R81 Jumbo Hotfix Take 68

 

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 68

Released on 27 April 2022 and declared as Recommended on 12 June 2022

PRJ-29848,
PRHF-18734

Diagnostics

In some scenarios, CPView shows the SNMP data partially.

PRJ-30407,
PRHF-19450

Security Management

UPDATE:

  • Added the "--help" and "-h" flags to "mdsstop", "mdsstart" and "mdsstat".
  • It is no longer possible to run the "mdsstop" and "mdsstart" commands with wrong parameters.

PRJ-34228,
PRHF-21357

Security Management

Deleting a Domain may fail when there is an administrator with API key authentication associated with this Domain.

PRJ-35479,
PMTR-77765

Security Management

Multi-Domain High Availability synchronization in the Global Domain may fail with the "There are invalid assignments on peer" error.

PRJ-32562,
PRHF-20316

Security Management

Login to SmartEvent with Certificate Authentication may fail. Refer to sk179144.

PRJ-34182,
PRHF-21215

Security Management

In rare scenarios, the Management Server becomes inaccessible if there are more than 5000 objects in the Gateways and Servers view.

PRJ-33804,
PMTR-76103

Security Management

The Management API command "set-multicast-address-range" does not remove IPs when the IPv4 or IPv6 address field is empty.

PRJ-34657,
PRHF-21286

Security Management

In a Multi-Domain Management environment, when fetching a Ldap branch using the "fetch" button from the Global Domain tab, the operation may fail.

PRJ-30113,
PRHF-17611

Security Management

In rare scenarios, the "show-changes" and "show-sessions" Management API commands may fail.

PRJ-36802,
PMTR-74772

Security Management

In some scenarios, the last modifier name is missing in unpublished sessions and SmartConsole unexpectedly closes.

PRJ-33401,
PRHF-20866

Security Management

When automatic purge is configured in a local Domain and there is an assignment between the Global Domain to that Domain, the "show-automatic purge" API command may fail in the Global Domain with the "Can't build automatic purge reply" error. Refer to sk176443.

PRJ-35950,
PRHF-21894

Security Management

In the Compliance view, after changing "Policy Range" to a value smaller than 100%, best practices results become not available. Refer to sk177544.

PRJ-33565,
PMTR-75061

Security Management

In rare scenarios, a "Create Domain", "Delete Domain" or "Delete Domain Server" task can be stuck at 5% with the "Task in queue" status.

PRJ-32848,
PMTR-74961

Security Management

In rare scenarios, taking over a session may fail with "SmartConsole has experienced an unexpected error. Session operation failure".

PRJ-34178,
PRHF-20991

Security Management

In rare scenarios, Install Policy Presets may fail with "Failed to run Install Policy on the active Domain Server".

PRJ-35225,
PRHF-21778

Security Management

When exporting rules with "hit counts" and the timeframe is set to a different value than "all", the "hit counts" are missing from the export file. Refer to sk177265.

PRJ-32718,
PRHF-20332

Security Management

If there is a Global Domain Assignment, some results may be missing when searching in Packet Mode. Refer to sk178491.

PRJ-35017,
PRHF-21705

Security Management

Install Policy Verification may fail with the "Rule has security zone objects that are not attached to any interface used" error when configuring cluster's interfaces on only one member. Refer to sk177129.

PRJ-32132,
PRHF-20181

Security Management

When working with End Point Cloud, the License tab under "Gateways and Servers" in SmartConsole may show "Certificate error: CertAuthorityInvalid".

PRJ-33242,
PRHF-20643

Security Management

In rare scenarios, after an update, the Management Server fails to start.

PRJ-34772,
PRHF-20960

Security Management

Policy installation on R81 (and below) Gateways may fail when there are multiple login options configured with SAML which uses Identity Provider as an authentication method. Refer to sk176725.

PRJ-35339,
PRHF-21851

Security Management

In rare scenarios, the Management Server may fail to start after an upgrade.

PRJ-33365,
PRHF-20847

Security Management

Global Domain Assignment fails with "An internal error has occurred" when there are more than 32K Threat Prevention Overrides in the local Domain. Refer to sk176464.

PRJ-32746,
PRHF-20512

Security Management

In a rare scenario, the FWM process unexpectedly exits.

PRJ-32802,
PRHF-20435

Security Management

The mgmt_cli tool (API) with certificate login may not work.

PRJ-37578,
PMTR-80846

Security Management

In some scenarios, after editing Blades in simple-gateway/cluster Ansible modules, the Blades are not changed, and Ansible shows that no changes occurred.

PRJ-36622,
PMTR-79023

Logging

UPDATE: SmartView reports will now show the new Check Point logo.

PRJ-30550,
PRHF-19084

Logging

In rare scenarios, when QoS Blade is enabled, the FWD process may unexpectedly exit. Refer to sk177783.

PRJ-29174,
PRHF-18866

Logging

Removed unnecessary debug messages: "fwbintabreplace: table svm_range_gateways not found" and "fwbintabreplace: table svm_range_gateways_valid not found" from the fwd debug log.

PRJ-32018,
PRHF-20117

Logging

When running the "show_logs" API command with "query-id argument" and the session is expired, the command ends with a timeout instead of presenting an error.

PRJ-32373,
PRHF-18699

Logging

When running CPinfo in a large scale environment, the SmartEventCollectLogs process may get stuck.

PRJ-30145,
PMTR-60786

Logging

Recurring "Unable to open '/dev/fw0': No such file or directory" may be printed in the fwd.elg file.

PRJ-35201,
PRHF-20349

Logging

In a rare scenario, the Security Management Server does not automatically delete older log files.Refer to sk177627.

PRJ-34142,
PRHF-21218

Logging

On the Domain level, in the Logs view, available services may not appear in the drop-down filter list. Refer to sk178904.

PRJ-32580,
PRHF-20447

Logging

In some scenarios, it is not possible to add the "Policy Rule UID" column to the Logs view in the SmartView Web Application.

PRJ-31495,
PRHF-7049

Security Gateway

UPDATE: A shadow rule can be added if the new rule and the existing rule have different timeouts.

PRJ-29963,
UP-452

Security Gateway

UPDATE: Added two minutes grace period before dropping the non-TCP server-to-client packets upon policy installation and rematch flow. Refer to sk173287.

PRJ-35098,
PMTR-76491

Security Gateway

UPDATE: Added a new global parameter: "fw_daf_module_mac_mode". It allows mirroring traffic to a Linux-based device. It is set to "0" by default. Refer to sk178127.

PRJ-35098,
PMTR-76491

Security Gateway

UPDATE: Added a new global parameter: "fw_daf_module_mac_mode". It allows mirroring traffic to a Linux-based device. It is set to "0" by default. Refer to sk178127.

PRJ-31666,
PMTR-68092

Security Gateway

UPDATE: Adding Connection and Packet Distribution statistics in CPView.

PRJ-38236,
PMTR-81910

Security Gateway

UPDATE: Apache HTTPD version was updated from 2.4.51 to 2.4.53.

PRJ-31495,
PRHF-7049

Security Gateway

UPDATE: Following sk110157, adding a shadow SAM V1 rule is now possible only if the new rule and the existing rule have different timeouts. If a shadow rule exists, the new shadow rule will override the existing shadow rule.

PRJ-32792,
PRHF-20498

Security Gateway

Matched rules on Inline layer may appear as the "Accept'"/ "Drop" action instead of "Inline".

PRJ-35007,
PRHF-21742

Security Gateway

The dynamic NAT allocation port warning is continuously printed in /var/log/messages. Refer to sk177228.

PRJ-32926,
PRJ-32352

Security Gateway

When running the "cpstop" and "cpstart" commands, NAT statistics may fail with "fwx_alloc_global_find_free_port_atomic: failed to update NAT statistics".

PRJ-28821,
PMTR-71776

Security Gateway

In rare scenarios, policy installation fails when adding a Cloudguard object to the NAT rulebase.

PRJ-36048,
PMTR-78861

Security Gateway

In a rare scenario, DNS connection may be dropped with a "up_manager_cmi_handler_match_cb: connection not found" message.

PRJ-34727,
PRHF-21103

Security Gateway

In rare scenarios, if temporary files were not deleted successfully, downloading certain file types may fail with one of these errors:

  • "Content Awareness - Error while processing X: Timeout reach during text extraction"
  • "Content Awareness - Error while processing X: File appears corrupted"
  • "Too many files in archive: SSH parsing error occurred"

PRJ-36994,
PRJ-36993

Security Gateway

  • On 2200 appliances, the CPD process may unexpectedly exit because of sensor read failure.
  • Sensor table values for 3600, 3600T, 3800, 6200B, 6200P, 6200T, 6400, 6600, 6700, 6900, 7000, 600-S are incorrect.

PRJ-33612,
PRHF-20810

Security Gateway

In a rare scenario, the FWD process may unexpectedly exit.

PRJ-34256,
PRHF-20783

Security Gateway

It may not be possible to use the Office 365 Tenant Restrictions feature when ICAP client is enabled.

PRJ-33998,
PRHF-18340

Security Gateway

In rare scenarios, slow path connections that should be terminated/aborted may remain open until the timeout.

PRJ-23480,
PRHF-16013

Security Gateway

Policy installation may fail when there is a heavy load on memory on the Security Gateway.

PRJ-33274,
PMTR-26836

Security Gateway

The control connection may not be refreshed together with the data connection if the data connection is accelerated. Refer to sk168952.

PRJ-31208,
PRHF-19333

Security Gateway

The Security Gateway may crash during policy installation due to memory allocation problems.

PRJ-34268,
PRHF-19587

Security Gateway

The log_exporter process may consume a high CPU.

PRJ-37529,
PRHF-22491

Security Gateway

Improved Gateway internal memory allocation logic.

PRJ-35154

Threat Prevention

While using the Security Zone object in the "Source" column in the Threat Prevention policy, Security Gateways R80.40 and lower do not drop traffic. Refer to sk177605.

PRJ-34218,
PRJ-34088

Threat Prevention

IPS and other Threat Prevention logs may not contain packet capture. And dmesg may be flooded with related errors.

PRJ-34705,
PMTR-77304

Threat Prevention

In a rare scenario, after excessive memory usage, kernel may crash.

PRJ-30445,
PRHF-17552

Threat Prevention

In a rare scenario, the DLP process leaves open unused file descriptors in the $FWDIR/tmp/dlp directory which may take up a large amount of disk space.

PRJ-36165,
PRHF-21680

Identity Awareness

In a rare scenario, the PDP process may unexpectedly exit with a core dump file.

PRJ-28219,
PRHF-15223

Identity Awareness

There may be connectivity issues and high CPU spikes on the PDPD, VPND processes, and on the Gateway when installing policy. Refer to sk174144.

PRJ-35821,
PRHF-21396

Identity Awareness

On Scalable Platforms\Cluster LS, the Identity Database may become corrupted when an identity session is revoked from a non-master member.

PRJ-32699,
PRHF-14110

Identity Awareness

Memory usage may be high for the pdpd process in a scenario, related to Identity Awareness nested groups in state 2 and 4.

PRJ-33148,
PRHF-20682

URL Filtering

In some scenarios, websites encrypted with SSL are not matched correctly when categorization mode is on Hold and IDA is enabled. Refer to sk176283.

PRJ-34515,
PRHF-20998

URL Filtering

In a rare scenario, when URL Filtering Blade is active, in Website categorization background mode, the FWK process crashes and creates a core dump.

PRJ-37544,
PRHF-22301

IPS

In a rare scenario, when the Security Gateway is configured as a proxy, file download may fail.

PRJ-29428,
PRHF-18966

IPS

When Website categorization mode is set to "Hold" and Gateway is Proxy, some connections may be incorrectly terminated.

PRJ-32610,
PRHF-20132

IPS

When Anti-Virus and/or gzip inspection are enabled on the Gateway, during CloudFlare inspection of specific websites, the Gateway may drop traffic.

PRJ-34645,
PRHF-21416

DLP

In a rare scenario, the DLP process may not delete temporary files used for scanning.

PRJ-33210,
PRHF-20674

DLP

The dlpu process may unexpectedly exit, producing a core dump file.

PRJ-33002,
PMTR-75153

SSL Inspection

UPDATE: Upgraded the default Infrastructure for local communication between some processes to TLS 1.2.

PRJ-38257,
PMTR-81157

SSL Inspection

In some scenarios, the FWK process may unexpectedly exit during the TLS handshake.

PRJ-33669,
PMTR-75807

SSL Inspection

In some scenarios, the WSTLSD daemon may unexpectedly exit during TLS probing.

PRJ-36355,
PMTR-79533

SSL Inspection

A connectivity issue may occur with certain TLS clients.

PRJ-30125,
PMTR-66344

SSL Inspection

When HTTPS Inspection is enabled, and traffic is inspected, detect logs for HTTPS traffic may show the "Invalid CRL Retrieved" and "No Valid CRL" error messages. Refer to sk172345.

PRJ-36299,
PMTR-76171

SSL Inspection

A memory leak related to TLS probe may occur in the WSTLSD process.

PRJ-36496,
PMTR-79264

SSL Inspection

In a rare scenario, the WSTLSD process may unexpectedly exit while validating signatures of sites with improper certificate chains.

PRJ-35782,
PMTR-76030

SSL Inspection

When running cipher_util in any VS other than VS0, the "Cannot access features configuration directory" error is shown.

PRJ-34701,
PMTR-76511

SSL Inspection

Connections may hang and reach a timeout during browsing if the number of WSTLSD instances is reduced through configuration settings.

PRJ-33955,
PMTR-75000

SSL Inspection

A connectivity issue may occur after changing the Security Gateway's name and installing policy.

PRJ-34974,
PMTR-77321

SSL Inspection

In rare scenarios, the WSTLSD daemon may unexpectedly restart.

PRJ-35935,

PRJ-35934

SSL Network Extender

UPDATE: SSL Network Extender was updated to version 800008304. It provides TLS 1.2 cipher suites support on macOS.

PRJ-35245,
PMTR-78041

Mobile Access

MAB Guacamole-based clientless RDP/SSH connections, when closed prematurely, may cause the GuacProxy process to consume 100% CPU.

PRJ-36059,
PRHF-22134

Mobile Access

Capsule Workspace cannot connect to a Mobile Access Gateway when Citrix application is configured and allowed to the end-user's group.

PRJ-35979,
PMTR-74818

ClusterXL

A cluster failover may take longer than it should.

PRJ-36915,
PRHF-22274

ClusterXL

During policy installation, the state of SMO may not be stable.

PRJ-38370,
PRHF-23291

ClusterXL

Multicast packets may be dropped after policy installation.

PRJ-33582,
PMTR-75970

SecureXL

In some scenarios, fragmented Cluster LS packets are dropped by SecureXL.

PRJ-36471,
PRHF-21775

SecureXL

The VSX Gateway may crash when trying to route traffic from a VS to a Virtual Switch (VSW).

PRJ-36073,
PRJ-34902

SecureXL

In some scenarios, related to sending multicast packets, the ICMP errors may be shown.

PRJ-34340,
PMTR-73930

SecureXL

The "fwaccel dos rate add" command may fail with the "Another fwaccel command is already in progress" error.

PRJ-30714,
PRHF-18975

Routing

Connectivity issues may occur after configuration of route based VPN (VTI interface). Refer to sk176368.

PRJ-34711,
PMTR-73184

Routing

In rare scenarios, the ROUTED daemon may unexpectedly exit or write logs in the incorrect order.

PRJ-35769,
PMTR-77756

Routing

UPDATE: Routed debug log will now show IP addresses.

PRJ-35341

Routing

The ROUTED daemon may unexpectedly exit with core dump when some interfaces lose connection with the PIM router.

PRJ-37590,
PRHF-22751

VPN

During policy installation when using DAIP behind hide NAT, CPU usage for the VPND process may be high.

PRJ-29881,
PRHF-19050

VPN

Improved VPN interoperability.

PRJ-34374,
PMTR-75526

VPN

In rare scenarios, Remote Access users cannot connect to the Gateway because of certificate authentication failure.

PRJ-35430,
PMTR-78314

VPN

In some scenarios, L2TP users cannot connect to the Gateway in a cluster environment.

PRJ-34493

VPN

Remote Access users may not be able to connect when authenticating using a certificate issued by a subordinate CA.

PRJ-38810,
PRJ-38729

VPN

In some scenarios, it is not possible to connect with Remote Access using DHCP for Office Mode. Refer to sk178767.

See the Important Notes section.

PRJ-33656,
PRHF-21022

VPN

The VPND process may unexpectedly exit with a core dump file.

PRJ-35766,
SMB-16977

VPN

Enhanced stability of Site-to-Site VPN with interoperable devices.

PRJ-35391,
VPNS2S-2769

VPN

Improvements for IKEv2 when working with DAIPs.

PRJ-35474,
PRJ-35309,
VPNS2S-2847,
PMTR-74009

VPN

Added VPN improvements for IKEv2 SA re-key.

PRJ-35047,
PMTR-77549

VPN

In some scenarios, NAT-T tunnel establishment may fail.

PRJ-29544,
VPNS2S-2548

VPN

Newly defined ROBO Gateways cannot connect until policy installation.

PRJ-35559,
PMTR-78462

VPN

A memory leak may occur in the VPND process when using Remote Access Secondary Connect.

PRJ-35343,
VPNS2S-2701

VPN

Policy installation and establishing a connection from a Gateway with Static IP may fail, if the IP address was previously used by a peer Gateway with DAIP IP which was configured before and had a connection from the DAIP Encryption Domain.

PRJ-35231,
PMTR-73490

VPN

SSL entries may not be deleted from the "vpn tu tlist" command output, although there was a graceful exit.

PRJ-35398,
PRJ-35346,
PRJ-35401,PRJ-35404,
VPNS2S-2457,
VPNS2S-2770,
VPNS2S-2848,
VPNS2S-2822

VPN

IKEv2 Improvements for DAIP Gateway behind Hide NAT.

PRJ-36180,
PMTR-78626

VPN

The FWK process may unexpectedly exit on a VS with an S2S VPN tunnel.

PRJ-35535,
PMTR-78432

VPN

A memory leak may occur in the VPND process when using remote Access Back Connection.

PRJ-35387,
VPNS2S-2726

VPN

In some scenarios, the RIM script is not activated in DPD Tunnel monitoring.

PRJ-35556,
PMTR-78436

VPN

A memory leak may occur in the VPND process when using Remote Access with Multiple Entry Points configured.

PRJ-34211,
PMTR-74824

VPN

IKEv2 ID configuration may not be applied when an IPv6 address is written as a certificate's alternative name.

PRJ-35488,
VPNS2S-2740

VPN

In ike_sa_table there may be an entry with an IP address and not with a DAIP ID.

PRJ-36238,
PRHF-22206

VPN

A memory leak may occur in the VPND process.

PRJ-34672,
PMTR-77130

VSX

UPDATE: The "vsx_util reconfigure" operation is not supported on a VSX cluster member or VSX Gateway which has no virtual systems configured. The operation will now alert about the absence of virtual systems.

PRJ-36688,
PMTR-72627

VSX

In a Multi-Domain environment, the "vsx_util vsls" command may take a few minutes to run.

PRJ-32079,
PMTR-74295

VSX

When creating a static route on a virtual system, some network objects may be created with the same name inside the network group which causes failure in writing the object to the database.

PRJ-35000,
PMTR-77287

VSX

The "vsx_util reconfigure" command may fail without printing the cause of the error.

PRJ-34603,
PMTR-74840

VSX

In some scenarios, the VSX Gateway may incorrectly handle broadcast packets received from a Virtual Switch.

PRJ-35070,
PMTR-67275

VSX

When creating a new virtual system, some VSLS parameters like the Virtual System's weight value may be displayed wrong.

PRJ-36770,
PRJ-36756

Gaia OS

NEW: Gaia API (version 1.6 with Python3 support) will now be deployed via Jumbo Hotfix. Refer to sk143612.

PRJ-35003,
PMTR-77709

Gaia OS

Fixed the CVE-2020-14145 vulnerability.

PRJ-31696,
PMTR-73594

Gaia OS

The "cpopenssl" command may fail with "No such file or directory".

PRJ-36543,
PRHF-13255

Gaia OS

When adding an SSH host key, it won't be displayed because the total length of the command line cannot contain more than 512 characters.

PRJ-37224,
PMTR-63343

Gaia OS

Upgrade process may fail due to corrupted sic_local_cert.p12 certificate. Refer to sk171253.

PRJ-27909,
PRHF-17814

Harmony Endpoint

In some scenarios, logs related to Harmony Endpoint may be missing.

PRJ-29972,
PRHF-16925

Harmony Endpoint

In some scenarios, a query which counts host_ckp objects may return more results than expected. It leads to a memory leak with the "Out Of Memory" error.

PRJ-36364,
PRHF-22181

CloudGuard Network

When booting up, the NSX-T CloudGuard Gateway may crash.

PRJ-36274,
PRHF-22059

CloudGuard Network

In some scenarios, incorrect data center updates are pushed to the Gateway.

PRJ-34527,
PRHF-21383

CloudGuard Network

When a Gateway's object name was changed, CloudGuard Central License Tool may fail to distribute licenses to the Gateway.

PRJ-32917,
PMTR-75175

CloudGuard Network

NEW:

  • Rule base search in SmartConsole now also matches rules with Data Center Objects.
  • In SmartConsole, it is now possible to see IP addresses of all the objects included in: AWS VPC and Availability Zone, Azure Virtual Network, GCP Network
  • In SmartConsole, improved searching objects using tags.

PRJ-35548,
PRHF-21841

CloudGuard Network

When there are VS's with same name prefix, the CloudGuard Controller fails to update the VS with Data Center Objects.

PRJ-37053,
PRHF-20096

CloudGuard Network

In some scenarios, Data Center objects are not enforced on an AWS GEO cluster (Active/Active) Gateway. Refer to sk175904.

See the Important Notes section.

PRJ-36704,
ODU-244

Public Cloud CA Bundle

Added Take 14 of Public Cloud CA Bundle. Refer to sk172188.

PRJ-35612,
PMTR-77091

Scalable Platforms

Setting time on Quantum Scalable Chassis may fail with the "Failed to update the date WARNING: CliError( ) called without module or error code" error.

PRJ-29821,
PMTR-73394

Scalable Platforms

On a Scalable Platform configured in VSX mode, a new member added to a Security Group may stay in Down state because of a false-positive license issue.

PRJ-36593,
MBS-13315

Scalable Platforms

NEW: A new module parameter "ccl_correct_dr_between_chassis" is added.

  • Setting it to 0 disables inter-chassis corrections.
  • Setting it to 1 returns to the default behavior.

Refer to sk177943.

PRJ-36650,
MBS-15367

Scalable Platforms

Running "cphaconf debug_data" in VSX context may cause the Gateway to crash.

PRJ-35090,
PRHF-21133

Scalable Platforms

Security Group may drop traffic during an internal failover between Security Group members when Dynamic Anti-Spoofing is enabled. Refer to sk177946.

PRJ-34216,
PMTR-76383

Scalable Platforms

In some scenarios, when accelerated policy installation is performed on a Security Gateway that doesn't have a valid policy, an obscure failure message is shown.

PRJ-36360,
PRHF-22250

Scalable Platforms

OSPF may install a route to the incorrect IP when configured as P2P. Refer to sk177686.

PRJ-37216,
PMTR-80218

Scalable Platforms

Local connection from a Standby site may be dropped if there is a switch between the sites. Refer to sk178045.

PRJ-26825

Scalable Platforms

Restoring a backup on the security group may get stuck upon reboot.

PRJ-34048,
PMTR-76324

Scalable Platforms

After changing Multi-Queue configurations, members may remain in Down state.

PRJ-36830,
ODU-287

HCP

Added Update 7 of HealthCheck Point (HCP) Release. Refer to sk171436.