R81 Jumbo Hotfix Take 69
List of Resolved Issues and New Features
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 69 Released on 23 June 2022 and declared as Recommended on 22 August 2022 |
||
PRJ-38151, |
Security Management |
UPDATE: Additional improvements to Access Policy installation time. |
PRJ-32817, |
Security Management |
In rare scenarios, when installing a policy after performing "revert to revision", some changes made to a policy may not be installed on the Security Gateway. Refer to sk176768. |
PRJ-37396, |
Security Management |
After performing the Solr Cure procedure, objects may appear as duplicated in SmartConsole. Refer to sk178084. |
PRJ-37495, |
Security Management |
In some scenarios, the "show-hosts" Management API command fails with "generic_error" when running it with "details-level full". Refer to sk178249. |
PRJ-36746, |
Security Management |
Accelerated Install Policy may fail with the verification error: "Rule-name has security zone objects that are not attached to any interface used in Cluster-name ", when the rule contains Security Zone and the install-on target is a cluster. |
PRJ-33076, |
Security Management |
Updating objects with Management API may fail when editing the "groups" field and object UID is specified. |
PRJ-35298, |
Security Management |
When cloning an IPS profile, the advanced settings of cloud protection may not be copied to the new profile. |
PRJ-37327, |
Security Management |
In some scenarios, the policy installation may fail after editing the trac_client_1.ttm configuration file. Refer to sk174646 |
PRJ-37862, |
Security Management |
Dynamic Objects defined on LSM Gateway in SmartProvisioning may be removed from the Security Gateway after fetching policy or pushing policy from the Security Management Server to the Security Gateway. |
PRJ-38148, |
Security Management |
Cloud Shadow Objects verification may take several minutes. |
PRJ-35311, |
Security Management |
The web_api_show_package.sh script and some Management API commands with the "details-level full" option may fail when VPN settings are not defined for Interoperable objects. Refer to sk178410. |
PRJ-36849, |
Security Management |
In rare scenarios, the Management Server may fail to start because of incorrect session handling. |
PRJ-37025, |
Security Management |
Viewing sessions in SmartConsole may fail with an "Error retrieving results" message while importing a Domain. |
PRJ-37259, |
Security Management |
In a large scale environment, the "show-access-rulebase" Management API command may take a significant amount of time to complete or time out after 5 minutes. |
PRJ-37709, |
Security Management |
Install Policy preset fails if the Threat Prevention policy was uninstalled. |
PRJ-37504, |
Security Management |
In rare scenarios, Global Domain Assignment may fail with a "class name not found for object" error message. |
PRJ-37635, |
Security Management |
After changing the IP address of the Secondary Management Server, the old IP address is still shown in the High Availability window until the services are restarted. |
PRJ-37523, |
Security Management |
Reassign Global Policy tasks may be stuck for Domains active on a different Multi-Domain Server even though the task is completed on the destination Multi-Domain Server. |
PRJ-37027, |
Security Management |
Policy Installation may fail with the "Unable to start policy installation" error when the Import Domain task is running in the background. |
PRJ-39177, PRHF-23750 |
Security Management |
In some scenarios, the Management API command "show-packages" with "details-level full" may fail with the "Could not commit JPA transaction" error. |
PRJ-38393, PMTR-72637 |
SmartConsole |
UPDATE: It is now possible to execute the "run-script" Management API command on the Multi-Domain Server (MDS) and Multi-Domain Log Module (MLM) from the System Domain. |
PRJ-33517, |
Logging |
In SmartView Widgets, improved samples visibility. |
PRJ-36027, |
Logging |
In IPS Core Protections logs, the link to the Threat Prevention profile is written incorrectly. |
PRJ-33816, PMTR-72206 |
Logging |
The "log_exporter_reexport" command may export the logs from the beginning of the log file and not from the provided start position. |
PRJ-34250, |
Logging |
There may be an incorrect error message related to MakeConnection method. |
PRJ-37896, |
Logging |
Logs may be missing from SmartConsole after upgrading the Log Server if a VS object is configured without an IP. |
PRJ-34142, PRHF-21218 |
Logging |
On the Domain level, in the Logs view, available services may not appear in the drop-down filter list. Refer to sk178904. |
PRJ-35976, PRHF-21400 |
Logging |
"Failed to open /opt/CPsuite-R81.10/fw1/log/" messages may appear in the log_indexer.elg file because of files ending with the ".log" suffix although they are not actual log files. |
PRJ-36655, |
Security Gateway |
NEW: Added a new kernel parameter "fw_ignore_before_drop_rules". It allows to skip the "before drop" implied rules and enforce policy according to the explicit rule in the Access Rule Base. By default, this capability is disabled. Refer to sk105740. |
PRJ-38689, |
Security Gateway |
UPDATE: When using Routing Separation, hosts and servers configured in Clish will be automatically added to Management Plane (MPLANE). |
PRJ-19036, |
Security Gateway |
UPDATE: In CPView overview, the "FW" field will now show physical memory used instead of virtual memory used. The change is only cosmetic. |
PRJ-33859, |
Security Gateway |
In ISP Redundancy settings, when using the "dead on all host" feature and defining one link without any host (which is a misconfiguration) the ISP link is down. |
PRJ-37609, |
Security Gateway |
When using the DAIP Gateway object in the Access Rulebase, debug error "fwdnd_log_info_lookup failed" may appear in the fwk.elglog, if the relevant rule has log track. Refer to sk178670. |
PRJ-37012, |
Security Gateway |
Multiqueue Clish "show" commands may fail in a Management Data Plane Separation (MDPS) environment. |
PRJ-27894, |
Security Gateway |
In rare scenarios, connectivity issues to specific websites may occur during web traffic inspection. |
PRJ-33930, |
Security Gateway |
Cluster failover may trigger the FWK process to exit, with no traffic impact. |
PRJ-33699, |
Security Gateway |
In some scenarios, file download may fail with the "Connection queue exceeded max size" error. |
PRJ-36120, |
Security Gateway |
In CPView, under Network, Bytes Per Sec value in Traffic Rate may be incorrect. |
PRJ-36515, PRHF-22273 |
Security Gateway |
In a rare scenario, a memory leak in the FWD process may occur during installing Threat Prevention policy. |
PRJ-38044, |
Threat Prevention |
Added Update 14 of Autonomous Threat Prevention Management integration Release Updates. Refer to sk167109. |
PRJ-38684, PRHF-23324 |
Threat Prevention |
In a rare scenario, an IPS, Anti-Virus, or Anti-Bot update package may fail to load because of a timeout. |
PRJ-35852, |
Identity Awareness |
The PEP process may unexpectedly exit. |
PRJ-37979, |
IPS |
In very rare scenarios, a traffic outage may occur. |
PRJ-36521, PMTR-77922 |
IPS |
Improved detection in some IPS protections. |
PRJ-37714, |
IPS |
In some scenarios, an "[ERROR]: kfunc_cmik_loader_execute_dyn_ctx: cmi_match_env is NULL" message may be printed in the /var/log/messages file. |
PRJ-36160, |
ClusterXL |
UPDATE: It is now possible to edit minimal number of required subordinate interfaces for Bond Load Sharing via Clish. The new Clish command is "set interface <interface_name> links <value>". |
PRJ-37435, |
ClusterXL |
There may be connectivity issues for multicast traffic in PIM Sparse Mode. |
PRJ-35168, |
ClusterXL |
A single cluster member with Dynamic Routing configuration may stay permanently in DOWN state producing routed pnote during a boot. |
PRJ-36603, |
ClusterXL |
Data connection may be interrupted during a Multi-Version Cluster (MVC) upgrade. |
PRJ-36615, |
ClusterXL |
During a Multi-Version Cluster (MVC) upgrade from R80.30 or lower, Active-Active split brain may happen. Refer to sk174510. |
PRJ-36177, |
ClusterXL |
In Virtual Device Status table, in vs0 context, the output shows the Active-Active status on two members instead of Active-Standby. |
PRJ-35228, |
ClusterXL |
In an Active/Active cluster, potential FTP data connection interruption may occur during failover. |
PRJ-26972, |
ClusterXL |
Local connection from the Management interface on a non-standard port (e.g. 8000) may fail. |
PRJ-37882, |
ClusterXL |
Local connection from a Standby member may fail when packets are not fragmented even if the interface MTU is smaller than the packet size. |
PRJ-38803, PMTR-82026 |
ClusterXL |
When moving a cluster from Unicast to Multicast LS, Gratuitous ARP Request (GARP) may not be sent. The cluster cannot update multicast MAC entries on peers, which can cause traffic lost. |
PRJ-37001 |
SecureXL |
NEW: In some scenarios, the Security Gateway may not forward traffic to a client if its IP address is changed by DHCP. Added a global parameter "cphwd_refresh_nh", disabled by default. It determines whether or not the Security Gateway will invoke its own refresh ARP mechanism after a successful route lookup. Refer to sk175603. |
PRJ-32709, |
SecureXL |
UPDATE: Virtual Extensible LAN (VXLAN) interfaces can now be configured over interfaces with an alias IP address. VXLAN interfaces will not use the alias IP address as the local IP address of the tunnel. |
PRJ-39009, PRHF-22881 |
SecureXL |
SYN Defender may not properly handle the S2C traffic related to Allow List. As a result, this traffic may be dropped. |
PRJ-39003, PRHF-23644 |
SecureXL |
SYN Defender may change MSS in an SYN packet to a larger value, potentially causing traffic drop. |
PRJ-38502, PRHF-23143 |
CoreXL |
An Active member in a cluster may make a full reboot during policy installation. |
PRJ-36939, |
Routing |
In a rare scenario, the ROUTED daemon may unexpectedly exit during a Multi-Version Cluster (MVC) upgrade when using OSPF. |
PRJ-37463, |
VPN |
The VPND process may unexpectedly exit. |
PRJ-37282, |
VPN |
VPN tunnel may not be stable in cluster load-sharing multicast and unicast environments. |
PRJ-36437, |
VPN |
Machine Authentication stability improvements for Remote Access Endpoint Clients. |
PRJ-35421, |
VPN |
When using Remote Access SAML authentication, the "Remote access client IP address and port were changed" log may contain incorrect data in the "Old IP" field. |
PRJ-37774, |
VPN |
Capsule Connect (IPSec VPN) may fail to re-authenticate. |
PRJ-36450, |
VSX |
UPDATE: When resetting SIC for a specific Virtual System (sk34098), the new certificate on the Security Gateway will now be automatically pulled from SmartConsole. |
PRJ-38203, |
VSX |
In some scenarios, the VSX Security Gateway may not decrease the packet's TTL. |
PRJ-36768, |
VSX |
VSX Cluster Internal Communication Network IP address is shown in ifconfig after changing the name or VLAN of a VR physical interface. |
PRJ-33471, |
VSX |
In some scenarios, the "vsx_util reconfigure" command cannot fetch the policy installed previously. |
PRJ-35504, |
VSX |
There may be a mismatch of policy name on virtual switch when using the "fw stat" and "vsx stat -v" commands. The issue is only cosmetic. |
PRJ-37617, |
VSX |
After an upgrade from R80.20SP/R80.30SP to R81, pushing accelerated policy may cause all non-SMO SG Members to go down. |
PRJ-35278, |
VSX |
In some scenarios, if VSX Gateway creation fails and rollback is done, the default route of the Security Gateway that was configured via clish is deleted without validation. |
PRJ-37806, |
VSX |
Running the "vsx_util vsls" command may end with the "Segmentation fault" error. |
PRJ-28546, |
VSX |
Latency and packet loss issues may occur when traffic goes through external VS connected to Virtual switch (VSW). Refer to sk177344. |
PRJ-36787, |
VSX |
The "snmpwalk" command may time out after reaching SNMPv2-SMI::mib-2.68.1.2.0. |
PRJ-36524, PMTR-72069 |
Gaia OS |
NEW: Added a Gaia Clish command "show configuration vxlan" to show all VXLAN info (interface creation, IP, MTU, comments, state). |
PRJ-36087, |
Gaia OS |
WebUI session may end when creating a Role with full permissions. |
PRJ-38961, |
Gaia OS |
When loading a configuration file to the new Security Gateway, VLAN interfaces may not be added to the bridge as expected. |
PRJ-38230, |
Gaia OS |
When running the "save configuration" command on a VSX device, other interfaces besides the Management interface are still presented. This is a cosmetic issue. |
PRJ-33556, PMTR-75925 |
Gaia OS |
In some scenarios, in 7000 appliances, Power Supply Unit (PSU) status information may be incorrect. Refer to sk174443. |
PRJ-37119, |
VoIP |
When static NAT is configured, VoIP calls may not work. |
PRJ-38568, PRHF-23328 |
CloudGuard Network |
UPDATE: Previously, because of connectivity issues with Azure, CloudGuard Controller was deleting IP addresses of Data Center objects from the Security Gateway. CloudGuard Controller will now show an error message instead of revoking identities from the Security Gateway. |
PRJ-37603, |
CloudGuard Network |
In Amazon Web Services (AWS), some Gateways may be crashing frequently with vmcores. |
PRJ-37949, |
CloudGuard Network |
In some scenarios, mapping of AWS Data Centers may take a long time to complete. |
PRJ-37776, |
CloudGuard Network |
During boot on KVM with 10 or more interfaces, the interface order may change. |
PRJ-38870, |
CloudGuard Network |
After changing the default behavior in Identity session conciliation, the "delete-identity" request may trigger Cloud Controller to delete IP addresses from other Identity sources. |
PRJ-38023, |
Public Cloud CA Bundle |
Added Take 18 of Public Cloud CA Bundle. Refer to sk172188. |
PRJ-38036, |
Scalable Platforms |
Added Take 21 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414. |
PRJ-34396, |
Scalable Platforms |
Non-SMO members may go to Down state after Anti-Malware policy installation failed. |
PRJ-36915, |
Scalable Platforms |
During policy installation, the state of the Single Management Object (SMO) may not be stable. |
PRJ-32450, |
Scalable Platforms |
In rare scenarios, changing the number of CoreXL instances in SP environments with many Virtual Systems may fail. |
PRJ-33923, |
Scalable Platforms |
On Scalable platform Chassis in VSX mode, when adding a new member to Security Gateway, the "dxl stat" command may fail with the "Failed to retrieve dxl status" error. |
PRJ-38298, |
Scalable Platforms |
During Jumbo Hotfix Accumulator installation, the sgm_lsp core dump may be created. |
PRJ-38482, |
Scalable Platforms |
When running the CPUSE "installer" command in Gaia gClish of a Security Group, the output may show: "Error Failed to invoke action." Refer to sk178647. |
PRJ-38224, |
HCP |
Added Update 8 of HealthCheck Point (HCP) Release. Refer to sk171436. |