R81 Jumbo Hotfix Take 60

 

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 60

Released on 15 Mar 2022

PRJ-29395,
PMTR-72424

Security Management

NEW: Added support for Management API commands: "add-rules-batch" and "delete-rules-batch".

PRJ-32892,
PRHF-20657

Security Management

UPDATE: It is now possible to increase the timeout value for Management High Availability synchronization. Refer to sk176165.

PRJ-32765,
PMTR-71549

Security Management

UPDATE: Meta-info and comments fields are now displayed in the output of the "show-tasks" API command with "details-level standard".

PRJ-24931,
PRHF-16947

Security Management

UPDATE: Added a warning message in SmartConsole, alerting if during policy installation memory utilization of the FWM process exceeded 3.5GB.

PRJ-32959,
ODU-154

Security Management

Added Update 13 of Autonomous Threat Prevention Management integration Release. Refer to sk167109.

PRJ-31672,
PRHF-19891

Security Management

In rare scenarios, the API commands "show-automatic-purge" and "set-automatic-purge" may fail if there were two earlier attempts to update the Automatic Purge at the same time.

PRJ-30475,
PRHF-19577

Security Management

Desktop policy installation may fail with the "Service ReferenceObject of type is not supported!" error.

PRJ-30898,
PMTR-73253

Security Management

In rare scenarios, installing policy on an OSE device may fail with "Policy installation had failed due to an internal error".

PRJ-32650,
PMTR-74947

Security Management

In rare scenarios, deleting a Domain fails, leaving some remnants in the Management database.

PRJ-33979,
PRHF-21115

Security Management

Policy installation from the Multi-Domain Server level may trigger installation of two policies for the same VS.

PRJ-28169,
PRHF-18380

Security Management

In rare scenarios, the Management Server may fail to start due to incorrect sessions handling.

PRJ-34200,
PRJ-35072

Security Management

High Availability synchronization fails when one Management Server is installed on an appliance of 6000 series and the other one is an Open Server, a Virtual Machine, or installed on an appliance of different series.

PRJ-30385,
PRHF-16024

Security Management

In rare scenarios, editing a cluster object fails with the "Code: 0x8003001D, Could not access file for write operation" error. Refer to sk176930.

PRJ-32360,
PMTR-74598

Security Management

In some cases, when changing only the "color" and "comment" object fields, policy installation may not be accelerated.

PRJ-32669,
PRHF-20485

Security Management

When searching for tags usage, the "where-used" Management API command may fail with "Requested object not found".

PRJ-29240,
PRHF-18890

Security Management

In some scenarios, the Management API command "show-packages" with "details-level full" may fail with an error. Refer to sk176805.

PRJ-32857,
PRHF-20444

Security Management

After the Management Server restart, the API command "show_tasks" may show some suppressed tasks as "in progress", if before the restart they were cleared in SmartConsole while they were still running.

PRJ-33464,
PMTR-71195

Security Management

While editing a Small Office LSM Profile object, SmartConsole may unexpectedly close when enabling Threat Emulation and navigating to the Configuration tab.

PRJ-30068,
PRHF-19326

Security Management

  • The High Availability status on Security Management Server may be incorrect and performing failover is not possible.
  • On Multi-Domain Server, after performing failover in the Global Domain and restarting services, the former active Global Domain Server still appears as active (although it is standby).

PRJ-31892,
PMTR-73413

Security Management

In some scenarios, the API command "show-changes" fails with "Diff operation failed: Unable to build the diff reply."

PRJ-32092,
PRHF-20162

Security Management

When searching an IP in Object Explorer, network objects with both IPv6 and IPv4 configured, may not appear in the results, although they match the IP.

PRJ-34080,
PMTR-74982

Security Management

In some scenarios, after running an Ansible Playbook, objects are locked even though they were not changed.

PRJ-34226,
PRHF-21356

Security Management

When performing IPS Update or Global Domain Assignment, creating a Domain at the same time may fail with "Internal Error".

PRJ-33864,
PRHF-21129

Security Management

When creating or updating a service object via Management API, it is not possible to specify a custom aggressive-aging timeout.

PRJ-32109,
PMTR-63070

Security Management

Policy installation may fail if more than 20,000 objects are created and added to rules.

PRJ-20592,
PRHF-14327

Security Management

In rare scenarios, if one of the Multi-Domain Servers is down, reconfiguring VSX may fail.

PRJ-31260,
PMTR-69264

Security Management

In some scenarios, the API command "login-to-domain" fails, and the cpm.elg log shows "Null Pointer Exception".

PRJ-26781,
PRHF-17767

Security Management

In some scenarios, in Override Categorization, it may not be possible to sort or to find objects by name using Object Explorer. Refer to sk175245.

PRJ-32360,
PMTR-74598

Security Management

In some cases, when changing only the "color" and "comment" object fields, policy installation may not be accelerated.

PRJ-30100,
PRHF-19248

Security Management

In rare scenarios, a Multi-Domain administrator's profile may be changed after deleting a Domain if the administrator had custom permissions for it.

PRJ-30531,
PRHF-19542

Security Management

Creating an administrator in a Multi-Domain environment may cause SmartConsole to freeze and time out.

PRJ-33287,
PRHF-20525

Security Management

When reassigning Global policy after an IPS update on the Global Domain, the updated IPS version in the Audit Logs view may appear with "-1" value instead of the actual IPS version number.

PRJ-29910,
PRHF-18974

Security Management

In some scenarios, it is possible to disable a shared layer, although it is used in more than one rule.

PRJ-32448,
PRHF-20062

Security Management

In rare scenarios, in a Multi-Domain environment, after performing an IPS Update, High Availability synchronization in the Global Domain fails with "NGM failed to import data".

PRJ-30035,
PRHF-19187

Security Management

  • The API command "show_packages_details" does not support the "OneTimeProb" parameter, although it is supported in GUI.
  • In some scenarios, the API command "show_packages" with "details-level full" fails with "generic_error".

PRJ-25710,
PRHF-17010

Security Management

Deleting a network group may fail because it is used, although "Where Used" shows no usage.

PRJ-33521,
PRHF-20971

Security Management

In rare scenarios, the Management Server may fail to start.

PRJ-32429,
PRHF-20440

Security Management

In rare scenarios, adding a service to a rule in Access Policy:

  • may take a long time (more than several seconds)
  • may cause SmartConsole to unexpectedly exit.

Refer to sk176004.

PRJ-30681,
PRHF-19185

Security Management

Policy installation with Directional VPN rules may fail with a verification error.

PRJ-30884,
PMTR-62059

Security Management

In rare scenarios, during an upgrade, the FWM process may unexpectedly exit with a core dump file.

PRJ-22266,
PRHF-15674

Security Management

In some scenarios, the user may fail to connect to VPN Remote Access if there are expiration dates saved in a non-English date format. The issue can occur when SmartConsole is installed on a Windows client that uses a non-English locale. Refer to sk173967.

PRJ-33553,
PRHF-20961

Security Management

When using the API to create an OPSEC CPMI application with a custom permissions profile, the default Super User profile is chosen instead.

PRJ-33056,
PMTR-73543

Security Management

In some scenarios, when editing Exceptions in Inspection Settings, Gateways without IPS Blade may be missing from the "Install On" list.

PRJ-30282,
PRHF-19412

Security Management

SmartConsole may unexpectedly close when the user opens the Global Assignment view after doing the "Solr Cure" procedure. Refer to sk175443.

PRJ-34035,
PMTR-73939

Security Management

When many sessions are opened:

  • Publish operation may be slow
  • APPI Update may be stuck on 30% and eventually fail
  • Domain Import task may be stuck after 50% and then fail

PRJ-30416,
PRHF-18883

Security Management

Scheduled IPS updates data may not be shown in the IPS update report.

PRJ-32041,
PRHF-20220

Security Management

In some scenarios, the $MDS_FWDIR/log/cpm.elg file contains many lines about "UnmarshalException".

PRJ-33951,
PRHF-20891

Security Management

The "fwm logexport" command may fail with the "Failed to dump tables from NGM" error when running it from the Global Domain on the Multi-Domain Server or from the Log Server.

PRJ-31742,
PMTR-73756

Security Management

In some scenarios, deleting a Domain fails when there is an administrator with API key authentication associated with this Domain.

PRJ-30059,
PRHF-19250

Security Management

In rare scenarios, after Management Server upgrade, importing the database may fail with "Tried to persist object".

PRJ-30337,
PRHF-18150

Security Management

When one Server in a logical Server group is down, the second Server keeps trying to access it, no matter how long the Server is down.

PRJ-31082,
PRHF-19251

Security Management

In rare scenarios, the FWM process on the Security Management Server unexpectedly exits.

PRJ-30351,
PRJ-30352,
PRHF-19421

Multi-Domain Management

During a CPUSE upgrade of a Multi-Domain Server, if there are multiple external interfaces defined, the Domain Servers may be assigned to an incorrect interface.

PRJ-30526,
PRHF-19541

Multi-Domain Management

In rare scenarios, running the "fwm sic_reset" command on Multi-Domain Server may fail.

PRJ-33168,
PRHF-20782

Multi-Domain Management

The mds_backup script may not collect Multi-Domain Server log files from $MDSDIR/log/.

PRJ-29311,
PRHF-18767

SmartConsole

The Compliance "Security Best Practices" report for the Anti-Bot practice contains unrelated objects starting with "AB_". Refer to sk174911.

PRJ-29133,
PRJ-27606

Compliance

In some scenarios, auto-update flow fails during updatable object registration.

PRJ-36042

Web SmartConsole

UPDATE: Released Take 55 with new features and improvements. Refer to sk170314.

PRJ-34293,
PMTR-75623

Compliance

After disabling Best Practices, the user receives security alerts.
  • Requires R81 SmartConsole Build 559 (or higher).

PRJ-30092,
PRHF-18939

Logging

In rare scenarios, the LOG_INDEXER process stops working and logs are missing. Refer to sk176403.

PRJ-19839,
PRHF-14286

Logging

On Gateways with many interfaces, after policy installation or after reboot, Real-Time Monitor (RTM) may consume a high CPU on the Gateway. Refer to sk170928.

PRJ-30664,
PRHF-19620

Logging

  • The "fw log" and "fwm logexport" commands may fail with "Error: Failed to read field".
  • The exported log file may not contain all logs.

Refer to sk176644.

PRJ-31617,
PRHF-19834

Logging

Non-English letters in SmartView reports exported as CSV may be displayed incorrectly. Refer to sk175543.

PRJ-29124,
PRHF-18445

Logging

SmartEvent may not show some of the Anti-Virus logs.

PRJ-25654,
PRHF-17000

Logging

When SmartView Web is configured to not return empty values, a query may fail with a "query failed" message.

PRJ-32588,
PRHF-20276

Logging

There may be empty values in the "Office Mode IP" field in the Logs view.

PRJ-32303,
PRHF-18539

Logging

When configuring an Email alert as an Automatic Reaction in SmartEvent, and the alert contains data from the event, some fields may be missing in the generated email.

PRJ-32029,
PRHF-19715

Logging

In some scenarios, the "vpn_user" field is empty in the Logs view and SmartEvent Reports, even though it contains values in the raw log.

PRJ-23314,
PRHF-16137

Logging

Daily Log/Indexes Maintenance does not delete old index files from $RTDIR/log_indexes if they contain files or subdirectories with a format different than %Y-%m-%d.

PRJ-28317,
PRHF-18428

Logging

The "Last Update Time" field of a Session Log may show incorrect values.

PRJ-26682,
PRHF-17724

Logging

Logs that are sent by Log Exporter in CEF format, cannot be displayed if they include non-digit characters in the "dst_phone_number" field.

PRJ-28324,
PRHF-17811

Logging

In some scenarios, in SmartLog, free-text search does not work for some inspection settings logs and their description is missing.

PRJ-26031,
PRHF-17325

Logging

In a rare scenario, after an NSX Gateway upgrade, enforcement details/identities are not pushed by the controller to the Gateway automatically, it can be done only by manual update. Refer to sk173323.

PRJ-26308,
PRHF-17314

Logging

In rare scenarios, in SmartConsole, some logs are not shown.

PRJ-20768,
PRHF-12617

Logging

In SmartConsole:

  • In Gateways and Servers view, IP statuses may not be accurate
  • In the Threat Prevention Policy tab, under "Updates", Gateways IPS update status may not be up-to-date, although the new IPS package was received successfully.

PRJ-32086,
PMTR-74297

Logging

A duplicate entry appears in /etc/cpshell/log_rotation.conf. This issue is only cosmetic.

PRJ-31808,
PRHF-19710

Security Gateway

NEW: Added a new kernel parameter "cphwd_medium_path_qid_by_cpu_id". The parameter is disabled by default. Refer to sk175890.

PRJ-32073,
STRM-737

Security Gateway

UPDATE: Check Point Active Streaming (CPAS) TCP Window scale factor is now increased up to 6.

PRJ-34450,
PRHF-21182

Security Gateway

UPDATE: The "fw unloadlocal" command can now be used on a Virtual System only with the "-f" flag added. Otherwise, a warning message is displayed, indicating that unloading policy on a Virtual System will cause traffic issues with any Virtual System connected to a Virtual Switch or a Virtual System in Bridge mode.

PRJ-33748,
PMTR-76138

Security Gateway

UPDATE: Added a new flag to the "dynamic_objects" command: "-uo <name of object>". The user can now see all content of a specific updatable object.

PRJ-31273,
PMTR-73504

Security Gateway

UPDATE: The "-c" and "-i" flags in Top Connections Tool are now supported on VSX Gateways. Refer to sk172229.

PRJ-30012,
PRHF-18938

Security Gateway

In a rare scenario, when QoS is enabled, Security Gateway may crash while interfaces go down and up.

PRJ-30296,
PMTR-73017

Security Gateway

Enhanced Check Point Active Streaming (CPAS). Refer to sk177025.

PRJ-30693

Security Gateway

The "Matched rule is not found" error appear when using Suspicious Activity Monitoring (SAM) rules with source and destination networks, or with a NATed IP.

PRJ-30783,
PRHF-19506

Security Gateway

Access Policy installation may fail with "Error code 1-2000078".

PRJ-33606,
PMTR-75976

Security Gateway

When there are security zones configured in the NAT rulebase and the connection has NAT on the destination, the Security Gateway IP address may still be shown as the source IP, although it should not.

PRJ-20628,
PRHF-14374

Security Gateway

Running the "threshold_config" command may cause the CPD process to consume a high CPU.

PRJ-33082,
PRHF-20436

Security Gateway

Extended logging may show a wrong status of Content Awareness Blade. The issue is only cosmetic.

PRJ-25150,
PRHF-14366

Security Gateway

In a rare scenario, the TCP Half Closed timer (sk137672) may fail when configured for medium/fast connections.

PRJ-33360,
PMTR-72975

Security Gateway

First policy installation after an upgrade may be followed by a warning message: "Updatable Objects are used in the policy but Gateway package is missing (see sk121877)".

PRJ-29541,
PRHF-19048

Security Gateway

After reboot and policy installation, the "No interface configured in SmartCenter server with name mdps_tun. Matching by IP address to interface Mgmt" error may be printed in fwk.elg.

PRJ-33513,
PMTR-75878

Security Gateway

CPView may show corrupted numbers in "F2V-Reasons". This issue is only cosmetic.

PRJ-26965,
PMTR-70393

Security Gateway

Improved CPS rate on Autoscale deployments of Amazon Web Services (AWS).

PRJ-30670,
PRHF-19179

Security Gateway

In rare scenarios, when a Security Gateway is configured as Proxy, a wrong NAT port reuse may happen for 5 minutes long proxied connections.

PRJ-25029,
PMTR-16149

Security Gateway

When deleting all Suspicious Activity Monitoring (SAM) rules, adding a large number of new rules, and installing policy, the system may hang.

PRJ-27610,
PRHF-18068

Security Gateway

A debug message may be printed as an error.

PRJ-31968,
PMTR-74144

Security Gateway

In a rare scenario, "Connection/sec" data for accelerated traffic in CPView may differ from the statistics in SNMP.

PRJ-31218,
PRHF-19896

Security Gateway

When a large number of VPN tunnels is configured and each one is used by a static route with ping, the ROUTED process may get incorrect cluster IPs for those tunnels. Refer to sk175887.

PRJ-32337,
PMTR-72682

Security Gateway

Defining an IPv6 NAT rule with address range (hide) on the translated column may fail with an incorrect error message.

PRJ-30614,
PRHF-19614

Security Gateway

In rare scenarios, when SACK is enabled, there may be connectivity issues.

PRJ-30180,
PRHF-19438

Security Gateway

In a rare scenario, policy push to multiple Security Gateways may fail. Refer to sk177963.

PRJ-18400,
PMTR-57716

Security Gateway

The FWD process may unexpectedly exit due to a rare race condition. Refer to sk173424.

PRJ-29698,
PRHF-19097

Security Gateway

In rare a scenario, a memory leak may occur with a "cpas_streamh_init_from_cookie failed" message printed in /var/log/messages.

PRJ-32658,
PRHF-20471

Security Gateway

The Security Gateway may unexpectedly reboot and create a vmcore file.

PRJ-32050,
PMTR-72836

Security Gateway

In a rare scenario, the Security Gateway may crash during policy installation.

PRJ-32575,
PMTR-74852

Security Gateway

When deleting connection table entries with "fw ctl conntab -x", and using "rule", "service", "type", "flags" or "state" filters, entries that do not match these filters may still be deleted.

PRJ-33125,
PRHF-20306

Security Gateway

In some scenarios, memory consumption and CPU usage may increase consistently. Refer to sk176370.

PRJ-33493

Security Gateway

The "Policy installation failed on gateway" error message is shown when the policy is pushed to multiple R80.20 Quantum Spark appliances. Refer to sk176713.

PRJ-28448,
PMTR-64790

Security Gateway

DNS Server is getting overloaded with DNS requests from the Security Gateway when Domains or updatable objects are used in policy. The "Domain doesn't exist" error is shown.

PRJ-35902

Security Gateway

Uninstalling Jumbo Hotfix may cause interfaces to disappear.

PRJ-31017,
PRHF-19772

Internal CA

In a rare scenario, when CRL files are created, some of them may be generated with a large number in the filename. When deleting CRL files, CPCA repeatedly fails to start.

PRJ-33250,
PRHF-20709

Internal CA, VPN

Creating a certificate for a third party Gateway with Check Point Internal CA may fail on the third party side. Refer to sk176468.

PRJ-31462,
PRJ-27750

Threat Prevention

When the "Automatically download Blade Contracts, new software, and other important data" checkbox is unchecked, Security Gateway may fail to update Threat Prevention packages.

PRJ-33544,
PMTR-74799

Threat Prevention

When IPS Automatic update is enabled, a memory leak may occur in the FWD process. Refer to sk176947.

PRJ-37475,
PMTR-80602

Identity Awareness,

Identity Logging

UPDATE: Adjusted AD-Query and Identity Logging solutions to work with Microsoft hardening changes in DCOM which were required for CVE-2021-26414. Refer to sk176148.

PRJ-30493,
IDA-4120

Identity Awareness

UPDATE: Enhanced Identity Sharing SmartPull mechanism for large scale environments.

PRJ-32872,
PMTR-75155

Identity Awareness

When Identity Awareness Blade is enabled on the Security Gateway, rebooting of a member may trigger additional reboots. This may cause
one of the members to go down with a configuration pnote.

PRJ-30948,
IDA-4253

Identity Awareness

In some scenarios, persistent high CPU is caused by ADQuery due to a large number of authentication requests.

PRJ-30994,
PMTR-66375

Identity Awareness

In a rare scenario, the priorities defined in User Directory (Gateway level) override the default Domain Controller (DC) priorities defined in the LDAP Account unit. Servers with priority above 1000 are not ignored, although they should be.

PRJ-27736,
PRHF-17620

Identity Awareness

The PDPD process may fail with "daemon did not respond or not running!" or cause a high CPU.

PRJ-32127,
MPTT-5094

Identity Awareness

An Identity Broker subscriber may be shown as the session owner for Remote Access VPN sessions received from another publisher.

PRJ-28055,
SPC-1602

Application Control

In a rare scenario, the SSM may encounter an issue and stop working.

PRJ-29769,
PRHF-18914

URL Filtering

In a very rare scenario, when the Application Control (APPI) and URL filtering Blades are active, in hold mode, some applications cannot be identified and the traffic is dropped.

PRJ-28739,
PRHF-17049

IPS

In some scenarios, the destination IP is missing from the IPS logs. Refer to sk174588.

PRJ-30803,
PMTR-70772

IPS

After installing a Threat Prevention policy with many rules and/or exceptions, on multiple Security Gateways together, Security Gateways may consume more CPU during rule-match of new connections.

PRJ-23348,
PRHF-15859

IPS

The track logging configuration of Network Quota protection is not applied.

PRJ-28491,
PMTR-60451

IPS

In Autonomous Threat Prevention mode, "Profile Name" and "SmartDefense" fields may be missing in the IPS log.

PRJ-30606,
PRHF-18893

DLP

UPDATE: Added temporary files cleaner for file converting operation.

PRJ-30426,
PRHF-17395

DLP

The dlpu process may unexpectedly exit with core dump file.

PRJ-31167,
PMTR-72136

SSL Inspection

In some scenarios, the WSTLSD process may unexpectedly close, or a memory leak may occur.

PRJ-34446,
PRHF-21039

SSL Inspection

The fwk process may unexpectedly exit during the TLS handshake.

PRJ-34272,
PMTR-76812

SSL Inspection

A memory leak may occur in the WSTLSD process during session resumption for TLS 1.2.

PRJ-31202,
PMTR-73538

SSL Inspection

If TLS 1.3 is enabled, using imported ECDSA certificates for HTTPS Inspection may cause the Security Gateway to crash.

PRJ-31497,
PMTR-73619

SSL Inspection

When HTTPS Inspection is disabled and the "Categorize HTTPS websites" option is enabled, the "failed attaching RSA stub certificate to server" errors may appear in the fwk.elg and wstlsd.elg files during policy installation.

PRJ-32884,
PMTR-75079

SSL Inspection

When TLS 1.3 support is disabled, a memory leak may occur in the WSTLSD process during TLS session renegotiation.

PRJ-31173,
PMTR-72409

SSL Inspection

A memory leak, related to TLS probing, may occur in the WSTLSD process.

PRJ-33407,
PMTR-72934

SSL Inspection

In rare scenarios, TLS probing connections may remain open for extended periods.

PRJ-32901,
PRHF-20458

SSL Inspection

In a rare scenario, the WSTLSD process may unexpectedly exit and produce a core dump file.

PRJ-31232,
SNX-67

SSL Network Extender

SSL Network Extender (SNX) may fail during large file transfers. Refer to sk87760.

PRJ-31177,
PMTR-73946

Mobile Access

UPDATE: Upgraded JQuery library version (from 1.1 to 3.6).

PRJ-33876,
PMTR-61452

Mobile Access

Policy installation may fail due to table creation issues.

PRJ-32471,
PMTR-74101

ClusterXL

Added Syslog support for Cluster events messages.

PRJ-30382,
PRHF-19273

ClusterXL

In a rare scenario, after an upgrade and reboot, a Standby member is set to down with a FULLSYNC PNOTE and cannot synchronize.

PRJ-30819,
PRHF-19417

SecureXL

In a rare scenario, after an upgrade, HTTPS traffic may be dropped.

PRJ-28645,
PMTR-67800

SecureXL

A redundant message "ACC: Accelerator started. " is printed in dmesg logs.

PRJ-31487,
PRHF-19472

Routing

In some scenarios, the Security Gateway may not forward traffic to a client if its IP address is changed by DHCP. Refer to sk175603.

PRJ-24057,
PRHF-10260

Routing

In some scenarios, when using DHCP, the Security Gateway may not correctly route traffic to hosts.

PRJ-33356,
PMTR-75438

Routing

  • Security Gateway may crash when OSPF inserts or removes an LSA from its database.
  • Neighbor dead timers may have negative values.

PRJ-30027,
PMTR-69491

Routing

After a failover, OSPF may restart immediately after the ROUTED daemon starts which causes the Active member to go into Down state instead of Standby state.

PRJ-32424,
PRHF-20294

VPN, Multi-Portal

UPDATE: Certificate validation flow will use OCSP as the default revocation validation method. If OCSP URL does not exist, CRL will be used as a revocation validation method.

PRJ-31473,
PMTR-68362

VPN

UPDATE: In policy installation, the type of messages, related to VPN certificate expiration, is changed from "info" to "warning". This issue is only cosmetic.

PRJ-33738,
PMTR-75801

VPN

When applying Secure Configuration Verification (SCV) VPN client is not able to distinguish between Windows 10 and Windows 11.

PRJ-31108,
PRJ-28269,
PMTR-73487,
PRHF-7443

VPN

In some scenarios, a memory leak may occur in the VPND process.

PRJ-31290,
PRHF-19707

VPN

Hardened the ability to use narrowed IKEv2 tunnels. Refer to sk166417.

See the Important Notes section.

PRJ-32550,
PMTR-74599

VPN

A memory leak may occur during Office Mode IP allocation.

PRJ-32519,
PMTR-74732

VPN

Improved establishing IKEv2 tunnel with DAIP peer.

PRJ-30330,
PMTR-73629

VPN

In some scenarios, IKEv2 tunnel may not work due to SA expiration.

PRJ-30957,
PRHF-19492

VPN

Improvements for DAIP Gateway behind Hide NAT.

PRJ-32760,
PMTR-74107

VPN

The output of the "vpn tu tlist" command may show an incorrect type of S2S tunnels protocol.

PRJ-31132,
PMTR-73498

VPN

In some scenarios, a memory leak may occur in the VPND process.

PRJ-29782,
PMTR-72241

VPN

Although the Simultaneous Login Prevention (SLP) feature is on, the user can connect with two clients and receive the same statically assigned Office-Mode IP.

PRJ-32366,
PRHF-20315

VPN

Improved IKEv2 narrowing.

PRJ-32130,
PMTR-74244

VPN

The output of the "vpn tu tlist" command may show a wrong date and time in "Authenticated at" line, although machine date and time settings are correct.

PRJ-33834,
VPNRA-831

VPN

In rare scenarios, when SSL Network Extender (SNX) is in Application Mode, the VPND process may unexpectedly exit.

PRJ-31700,
PMTR-73801

VPN

When the IKE daemon is enabled, VPN counters in CPView may show incorrect value.

PRJ-30765,
PRHF-19548

VPN

In a very rare scenario, a cluster member may unexpectedly crash and restart, creating a core dump file.

PRJ-32596,
PMTR-72056

VPN

In some scenarios, Remote Access VPN users cannot connect to the Gateway due to a kernel table issue.

PRJ-24188,
PRHF-16198

VPN

VPN connectivity issues may occur when there are too many SAs. Refer to sk173828.

PRJ-32612,
PRHF-20449

VPN

In some scenarios, Remote Client connections in Visitor Mode may cause the fwk process to exit.

PRJ-31588,
PRHF-19959

VPN

In some scenarios, VPN tunnels statuses in SmartView Monitor are displayed incorrectly.

PRJ-30649,
ESVPN-2665

VPN

A machine-only tunnel cannot be established when VPN default realm is disabled.

PRJ-36420,
PMTR-79305

VPN

In some scenarios, when VPN logs are enabled and DAIP (Dynamically Assigned IP) peer is configured, the VPND daemon may unexpectedly exit.

PRJ-32533,
PMTR-74770

VSX

UPDATE: It is now possible to define interface topology as "defined by routes" using the VSX provisioning tool.

PRJ-33836,
PMTR-76280

VSX

UPDATE: Shadow bridges will now be automatically disabled on VSX Gateways if the bridges are not in Active/Active mode.

PRJ-22483,
PRHF-15744

VSX

In some scenarios, running the "snmpwalk" command may fail with incorrect OSPF-MIB information for VSX. Refer to sk172064.

PRJ-33946,
PMTR-76402

VSX

Policy installation on a VS may fail after a cluster conversion between High Availability and Virtual System Load Sharing with the "vsx_util" command.

PRJ-26975,
PRHF-17665

VSX

Multi-Queue configuration does not survive reboot on VSX. Refer to sk173950.

PRJ-37422,
PMTR-79515

VSX

After deleting a warp interface in SmartConsole, the active VSX cluster member may crash.

PRJ-30315,
PMTR-72515

Gaia OS

NEW: Gaia API (version 1.6) will now be deployed via Jumbo Hotfix. Refer to sk143612.

PRJ-31560,
PRJ-29510

Gaia OS

NEW: Added support for TE2000XN appliances.

PRJ-30202,
PRHF-18610

Gaia OS

UPDATE: Added a Clish command "add/show/delete ntp interface" to choose to which interfaces the NTP daemon shall bind.

PRJ-33688,
PMTR-75891

Gaia OS

Potential vulnerability related to specific Gaia API command on VSX systems.

PRJ-28685,
PMTR-71763

Gaia OS

In some scenarios, in appliances: 6600,6700,6900, Power Supply Unit (PSU) status information may be incorrect. Refer to sk174443.

PRJ-31754,
PMTR-70869

Gaia OS

In some scenarios, after adding an SNMP USM user, the confd process may unexpectedly exit.

PRJ-34589,
PRJ-33871

Gaia OS

Enhanced SNMP module stability.

PRJ-30212,
PRHF-19017

Gaia OS

  • VLAN IPv6 address disappears after setting the parent interface state "off" and "on".
  • IPv6 address disappears after enabling Layer 3 bridge interface monitoring.

Refer to sk174969.

PRJ-29065,
PMTR-62235

Gaia OS

Wrong output of the "set/delete ip-conflicts-monitor interface" command. The word "value" is printed multiple times. The issue is only cosmetic.

PRJ-33508,
PMTR-75443

Gaia OS

Fixed CVE-2021-30361 - Gaia Portal Authenticated Command Injection. Refer to sk179128.

PRJ-32248,
EPS-32816

Harmony Endpoint

NEW: Added new push operations to Endpoint Web Management:

  • Kill Process
  • Remote Command Execution
  • Application Scan

PRJ-33389,
EPS-33930

Harmony Endpoint

NEW: It is now possible to configure Super Node in Harmony Endpoint. Refer to sk171703.

PRJ-32886

Harmony Endpoint

NEW:

  • Added ability to rename the Export Package
  • Added persistent Notifications Center
  • Improved performance of Asset Management
  • Added extra fields to Asset Management table
  • It is now possible to configure user session idle time on-premise
  • Added support for macOS Port Protection
  • Added Connection Awareness settings
  • Added ability to manage IoCs

PRJ-32645,
PRHF-20524

Harmony Endpoint

  • When in "cpconfig"-> "GUI clients"-> "Modify" the option "Any" is deleted, the Endpoint Security Server UEPM Apache cannot start.
  • When manually launching UEPM Apache the following output is shown: "AH00526: Syntax error on line 1 of /opt/CPuepm-R81/apache/conf/acl.conf:ip address 'Require' appears to be invalid"

Refer to sk176186.

PRJ-27848,
PRHF-18031

Harmony Endpoint

SmartEndpoint may show deleted certificates as expired.

PRJ-32390,
PRHF-19878

VoIP

When using SIP, memory usage may increase over time on Active and Standby members.

PRJ-34519,
ODU-200

Smart-1 Cloud

After a cluster failover CloudGuard Controller may not be able to find cloud objects. Refer to sk166056.

PRJ-31769,
PMTR-73896

CloudGuard Network

Improved the handling of NSX-T Data Center throttling issues.

PRJ-31772,
PRHF-19949

CloudGuard Network

In a rare scenario, there is a high CPU0 utilization on Azure Security Gateway.

PRJ-32231,
CGIS-636

CloudGuard Network

The "vsec_lic_cli update" command now supports IP change in the license string.

PRJ-27035,
PRHF-16098

QoS

In a rare scenario, when QoS is enabled, in SmartView Monitor, some traffic may be shown as "No Match".

PRJ-30235,
PRHF-18342

QoS

In a rare scenario, the FWD process may unexpectedly exit due to invalid QoS logs.

PRJ-35158,
ODU-199

Scalable Platforms

NEW: Added a self-updatable package of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414.

PRJ-26373,
PMTR-68629

Scalable Platforms

NEW: Added ability to create and manage VSX objects of R80.30SP version via vsx_util and vsx_provisioning_tool.

PRJ-25360,
MBS-10302

Scalable Platforms

UPDATE:

  • The "asg_reboot" command was changed to perform a software reboot only.
  • The "asg_hard_reboot" command was added to perform a hardware reboot.

PRJ-28902,
MBS-5883

Scalable Platforms

UPDATE: Added ability to run the "hw_utilization" command on Quantum Maestro members.

PRJ-25339,
MBS-11397

Scalable Platforms

UPDATE: Added support for 40G SFP Transceiver for SSM440 (BTI40GSRQSFPP).

PRJ-29023,
PRHF-15323

Scalable Platforms

In a Dual Site Quantum Maestro environment, traffic may be interrupted intermittently when a Domain object is used in the Rule Base.

PRJ-33380,
MBS-14189

Scalable Platforms

VPN traffic may be dropped due to certificate issues.

PRJ-32952,
MBS-14928

Scalable Platforms

Identity Sharing in VSLS Mode may not work as expected.

PRJ-31405,
MBS-11234

Scalable Platforms

The "config_verify" command may fail in a Scalable Platforms environment.

PRJ-34102,
MBS-15063

Scalable Platforms

Changing VLAN of an existing interface may cause arp reply not to be processed by the Gateway. Refer to sk176929.

PRJ-31310,
PRHF-19908

Scalable Platforms

When IGMP snooping is disabled, using OSPF Multicast may lead to Anti Spoofing drops in SmartConsole.

PRJ-33203,
PMTR-75375

Scalable Platforms

RADIUS user that has gclish set as default shell cannot login into the Security Group on Scalable Platforms R81.10: "Unable to get user permissions". Refer to sk176364.

PRJ-30111,
MBS-14105

Scalable Platforms

VPN tunnel may fail to establish with "dropped by vpn_inbound_pilicy_chain Reason: VPN inbound nat after vm failed". Refer to sk176404.

PRJ-31838,
MBS-14732

Scalable Platforms

The CMM is not updated with the time from a configured NTP Server. As a result, SGMs stay in the Down state for a long time.

PRJ-26428,
MBS-13474

Scalable Platforms

In rare scenarios, the command "hw_utilization -d" fails when more than 9 Virtual Systems are configured.

PRJ-31138,
MBS-14560

Scalable Platforms

Connectivity issues may occur on Identity Server (PDP) in large VSX setups.

PRJ-25355,
MBS-10619

Scalable Platforms

The "Software Versions" asg diag test may show false failure because of a CMM version mismatch.

PRJ-28660,
MBS-14165

Scalable Platforms

SNMP OID .1.3.6.1.4.1.2620.1.48.16 (asgSecureXLStatusBitmask) returns the status of SecureXL as enabled, even when it is not.

PRJ-31590,
MBS-9793

Scalable Platforms

When running the "asg_dr_verifier" command in the context of a Virtual System other than VS0, the output in the "BGP peers" section incorrectly shows: "Status: Inconsistency found on some of the SGMs".

PRJ-34619,
MBS-14133

Scalable Platforms

In some scenarios, a physical link issue on a Maestro Gateway may cause an unexpected site failover, a cluster state change on other Gateways, or packet drops.

PRJ-31506,
PRHF-19991

Scalable Platforms

During policy installation, AD Query may stop working in the Scalable Platforms environment.

PRJ-30616,
PMTR-70886

Scalable Platforms

Multiple traffic drops may occur on Scalable Platforms. Refer to sk173545.

PRJ-25665,
PMTR-68916

Scalable Platforms

In some scenarios, if SSM goes down in a Chassis setup, the failure report cannot be collected fully.

PRJ-33326

Scalable Platforms

Added support for a new VMAC design. Refer to sk165674.

PRJ-34442,
ODU-217

HCP

Added Update 6 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-22354,
INFRA-528

Infrastructure

UPDATE: Updated Python 2.7.17 to 2.7.18, Python 3.7.7 to 3.7.12, added Python 3.9.7 and a Python3 alias.

PRJ-29411,
PRHF-19016

Infrastructure

Policy installation fails with "Operation failed, install/uninstall has been improperly terminated" when a CMA name is more than 36 characters long. Refer to sk175452.

PRJ-29951,
PRHF-19115

Infrastructure

In a rare scenario, the user cannot connect to the Mobile Access Portal.