R81 Jumbo Hotfix Take 69

 

List of Resolved Issues and New Features

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 69

Released on 23 June 2022 and declared as Recommended on 22 August 2022

PRJ-38151,
PRHF-23149

Security Management

UPDATE: Additional improvements to Access Policy installation time.

PRJ-32817,
PRHF-20492

Security Management

In rare scenarios, when installing a policy after performing "revert to revision", some changes made to a policy may not be installed on the Security Gateway. Refer to sk176768.

PRJ-37396,
PRHF-22603

Security Management

After performing the Solr Cure procedure, objects may appear as duplicated in SmartConsole. Refer to sk178084.

PRJ-37495,
PRHF-22409

Security Management

In some scenarios, the "show-hosts" Management API command fails with "generic_error" when running it with "details-level full". Refer to sk178249.

PRJ-36746,
PRHF-22326

Security Management

Accelerated Install Policy may fail with the verification error: "Rule-name has security zone objects that are not attached to any interface used in Cluster-name ", when the rule contains Security Zone and the install-on target is a cluster.

PRJ-33076,
PMTR-75039

Security Management

Updating objects with Management API may fail when editing the "groups" field and object UID is specified.

PRJ-35298,
PMTR-75023

Security Management

When cloning an IPS profile, the advanced settings of cloud protection may not be copied to the new profile.

PRJ-37327,
PRHF-22577

Security Management

In some scenarios, the policy installation may fail after editing the trac_client_1.ttm configuration file. Refer to sk174646

PRJ-37862,
PRHF-22678

Security Management

Dynamic Objects defined on LSM Gateway in SmartProvisioning may be removed from the Security Gateway after fetching policy or pushing policy from the Security Management Server to the Security Gateway.

PRJ-38148,
PRHF-23139

Security Management

Cloud Shadow Objects verification may take several minutes.

PRJ-35311,
PRHF-21755

Security Management

The web_api_show_package.sh script and some Management API commands with the "details-level full" option may fail when VPN settings are not defined for Interoperable objects. Refer to sk178410.

PRJ-36849,
PRHF-22352

Security Management

In rare scenarios, the Management Server may fail to start because of incorrect session handling.

PRJ-37025,
PRHF-22355

Security Management

Viewing sessions in SmartConsole may fail with an "Error retrieving results" message while importing a Domain.

PRJ-37259,
PRHF-21969

Security Management

In a large scale environment, the "show-access-rulebase" Management API command may take a significant amount of time to complete or time out after 5 minutes.

PRJ-37709,
PRHF-22796

Security Management

Install Policy preset fails if the Threat Prevention policy was uninstalled.

PRJ-37504,
PRHF-22597

Security Management

In rare scenarios, Global Domain Assignment may fail with a "class name not found for object" error message.

PRJ-37635,
PRHF-22693

Security Management

After changing the IP address of the Secondary Management Server, the old IP address is still shown in the High Availability window until the services are restarted.

PRJ-37523,
PRHF-22656

Security Management

Reassign Global Policy tasks may be stuck for Domains active on a different Multi-Domain Server even though the task is completed on the destination Multi-Domain Server.

PRJ-37027,
PRHF-22356

Security Management

Policy Installation may fail with the "Unable to start policy installation" error when the Import Domain task is running in the background.

PRJ-39177,

PRHF-23750

Security Management

In some scenarios, the Management API command "show-packages" with "details-level full" may fail with the "Could not commit JPA transaction" error.

PRJ-38393,

PMTR-72637

SmartConsole

UPDATE: It is now possible to execute the "run-script" Management API command on the Multi-Domain Server (MDS) and Multi-Domain Log Module (MLM) from the System Domain.

PRJ-33517,
PMTR-71704

Logging

In SmartView Widgets, improved samples visibility.

PRJ-36027,
PMTR-70703

Logging

In IPS Core Protections logs, the link to the Threat Prevention profile is written incorrectly.

PRJ-33816,

PMTR-72206

Logging

The "log_exporter_reexport" command may export the logs from the beginning of the log file and not from the provided start position.

PRJ-34250,
PRHF-21188

Logging

There may be an incorrect error message related to MakeConnection method.

PRJ-37896,
PRHF-22858

Logging

Logs may be missing from SmartConsole after upgrading the Log Server if a VS object is configured without an IP.

PRJ-34142,

PRHF-21218

Logging

On the Domain level, in the Logs view, available services may not appear in the drop-down filter list. Refer to sk178904.

PRJ-35976,

PRHF-21400

Logging

"Failed to open /opt/CPsuite-R81.10/fw1/log/" messages may appear in the log_indexer.elg file because of files ending with the ".log" suffix although they are not actual log files.

PRJ-36655,
PMTR-77355

Security Gateway

NEW: Added a new kernel parameter "fw_ignore_before_drop_rules". It allows to skip the "before drop" implied rules and enforce policy according to the explicit rule in the Access Rule Base. By default, this capability is disabled.

Refer to sk105740.

PRJ-38689,
PRHF-22315

Security Gateway

UPDATE: When using Routing Separation, hosts and servers configured in Clish will be automatically added to Management Plane (MPLANE).

PRJ-19036,
PMTR-61532

Security Gateway

UPDATE: In CPView overview, the "FW" field will now show physical memory used instead of virtual memory used. The change is only cosmetic.

PRJ-33859,
PMTR-76224

Security Gateway

In ISP Redundancy settings, when using the "dead on all host" feature and defining one link without any host (which is a misconfiguration) the ISP link is down.

PRJ-37609,
PMTR-80518

Security Gateway

When using the DAIP Gateway object in the Access Rulebase, debug error "fwdnd_log_info_lookup failed" may appear in the fwk.elglog, if the relevant rule has log track. Refer to sk178670.

PRJ-37012,
PRHF-22369

Security Gateway

Multiqueue Clish "show" commands may fail in a Management Data Plane Separation (MDPS) environment.

PRJ-27894,
PRHF-17754

Security Gateway

In rare scenarios, connectivity issues to specific websites may occur during web traffic inspection.

PRJ-33930,
PRHF-20845

Security Gateway

Cluster failover may trigger the FWK process to exit, with no traffic impact.

PRJ-33699,
PMTR-72984

Security Gateway

In some scenarios, file download may fail with the "Connection queue exceeded max size" error.

PRJ-36120,
PMTR-71654

Security Gateway

In CPView, under Network, Bytes Per Sec value in Traffic Rate may be incorrect.

PRJ-36515,

PRHF-22273

Security Gateway

In a rare scenario, a memory leak in the FWD process may occur during installing Threat Prevention policy.

PRJ-38044,
ODU-283

Threat Prevention

Added Update 14 of Autonomous Threat Prevention Management integration Release Updates. Refer to sk167109.

PRJ-38684,

PRHF-23324

Threat Prevention

In a rare scenario, an IPS, Anti-Virus, or Anti-Bot update package may fail to load because of a timeout.

PRJ-35852,
PRHF-22037

Identity Awareness

The PEP process may unexpectedly exit.

PRJ-37979,
PMTR-81714

IPS

In very rare scenarios, a traffic outage may occur.

PRJ-36521,

PMTR-77922

IPS

Improved detection in some IPS protections.

PRJ-37714,
PRJ-20376

IPS

In some scenarios, an "[ERROR]: kfunc_cmik_loader_execute_dyn_ctx: cmi_match_env is NULL" message may be printed in the /var/log/messages file.

PRJ-36160,
PMTR-72454

ClusterXL

UPDATE: It is now possible to edit minimal number of required subordinate interfaces for Bond Load Sharing via Clish. The new Clish command is "set interface <interface_name> links <value>".

PRJ-37435,
PMTR-80319

ClusterXL

There may be connectivity issues for multicast traffic in PIM Sparse Mode.

PRJ-35168,
PMTR-77780

ClusterXL

A single cluster member with Dynamic Routing configuration may stay permanently in DOWN state producing routed pnote during a boot.

PRJ-36603,
PMTR-79447

ClusterXL

Data connection may be interrupted during a Multi-Version Cluster (MVC) upgrade.

PRJ-36615,
PMTR-71442

ClusterXL

During a Multi-Version Cluster (MVC) upgrade from R80.30 or lower, Active-Active split brain may happen. Refer to sk174510.

PRJ-36177,
PMTR-51050

ClusterXL

In Virtual Device Status table, in vs0 context, the output shows the Active-Active status on two members instead of Active-Standby.

PRJ-35228,
PMTR-70530

ClusterXL

In an Active/Active cluster, potential FTP data connection interruption may occur during failover.

PRJ-26972,
MBS-14060

ClusterXL

Local connection from the Management interface on a non-standard port (e.g. 8000) may fail.

PRJ-37882,
PMTR-81375

ClusterXL

Local connection from a Standby member may fail when packets are not fragmented even if the interface MTU is smaller than the packet size.

PRJ-38803,

PMTR-82026

ClusterXL

When moving a cluster from Unicast to Multicast LS, Gratuitous ARP Request (GARP) may not be sent. The cluster cannot update multicast MAC entries on peers, which can cause traffic lost.

PRJ-37001

SecureXL

NEW: In some scenarios, the Security Gateway may not forward traffic to a client if its IP address is changed by DHCP. Added a global parameter "cphwd_refresh_nh", disabled by default. It determines whether or not the Security Gateway will invoke its own refresh ARP mechanism after a successful route lookup. Refer to sk175603.

PRJ-32709,
PMTR-74854

SecureXL

UPDATE: Virtual Extensible LAN (VXLAN) interfaces can now be configured over interfaces with an alias IP address. VXLAN interfaces will not use the alias IP address as the local IP address of the tunnel.

PRJ-39009,

PRHF-22881

SecureXL

SYN Defender may not properly handle the S2C traffic related to Allow List. As a result, this traffic may be dropped.

PRJ-39003,

PRHF-23644

SecureXL

SYN Defender may change MSS in an SYN packet to a larger value, potentially causing traffic drop.

PRJ-38502,

PRHF-23143

CoreXL

An Active member in a cluster may make a full reboot during policy installation.

PRJ-36939,
PMTR-79381

Routing

In a rare scenario, the ROUTED daemon may unexpectedly exit during a Multi-Version Cluster (MVC) upgrade when using OSPF.

PRJ-37463,
PRHF-21891

VPN

The VPND process may unexpectedly exit.

PRJ-37282,
PRHF-22452

VPN

VPN tunnel may not be stable in cluster load-sharing multicast and unicast environments.

PRJ-36437,
PMTR-78967

VPN

Machine Authentication stability improvements for Remote Access Endpoint Clients.

PRJ-35421,
PMTR-77570

VPN

When using Remote Access SAML authentication, the "Remote access client IP address and port were changed" log may contain incorrect data in the "Old IP" field.

PRJ-37774,
PRHF-22871

VPN

Capsule Connect (IPSec VPN) may fail to re-authenticate.

PRJ-36450,
PMTR-65595

VSX

UPDATE: When resetting SIC for a specific Virtual System (sk34098), the new certificate on the Security Gateway will now be automatically pulled from SmartConsole.

PRJ-38203,
PRHF-23118

VSX

In some scenarios, the VSX Security Gateway may not decrease the packet's TTL.

PRJ-36768,
PMTR-52576

VSX

VSX Cluster Internal Communication Network IP address is shown in ifconfig after changing the name or VLAN of a VR physical interface.

PRJ-33471,
PMTR-73998

VSX

In some scenarios, the "vsx_util reconfigure" command cannot fetch the policy installed previously.

PRJ-35504,
PMTR-62860

VSX

There may be a mismatch of policy name on virtual switch when using the "fw stat" and "vsx stat -v" commands. The issue is only cosmetic.

PRJ-37617,
PMTR-80850

VSX

After an upgrade from R80.20SP/R80.30SP to R81, pushing accelerated policy may cause all non-SMO SG Members to go down.

PRJ-35278,
PMTR-76457

VSX

In some scenarios, if VSX Gateway creation fails and rollback is done, the default route of the Security Gateway that was configured via clish is deleted without validation.

PRJ-37806,
PMTR-81261

VSX

Running the "vsx_util vsls" command may end with the "Segmentation fault" error.

PRJ-28546,
PMTR-65366

VSX

Latency and packet loss issues may occur when traffic goes through external VS connected to Virtual switch (VSW). Refer to sk177344.

PRJ-36787,
PMTR-79249

VSX

The "snmpwalk" command may time out after reaching SNMPv2-SMI::mib-2.68.1.2.0.

PRJ-36524,

PMTR-72069

Gaia OS

NEW: Added a Gaia Clish command "show configuration vxlan" to show all VXLAN info (interface creation, IP, MTU, comments, state).

PRJ-36087,
PMTR-78169

Gaia OS

WebUI session may end when creating a Role with full permissions.

PRJ-38961,
PMTR-72373

Gaia OS

When loading a configuration file to the new Security Gateway, VLAN interfaces may not be added to the bridge as expected.

PRJ-38230,
PMTR-81516

Gaia OS

When running the "save configuration" command on a VSX device, other interfaces besides the Management interface are still presented. This is a cosmetic issue.

PRJ-33556,

PMTR-75925

Gaia OS

In some scenarios, in 7000 appliances, Power Supply Unit (PSU) status information may be incorrect. Refer to sk174443.

PRJ-37119,
PRHF-18358

VoIP

When static NAT is configured, VoIP calls may not work.

PRJ-38568,

PRHF-23328

CloudGuard Network

UPDATE: Previously, because of connectivity issues with Azure, CloudGuard Controller was deleting IP addresses of Data Center objects from the Security Gateway. CloudGuard Controller will now show an error message instead of revoking identities from the Security Gateway.

PRJ-37603,
PRHF-22145

CloudGuard Network

In Amazon Web Services (AWS), some Gateways may be crashing frequently with vmcores.

PRJ-37949,
PRHF-22994

CloudGuard Network

In some scenarios, mapping of AWS Data Centers may take a long time to complete.

PRJ-37776,
PMTR-76723

CloudGuard Network

During boot on KVM with 10 or more interfaces, the interface order may change.

PRJ-38870,
PRHF-23555

CloudGuard Network

After changing the default behavior in Identity session conciliation, the "delete-identity" request may trigger Cloud Controller to delete IP addresses from other Identity sources.

PRJ-38023,
ODU-342

Public Cloud CA Bundle

Added Take 18 of Public Cloud CA Bundle. Refer to sk172188.

PRJ-38036,
ODU-341

Scalable Platforms

Added Take 21 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414.

PRJ-34396,
MBS-14488

Scalable Platforms

Non-SMO members may go to Down state after Anti-Malware policy installation failed.

PRJ-36915,
PRHF-22274

Scalable Platforms

During policy installation, the state of the Single Management Object (SMO) may not be stable.

PRJ-32450,
PMTR-71738

Scalable Platforms

In rare scenarios, changing the number of CoreXL instances in SP environments with many Virtual Systems may fail.

PRJ-33923,
PMTR-75452

Scalable Platforms

On Scalable platform Chassis in VSX mode, when adding a new member to Security Gateway, the "dxl stat" command may fail with the "Failed to retrieve dxl status" error.

PRJ-38298,
MBS-15504

Scalable Platforms

During Jumbo Hotfix Accumulator installation, the sgm_lsp core dump may be created.

PRJ-38482,
MBS-15568

Scalable Platforms

When running the CPUSE "installer" command in Gaia gClish of a Security Group, the output may show: "Error Failed to invoke action." Refer to sk178647.

PRJ-38224,
ODU-349

HCP

Added Update 8 of HealthCheck Point (HCP) Release. Refer to sk171436.