R81 Jumbo Hotfix Take 72
List of Resolved Issues and New Features
|
Note - This Take contains all fixes from all earlier Takes. |
ID |
Product |
Description |
---|---|---|
Take 72 Published on 1 September 2022 |
||
PRJ-39461, |
Security Management |
UPDATE: Management API performance improvements:
|
PRJ-34853, |
Security Management |
UPDATE: Added validation of Custom Application/Site objects to prevent configuring invalid URLs, which causes Access policy installation failure. Refer to sk175187. |
PRJ-36920, |
Security Management |
When a Security Gateway is removed from a VPN community, it may still be seen under the permanent tunnel configuration. The issue is scoped to the Management side and does not impact the Gateway. |
PRJ-35655, |
Security Management |
The Security Cluster Wizard is not shown again after a Management restart in a Full High Availability cluster environment. |
PRJ-35600, |
Security Management |
An IPS update may fail if the user that performs the update is connected to the Multi-Domain Server on which the Global Domain is in Standby mode. |
PRJ-37763, |
Security Management |
The FWM process on the Management Server may unexpectedly exit, creating a core dump file. |
PRJ-35605, |
Security Management |
In SmartConsole, the "error retrieving results" message may be displayed when opening a new tab. |
PRJ-39471, |
Security Management |
Management HA synchronization may fail with the "NGM failed to import data" error. |
PRJ-38064, |
Security Management |
When uninstalling a Threat Prevention policy, there may be a verification warning "There are Threat Prevention uninstall candidates in policy targets", although the operation on the Gateway was completed successfully. |
PRJ-37886, |
Security Management |
Editing an object may fail with the "Could not access file for write operation" error. |
PRJ-38400, |
Security Management |
An Application Control and URL Filtering update may get stuck because of a lock object duplicate issue. |
PRJ-37509, |
Security Management |
Deleting a domain may fail when using the createDomainRecovery.sh script with the "UID" flag. |
PRJ-35060, |
Security Management |
Renaming the Security Management Server may fail with the "Failed to save object" error. Refer to sk177224. |
PRJ-37199, |
Security Management |
The Management API command "show-vpn-communities-star" for Diffie-Hellman groups 15-18 and group 24 fails with the "Invalid DH-Group in VPN Reply" error. Refer to sk27054. |
PRJ-38741, PRHF-23467 |
Security Management |
In a rare scenario, the FWM process may unexpectedly exit and create a core dump. |
PRJ-38799, |
Security Management |
In some scenarios, the "show-gateways-and-servers" Management API command fails with "generic_err_object_not_found" when running it with "details-level full". |
PRJ-39229, |
Security Management |
In some scenarios, the Hit Count column on the NAT policy shows zero hits on all rules, even though there are hits. |
PRJ-38120, |
Security Management |
Policy installation may fail with "an internal error" because of an orphan policy issue. Refer to sk122954. |
PRJ-40202, |
Security Management |
Upon policy installation, Security Gateways may not receive changes made in the Service Based Link Selection configuration file $FWDIR/conf/vpn_service_based_routing.conf as per instructions of sk56384. Refer to sk179699. |
PRJ-37340, |
Security Management |
Objects that do not belong to groups may be shown in the Group Membership view in SmartConsole. |
PRJ-38708, |
Security Management |
Login to Domain via Management API using FQDN as the Domain parameter may fail with the "Domain not found" error. |
PRJ-38217, |
Security Management |
If Log Domain reassignment fails, an Application Control and URL Filtering update may get stuck at 70 percent showing the "Running post update actions" status. |
PRJ-37911, |
Security Management |
The flag "--method" for a CME command is not supported in SmartConsole Command Line. |
PRJ-40110, |
Security Management |
After a policy installation failure, fetching policy on the Security Gateway side by running the "fw fetch local" command may also fail. |
PRJ-40204, |
Security Management |
In some scenarios, certificate based login to a Log Server may fail with "Authentication Error". Refer to sk179144. |
PRJ-39020, PRHF-23435 |
Licensing |
|
PRJ-37988, PRHF-22589 |
SmartConsole |
After an Application Control update, some application control objects may disappear from SmartConsole, although they are not deprecated. |
PRJ-39118, ODU-377 |
Web SmartConsole |
UPDATE: Released Take 59 with new features and improvements. Refer to sk170314. |
PRJ-23758, |
Logging |
UPDATE: The local logging test will no longer run on the "asg_perf_hogs" utility, as it has its HCP (HealthCheck Point) test. Refer to sk171436. |
PRJ-37102, |
Logging |
UPDATE: Scheduled email reports will now use TLS1.2 instead of TLS1.0. Refer to sk178125. |
PRJ-36462, |
Logging |
When running the "cp_log_export filter-Blade-in" command with the value "Endpoint" and restarting the LOG_EXPORTER process, LOG_EXPORTER may fail to start. |
PRJ-38415, |
Logging |
When there are several Log Servers, a log distribution issue may occur. |
PRJ-39296, |
Logging |
An error may occur when changing Default Time Frame while the SmartView language is not English. |
PRJ-39589, |
Logging |
The FWD process may unexpectedly exit and create core dump files. |
PRJ-36020, |
Logging |
In SmartView, the "Top Users that Downloaded Malicious Files" widget in the "Hosts that Encountered Malicious files" view may show no results, although there are matches. |
PRJ-35996, |
Logging |
Logs with actions "Expired" and "Hold" may be missing from the Logging view. |
PRJ-39679, |
Logging |
When exporting the logs table with "All Columns" to a CSV file, the first cell of the first log (time column) displays a non-ASCII character ("ן»¿"), and the time is split into two cells. |
PRJ-39676, |
Logging |
A CSV file exported from SmartView may contain duplicated lines of headers. |
PRJ-40510, |
Security Gateway |
UPDATE: Added a defense mechanism against partial header attacks known as "Slowloris DoS" (CVE-2007-6750). |
PRJ-34679, |
Security Gateway |
UPDATE: Decreased the threshold for connections suspected as heavy from 5 to 3 seconds. Refer to sk164215. |
PRJ-39667, PRHF-23392 |
Security Gateway |
It may not be possible to monitor Security Gateways with enabled Management Data Plane Separation (MDPS). Refer to sk138672. |
PRJ-27916, |
Security Gateway |
When Strict Hold is enabled, traffic is logged with the log "HTTP parsing error detected. Bypassing the request as defined in the Inspection Settings". Refer to sk169995. |
PRJ-37518, |
Security Gateway |
The FW Monitor tool may fail when it is used on VSX with the "-v" and "-p all" options. |
PRJ-40999, PRJ-40954 |
Security Gateway |
In a VSX environment, SNMP queries to OSPF OIDs may fail. |
PRJ-40254, |
Security Gateway |
There may be a delay in the Logging view when more than 1000 Security Gateways are connected to the same Log Server. |
PRJ-34403, |
Security Gateway |
Deleting IP addresses in the SAM Database may fail. |
PRJ-37952, |
Security Gateway |
There is a Content Awareness alert for multiple connections and the processing error "Failed to extract text" is printed in logs. |
PRJ-40441, PRJ-38912 |
Security Gateway |
When Anti-Virus Blade is enabled, there may be a continuous high memory consumption which can lead to latency. |
PRJ-39215, |
Security Gateway |
The Security Gateway may crash during PM Stats collection. |
PRJ-39860, PRHF-23952 |
Security Gateway |
After renewing an Internal Certificate Authority (ICA) certificate, policy installation on Virtual Systems may fail with "Internal SSL authentication SSL error (Unknown)". |
PRJ-39685, |
Security Gateway |
An ICAP client crash may cause the Security Gateway also to crash and generate an FWK core dump. |
PRJ-38076, |
Security Gateway |
The Security Gateway may crash with a vmcore. |
PRJ-41455, |
Security Gateway |
During a DDoS attack, the CPD and CPRID processes may unexpectedly exit with core dump files and cause latency. |
PRJ-27778, PMTR-70632 |
Security Gateway |
The RAD daemon may fail and create core dump files on VSX Gateways. |
PRJ-36568, |
Internal CA |
UPDATE: In SmartConsole, added an alert to inform that the ICA certificate will be expired in less than one year. Refer sk158096. |
PRJ-40432, |
Threat Prevention |
UPDATE: The Global Detect value will now be updated in the "ips stat" command output. |
PRJ-39323, |
Threat Prevention |
Improved memory consumption by decreasing the size of the mal_conns table. |
PRJ-40396, ODU-385 |
Threat Prevention |
Added Update 15 of Autonomous Threat Prevention Management integration Release Updates. Refer to sk167109. |
PRJ-41445, |
Threat Prevention |
In a specific HTTP connection scenario, the Security Gateway may become unresponsive. And the /var/log/messages file contains these messages during the time of the issue: " FW-1: fw_kfree: wrong magic number at tail end of XXX (XXX) caller is 'cmik_loader_fw_pm_match_cb' sz=80. FW-1 panic: cmik_loader_fw_pm_match_cb: fw_kfree: wrong magic number at tail (kiss_memory.c:XXX)". See the Important Notes section. |
PRJ-36293, |
Threat Prevention |
A "sft_rule_str_match_init: allocates 0 bytes" message may be printed many times in the /var/log/messages file. |
PRJ-36384, |
Application Control |
Refer to sk178406. |
PRJ-29435, |
URL Filtering |
When the Security Gateway works in proxy mode, the Application Control and URL Filtering rules may not match correctly. |
PRJ-39058, |
IPS |
In a VSX setup, the IP address used as the origin SIC name in the IPS address log may differ from the IP in other reports. |
PRJ-36434, |
IPS |
When ClusterXL is configured, a file may pass without inspection during a failover. |
PRJ-39151, |
Anti-Bot |
|
PRJ-34073, |
Mobile Access |
Manual Web Form Single Sign-On (SSO) may fail when passwords contain special characters. |
PRJ-39153, |
Mobile Access |
Login to Mobile Access Citrix application may fail. |
PRJ-34724, |
Mobile Access |
In some scenarios, The Mobile Access applications fail to login because the Security Gateway may not forward HTTP request cookies of some browser-initiated requests to an internal Server. |
PRJ-35292, |
Mobile Access |
In some scenarios, when Mobile Access Blade is enabled, the Security Gateway may crash. |
PRJ-38435, PMTR-82133 |
Mobile Access |
When installing a specific hotfix, the CVPND process may unexpectedly exit. |
PRJ-34870, |
ClusterXL |
UPDATE: Added support for the "Same VMAC" feature. |
PRJ-37489, |
ClusterXL |
In a VSLS cluster with a few members and Virtual Systems, when shutting down a bond connected to one of the Virtual Systems, all Virtual Systems on this member may go to Down state. |
PRJ-40200, |
ClusterXL |
In a cluster configured in the Active-Active mode, there may be connectivity issues when one of the cluster interfaces is down on one of the cluster members. |
PRJ-39958, |
ClusterXL |
During a Multi-Version Cluster (MVC) upgrade, there may be state flapping when using the sync interface MAC address bit "02". |
PRJ-39839, |
ClusterXL |
When reconnecting the OSPF interface on both members in a cluster, a failover may occur when receiving a ROUTED PNOTE on the Active member. |
PRJ-37943, |
ClusterXL |
In a VSX cluster with three or more members, sudden failover and recovery of the Standby VS may occur, causing termination of connections from the Active member. Refer to sk179446. |
PRJ-38594, |
SecureXL |
UPDATE: Added a new parameter cphwd_mcast_routing_interval_ms (default value is 0), which allows the multicast routing interval to be expressed in milliseconds. |
PRJ-37631, PRHF-22691 |
SecureXL |
UPDATE: The MSS value in the SYN Cookie response can now be configured. |
PRJ-40294, |
SecureXL |
A kernel memory leak may occur in an environment with a cluster in Active/Standby bridge mode. |
PRJ-38559, |
Routing |
UPDATE: Source Pruning will now be disabled by default when VRRP is enabled. This will prevent an interface from keeping the Standby member in Master state after port flapping. The issue is relevant only for Intel X710 network cards using the I40E driver. Refer to sk178484. |
PRJ-40091, PMTR-84418 |
Routing |
When running CPView and working in Source-Specific Multicast Mode (PIM-SSM) simultaneously, the ROUTED process may unexpectedly exit and create a core dump file. |
PRJ-37940, |
VPN |
NEW: KAT tests for IKE and TLS are now validated for FIPS certification. |
PRJ-37548, |
VPN |
In some scenarios, when StrongSwan client is connecting to a site or Security Gateway, the connection is established successfully, and the tunnel is created, but there is no traffic. Refer to sk118536. |
PRJ-37555, |
VPN |
An outage may occur when using IKEv2. |
PRJ-40663, |
VPN |
There may be a low throughput in a Site-to-Site VPN tunnel between two VSX Gateways with enabled. |
PRJ-38633, |
VPN |
Connection to Endpoint Security Client from the Remote Access VPN may be lost when the VPN tunnel timeout is reached. Refer to sk178891. |
PRJ-39064, |
VPN |
Capsule Connect may fail to connect to the Security Gateway because of an Office Mode IP allocation failure. |
PRJ-32680, |
VPN |
An IKEv1 tunnel may be deleted after the Dead Peer Detection (DPD) exchange and can cause an outage. |
PRJ-16239, |
VSX |
UPDATE: Added verification to prevent adding a bridge to a Virtual Router (VR) via the vsx_provisioning tool. |
PRJ-29583, |
VSX |
UPDATE: Decreased the time to edit routes in topologies where multiple Virtual Systems are connected to a Virtual Switch (VSW). |
PRJ-19530, |
VSX |
Policy installation may fail after resetting a Security Geteway and restoring a VSX cluster member backup. |
PRJ-32706, |
VSX |
After restoring the VSX Gateway backup, the SNMP agent stops responding when the context is set for a specific VS. |
PRJ-38726, |
VSX |
When running the "vsx_util downgrade" command, R80.20SP may not be listed as an available version. |
PRJ-38010, |
VSX |
"Loading kernel module for a network device with CAP_SYS_MODULE (deprecated). Use CAP_NET_ADMIN..." may be printed in dmesg. |
PRJ-39113, |
VSX |
CoreXL instances of SND type may appear in CPView as "OTHER" and not as "CoreXL_SND". |
PRJ-39353, |
VSX |
Running the "brctl_show" command in a non-VS0 context may give VS0 results. |
PRJ-33315, |
VSX |
The FWM process may unexpectedly exit after using the VSX Provisioning tool. |
PRJ-32407, |
VSX |
The OID "Syslocation" can now be configured in the context of a virtual system as described in the article (IV-1) Advanced SNMP configuration in sk90860. |
PRJ-34766, PRHF-21568 |
VSX |
When using Link Selection probing, the VPND process may unexpectedly exit and create a core dump file. |
PRJ-38828, PMTR-82551 |
VSX |
The FWK process of Virtual Switch (VSW) may consume a high CPU. |
PRJ-33041, PMTR-69098 |
VSX |
In a VSX cluster, after pushing Bridge configuration, the state may change from Active/Active to Active/Standby. |
PRJ-32477, |
VSX |
When using the VSX Provisioning Tool, it may not be possible to create a new warp interface and then change the main IP address of the VS in the same transaction. |
PRJ-38408, PMTR-73704 |
VSX |
When creating a virtual system, the "Failed to create Virtual System directories" error is displayed. |
PRJ-38793, PMTR-82492 |
VSX |
In some scenarios, it is not possible to start a vsx_util upgrade/downgrade after a failed attempt. |
PRJ-40250, |
VSX |
In VSX, when deleting a warp interface (either by deleting the warp itself or by performing the "reset_gw" command, which deletes all Virtual Devices), the VSX Gateway may crash. |
PRJ-34095, |
VSX |
When running the "vsx showncs" command, the "cannot retrieve vsid for VSW_gw" error may be shown. |
PRJ-40360, |
VSX |
Improved packet rate performance on warp interfaces. |
PRJ-40072, |
VSX |
A "SIC Error for EntitlementManager: Peer sent wrong DN: CN=xxx,O=xxx" message may be displayed during boot or after running the "cpstart" command. Refer to sk179586. |
PRJ-35585, |
Gaia OS |
UPDATE: It is now possible to use Gaia proxy addresses with more than 16 characters. |
PRJ-24566, PRHF-16407 |
Gaia OS |
UPDATE: Added support for the Excluded Files feature (sk116679) for XFS file system on Kernel 3.10. |
PRJ-27471, |
Gaia OS |
UPDATE: A description was added to the output of the "show backup logs" command with information about each column. Refer to sk173970. |
PRJ-24454, |
Gaia OS |
UPDATE: Changed the Syslog message severity from "error" to "info" and removed the exclamation mark in a specific message which is displayed during the normal backup operation flow. |
PRJ-39378, |
Gaia OS |
The CONFD process may unexpectedly exit and generate a core dump file. |
PRJ-40365, |
Gaia OS |
Gaia Snapshot fails in Gaia Portal ("Maintenance" section > "Snapshot Management" page) - after clicking the "New" button, the progress gets to 100%, but the snapshot file is never created. Refer to sk180579. |
PRJ-37348, |
Gaia OS |
When adding and deleting a neighbor-entry ipv6-address, an error message is displayed, although the operation is successful. |
PRJ-39479, |
Gaia OS |
For TACACS users the ">" character is missing to separate the hostname from the commands. The fix is only cosmetic. |
PRJ-36697, |
Gaia OS |
The /var/log/messages file may be flooded with "failed to update arp table file" messages. |
PRJ-30118, |
CloudGuard Network |
UPDATE: After a failed Data Center mapping, the next scan retry will be initiated with a delay to provide sufficient recovery time. |
PRJ-33577, |
CloudGuard Network |
When trying to add a comment to a Data Center object with API, the name of the object may get the value of the "comments". |
PRJ-38070, |
CloudGuard Network |
Policy install or publish may fail because of the CPM process operations overload. |
PRJ-38643, |
VoIP |
NEW: Added a new tab for VoIP monitoring in CPView. |
PRJ-40929, PRJ-40928 |
VoIP |
After an upgrade, the MGCP traffic may be dropped. The output of the "fw ctl zdebug + drop" command shows: "dropped by fw_early_sip_nat reason: failed to get MGCP ports". |
PRJ-39816, |
VoIP |
The Security Gateway may crash when running UDP and TCP SIP traffic. |
PRJ-32417, |
Harmony Endpoint |
Web Remote Help returns to the sign-in page after generating the response code. Refer to sk172666. |
PRJ-39109, |
Scalable Platforms |
UPDATE: Added ability to change CIN interface IP ranges. Refer to sk179028. |
PRJ-37868, |
Scalable Platforms |
UPDATE: The asg_info command is no longer supported on Scalable Platforms. The "cpinfo -Q" command should be used instead. |
PRJ-39721, |
Scalable Platforms |
Changed the message informing that CPUSE upgrade packages are not available on Scalable Platforms appliances with VPN enabled. The fix is only cosmetic. |
PRJ-39116, |
Scalable Platforms |
The "asg_excp_conf get" command may fail. Existing exceptions cannot be printed due to unaligned exception max size between kernel and userspace (cphaprob). |
PRJ-39637, |
Scalable Platforms |
The Hit Count feature may not provide data for non-SMO members on VSX with Kernel 3.10. |
PRJ-31427, |
Scalable Platforms |
Running the "cphaconf debug_data" command before the member finished the boot phase may cause a crash. |
PRJ-38700, |
Scalable Platforms |
The ROUTED process may unexpectedly exit when OSPF is configured as P2P. |
PRJ-37970, PMTR-76980 |
Scalable Platforms |
In some scenarios, CPWD and HCP report the CPUS_USGS process as terminated. |
PRJ-35284, |
Scalable Platforms |
A cluster member may fail to perform Full Sync and remain in Down state with FULLSYNC PNOTE. |
PRJ-37650, |
Scalable Platforms |
The "asg_copy_capture" logs repeatedly appear in the var/log/messages file. The reason given in the logs is "capture file was not found on remote SGMs". |
PRJ-40308, ODU-454 |
HCP |
Added Update 9 of HealthCheck Point (HCP) Release. Refer to sk171436. |
PRJ-40670, ODU-478 |
HCP |
Added Update 10 of HealthCheck Point (HCP) Release. Refer to sk171436. |