R81 Jumbo Hotfix Take 68
List of Resolved Issues and New Features
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 68 Released on 27 April 2022 and declared as Recommended on 12 June 2022 |
||
PRJ-29848, |
Diagnostics |
In some scenarios, CPView shows the SNMP data partially. |
PRJ-30407, |
Security Management |
UPDATE:
|
PRJ-34228, |
Security Management |
Deleting a Domain may fail when there is an administrator with API key authentication associated with this Domain. |
PRJ-35479, |
Security Management |
Multi-Domain High Availability synchronization in the Global Domain may fail with the "There are invalid assignments on peer" error. |
PRJ-32562, |
Security Management |
Login to SmartEvent with Certificate Authentication may fail. Refer to sk179144. |
PRJ-34182, |
Security Management |
In rare scenarios, the Management Server becomes inaccessible if there are more than 5000 objects in the Gateways and Servers view. |
PRJ-33804, |
Security Management |
The Management API command "set-multicast-address-range" does not remove IPs when the IPv4 or IPv6 address field is empty. |
PRJ-34657, |
Security Management |
In a Multi-Domain Management environment, when fetching a Ldap branch using the "fetch" button from the Global Domain tab, the operation may fail. |
PRJ-30113, |
Security Management |
In rare scenarios, the "show-changes" and "show-sessions" Management API commands may fail. |
PRJ-36802, |
Security Management |
In some scenarios, the last modifier name is missing in unpublished sessions and SmartConsole unexpectedly closes. |
PRJ-33401, |
Security Management |
When automatic purge is configured in a local Domain and there is an assignment between the Global Domain to that Domain, the "show-automatic purge" API command may fail in the Global Domain with the "Can't build automatic purge reply" error. Refer to sk176443. |
PRJ-35950, |
Security Management |
In the Compliance view, after changing "Policy Range" to a value smaller than 100%, best practices results become not available. Refer to sk177544. |
PRJ-33565, |
Security Management |
In rare scenarios, a "Create Domain", "Delete Domain" or "Delete Domain Server" task can be stuck at 5% with the "Task in queue" status. |
PRJ-32848, |
Security Management |
In rare scenarios, taking over a session may fail with "SmartConsole has experienced an unexpected error. Session operation failure". |
PRJ-34178, |
Security Management |
In rare scenarios, Install Policy Presets may fail with "Failed to run Install Policy on the active Domain Server". |
PRJ-35225, |
Security Management |
When exporting rules with "hit counts" and the timeframe is set to a different value than "all", the "hit counts" are missing from the export file. Refer to sk177265. |
PRJ-32718, |
Security Management |
If there is a Global Domain Assignment, some results may be missing when searching in Packet Mode. Refer to sk178491. |
PRJ-35017, |
Security Management |
Install Policy Verification may fail with the "Rule has security zone objects that are not attached to any interface used" error when configuring cluster's interfaces on only one member. Refer to sk177129. |
PRJ-32132, |
Security Management |
When working with End Point Cloud, the License tab under "Gateways and Servers" in SmartConsole may show "Certificate error: CertAuthorityInvalid". |
PRJ-33242, |
Security Management |
In rare scenarios, after an update, the Management Server fails to start. |
PRJ-34772, |
Security Management |
Policy installation on R81 (and below) Gateways may fail when there are multiple login options configured with SAML which uses Identity Provider as an authentication method. Refer to sk176725. |
PRJ-35339, |
Security Management |
In rare scenarios, the Management Server may fail to start after an upgrade. |
PRJ-33365, |
Security Management |
Global Domain Assignment fails with "An internal error has occurred" when there are more than 32K Threat Prevention Overrides in the local Domain. Refer to sk176464. |
PRJ-32746, |
Security Management |
In a rare scenario, the FWM process unexpectedly exits. |
PRJ-32802, |
Security Management |
The mgmt_cli tool (API) with certificate login may not work. |
PRJ-37578, |
Security Management |
In some scenarios, after editing Blades in simple-gateway/cluster Ansible modules, the Blades are not changed, and Ansible shows that no changes occurred. |
PRJ-36622, |
Logging |
UPDATE: SmartView reports will now show the new Check Point logo. |
PRJ-30550, |
Logging |
In rare scenarios, when QoS Blade is enabled, the FWD process may unexpectedly exit. Refer to sk177783. |
PRJ-29174, |
Logging |
Removed unnecessary debug messages: "fwbintabreplace: table svm_range_gateways not found" and "fwbintabreplace: table svm_range_gateways_valid not found" from the fwd debug log. |
PRJ-32018, |
Logging |
When running the "show_logs" API command with "query-id argument" and the session is expired, the command ends with a timeout instead of presenting an error. |
PRJ-32373, |
Logging |
When running CPinfo in a large scale environment, the SmartEventCollectLogs process may get stuck. |
PRJ-30145, |
Logging |
Recurring "Unable to open '/dev/fw0': No such file or directory" may be printed in the fwd.elg file. |
PRJ-35201, |
Logging |
In a rare scenario, the Security Management Server does not automatically delete older log files.Refer to sk177627. |
PRJ-34142, |
Logging |
On the Domain level, in the Logs view, available services may not appear in the drop-down filter list. Refer to sk178904. |
PRJ-32580, |
Logging |
In some scenarios, it is not possible to add the "Policy Rule UID" column to the Logs view in the SmartView Web Application. |
PRJ-31495, |
Security Gateway |
UPDATE: A shadow rule can be added if the new rule and the existing rule have different timeouts. |
PRJ-29963, |
Security Gateway |
UPDATE: Added two minutes grace period before dropping the non-TCP server-to-client packets upon policy installation and rematch flow. Refer to sk173287. |
PRJ-35098, |
Security Gateway |
UPDATE: Added a new global parameter: "fw_daf_module_mac_mode". It allows mirroring traffic to a Linux-based device. It is set to "0" by default. Refer to sk178127. |
PRJ-35098, |
Security Gateway |
UPDATE: Added a new global parameter: "fw_daf_module_mac_mode". It allows mirroring traffic to a Linux-based device. It is set to "0" by default. Refer to sk178127. |
PRJ-31666, |
Security Gateway |
UPDATE: Adding Connection and Packet Distribution statistics in CPView. |
PRJ-38236, |
Security Gateway |
UPDATE: Apache HTTPD version was updated from 2.4.51 to 2.4.53. |
PRJ-31495, |
Security Gateway |
UPDATE: Following sk110157, adding a shadow SAM V1 rule is now possible only if the new rule and the existing rule have different timeouts. If a shadow rule exists, the new shadow rule will override the existing shadow rule. |
PRJ-32792, |
Security Gateway |
Matched rules on Inline layer may appear as the "Accept'"/ "Drop" action instead of "Inline". |
PRJ-35007, |
Security Gateway |
The dynamic NAT allocation port warning is continuously printed in /var/log/messages. Refer to sk177228. |
PRJ-32926, |
Security Gateway |
When running the "cpstop" and "cpstart" commands, NAT statistics may fail with "fwx_alloc_global_find_free_port_atomic: failed to update NAT statistics". |
PRJ-28821, |
Security Gateway |
In rare scenarios, policy installation fails when adding a Cloudguard object to the NAT rulebase. |
PRJ-36048, |
Security Gateway |
In a rare scenario, DNS connection may be dropped with a "up_manager_cmi_handler_match_cb: connection not found" message. |
PRJ-34727, |
Security Gateway |
In rare scenarios, if temporary files were not deleted successfully, downloading certain file types may fail with one of these errors:
|
PRJ-36994, |
Security Gateway |
|
PRJ-33612, |
Security Gateway |
In a rare scenario, the FWD process may unexpectedly exit. |
PRJ-34256, |
Security Gateway |
It may not be possible to use the Office 365 Tenant Restrictions feature when ICAP client is enabled. |
PRJ-33998, |
Security Gateway |
In rare scenarios, slow path connections that should be terminated/aborted may remain open until the timeout. |
PRJ-23480, |
Security Gateway |
Policy installation may fail when there is a heavy load on memory on the Security Gateway. |
PRJ-33274, |
Security Gateway |
The control connection may not be refreshed together with the data connection if the data connection is accelerated. Refer to sk168952. |
PRJ-31208, |
Security Gateway |
The Security Gateway may crash during policy installation due to memory allocation problems. |
PRJ-34268, |
Security Gateway |
The log_exporter process may consume a high CPU. |
PRJ-37529, |
Security Gateway |
Improved Gateway internal memory allocation logic. |
PRJ-35154 |
Threat Prevention |
While using the Security Zone object in the "Source" column in the Threat Prevention policy, Security Gateways R80.40 and lower do not drop traffic. Refer to sk177605. |
PRJ-34218, |
Threat Prevention |
IPS and other Threat Prevention logs may not contain packet capture. And dmesg may be flooded with related errors. |
PRJ-34705, |
Threat Prevention |
In a rare scenario, after excessive memory usage, kernel may crash. |
PRJ-30445, |
Threat Prevention |
In a rare scenario, the DLP process leaves open unused file descriptors in the $FWDIR/tmp/dlp directory which may take up a large amount of disk space. |
PRJ-36165, |
Identity Awareness |
In a rare scenario, the PDP process may unexpectedly exit with a core dump file. |
PRJ-28219, |
Identity Awareness |
There may be connectivity issues and high CPU spikes on the PDPD, VPND processes, and on the Gateway when installing policy. Refer to sk174144. |
PRJ-35821, |
Identity Awareness |
On Scalable Platforms\Cluster LS, the Identity Database may become corrupted when an identity session is revoked from a non-master member. |
PRJ-32699, |
Identity Awareness |
Memory usage may be high for the pdpd process in a scenario, related to Identity Awareness nested groups in state 2 and 4. |
PRJ-33148, |
URL Filtering |
In some scenarios, websites encrypted with SSL are not matched correctly when categorization mode is on Hold and IDA is enabled. Refer to sk176283. |
PRJ-34515, |
URL Filtering |
In a rare scenario, when URL Filtering Blade is active, in Website categorization background mode, the FWK process crashes and creates a core dump. |
PRJ-37544, |
IPS |
In a rare scenario, when the Security Gateway is configured as a proxy, file download may fail. |
PRJ-29428, |
IPS |
When Website categorization mode is set to "Hold" and Gateway is Proxy, some connections may be incorrectly terminated. |
PRJ-32610, |
IPS |
When Anti-Virus and/or gzip inspection are enabled on the Gateway, during CloudFlare inspection of specific websites, the Gateway may drop traffic. |
PRJ-34645, |
DLP |
In a rare scenario, the DLP process may not delete temporary files used for scanning. |
PRJ-33210, |
DLP |
The dlpu process may unexpectedly exit, producing a core dump file. |
PRJ-33002, |
SSL Inspection |
UPDATE: Upgraded the default Infrastructure for local communication between some processes to TLS 1.2. |
PRJ-38257, |
SSL Inspection |
In some scenarios, the FWK process may unexpectedly exit during the TLS handshake. |
PRJ-33669, |
SSL Inspection |
In some scenarios, the WSTLSD daemon may unexpectedly exit during TLS probing. |
PRJ-36355, |
SSL Inspection |
A connectivity issue may occur with certain TLS clients. |
PRJ-30125, |
SSL Inspection |
When HTTPS Inspection is enabled, and traffic is inspected, detect logs for HTTPS traffic may show the "Invalid CRL Retrieved" and "No Valid CRL" error messages. Refer to sk172345. |
PRJ-36299, |
SSL Inspection |
A memory leak related to TLS probe may occur in the WSTLSD process. |
PRJ-36496, |
SSL Inspection |
In a rare scenario, the WSTLSD process may unexpectedly exit while validating signatures of sites with improper certificate chains. |
PRJ-35782, |
SSL Inspection |
When running cipher_util in any VS other than VS0, the "Cannot access features configuration directory" error is shown. |
PRJ-34701, |
SSL Inspection |
Connections may hang and reach a timeout during browsing if the number of WSTLSD instances is reduced through configuration settings. |
PRJ-33955, |
SSL Inspection |
A connectivity issue may occur after changing the Security Gateway's name and installing policy. |
PRJ-34974, |
SSL Inspection |
In rare scenarios, the WSTLSD daemon may unexpectedly restart. |
PRJ-35935, PRJ-35934 |
SSL Network Extender |
UPDATE: SSL Network Extender was updated to version 800008304. It provides TLS 1.2 cipher suites support on macOS. |
PRJ-35245, |
Mobile Access |
MAB Guacamole-based clientless RDP/SSH connections, when closed prematurely, may cause the GuacProxy process to consume 100% CPU. |
PRJ-36059, |
Mobile Access |
Capsule Workspace cannot connect to a Mobile Access Gateway when Citrix application is configured and allowed to the end-user's group. |
PRJ-35979, |
ClusterXL |
A cluster failover may take longer than it should. |
PRJ-36915, |
ClusterXL |
During policy installation, the state of SMO may not be stable. |
PRJ-38370, |
ClusterXL |
Multicast packets may be dropped after policy installation. |
PRJ-33582, |
SecureXL |
In some scenarios, fragmented Cluster LS packets are dropped by SecureXL. |
PRJ-36471, |
SecureXL |
The VSX Gateway may crash when trying to route traffic from a VS to a Virtual Switch (VSW). |
PRJ-36073, |
SecureXL |
In some scenarios, related to sending multicast packets, the ICMP errors may be shown. |
PRJ-34340, |
SecureXL |
The "fwaccel dos rate add" command may fail with the "Another fwaccel command is already in progress" error. |
PRJ-30714, |
Routing |
Connectivity issues may occur after configuration of route based VPN (VTI interface). Refer to sk176368. |
PRJ-34711, |
Routing |
In rare scenarios, the ROUTED daemon may unexpectedly exit or write logs in the incorrect order. |
PRJ-35769, |
Routing |
UPDATE: Routed debug log will now show IP addresses. |
PRJ-35341 |
Routing |
The ROUTED daemon may unexpectedly exit with core dump when some interfaces lose connection with the PIM router. |
PRJ-37590, |
VPN |
During policy installation when using DAIP behind hide NAT, CPU usage for the VPND process may be high. |
PRJ-29881, |
VPN |
Improved VPN interoperability. |
PRJ-34374, |
VPN |
In rare scenarios, Remote Access users cannot connect to the Gateway because of certificate authentication failure. |
PRJ-35430, |
VPN |
In some scenarios, L2TP users cannot connect to the Gateway in a cluster environment. |
PRJ-34493 |
VPN |
Remote Access users may not be able to connect when authenticating using a certificate issued by a subordinate CA. |
PRJ-38810, |
VPN |
In some scenarios, it is not possible to connect with Remote Access using DHCP for Office Mode. Refer to sk178767. See the Important Notes section. |
PRJ-33656, |
VPN |
The VPND process may unexpectedly exit with a core dump file. |
PRJ-35766, |
VPN |
Enhanced stability of Site-to-Site VPN with interoperable devices. |
PRJ-35391, |
VPN |
Improvements for IKEv2 when working with DAIPs. |
PRJ-35474, |
VPN |
Added VPN improvements for IKEv2 SA re-key. |
PRJ-35047, |
VPN |
In some scenarios, NAT-T tunnel establishment may fail. |
PRJ-29544, |
VPN |
Newly defined ROBO Gateways cannot connect until policy installation. |
PRJ-35559, |
VPN |
A memory leak may occur in the VPND process when using Remote Access Secondary Connect. |
PRJ-35343, |
VPN |
Policy installation and establishing a connection from a Gateway with Static IP may fail, if the IP address was previously used by a peer Gateway with DAIP IP which was configured before and had a connection from the DAIP Encryption Domain. |
PRJ-35231, |
VPN |
SSL entries may not be deleted from the "vpn tu tlist" command output, although there was a graceful exit. |
PRJ-35398, |
VPN |
IKEv2 Improvements for DAIP Gateway behind Hide NAT. |
PRJ-36180, |
VPN |
The FWK process may unexpectedly exit on a VS with an S2S VPN tunnel. |
PRJ-35535, |
VPN |
A memory leak may occur in the VPND process when using remote Access Back Connection. |
PRJ-35387, |
VPN |
In some scenarios, the RIM script is not activated in DPD Tunnel monitoring. |
PRJ-35556, |
VPN |
A memory leak may occur in the VPND process when using Remote Access with Multiple Entry Points configured. |
PRJ-34211, |
VPN |
IKEv2 ID configuration may not be applied when an IPv6 address is written as a certificate's alternative name. |
PRJ-35488, |
VPN |
In ike_sa_table there may be an entry with an IP address and not with a DAIP ID. |
PRJ-36238, |
VPN |
A memory leak may occur in the VPND process. |
PRJ-34672, |
VSX |
UPDATE: The "vsx_util reconfigure" operation is not supported on a VSX cluster member or VSX Gateway which has no virtual systems configured. The operation will now alert about the absence of virtual systems. |
PRJ-36688, |
VSX |
In a Multi-Domain environment, the "vsx_util vsls" command may take a few minutes to run. |
PRJ-32079, |
VSX |
When creating a static route on a virtual system, some network objects may be created with the same name inside the network group which causes failure in writing the object to the database. |
PRJ-35000, |
VSX |
The "vsx_util reconfigure" command may fail without printing the cause of the error. |
PRJ-34603, |
VSX |
In some scenarios, the VSX Gateway may incorrectly handle broadcast packets received from a Virtual Switch. |
PRJ-35070, |
VSX |
When creating a new virtual system, some VSLS parameters like the Virtual System's weight value may be displayed wrong. |
PRJ-36770, |
Gaia OS |
NEW: Gaia API (version 1.6 with Python3 support) will now be deployed via Jumbo Hotfix. Refer to sk143612. |
PRJ-35003, |
Gaia OS |
Fixed the CVE-2020-14145 vulnerability. |
PRJ-31696, |
Gaia OS |
The "cpopenssl" command may fail with "No such file or directory". |
PRJ-36543, |
Gaia OS |
When adding an SSH host key, it won't be displayed because the total length of the command line cannot contain more than 512 characters. |
PRJ-37224, |
Gaia OS |
Upgrade process may fail due to corrupted sic_local_cert.p12 certificate. Refer to sk171253. |
PRJ-27909, |
Harmony Endpoint |
In some scenarios, logs related to Harmony Endpoint may be missing. |
PRJ-29972, |
Harmony Endpoint |
In some scenarios, a query which counts host_ckp objects may return more results than expected. It leads to a memory leak with the "Out Of Memory" error. |
PRJ-36364, |
CloudGuard Network |
When booting up, the NSX-T CloudGuard Gateway may crash. |
PRJ-36274, |
CloudGuard Network |
In some scenarios, incorrect data center updates are pushed to the Gateway. |
PRJ-34527, |
CloudGuard Network |
When a Gateway's object name was changed, CloudGuard Central License Tool may fail to distribute licenses to the Gateway. |
PRJ-32917, |
CloudGuard Network |
NEW:
|
PRJ-35548, |
CloudGuard Network |
When there are VS's with same name prefix, the CloudGuard Controller fails to update the VS with Data Center Objects. |
PRJ-37053, |
CloudGuard Network |
In some scenarios, Data Center objects are not enforced on an AWS GEO cluster (Active/Active) Gateway. Refer to sk175904. See the Important Notes section. |
PRJ-36704, |
Public Cloud CA Bundle |
Added Take 14 of Public Cloud CA Bundle. Refer to sk172188. |
PRJ-35612, |
Scalable Platforms |
Setting time on Quantum Scalable Chassis may fail with the "Failed to update the date WARNING: CliError( ) called without module or error code" error. |
PRJ-29821, |
Scalable Platforms |
On a Scalable Platform configured in VSX mode, a new member added to a Security Group may stay in Down state because of a false-positive license issue. |
PRJ-36593, |
Scalable Platforms |
NEW: A new module parameter "ccl_correct_dr_between_chassis" is added.
Refer to sk177943. |
PRJ-36650, |
Scalable Platforms |
Running "cphaconf debug_data" in VSX context may cause the Gateway to crash. |
PRJ-35090, |
Scalable Platforms |
Security Group may drop traffic during an internal failover between Security Group members when Dynamic Anti-Spoofing is enabled. Refer to sk177946. |
PRJ-34216, |
Scalable Platforms |
In some scenarios, when accelerated policy installation is performed on a Security Gateway that doesn't have a valid policy, an obscure failure message is shown. |
PRJ-36360, |
Scalable Platforms |
OSPF may install a route to the incorrect IP when configured as P2P. Refer to sk177686. |
PRJ-37216, |
Scalable Platforms |
Local connection from a Standby site may be dropped if there is a switch between the sites. Refer to sk178045. |
PRJ-26825 |
Scalable Platforms |
Restoring a backup on the security group may get stuck upon reboot. |
PRJ-34048, |
Scalable Platforms |
After changing Multi-Queue configurations, members may remain in Down state. |
PRJ-36830, |
HCP |
Added Update 7 of HealthCheck Point (HCP) Release. Refer to sk171436. |