R81 Jumbo Hotfix Take 51

 

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 51

Released on 29 December 2021

PRJ-27433,
PMTR-61440

Security Management

NEW: Added support for CloudGuard Edge appliances in LSM and SmartConsole.

  • Requires R81.00 SmartConsole Build 556 (or higher).

PRJ-31537,
MAT-1912

Security Management

UPDATE: The Management API "show-logs" command timeout increased from 2.5 minutes to 5 minutes.

PRJ-29237,
TPM-2843

Security Management

UPDATE: Added a new flag to the Threat Prevention "show-protections" API command ("show-capture-packets-and-track") that allows not to return capture-packets and track information.

PRJ-30365,
PMTR-63855

Security Management

UPDATE: Added new flags for Management API commands "add/set simple-gateway" and "add/set simple-cluster":

  • "nat-hide-internal-interfaces" and "nat-settings" for NAT configuration.
  • "fetch-policy" for Fetch Policy configuration.
  • "advanced-settings.sam" for SAM configuration.
  • "advanced-settings.connection-persistence" for Connection Persistence configuration.

PRJ-27424,
PRHF-17841

Security Management

UPDATE: The "show application-sites" Management API command now returns additional fields for UIDs of primary category and additional categories.

PRJ-31057,
PMTR-64687

Security Management

In rare scenarios, Security Management upgrade or migration may fail due to missing temporary files.

PRJ-29188,
PRHF-18470

Security Management

In a rare scenario, High Availability full synchronization may fail due to a large number of records.

PRJ-29305,
PMTR-72376

Security Management

In environments with a large number of objects, licenses for cluster members in the Licenses tab may not be displayed.

PRJ-28901,
PRHF-18508

Security Management

When searching IP addresses using logical operators (AND / OR), the results may be incorrect:

  • in SmartConsole in the Object Explorer view
  • with the Management API command "show objects" and the "filter" field

Some matched objects may be missing, while some unmatched objects may be present.

PRJ-28649,
PRHF-18508

Security Management

In some scenarios, when using a VPN community, the status of the Global Domain Assignment may change to "not up to date", although no changes were made in the Global Domain.

PRJ-28536,
PRHF-18063

Security Management

In rare scenarios, Global Policy Assignment may fail with the "class name not found for object" error.

PRJ-27921,
PMTR-71261

Security Management

In rare scenarios, more than one IP address may be shown in SmartConsole's Sessions view under the "Connected From" column.

PRJ-28896,
PRHF-18677

Security Management

If there are no explicit rules in one or more policy layers, policy verification may fail with the "No active rules found in the Security Policy" error.

PRJ-28001,
PRHF-18245

Security Management

If Brute Force Password Guessing Protection is set to the value of more than 25 seconds, login to SmartConsole fails.

  • Requires R81.00 SmartConsole Build 556 (or higher).

PRJ-20287,
SMCUPG-1533

Security Management

In rare scenarios, the second attempt of a Secondary Management Server upgrade may fail with "Task was interrupted because server restart".

PRJ-26522,
PRHF-17679

Security Management

In a rare scenario, policy installation may fail with a "Policy installation had failed due to an internal error" message.

PRJ-24634,
PRHF-16582

Security Management

In rare scenarios, policy installation may fail with an internal error due to missing permissions. Refer to sk17384.

PRJ-26522,
PRHF-17679

Security Management

In a rare scenario, policy installation may fail with a message: "Policy installation had failed due to an internal error".

PRJ-25629,
PRHF-17284

Security Management

In rare scenarios, a Management Server upgrade may fail with an "Object not found - [UID]" error message in the cpm.elg log file.

PRJ-25566,
PRHF-17182

Security Management

In rare scenarios, an upgrade may fail when there is an OPSEC Server object configured.

PRJ-23433,
PRHF-12488

Security Management

Upgrade to R81 may fail if one of the objects does not have a creator.

PRJ-28785,
PRHF-18557

Security Management

In some scenarios, "show-mdss" and "show-domains" Management API commands take a significant amount of time to complete or time out after 5 minutes.

PRJ-28570,
PRHF-18422

Security Management

In some scenarios, the Purge Revisions operation fails with the "An error has occurred while performing revisions purge operation, Incident ID - xxxxx-xxxxxxx-xxxxx-xxxxx" error message. Refer to sk174645.

PRJ-28423,
PMTR-10273

Security Management

Virtual session timeout for a TCP service cannot exceed 86400 seconds. Refer to sk168872.

PRJ-28293,
PRHF-18210

Security Management

In rare scenarios, High Availability incremental synchronization may fail with a wrong status message.

PRJ-28299,
PRHF-18362

Security Management

In rare scenarios, High Availability on the Global Domain may fail to synchronize the Multi-Domain Log Server if IPS protection was added or removed in the Threat Prevention rulebase.

PRJ-28064,
PRJ-28062

Security Management

In rare scenarios:

  • Login to the Management Server may timeout and fail
  • Publish operation may take a long time.

PRJ-28088,
PMTR-70942

Security Management

In some scenarios, the Administrators view may not filter Domain names according to the permission profile of the connected administrator.

PRJ-13161,
PRHF-11027

Security Management

The "show-global-assignment" command returns the default limit when the limit request is greater than the default limit.

PRJ-26736,
PRHF-17606

Security Management

In a rare scenario, the "show hosts" Management API command with "details-level full" fails with a "Java.util.InputMismatchException: got at least one duplicate UID in requested list, duplicates UIDs:" message.

PRJ-26677,
PRHF-17744

Security Management

The "show gateways and servers" Management API command does not show policy information for cluster members.

PRJ-27486,
PRHF-18079

Security Management

Global Policy reassignment may fail with "An internal error has occurred" due to duplicated Access Policy Assignment object. Refer to sk174183.

PRJ-27480,
PRHF-16976

Security Management

If there is an Administrator is named "Endpoint", an upgrade of Endpoint Security Server from R77.30 fails.

PRJ-21788,
PRHF-15257

Security Management

In some scenarios, the output of the "cpmistat" command may contain partial information.

PRJ-29898,
PRHF-18828

Security Management

In some scenarios, login to a Domain from the System Domain dashboard may fail with "Failed to connect to server".
Refer to sk174910.

PRJ-28157,
PRHF-17926

Security Management

In rare scenarios, if Domain migration fails, the operation may not revert fully and leave some remnants in the database of the Management Server.

PRJ-29517,
PMTR-72306

Security Management

In rare scenarios, when installing a policy immediately after publishing a session, the installation is not accelerated.

PRJ-29158,
PRHF-18883

Security Management

Scheduled IPS updates data may not be shown in the IPS update report.

PRJ-30048,
PMTR-72849

Security Management

The Management API command "show-sessions" may return sessions that were purged and no longer exist in the Management database.

PRJ-29968,
PRHF-19308

Security Management

In some scenarios, simultaneous policy installation on multiple Gateways may fail if there is at least one Gateway on R77.X and one Gateway on R80.X.

PRJ-25197,
PMTR-68090

Security Management

The "Packet capture is not supported on this platform" warning appears after policy installation on SMB Gateways, although no packet capture is used.

PRJ-30622,
PRJ-30624

Security Management

In rare scenarios, after the Security Management Server starts up, when connecting to SmartConsole, some objects appear more than once.

PRJ-30054,
PRHF-18928

Security Management

In rare scenarios, the FWM process unexpectedly exits and fails to start, creating core dumps in the /var/log/dump/usermode directory. Refer to sk175007.

PRJ-29469,
PRHF-19006

Security Management

In some scenarios, an API query to VRRP cluster for "show simple-cluster name <name>" returns an incorrect cluster type. Refer to sk174866.

PRJ-21877,
PRHF-15460

Security Management

In some scenarios, applying the "Where used" action may show incorrect data when an object exists more than once in an Inline Layer.

PRJ-21831,
PRHF-15448

Multi-Domain Management

In rare scenarios, after an upgrade, the CPD process in a Multi-Domain environment may unexpectedly exit, creating a core dump file.

PRJ-23852,
PMTR-66674

Security Management

Management Server upgrade may fail, if there is a large amount of customized column profiles in the Logs view.

PRJ-30019,
PMTR-72786

Security Management

In rare scenarios, the "set-group" API command may return the "generic_err_invalid_parameter" error.

PRJ-27764,
PRHF-17484

Security Management

The Management API commands "import-smart-task" and "export-smart-task" are enabled at the System Domain level, although Smart Tasks are only supported at the Local Domain level.

PRJ-29199,
PRHF-18782

Security Management

After an upgrade from R77.x. in a multi-site environment, High Availability full synchronization may fail with an "NGM failed to load data" message.

PRJ-25280,
PRHF-17037

Security Management

In rare scenarios, login to Multi-Domain Management fails with the "No Valid Domains were found for [username]" error. Refer to sk175005.

PRJ-28816,
PRHF-18712

Security Management

In some scenarios, the "show gateways-and-servers" Management API command fails with "generic_error" when running it with "details-level full".

PRJ-21778,
PMTR-63316

Licensing

In some scenarios, the total number of "sr" licenses may be counted incorrectly.

PRJ-27346,
PMTR-64049

Licensing

In a rare scenario, the licensing status in SmartConsole is displayed incorrectly.

PRJ-29804

Web SmartConsole

Added enhancements for Task Manager and policy installation. Refer to Take 48 in sk170314.

PRJ-30384,
PRJ-30370

CPInfo

UPDATE: Added CPInfo build 914000219. Refer to sk92739.

PRJ-20498,
PMTR-63033

CPUSE

The "Recommended" Package value is not changed from true to false in SmartConsole while installing Jumbo Hotfix. Refer to sk174508.

PRJ-22893,
PMTR-61926

CPView

In some scenarios, SNMP statistics per VS may not be displayed in CPView.

PRJ-29825,
PMTR-72671

SmartView

UPDATE: In SmartView, new MITRE ATT&CK techniques were added to the heatmap view.

PRJ-22159,
SL-5368

Logging

NEW:

  • In SmartEvent GUI added new products: "Behavioral Guard", "Anti-Exploit", "Anti-Bot" and "Anti-Ransomware"
  • For Endpoint logs correlation, added a new pre-defined event: "Harmony Endpoint" under Legacy -> Endpoint Security.

PRJ-26809,
PMTR-70072

Logging

NEW: In SmartEvent GUI, added the "referrer" field for filtering correlation unit events.

PRJ-25888,
PMTR-60610

Logging

UPDATE: During Management and Log Servers upgrade from R80.X to R81, indexes, stored in external storage (sk66003), can now be upgraded as part of the flow.

PRJ-25897,
PMTR-69195

Logging

UPDATE: Improved the time of search that require scanning logs for several days.

PRJ-29117,
PRHF-11939

Logging

In some scenarios, emails of DLP Blade may be sent with obfuscated information, with no option to present the full data. Refer to sk106430.

PRJ-29221,
PRHF-12847

Logging

In a rare scenario, Application Control events may not be displayed in SmartEvent.

PRJ-24979,
PRHF-16943

Logging

When AES authentication is configured, the "thresold_config" command does not send traps for SNMP v.3. Refer to sk173045.

PRJ-23868,
PRHF-16183

Logging

In SmartView reports, the "Show only icon" option for table widgets does not work as expected.

PRJ-26695,
PMTR-70010

Logging

When adding the "UC Block" action, log queries may not show UserCheck logs. Refer to sk174543.

PRJ-25833,
PMTR-68506

Logging

The LOG_INDEXER process on the SmartEvent Server may consume a high CPU when the Mobile Access Blade is enabled on the Security Gateway.

PRJ-25974,
PMTR-67094

Logging

In a rare scenario, logs that are created exactly at midnight, are shown in the SmartConsole Logs view tab but not shown in SmartView web.

PRJ-24524,
PMTR-67575

Logging

In a low log rate, there may be a delay in exporting logs using the Log Exporter.

PRJ-26116,
PMTR-69276

Logging

In a multi-site MDM environment, Log queries may fail to retrieve results from a CMA or CLM, if there is another CMA or CLM with the same sic_name.

PRJ-22346,
PRHF-15696

Logging

In SmartView, the "Duration" field is missing from Reports and Views.

PRJ-28301,
PMTR-69800

Logging

When using the LEEF format in the Log Exporter tool, product names miss the last letter.

PRJ-26726,
PRHF-17205

Logging

In some scenarios, the FWD process on Security Gateway may cause high memory consumption when Log Forwarding is configured or when running the "fw fetchlogs" command.

PRJ-27619,
PRHF-18157

Logging

The CPSEMD process on SmartEvent Server may unexpectedly exit when trying to send two automatic reactions simultaneously for the same event.

PRJ-27050,
PRHF-17285

Logging

In rare scenarios, Management object changes may not be reflected in the Logs view. When the issue occurs, the CPM process may also consume a high CPU.

PRJ-21313,
PMTR-62117

Logging

  • In environments with more than 500K network objects, the LOG_INDEXER process may lead to a memory leak.
  • In some scenarios, when there are offline logs to index, queries are slower than expected.

PRJ-28341,
PMTR-69859

Logging

In some scenarios, Log Exporter configured to export in TLS, cannot authenticate a certificate from an external certificate authority.

PRJ-25442,
PRHF-17184

Logging

On a Management Server, with SmartEvent enabled and many Networks configured in the database, login to SmartConsole may fail with an "Error: the operation timeout" message, and the FWM process is running with a high CPU. Refer to sk167239.

PRJ-29030,
PRHF-17596

Logging

In rare scenarios, SmartEvent may show no results or partial results in the Audit Log report.

PRJ-25623,
PMTR-68809

Logging

In environments with more than 500K network objects, the LOG_INDEXER process on SmartEvent and Correlation Unit Server may unexpectedly close with the "Out of memory" error and a dump core file, although limited resolving is enabled (according to sk164452).

PRJ-23681,
PMTR-62763

Logging

In rare scenarios, in environments with many network objects, when typing a query in the Logs tab Search bar, SmartConsole may close unexpectedly.

PRJ-30228

Logging

When traffic is dropped due to a Threat Prevention rule, fetching a packet capture from a security Blade violation log may not work.

PRJ-31210,
PRJ-30722

Logging

In a rare scenario, logs export from SmartView web view to CSV may fail. Refer to sk175545.

PRJ-29576,
PRHF-15052

Security Gateway

NEW: Added a new kernel parameter "up_disable_early_drop_optimization_for_reject" to disable "Early Drop Optimization" for reject rules. The parameter is enabled by default.

PRJ-28853,
PRHF-18624

Security Gateway

UPDATE: Added DNS Passive Learning support for DNS responses containing the Domain name in uppercase letters.

PRJ-29443,
PMTR-72448

Security Gateway

UPDATE: The default value for the kiss_kthread_allow_resched kernel parameter is changed to 1. Refer to sk170560.

PRJ-32157,
PMTR-74372

Security Gateway

UPDATE: Apache HTTPD version was updated from 2.4.41 to 2.4.51.

PRJ-30982,
PMTR-73404

Security Gateway

UPDATE: Added L3 routing support for bridge interface assigned with IP address. To enable it, set _fw_bridge_with_ip_routing=1_ in the _$FWDIR/fwkern.conf_ file. Refer to sk165560.

PRJ-29505,
PRHF-18863

Security Gateway

In some scenarios, using automatic Network Static NAT/Address range objects may cause connectivity issues.

PRJ-29088,
PRHF-13493

Security Gateway

In some scenarios, the CPD process may consume high CPU because of the memory leak in File Download Tool (FDT).

PRJ-28830,
PRHF-18098

Security Gateway

Improved the ICAP Server internal memory allocation logic.

PRJ-26036,
PMTR-67536

Security Gateway

A "fw_xlate_rule_count_dec: refcount is negative" message may be displayed in dmesg when IP pool NAT is used on a cluster environment.

PRJ-19771,
PRHF-14017

Security Gateway

Security Gateway may crash after policy installation.

PRJ-24692,
PRHF-16403

Security Gateway

In rare scenarios, creating a new SAM rule on a Management machine may fail.

PRJ-25294,
PRHF-16907

Security Gateway

In rare scenarios, a re-matched connection has 2 logs in SmartConsole.

PRJ-26077,
PRHF-11760

Security Gateway

After policy installation, Security Gateway may stop responding due to memory leaks.

PRJ-26393,
PRHF-17436

Security Gateway

In some scenarios, the WSDNSD process may unexpectedly exit and create a core file. Refer to sk173627.

PRJ-28810,
PRHF-18657

Security Gateway

Added cosmetic fixes of the "cpwd_admin list" command output.

PRJ-27560,
PRHF-17949

Security Gateway

In some scenarios, configuring an un-numbered virtual interface may cause ARP requests to stay not answered by the interface. Refer to sk174188.

PRJ-28104,
PRHF-18024

Security Gateway

In a rare scenario, a memory leak may occur on the Security Gateway.

PRJ-27872,
PRHF-18234

Security Gateway

After a reboot or policy installation, the Cluster Under Load(CUL) messages in the fwk.ekg show CPU usage higher than 100%.

PRJ-26824,
PRHF-17872

Security Gateway

In rare scenarios, a duplicate entry may appear in the /etc/cpshell/log_rotation.conf file. This issue is only cosmetic.

PRJ-27077,
PMTR-70300

Security Gateway

In rare scenarios, using IP Pool NAT with only IPv4/IPv6 addresses configured may cause Security Gateway to crash.

PRJ-27127,
PRHF-17942

Security Gateway

In some scenarios, the ROUTED process may unexpectedly exit.

PRJ-28873,
PRHF-18560

Security Gateway

In a rare scenario, when using ICAP client, Security Gateway may crash.

PRJ-26931,
PRHF-17758

Security Gateway

SNMP lowDiskSpace trap with MDPS does not work with SNMP versions v1/v2 . Refer to sk173811.

PRJ-26584,
PMTR-68272

Security Gateway

In a rare scenario, CPView may show incorrect SecureXL statistics per VS.

PRJ-27651,
PMTR-70634

Security Gateway

Negative values may appear in the output of the "fw tab -t connections -s" command and under the NAT section.

PRJ-29130,
PRHF-18716

Security Gateway

In rare scenarios, policy installation may fail with an "Operation failed, install/uninstall has been improperly terminated" message.

PRJ-30215,
MPTT-4834

Security Gateway

In some scenarios, policy installation may take longer or fail when GEO Updatable Objects are used in the policy.

PRJ-30204,
PMTR-72814

Security Gateway

In some scenarios, NATed VPN traffic may be routed out through the wrong interface. Refer to sk176785.

PRJ-29743,
PMTR-72615

Security Gateway

In a rare scenario, due to TCP connection reuse, a TCP connection may not be initiated Refer to sk11088.

PRJ-29543,
PRHF-17386

Security Gateway

There is no option to enable hyperthreading via cpconfig.

PRJ-29527,
PRHF-18984

Security Gateway

In a very rare scenario, the ICAP Server may crash with a core dump file generated.

PRJ-29420,
PMTR-71855

Security Gateway

In a rare scenario, policy installation on the Security Gateway may fail with an "Error code: 0-2000108" message. Refer to sk170673.

PRJ-29139,
PRHF-18403

Security Gateway

The cpsicdemux process may unexpectedly exit, causing the Secure Internal Communication (SIC) connection to fail.

PRJ-28554,
PMTR-71632

Security Gateway

Capsule Workspace end users may fail to authenticate to their Exchange Mail Server via Mobile Access SSO when authenticated with Kerberos, and the end users belong to many user groups or user groups with very long names.

PRJ-29588,
PRHF-19049

Security Gateway

In a rare scenario, Security Gateway may crash.

PRJ-26671,
PRHF-17760

Security Gateway

In a rare scenario, traffic outage may occur. It is caused by a memory leak related to delayed logs.

PRJ-30251,
PMTR-70219

Security Gateway

Added a translation of the error exit code of cprid_util in $CPDIR/log/cprid_util.elg debug log.

PRJ-31370,
PRHF-19693

Security Gateway

Improved the handling of a large number of sessions per single HTTP/S connection.

PRJ-31031,
PMTR-69049

Security Gateway

In a rare scenario, the Security Gateway may crash when disabling or enabling Threat Prevention Blade.

PRJ-28680,
AVIR-1444

Threat Prevention

UPDATE: Added the option to remove proxy usage in ioc_feeds tool.

PRJ-28520,
TPP-1291

Threat Prevention

In rare scenarios, the Security Gateway may crash when the TCP connection is unexpectedly closed.

PRJ-26543,
PMTR-69186

Threat Prevention

In some scenarios, the IPS update status in SmartConsole is incorrect after the automatic update fails with the "Update failed. Failed to load database" error.

PRJ-26007,
PMTR-68402

Threat Prevention

SSH Deep Packet Inspection (SSH DPI) may fail after upgrade to R81.

PRJ-25778,
PMTR-68801

Threat Prevention

In a rare scenario, the FWD process may unexpectedly exit after an upgrade.

PRJ-28607,
PMTR-68865

Threat Prevention

Large file transfer in connections inspected by SSH Deep Packet Inspection (SSH DPI) may fail if SSH renegotiation is performed during the transfer.

PRJ-28764,
PMTR-71415

Threat Prevention

In some scenarios, when using OpenSSH 8.2 Server, file download fails after starting the transfer.

PRJ-28939,
PRJ-28975

Threat Prevention

Improved telemetry for Infinity Vision SOC.

PRJ-29616,
PRJ-30706

Threat Prevention

After an upgrade from R80.30, if Custom Intelligence Feeds (IoC) feature is enabled, Threat Prevention policy on VSX cluster may fail with "failed to handle indicators".

PRJ-29926,
PRHF-19208

Threat Prevention

Threat Prevention policy installation may fail when loading 2 IoC feeds that contain the same signature name for one of the observables.

PRJ-28135,
PRJ-27437

Threat Extraction

In some scenarios, the "fw_send_kmsg: No buffer for tsid 44" error is printed in dmesg.

PRJ-29488,
IDA-4049

Identity Awareness

UPDATE:

  • Increased the default timeout values of entries: connected_pdp_refresh_interval is now set to 240 seconds and connected_pdp_grace_period is now set to 360 seconds.
  • Added the "Identity information / Network information will be deleted" alert to SmartConsole.

PRJ-32355,
PRJ-32353

Identity Awareness

UPDATE: The default threshold value for Identity Collector Service Accounts exclusion was changed from 10 to 100. Refer to sk174266.

PRJ-29397,
IDA-4087

Identity Awareness

Improved the Identity Server (PDP) performance for publishing new network on Identity Sharing with SmartPull.

PRJ-27476,
PRHF-18015

Identity Awareness

When using sk167118, the user may fail to authenticate if the "Ask user for password" checkbox is enabled.

PRJ-26804,
MBS-13669

Identity Awareness

In a rare scenario, the Security Gateway may crash.

PRJ-27943,
IDA-4112

Identity Awareness

In some scenarios, users may not be able to reach Identity Gateway (PEP). Refer to sk174105.

PRJ-29614,
PRHF-18943

Identity Awareness

In a rare scenario, some IPv6 sessions may get deleted due to an incorrect update of Identity Gateway (PEP) kernel tables.

PRJ-27193,
PRHF-17768

Application Control

UPDATE: Improved matching of URLs for custom applications.

PRJ-27260,
PMTR-65461

IPS

Proxy source IP address is not printed in the IPS logs.

PRJ-27959,
PRHF-18158

IPS

In some scenarios for HTTP, Gateway closes a connection from the Server side, but the user side may remain open.

PRJ-26463,
PRHF-16635

IPS

An HTTP download of a large file may unexpectedly stop with an error message.

PRJ-28245,
PRHF-18338

IPS

In some scenarios, HTTP Parser in the CPView statistics may show incorrect values for connections with more than 50 sessions.

PRJ-29941,
PRHF-18992

IPS

In rare scenarios, if IPS Geolocation is enabled, the Security Gateway may crash.

PRJ-32499,
PRJ-32415

IPS

In some scenarios, when IPS Automatic update is enabled, a memory leak may occur in the FWD process.

PRJ-31694,
PMTR-73790

IPS

Improved the handling of decoded HTTP/S traffic.

PRJ-29192,
TPP-1157

Anti-Bot

UPDATE: Improved performance of Anti-Bot URL Reputation.

PRJ-29476,
PMTR-72234

SSL Inspection

In some scenarios, a memory leak may occur when creating ECDHE keys.

PRJ-30460,
PRHF-19516

SSL Inspection

In rare scenarios, HTTPS connections may hang indefinitely during the TLS handshake, causing timeout.

PRJ-30701,
PMTR-72756

SSL Inspection,
VPN

A memory leak in HTTPS Inspection and HTTPS portals may occur when using ECDHE ciphers.

PRJ-29269,
PRJ-29262,
PRHF-3700,
PRHF-3742

Mobile Access

In a rare scenario, a memory leak may occur in the CVPND process.

PRJ-28258,
PRHF-16057

Mobile Access

In a rare scenario, the VPND process may unexpectedly exit causing user disconnections from Checkpoint Mobile client.

PRJ-27297,
VPNRA-761

Mobile Access

In rare scenarios, when SNX client is used with Application mode on the Mobile Access Blade, the VPND process may unexpectedly exit.

PRJ-27453,
PRHF-17458

ClusterXL

In a very rare scenario, after adding a member to a cluster, the FWK process may unexpectedly exit, creating core dumps.

PRJ-28283,
PRJ-28054

SecureXL

In a rare scenario, DoS/Rate Limiting when using rules with country codes (CC) or autonomous system numbers (ASN) may not update Geo IP files correctly.

PRJ-26953,
PMTR-70242

SecureXL

TCP packets may be dropped as "TCP out of state" although following sk11088.

PRJ-32940,
PMTR-75157

SecureXL

In some scenarios, when configuring internal/external enforcement for DOS/Rate limiting, a syslog error message may be displayed.

PRJ-30030,
PRHF-19268

Routing

In some scenarios, when BootP is configured, during policy installation, the Security Gateway may become unresponsive and the ROUTED process may crash.

PRJ-27820,
PMTR-63965

Routing

If the interface cable is unplugged, after a failover, Border Gateway Protocol (BGP) stops receiving routes from Primary member to Secondary and back to Primary.

PRJ-23816,
PMTR-63250

Routing

During the boot process "pbrroute-conf" messages may appear. Refer to sk173514.

PRJ-26754,
PRJ-26750

Routing

In some scenarios, the NetFlow Packet may report a wrong source IP Address.

PRJ-29497,
ROUT-1745

Routing

BGP sessions may unexpectedly close because of unrecognized AFI/SAFI pairs in multiprotocol capability advertisements from a peer.

PRJ-28958,
PRHF-17739

Routing

The ROUTED process may unexpectedly exit.

PRJ-29320,
ROUT-1721

Routing

AS path loops may occur, although BGP multihop is configured.

PRJ-28840,
PMTR-51501

Routing

In some scenarios, an outage may occur because of premature graceful-restart exit.

PRJ-31127,
PMTR-73496

Routing

In rare cases, if Graceful Restart is not configured on the BGP peer, BGP routes may be lost near the Graceful Restart ending.

PRJ-28172,
PMTR-71425

VPN

NEW: Added StrongSwan clients counter to the VPN TU Tool.

PRJ-29533,
PRHF-18564

VPN

RIM script is not invoked for DAIP peer with Dead Peer Detection (DPD) permanent tunnels in passive mode.

PRJ-31115,
PMTR-73488

VPN

In some scenarios, when connecting with both Endpoint and SSL Network Extender (SNX) clients to a single Gateway, a memory leak may occur.

PRJ-31148,
PMTR-73511

VPN

In some scenarios, a memory leak may occur when using the SSL Network Extender (SNX) client to create a site.

PRJ-27856,
PMTR-71136

VPN

When deleting an entry from m_ht hash table, a memory leak may occur.

PRJ-27687,
PMTR-70957

VPN

In a rare scenario, a memory leak may occur.

PRJ-27683,
PMTR-71025

VPN

When saving the login info of the client, a memory leak may occur.

PRJ-27679,
PMTR-71013

VPN

Reauthentication of the client may lead to a memory leak.

PRJ-28772,
PMTR-71850

VPN

In some scenarios, in High Availability clusters with enabled CoreXL, SSL clients cannot connect to the Security Gateway because of incorrect license calculation.

PRJ-28027,
PMTR-71319

VPN

When StrongSwan client connecting with a RADIUS user, it may not receive an Office Mode IP address.

PRJ-25884,
PRHF-16370

VPN

In some scenarios, when DAIP peer initiates IKEv2 negotiation with certificate authentication, the VPND process may unexpectedly exit. Refer to sk174665.

PRJ-28378,
PMTR-71772

VPN

Improved VPN Site to Site tunnel establishment scenario with IKEv2. Refer to sk175092.

PRJ-28075,
PRHF-18369

VPN

A Remote Access client fails to login when a DN record length is bigger than 256. Refer to sk174249.

PRJ-21639,
PRHF-15318

VPN

The VPN Logs view show IP address octets in an unexpected (reversed) order. Refer to sk172807.

PRJ-27814,
PMTR-71098

VPN

In some scenarios, the VPN tunnel between GCP cluster and GCP peer fails to establish.

PRJ-27314,
PRHF-14851

VPN

IPSec VPN uses the wrong source IP address when initiating NAT-T encrypted traffic. Refer to sk172805.

PRJ-22119,
PMTR-31204

VPN

In rare scenarios, after policy installation, the VPND process may unexpectedly exit with core dump.

PRJ-27675,
PMTR-70855

VPN

In some scenarios, the user may not be able to connect because the CVPND process unexpectedly exits.

PRJ-25236,
PMTR-68326

VPN

Added improvements for DAIP Gateway behind Hide NAT and ROBO peer Gateways.

PRJ-28558,
PMTR-20176

VPN

In some scenarios, when sending the SCV drop log, a memory leak may occur.

PRJ-28265,
PRHF-18295

VPN

A memory leak may occur when clearing the CRL cache file.

PRJ-28513,
PRHF-18408

VPN

In some scenarios, a memory leak may occur on the Security Gateway.

PRJ-29283,
PRHF-18818

VPN

In rare scenarios, re-configuring a trusted CA bundle may cause a memory leak in the VPND process.

PRJ-28506,
PRHF-18400

VPN

A memory leak may occur in the VPND process.

PRJ-28575,
PRHF-17880

VPN

In some scenarios, Server connections to Remote Access L2TP clients may be unstable.

PRJ-29483,
PMTR-72463

VPN

A memory leak may occur in the VPND process in IKEv2 Site to Site VPN.

PRJ-30869,
PRHF-19755

VPN

A memory leak may occur in the VPND process.

PRJ-30756,
PRHF-19484

VPN

In some scenarios, when NAT is enabled, Route Based VPN traffic may be dropped.

PRJ-29277,
PRHF-3784

VPN

A memory leak may occur in the CVPND process.

PRJ-17830,
PRJ-17746

VSX

Recreation of a virtual system may fail due to an internal error.

PRJ-27970,
PMTR-35890

VSX

When querying a VS for "sysObjectID" via SNMP, a generic net-SNMP value ("NET-SNMP-MIB::netSnmpAgentOIDs.10") returns instead of a Checkpoint value ("SNMPv2-SMI::enterprises.2620.1.6.123.1.62").

PRJ-29553,
PRHF-18753

VSX

After reboot, the VS's clish static arps configurations exist, but the static arps may be missing.

PRJ-27543,
PMTR-70755

VSX

The weight of VSB in "cphaprob stat" is 0. This impacts load balancing between cluster members in a VSX cluster in VSLS mode.

PRJ-22691,
PMTR-65535

VSX

This fix allows create/change a VSX cluster/Gateway to have up to 32 CoreXL instances with VSX Provisioning Tool. Currently, it is possible to do this only in SmartConsole.

PRJ-30276,
PMTR-72997

Gaia OS

UPDATE: Upgraded OpenSSL to 1.1.1L. Merged the CVE-2021-3711 and CVE-2021-3712 fixes.

PRJ-25766,
PRHF-17216

Gaia OS

After 248 days of up time, the VMSS Gateway sends a Cold restart alert reboot, but the VMSS does not reboot. Refer to sk173413.

PRJ-27001,
PRHF-17900

Gaia OS

Setting hashed SHA256/SHA512 expert password may fail with an error message: "set password-controls password-hash-type <password_hased> GAIA9999 Invalid Salted Hash". Refer to sk176703.

PRJ-27613,
PRJ-27612

Gaia OS

If NTPD service is configured in Management Data Plane Separation (MDPS) settings, NTPD error logs appear in var/log/messages after a reboot.

PRJ-27696,
PRHF-17721

Gaia OS

When a non-TACACS user logs out from WebUI, "Cannot get pid" is printed as an error to the /var/log/messages file.

PRJ-27978,
PMTR-69876

Gaia OS

A memory leak may occur on a Security Gateway while configuring Secure Internal Communication (SIC).

PRJ-26024,
PRHF-12090

Gaia OS

In some scenarios, after an upgrade, Multi-Queue commands may fail without producing any output due to licensing issue. Refer to sk168178.

PRJ-26430,
GAIA-8922

Gaia OS

The Link Layer Discovery Protocol (LLDP) sends the hostname with a dot when the Domain name is empty.

PRJ-28797,
PRHF-18683

Gaia OS

In a rare scenario, a memory leak may occur in the monitord process.

PRJ-29858,
PRHF-17602

Harmony Endpoint

UPDATE: In SmartEndpoint, besides FDE Remote Help, Bitlocker Management Recovery is now available for administrators with limited rights.

PRJ-29178,
PRHF-17857

Harmony Endpoint

Remote installation push operation "Deployed new Endpoints" does not work on on-prem Servers because of self-signed certificates.

PRJ-27751,
PRHF-18108

Harmony Endpoint

Endpoint Firewall may start dropping all network traffic after a Management Server upgrade from R80.10 or older versions.

PRJ-31100,
PRHF-16439

Harmony Endpoint

Restoring a UEPM Server backup via the Web Gaia Portal may not work on a new Server where the UEPM Blade is not activated.

PRJ-30519,
PMTR-73094

Harmony Endpoint

In the Smart Endpoint tabs, the Server may generate reports where users have long names starting with "ntdomain://".

PRJ-22501,
PRHF-15623

VoIP

Holding last source port table lock while searching for next free port may cause performance issues.

PRJ-29515,
VSECC-1418

CloudGuard Network

NEW: In Amazon Web Services (AWS):

  • Added Load Balancers tags. The tags can now be viewed in SmartConsole and added to the rulebase.
  • Added support for IMDSv2

To enable the feature:

  1. Edit the $FWDIR/conf/vsec.conf on the Management Server and add the line: aws.enableLoadBalancersTags=true
  2. From SSH run: vsec stop;vsec start

Note: This feature requires adding DescribeTags and DescribeLoadBalancers permissions to the AWS Data Centers accounts.

NEW: In Azure:

  • Added Application Security Groups
  • Added Private Endpoints

To enable the feature:

  1. Edit the $FWDIR/conf/vsec.conf on the Management Server and add the line: azure.enableAsgAndPep=true
  2. From SSH run: vsec stop;vsec start

Note: This feature requires adding permissions to list Application Security Groups and Private Endpoints.

 

NEW: In AWS, Azure and Google Cloud Platform (GCP):

Added support for API calls with HTTP response with reason-code only (without reason-phrase).

PRJ-21216,
PMTR-63308

CloudGuard Network

The mq_mng tool does not show RX/TX packets counter statistics for the virtio_net driver.

PRJ-29651,
PRHF-17648

CloudGuard Network

Amazon Web Services (AWS) Data Center scan may fail and no updates are sent to the Security Gateway.

PRJ-22534,
PRJ-28171

CloudGuard Network

In some scenarios, when there are Data Center objects in Access Policy Rule Base, policy verification may fail although policy installation succeeds.

PRJ-30042,
ODU-104

Smart-1 Cloud

If wstunnel loses connectivity, after several attempts it may unexpectedly exit and not restart. Refer to sk166056.

PRJ-23019,
PRHF-15000

QoS

Added QoS support for source port matching, allowing DSCP to mark different streams packets correctly.

PRJ-29526,
MBS-11085

Scalable Platforms

The "Hits" counter value in the SmartConsole rulebase does not update when traffic reaches a non-SMO Security Group member (for Security Gateway only).

PRJ-21219,
MBS-12835

Scalable Platforms

The SSM Allow Management Loss feature (sk145792) sends alerts even if a failure event's duration is short.
Now the feature sends alerts only if a failure event's duration is long (30 seconds by default).

PRJ-27511,
PRHF-17895

Scalable Platforms

In a rare scenario, a memory leak that requires constant reboots may occur.

PRJ-25358,
MBS-10733

Scalable Platforms

When restarting the active CMM (for example, with the "ccutil restart_cmm active" command), a chassis may fail over, even if there is a Standby CMM.

PRJ-25347,
MBS-10732

Scalable Platforms

In a rare scenario, the Chassis Monitor daemon (cmd) fails to retrieve the CPU temperatures due to an SNMP timeout.

PRJ-21104,
SPC-1233

Scalable Platforms

In some scenarios, UIPC feature does not work if a non-VS0 Virtual System is configured with an IP on the same subnet as VS0 management network.

PRJ-25340,
SPC-3100

Scalable Platforms

Allow Management Loss feature (sk145792) may not enter into Management Loss mode when backplane interface total packets amount exceeds 2 Billion.

PRJ-28286,
PMTR-71419

Scalable Platforms

Using Static NAT for the destination in asymmetric connections may lead to Out of State traffic drops. Refer to sk174234.

PRJ-27319,
PMTR-70850

Scalable Platforms

Added a cosmetic fix in asgPeaksTable.

PRJ-27264,
MBS-14076

Scalable Platforms

The "asg perf" command may fail when it calculates the average load of CPU cores when CoreXL uses all CPU cores available in the Security Group.

PRJ-25368,
MBS-10506

Scalable Platforms

If a Bond interface that is assigned to a Security Group is configured in the 802.3AD (LACP) mode, packet loss may occur on a Security Appliance when the Security Appliance becomes active after a reboot.

PRJ-28427,
PMTR-71406

Scalable Platforms

In some scenarios, running the "asg perf" command with -vv flag fails.

PRJ-29760,
PMTR-71418

Scalable Platforms

In a rare scenario, the "asg perf" command may take up to 90 seconds to update the data. The information may differ from CPView results.

PRJ-30024,
MBS-13662

Scalable Platforms

When rebooting a member from the standby site, it may send GARP when booting and cause a connectivity issue. Refer to sk176523.

PRJ-29982,
MBS-12054

Scalable Platforms

The outage may occur when configuring OSPF over VPN/VTI interface because of a missing cluster IP address for VPN/VTI interface.

PRJ-25648

Scalable Platforms

Collect data and statistics report in a scenario where SSM state has changed to down or entered into management loss mode

PRJ-25781,
MBS-13969

Scalable Platforms

In some scenarios, boot on SP VSX setup may fail with an "Unable to open '/vs1/dev/fw0': Connection refused" message.

PRJ-27828,
PMTR-71149

Scalable Platforms

In a rare scenario, the "asg diag" command for verifying Interfaces may have an incorrect raw output.

PRJ-27739,
PMTR-71092

Scalable Platforms

In rare scenarios, after accelerated policy installation, security members may go to down states.

PRJ-28252,
PMTR-70624

Scalable Platforms

Added support for the command "snapshot-onetime" (import/export, from/to a remote Server) on Scalable Platforms.

PRJ-29520,
PMTR-72141

Scalable Platforms

After setting a specific range of Blades in gclish, some commands may fail.

PRJ-29390,
PMTR-72185

Scalable Platforms

During an upgrade of a Security Group, the "Fetching the policy from the Management Server and installing it" action fails on the upgraded Security Group Members.

PRJ-25648,
MBS-11227

Scalable Platforms

Scalable Platform automatically collects statistics and data in the /var/log/ssm_failure_reports/ directory, when:

  • An SSM enters the management loss state. Refer to sk145792.
  • An SSM goes down.

PRJ-24519,
MBS-12953

Scalable Platforms

After adding a new user via WebUI, the "asg diag" command may fail on configuration test (config_verify -v) due to inconsistent value in the database. The issue is only cosmetic.

PRJ-22891,
MBS-12346

Scalable Platforms

In some scenarios, the "asg diag" and "asg_license_verifier" commands fail with an incorrect message: "ERROR: No license for 'IPS-1' [mandatory feature 'ips']".

PRJ-29002,
PRJ-29001

Scalable Platforms

In some scenarios, after an upgrade of Scalable Platform, reboot of a member may trigger additional reboots.

PRJ-23306,
PMTR-60956

Carrier Security

UPDATE: The "FireWall-1 GX" module is renamed to "Carrier Security".

PRJ-22323,
PRHF-15689

Infrastructure

In some scenarios, the cpmiquerybin and dbedit processes may unexpectedly exit causing a buffer overflow.