending. |
PRJ-28172, |
VPN |
NEW: Added StrongSwan clients counter to the VPN TU Tool. |
PRJ-29533, |
VPN |
RIM script is not invoked for DAIP peer with Dead Peer Detection (DPD) permanent tunnels in passive mode. |
PRJ-31115, |
VPN |
In some scenarios, when connecting with both Endpoint and SSL Network Extender (SNX) clients to a single Gateway, a memory leak may occur. |
PRJ-31148, |
VPN |
In some scenarios, a memory leak may occur when using the SSL Network Extender (SNX) client to create a site. |
PRJ-27856, |
VPN |
When deleting an entry from m_ht hash table, a memory leak may occur. |
PRJ-27687, |
VPN |
In a rare scenario, a memory leak may occur. |
PRJ-27683, |
VPN |
When saving the login info of the client, a memory leak may occur. |
PRJ-27679, |
VPN |
Reauthentication of the client may lead to a memory leak. |
PRJ-28772, |
VPN |
In some scenarios, in High Availability clusters with enabled CoreXL, SSL clients cannot connect to the Security Gateway because of incorrect license calculation. |
PRJ-28027, |
VPN |
When StrongSwan client connecting with a RADIUS user, it may not receive an Office Mode IP address. |
PRJ-25884, |
VPN |
In some scenarios, when DAIP peer initiates IKEv2 negotiation with certificate authentication, the VPND process may unexpectedly exit. Refer to sk174665. |
PRJ-28378, |
VPN |
Improved VPN Site to Site tunnel establishment scenario with IKEv2. Refer to sk175092. |
PRJ-28075, |
VPN |
A Remote Access client fails to login when a DN record length is bigger than 256. Refer to sk174249. |
PRJ-21639, |
VPN |
The VPN Logs view show IP address octets in an unexpected (reversed) order. Refer to sk172807. |
PRJ-27814, |
VPN |
In some scenarios, the VPN tunnel between GCP cluster and GCP peer fails to establish. |
PRJ-27314, |
VPN |
IPSec VPN uses the wrong source IP address when initiating NAT-T encrypted traffic. Refer to sk172805. |
PRJ-22119, |
VPN |
In rare scenarios, after policy installation, the VPND process may unexpectedly exit with core dump. |
PRJ-27675, |
VPN |
In some scenarios, the user may not be able to connect because the CVPND process unexpectedly exits. |
PRJ-25236, |
VPN |
Added improvements for DAIP Gateway behind Hide NAT and ROBO peer Gateways. |
PRJ-28558, |
VPN |
In some scenarios, when sending the SCV drop log, a memory leak may occur. |
PRJ-28265, |
VPN |
A memory leak may occur when clearing the CRL cache file. |
PRJ-28513, |
VPN |
In some scenarios, a memory leak may occur on the Security Gateway. |
PRJ-29283, |
VPN |
In rare scenarios, re-configuring a trusted CA bundle may cause a memory leak in the VPND process. |
PRJ-28506, |
VPN |
A memory leak may occur in the VPND process. |
PRJ-28575, |
VPN |
In some scenarios, Server connections to Remote Access L2TP clients may be unstable. |
PRJ-29483, |
VPN |
A memory leak may occur in the VPND process in IKEv2 Site to Site VPN. |
PRJ-30869, |
VPN |
A memory leak may occur in the VPND process. |
PRJ-30756, |
VPN |
In some scenarios, when NAT is enabled, Route Based VPN traffic may be dropped. |
PRJ-29277, |
VPN |
A memory leak may occur in the CVPND process. |
PRJ-17830, |
VSX |
Recreation of a virtual system may fail due to an internal error. |
PRJ-27970, |
VSX |
When querying a VS for "sysObjectID" via SNMP, a generic net-SNMP value ("NET-SNMP-MIB::netSnmpAgentOIDs.10") returns instead of a Checkpoint value ("SNMPv2-SMI::enterprises.2620.1.6.123.1.62"). |
PRJ-29553, |
VSX |
After reboot, the VS's clish static arps configurations exist, but the static arps may be missing. |
PRJ-27543, |
VSX |
The weight of VSB in "cphaprob stat" is 0. This impacts load balancing between cluster members in a VSX cluster in VSLS mode. |
PRJ-22691, |
VSX |
This fix allows create/change a VSX cluster/Gateway to have up to 32 CoreXL instances with VSX Provisioning Tool. Currently, it is possible to do this only in SmartConsole. |
PRJ-30276, |
Gaia OS |
UPDATE: Upgraded OpenSSL to 1.1.1L. Merged the CVE-2021-3711 and CVE-2021-3712 fixes. |
PRJ-25766, |
Gaia OS |
After 248 days of up time, the VMSS Gateway sends a Cold restart alert reboot, but the VMSS does not reboot. Refer to sk173413. |
PRJ-27001, |
Gaia OS |
Setting hashed SHA256/SHA512 expert password may fail with an error message: "set password-controls password-hash-type <password_hased> GAIA9999 Invalid Salted Hash". Refer to sk176703. |
PRJ-27613, |
Gaia OS |
If NTPD service is configured in Management Data Plane Separation (MDPS) settings, NTPD error logs appear in var/log/messages after a reboot. |
PRJ-27696, |
Gaia OS |
When a non-TACACS user logs out from WebUI, "Cannot get pid" is printed as an error to the /var/log/messages file. |
PRJ-27978, |
Gaia OS |
A memory leak may occur on a Security Gateway while configuring Secure Internal Communication (SIC). |
PRJ-26024, |
Gaia OS |
In some scenarios, after an upgrade, Multi-Queue commands may fail without producing any output due to licensing issue. Refer to sk168178. |
PRJ-26430, |
Gaia OS |
The Link Layer Discovery Protocol (LLDP) sends the hostname with a dot when the Domain name is empty. |
PRJ-28797, |
Gaia OS |
In a rare scenario, a memory leak may occur in the monitord process. |
PRJ-29858, |
Harmony Endpoint |
UPDATE: In SmartEndpoint, besides FDE Remote Help, Bitlocker Management Recovery is now available for administrators with limited rights. |
PRJ-29178, |
Harmony Endpoint |
Remote installation push operation "Deployed new Endpoints" does not work on on-prem Servers because of self-signed certificates. |
PRJ-27751, |
Harmony Endpoint |
Endpoint Firewall may start dropping all network traffic after a Management Server upgrade from R80.10 or older versions. |
PRJ-31100, |
Harmony Endpoint |
Restoring a UEPM Server backup via the Web Gaia Portal may not work on a new Server where the UEPM Blade is not activated. |
PRJ-30519, |
Harmony Endpoint |
In the Smart Endpoint tabs, the Server may generate reports where users have long names starting with "ntdomain://". |
PRJ-22501, |
VoIP |
Holding last source port table lock while searching for next free port may cause performance issues. |
PRJ-29515, |
CloudGuard Network |
NEW: In Amazon Web Services (AWS):
To enable the feature:
Note: This feature requires adding DescribeTags and DescribeLoadBalancers permissions to the AWS Data Centers accounts. NEW: In Azure:
To enable the feature:
Note: This feature requires adding permissions to list Application Security Groups and Private Endpoints.
NEW: In AWS, Azure and Google Cloud Platform (GCP): Added support for API calls with HTTP response with reason-code only (without reason-phrase). |
PRJ-21216, |
CloudGuard Network |
The mq_mng tool does not show RX/TX packets counter statistics for the virtio_net driver. |
PRJ-29651, |
CloudGuard Network |
Amazon Web Services (AWS) Data Center scan may fail and no updates are sent to the Security Gateway. |
PRJ-22534, |
CloudGuard Network |
In some scenarios, when there are Data Center objects in Access Policy Rule Base, policy verification may fail although policy installation succeeds. |
PRJ-30042, |
Smart-1 Cloud |
If wstunnel loses connectivity, after several attempts it may unexpectedly exit and not restart. Refer to sk166056. |
PRJ-23019, |
QoS |
Added QoS support for source port matching, allowing DSCP to mark different streams packets correctly. |
PRJ-29526, |
Scalable Platforms |
The "Hits" counter value in the SmartConsole rulebase does not update when traffic reaches a non-SMO Security Group member (for Security Gateway only). |
PRJ-21219, |
Scalable Platforms |
The SSM Allow Management Loss feature (sk145792) sends alerts even if a failure event's duration is short. |
PRJ-27511, |
Scalable Platforms |
In a rare scenario, a memory leak that requires constant reboots may occur. |
PRJ-25358, |
Scalable Platforms |
When restarting the active CMM (for example, with the "ccutil restart_cmm active" command), a chassis may fail over, even if there is a Standby CMM. |
PRJ-25347, |
Scalable Platforms |
In a rare scenario, the Chassis Monitor daemon (cmd) fails to retrieve the CPU temperatures due to an SNMP timeout. |
PRJ-21104, |
Scalable Platforms |
In some scenarios, UIPC feature does not work if a non-VS0 Virtual System is configured with an IP on the same subnet as VS0 management network. |
PRJ-25340, |
Scalable Platforms |
Allow Management Loss feature (sk145792) may not enter into Management Loss mode when backplane interface total packets amount exceeds 2 Billion. |
PRJ-28286, |
Scalable Platforms |
Using Static NAT for the destination in asymmetric connections may lead to Out of State traffic drops. Refer to sk174234. |
PRJ-27319, |
Scalable Platforms |
Added a cosmetic fix in asgPeaksTable. |
PRJ-27264, |
Scalable Platforms |
The "asg perf" command may fail when it calculates the average load of CPU cores when CoreXL uses all CPU cores available in the Security Group. |
PRJ-25368, |
Scalable Platforms |
If a Bond interface that is assigned to a Security Group is configured in the 802.3AD (LACP) mode, packet loss may occur on a Security Appliance when the Security Appliance becomes active after a reboot. |
PRJ-28427, |
Scalable Platforms |
In some scenarios, running the "asg perf" command with -vv flag fails. |
PRJ-29760, |
Scalable Platforms |
In a rare scenario, the "asg perf" command may take up to 90 seconds to update the data. The information may differ from CPView results. |
PRJ-30024, |
Scalable Platforms |
When rebooting a member from the standby site, it may send GARP when booting and cause a connectivity issue. Refer to sk176523. |
PRJ-29982, |
Scalable Platforms |
The outage may occur when configuring OSPF over VPN/VTI interface because of a missing cluster IP address for VPN/VTI interface. |
PRJ-25648 |
Scalable Platforms |
Collect data and statistics report in a scenario where SSM state has changed to down or entered into management loss mode |
PRJ-25781, |
Scalable Platforms |
In some scenarios, boot on SP VSX setup may fail with an "Unable to open '/vs1/dev/fw0': Connection refused" message. |
PRJ-27828, |
Scalable Platforms |
In a rare scenario, the "asg diag" command for verifying Interfaces may have an incorrect raw output. |
PRJ-27739, |
Scalable Platforms |
In rare scenarios, after accelerated policy installation, security members may go to down states. |
PRJ-28252, |
Scalable Platforms |
Added support for the command "snapshot-onetime" (import/export, from/to a remote Server) on Scalable Platforms. |
PRJ-29520, |
Scalable Platforms |
After setting a specific range of Blades in gclish, some commands may fail. |
PRJ-29390, |
Scalable Platforms |
During an upgrade of a Security Group, the "Fetching the policy from the Management Server and installing it" action fails on the upgraded Security Group Members. |
PRJ-25648, |
Scalable Platforms |
Scalable Platform automatically collects statistics and data in the /var/log/ssm_failure_reports/ directory, when:
|
PRJ-24519, |
Scalable Platforms |
After adding a new user via WebUI, the "asg diag" command may fail on configuration test (config_verify -v) due to inconsistent value in the database. The issue is only cosmetic. |
PRJ-22891, |
Scalable Platforms |
In some scenarios, the "asg diag" and "asg_license_verifier" commands fail with an incorrect message: "ERROR: No license for 'IPS-1' [mandatory feature 'ips']". |
PRJ-29002, |
Scalable Platforms |
In some scenarios, after an upgrade of Scalable Platform, reboot of a member may trigger additional reboots. |
PRJ-23306, |
Carrier Security |
UPDATE: The "FireWall-1 GX" module is renamed to "Carrier Security". |
PRJ-22323, |
Infrastructure |
In some scenarios, the cpmiquerybin and dbedit processes may unexpectedly exit causing a buffer overflow. |