R82.10 Jumbo Hotfix Take 19

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 19

Released on 26 May 2026

Take 19 - New Functionality

 

PRJ-66478,
PMTR-119455

Security Management

NEW: Policy Auditor is a policy analytics and auditing tool that provides visibility into traffic behavior within the user's network. In SmartConsole > Security Policies > Access Control, Policy Auditor presents a matrix view of the network's logical segments and the access rules defined between them. The tool allows administrators to audit these security rules and verify that they align with organizational access policies and segmentation requirements.

  • Requires R82.10 SmartConsole Build 424 or higher.

PRJ-65860,
PRJ-65719

Security Management

NEW: Now you can manage SASE Internet Access policy and HTTPS Inspection policy directly from SmartConsole. By centralizing policy management, the integration ensures consistent policy enforcement across products, streamlines governance for security policies, and consolidates operations into one trusted, management platform.

PRJ-67022,
PMTR-124959

Security Management

NEW: Added a new Management API command to retrieve an entire Access Control Layer (including inline layers) - "export-access-rulebase".

PRJ-66628,
PMTR-124234

Security Management

NEW: Added integration between the Security Management Server and Illumio to extend Check Point micro-segmentation capabilities. This integration enables importing Illumio Workloads and Labels into SmartConsole and using them directly in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation.

Take 19 - Improvements and Resolved Issues

 

PRJ-67985,

PMTR-126652

Security Gateway

UPDATE: Resolved CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero. Refer to sk184981.

PRJ-67840,

PMTR-126457

Security Gateway

UPDATE: Resolved CVE-2026-48132 - VPN process may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP. Refer to sk184982.

PRJ-67875,

PMTR-126538

Security Gateway

UPDATE: Resolved CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion. Refer to sk184993.

PRJ-67837,

PMTR-126454

Security Gateway

UPDATE: Resolved CVE-2026-48134 - SQL injection issue in UserCheck Web Portal when DLP is active. Refer to sk184983.

PRJ-68010,

PMTR-126694

Security Gateway

UPDATE: Resolved CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests. Refer to sk184991.

PRJ-68356,

PMTR-126828

Security Management

UPDATE: Resolved CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance. Refer to sk184992.

-

-

This Jumbo Hotfix Accumulator Take includes dozens of code and functionality hardening changes.

PRJ-66495,
PMTR-123718

SSL Inspection

UPDATE: Upgraded OpenSSL from version 3.5.4 to version 3.5.5 to fix CVE-2025-66199.

PRJ-66682,
PMTR-124314

Mobile Access

UPDATE: The Magnific Popup JavaScript library is upgraded from the 1.1.0 version to 1.2.0.

PRJ-66598,
PMTR-123078

SSL Inspection

UPDATE: The HSM password is now configured in the secrets_manager tool using the "secrets_manager setpassword hsm" command. This provides centralized management and improved handling after configuration.

PRJ-67355,
PRHF-43660

Security Management

UPDATE: JRE is updated from version 8.0_8.50 to version 8.0_8.60.

PRJ-66177,
PRHF-44771

Security Management

UPDATE: Policy installation is now accelerated after performing Global Domain Reassignment.

PRJ-67101,

PMTR-89328

Security Management

UPDATE: Added a validation that helps to prevent assigning a single Security Gateway as both the Center and Satellite member within the same VPN Star Community.

PRJ-65618,
HEC-1347

HCP

UPDATE: Added a new HCP test that analyzes load balancing and NAT utilization, and suggests optimal distribution adjustments accordingly. Refer to sk171436.

PRJ-66950,
PRHF-44085

Security Gateway

UPDATE: Added the "tap_mode" parameter to a dispatcher (fwmultik_dispatcher_in_tap_mode). This parameter puts the multi-core dispatcher into the Tap Mode for inbound traffic. Refer to sk184455.

PRJ-63785,
PMTR-118923

Security Gateway

UPDATE: Added the ability to automatically stop kernel debugging after a specified number of seconds. See the R82 Quantum Security Gateway Administration Guide. Refer to the command "fw ctl debug -T <Number of Seconds>".

PRJ-66840

VPN

UPDATE: Improved the warning messages related to Tunnel Sharing behavior when transitioning between Route-Based and Domain-Based VPN community routing modes.

PRJ-65823,

CGNSIS-157

Cloud Firewall

UPDATE: Added support for Microsoft Azure Network Adapter (MANA) driver. Refer to sk183754.

PRJ-66209,

HEC-2331,

PRJ-66278,

PRJ-66316,

HEC-2296,

PRJ-66648,

PMTR-124220

Scalable Platforms

UPDATE: Added support for reusable target profiles to the Lightshot snapshot configuration.

PRJ-67871,

ODU-3950

Automatic Updates - CPSDC

UPDATE: Added Take 43 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414.

PRJ-68136,

ODU-3901

Automatic Updates - Policy Insights

UPDATE: Added Take 91 of Policy Insights Release Updates. Refer to sk183421.

PRJ-67868,

ODU-3957

Automatic Updates - HCP

UPDATE: Added Update 27 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-67791,

ODU-3852,

PRJ-67787,

ODU-3894,

PRJ-68756,

ODU-4023

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 165, Take 167, Take 170 via self-updatable package. Refer to sk170314.

PRJ-68748,
ODU-4030

Automatic Updates - Threat Prevention

UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109.

PRJ-65163,
PRHF-42879

Security Management

In SmartTask-generated emails, the Sender field displays the username instead of the user's email address.

PRJ-69084,

PMTR-127828

Security Management

Reinstallation of R82.10 Jumbo Hotfix Accumulator Take 6 may result in configuration loss.

See the Critical Information section.

PRJ-65037,

PRHF-42720

Security Management

In some scenarios, the status of a Security Gateway is incorrectly displayed in the Gateways & Servers View.

PRJ-66345,
PMTR-123469

Security Management

The "set-checkpoint-host" Management API command with the "interfaces" field may fail with the "generic_err_invalid_parameter" error.

PRJ-65448,
PRHF-43029

Security Management

In some scenarios, Global Domain assignment may fail with the "Failed to save the access policy assignment properties" error.

PRJ-66377,
PRHF-43684

Security Management

In some scenarios, SmartConsole disconnects during policy installation.

PRJ-64819,
PRHF-41049

Security Management

In some scenarios, when updatable objects are used in the policy, policy installation fails with error code "0-2-2000245". Refer to sk183844.

PRJ-66607,
PMTR-124200

Security Management

If the MGMTCOMP-DIFF-REPORT-CLIENT process becomes suspended on the Security Management Server, the Server-side Change Report Generator fails to generate and send reports when processing a large number of changes.

PRJ-66032,
PRHF-43621

Security Management

In some scenarios, the Management Server may generate excessive log messages, causing the cpm.elg log file to reach its size limit quickly.

PRJ-66396,
PRHF-38392

Security Management

Upon creation of a new Domain on a Multi-Domain Security Management Server, the Domain Server's virtual IP address is not added to the Gaia database, making it inaccessible via Clish commands. Refer to sk183941.

PRJ-66099,
PMTR-125251

Security Management

The "get interfaces" operation may fail when performed after adding a Data Center object to a VPN community.

PRJ-64691,

PRHF-34095

Security Management

The delay may be observed during the "compiling policy" and "generating policy files" stages in SmartConsole.

PRJ-65671,

PRHF-43067

Multi-Domain Security Management

In some scenarios, the Domain Log Management Server fails to connect to the Check Point Portal.

PRJ-67039

CPView

In some scenarios, CPVIEW_API_SERVICE may unexpectedly restart and generate a core dump file.

PRJ-68480,

PMTR-127026

CPView

A race condition may occur in the CPView API Service, which may result in the CPVIEWD daemon exiting during shutdown.

PRJ-68510,

PRJ-68481,

PMTR-127053

CPView

The CPVIEWD daemon may exit during startup.

PRJ-66685,
PRHF-41752

Logging

In SmartConsole, when exporting logs from the Logs tab to a CSV file, the "Rule" column may display only the parent rule number instead of the specific inline rule number.

PRJ-66532,

PRHF-44001

Logging

CPView may display "N/A" values for logging-related metrics when there is insufficient free disk space in the log partition.

PRJ-66652,

PRHF-35509

Logging

In the Connection logs, the Source Country and Destination Country fields may contain missing or incorrect values.

PRJ-66843,
PRHF-44182

Logging

In some scenarios, non-ASCII characters may appear garbled in SmartEvent Automatic Reaction emails.

PRJ-67271,
PRHF-38494

Logging

In HTTPS Inspection logs, some log entries may incorrectly display "Log Update" in the Software Blade field.

PRJ-65333,
PRHF-42927

Logging

In SmartView Monitor, opened from Logs & Events > Tunnel & User Monitoring, the "SmartEvent Correlation Unit" status may be displayed as "Not running" although the CPSEMD process is running.

PRJ-65365,
PMTR-122317

Logging

Improper memory handling within the CPD daemon may result in unexpected process restart.

PRJ-65551,
PRHF-39872

Security Gateway

Test feed fails when testing a Network Feed object with the feed parsing format configured as JSON. Refer to sk183618.

PRJ-64136,

PRHF-38489

Security Gateway

In rare scenarios, the FWK process may exit with core files because of a segmentation fault.

PRJ-67520,
PRHF-30983

Security Gateway

Running the "g_tcpdump mcap" with "-C" flag fails with the file matching or captured packets merging error.

PRJ-65712,
PRHF-41491

Security Gateway

Enabling the ForceAuth option for Remote Access VPN fails because of a typo in the saml_force_authn_override.sh script (sk182042).

PRJ-64181,
PRHF-41504

Security Gateway

In rare scenarios, the FWK process may exit when parsing an invalid SIP packet.

PRJ-66805,
PRHF-44149

Security Gateway

In rare scenarios, the FWK process may unexpectedly exit when the Anti-Bot Software Blade inspects a specific malformed domain.

PRJ-65443,
PRHF-42991

Security Gateway

The SD-WAN NAT rule may not be applied when no NAT is defined in the Access Control policy.

PRJ-64520,
PRHF-41790

Security Gateway

First packet may be delayed for around 10 seconds because of pending WSDNSD DNS lookup over TCP. Refer to sk184096.

PRJ-67358,
PRHF-44269

Security Gateway

In rare scenarios, after an upgrade, the Security Gateway may crash because of a missing route.

PRJ-66005,
PRHF-43522

Security Gateway

In a rare scenario, an incorrect zone assignment occurs when NAT Rule Base returns HOLD. Refer to sk184530.

PRJ-64835,
PRHF-42537

Security Gateway

Legitimate files may be incorrectly flagged as malicious when scanned with ICAP. Refer to sk184628.

PRJ-65054,
PRHF-42145

Security Gateway

In some scenarios, SNMPv3 monitoring fails on Data Plane when MDPS is enabled. Refer to sk184379.

PRJ-66199,

PRHF-43742

Security Gateway

In some scenarios, when processing HTTPS traffic in the accelerated pipelined path, the FWK process may unexpectedly exit.

PRJ-66360,
PRHF-43916

Security Gateway

The BMAC/VMAC verification for a VSX Maestro Security Group member incorrectly reports a failure on warp interfaces.

PRJ-66174,
PRHF-43692

Security Gateway

The Security Gateway may fail to correctly handle return traffic for pass-through GRE connections in scenarios with NAT.

PRJ-65269,
PMTR-121815

Security Gateway

In some scenarios, non-accelerated traffic from a Standby VSX Cluster member may not be routed to the correct virtual instance on the current Active member when SecureXL User Mode (UPPAK) is enabled.

PRJ-65586,

PRHF-43161

Threat Prevention

In Smart-1 Cloud environments, the "Threat Prevention" view may display 0 in the "Logs" column under the "Top Protections" widget. Refer to sk184505.

PRJ-65697,
PRHF-42937

Identity Awareness

In some scenarios, when Identity Sharing is configured to work with both IPv4 and IPv6 addresses, identity-based roles may not match the access roles.

PRJ-66257,
PMTR-123472

Identity Awareness

The TLS-based Identity Sharing connection between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) may fail to establish when using IPv6 transport.

PRJ-66217,
AAD-8684

Identity Awareness

In some scenarios, identity sessions are not propagated to the PEP when PDP multi-process is enabled.

PRJ-65790,
PRHF-42181

Identity Awareness

Identity Awareness AD user authentication takes a long time. Refer to sk183748.

PRJ-66925,
PMTR-122417

Identity Awareness

In some scenarios, when PDP Multi-Process is enabled, users or machines do not match their Identity-Based policy rules.

PRJ-65877,
PMTR-123004

Application Control

In a rare scenario, when using Dynamic URL List, updating the version file may result in a FWK process restart.

PRJ-65961,
PMTR-123099

Application Control

Updating two or more Dynamic URL Lists may result in partial updates.

PRJ-66301,
PRJ-66185

Anti-Virus

In some scenarios, the Security Gateway may drop DNS traffic with non-malicious Domains.

PRJ-66453,
PMTR-121764

SSL Inspection

Several WSTLSD processes running for each Security Gateway may exhaust memory consumption.

PRJ-66595,
PRHF-44051

Mobile Access

When Mobile Access is working in Path Translation (PT) Link Translation mode, the Citrix application may not load after an upgrade to Citrix version LTSR 2507.

PRJ-67249,
PRHF-44244

Mobile Access

On a Check Point Firewall 3900 appliance, the CVPND process may exit while serving Citrix applications.

PRJ-65902,
PMTR-123186

ClusterXL

After rebooting specific Security Group Members (SGMs) in a dual-site Maestro environment, PDP (Policy Decision Point) to PEP (Policy Enforcement Point) connections are not always corrected to the SMO (Single Management Object) as expected. This results in connection restarts and additional CPU load.

PRJ-64917,
PRHF-42671

ClusterXL

After creating a High Availability ClusterXL and syncing to Smart-1 Cloud, running the "get interfaces with topology" in Smart-1 Cloud may cause the Sync interface to be removed from the Cluster object.

PRJ-64091,
PRA-5003

ClusterXL

When MDPS is enabled, cluster members may remain in INIT or DOWN state after reboot.

PRJ-66294,
PMTR-123321

ClusterXL

In rare scenarios, CPHASTART, CPHACONF, and CPHAMCSET processes may intermittently unexpectedly exit.

PRJ-67240,
PRHF-44218

SecureXL

IPv4 addresses in the SYN Defender Allow List in SmartConsole may be loaded with the address octets reversed.

PRJ-67686,
PMTR-125951

SecureXL

Changes to the SYN Defender Allow List made in SmartConsole may not override or replace local modifications made directly on the Security Gateway.

PRJ-67243,
PRHF-44335

SecureXL

When loading the SYN Defender Allow List from the Gateway CLI using only the "-L" parameter, the entries are merged with the existing Allow List (including those configured in SmartConsole), rather than overwriting it.

PRJ-67246,
PRHF-44550

SecureXL

Maestro backplane interfaces may appear in the SYN Defender interface list. This is a cosmetic issue.

PRJ-67252,

PRHF-44552

SecureXL

The USIM process may exit on Check Point Firewall 3900 appliances during IPsec VPN traffic decryption.

PRJ-66368,
PMTR-121210

SecureXL

Local VXLAN connections may not work as expected.

PRJ-66508,
PMTR-122586

SecureXL

In some scenarios in a VSX Maestro Security Group, when SecureXL User Mode (UPPAK) is enabled, a cluster member may incorrectly forward traffic through a Warp interface to the incorrect Virtual System. This results in traffic not being processed by the intended Virtual System, potentially causing "Out of State" drops.

PRJ-66571

SecureXL

When SecureXL is running in User Mode (UPPAK) on ESXi with iavf SR-IOV enabled, setting the SND core count using "cpconfig" or the queue count using "mq_mng" to a value that is not a power of two (for example, any number other than 2, 4, 8, 16, and so on) may result in the Security Gateway entering an infinite boot loop.

PRJ-67078,
PMTR-121785

SecureXL

When using Virtio or net_iavf drivers, when configuring "mq_mng" and setting the core count to match the SND (Send) core count, a portion of network traffic may be lost.

PRJ-67067,
PMTR-124718

SecureXL

The FWK process may exit during an upgrade if DOS/Rate limiting is active.

PRJ-66172,
PRHF-43757

SecureXL

In some scenarios, when installing a policy fails, the Sand Blast Security Gateway becomes unresponsive and reboots automatically. The "Installation failed. Reason: Due to a timeout value of 600000 (millisecond) (port) (IP), Security Management Server aborted the connection with the peer" error is displayed in SmartConsole.

PRJ-65915,
PMTR-122248

SecureXL

When SecureXL User Mode (UPPAK) is enabled on a VSX Security Gateway, taking down a warp interface on any Virtual System may cause all Virtual Systems connected to the same Virtual Router or Switch to lose network connectivity.

PRJ-65449,
PMTR-120207

SecureXL

The Security Gateway with SecureXL User Mode (UPPAK) enabled may not properly update routes when bond interfaces are configured.

PRJ-65918,
PMTR-122434

Routing

A VSX Security Gateway may drop traffic with IPv4 options or IPv6 extension headers arriving from a Virtual Switch (VSW) interface.

PRJ-67174,
PRHF-44146

Routing

A ROUTED daemon may exit with a dump file during an OSPF route lookup on a route being redistributed between BGP and OSPF.

PRJ-66409,
PRHF-43907

Gaia OS

The SNMPD daemon fails to restart when an interface configured with an IPv6 address is set as the SNMP agent interface.

PRJ-65891,
PRHF-30690

Gaia OS

Custom log rotation configured using Gaia OS does not apply to SAML-related log files, so these logs are not rotated automatically. Refer to sk113241.

PRJ-65890,
PRHF-34965

Gaia OS

Custom log rotation configured using Gaia OS does not apply to UserCheck Portal log files, so these logs are not rotated automatically. Refer to sk113241.

PRJ-66752,
PRHF-44108

Gaia OS

Cloning groups may fail during configuration updates. Refer to sk184701.

PRJ-67883,

PMTR-126636

Gaia OS

In a Maestro setup with MDPS enabled, the Security Gateway may crash when processing IPv6 traffic while under load.

PRJ-66616,
PRHF-43985

Gaia OS

Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000. Refer to sk184653.

PRJ-68363,

PMTR-126985

Gaia OS

In rare scenarios, a Check Point Firewall 3900 appliance (3950, 3970/3980 model) may fail to identify the hard disk.

PRJ-64590,
PRHF-41203

Gaia OS

CPU spikes may occur in a cluster when SNMP is enabled.

PRJ-66271,
PMTR-123507

VPN

During VPN IKEv2 negotiations with third-party peers that offer multiple combined encryption algorithms (both AES-GCM-128 and AES-GCM-256), the Security Gateway may not properly match the proposal, resulting in IKE failure logs and the tunnel establishment failure.

PRJ-66821,
PMTR-124036

VPN

Multiple Entry Point (MEP) validation may be incorrectly triggered when switching a Star Community to a Route-Based community.

PRJ-65544,
PMTR-123634

VPN

VPN participant Domains may not be automatically removed when a device is deleted from a community.

PRJ-65012,
PRA-5001

VPN

SSL Network Extender Portal is accessible even when it is disabled in SmartConsole. Refer to sk184344.

PRJ-65827,
PRHF-43529

VPN

A customized Per-gateway Secure Configuration Verification (SCV) policy is not enforced for Remote Access VPN clients. Refer to sk184863.

PRJ-64814,
PMTR-120624

VPN

When switching a VPN community from Route-Based to Domain-Based mode, the Tunnel Sharing setting may not reset to its default value. After the switch, Tunnel Sharing remains set to Per Gateway Pair instead of reverting to the Domain-Based default of Per Subnet Pair. No notification is displayed to alert about the discrepancy, which may impact performance.

PRJ-65420,
PMTR-121924

VPN

After a Cluster failback, RDP (Routed Data Path) or DPD (Dead Peer Detection) probing may not be triggered, which can result in traffic continuing to use outdated Multiple Entry Point (MEP) Gateway selections.

PRJ-66366,
PMTR-123613

VPN

In some scenarios, over time, prolonged VPN traffic may lead to gradual memory growth.

PRJ-64081,
PRHF-41901

VPN

When generating a CPInfo file using the CPInfo utility, major CPU spikes may occur on the Security Gateway or Security Management Server.

PRJ-66013,

PMTR-117053

VPN

VPN traffic from L2TP clients may fail to pass through the Security Gateway working in SecureXL User Mode (UPPAK).

PRJ-68887,

PRJ-68715,

PMTR-127505

VPN

Remote Access Endpoint Security Client may disconnect and reconnect approximately every 15 seconds.

PRJ-65463,

PMTR-122433

VPN

Remote Access Endpoint Security Client may fail to connect.

PRJ-67928,

PRHF-45114

Multi-Portal

In a rare scenario, a security hardening change related to Multi-Portal connections may cause an unexpected Security Gateway restart when such a connection is terminated.

See the Critical Information section.

PRJ-67447,
PMTR-121363

VSX

When a Virtual System (VS) is deleted from a VSX Security Gateway, the Dynamic Split feature does not properly recognize the removal and continues to attempt fetching data or updating CPU affinity for the deleted VS. This results in repeated errors or log entries referencing the non-existent Virtual System, and may interfere with CPU core allocation and affinity management for the remaining VSs.

PRJ-66798,

PRHF-41154

VSX

A malformed or incorrect interface name in the "cphaprob -a if" command on VS0 triggers a fatal error in the cluster process, causing the member to go DOWN and generating a core dump.

PRJ-65935,
HEC-2260

VSX

The "show configuration" gClish command may fail for showing configuration for LLDP, VSNext, VSLS, SSH, and OSPF.

PRJ-65674,
PMTR-122609

VSX

Deleting a Virtual Switch (VSW) may break connectivity for unrelated Virtual Systems (VSs).

PRJ-67231,
PMTR-125258

VSX

Incorrect MAC address configuration on WRP interfaces in a VSNext environment leads to ClusterXL Load Sharing malfunctions and traffic correction issues.

PRJ-67115,
PMTR-123775

VSX

When adding or deleting static routes in the huge VSX environment (more than 50 Virtual Systems and hundreds of static routes), VS creation fails with "Unable to watch directory /etc/routed-mc-enable: init: Too many open files". Refer to sk181317.

PRJ-65389,
PMTR-122044

VSNext

In VSNext ElasticXL and VSNext Maestro, running the "cpconfig" command from Clish/gClish within a Virtual System context may trigger execution in the Global context.

PRJ-65387,

PMTR-122058

VSNext

When the Same VMAC Mode is enabled on ElasticXL, VS0 may lose connectivity (SSH).

PRJ-66386,

PRHF-43223

Cloud Firewall

The FWM may unexpectedly exit when attaching a license to a Security Gateway using vSEC license distribution (vsec_lic_cli).

PRJ-65297,

PRHF-42496

Cloud Firewall

When using VSLS with Identity Sharing enabled, CloudGuard Controller may fail to send updates to Virtual Systems that have no Data Center Objects in their policy.

PRJ-65014,
PRHF-42642

Cloud Firewall

Registration of Data Center assets with a numeric, non-UID unique identifier may fail, potentially causing performance impact on the Security Management Server.

PRJ-65940,
PRHF-42485

SD-WAN

In rare scenarios, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) may be incomplete, causing SD-WAN rules to match traffic incorrectly. Refer to sk184814.

PRJ-64736,
SDWANGW-5773

SD-WAN

A VPN IPv6 traffic outage may occur when a host/network object is defined with the Security Gateway's main IPv6 address.

PRJ-66034,
PMTR-109757

VoIP

Real-time Transport Protocol (RTP) may not function correctly, this results in the VoIP/RTP traffic being dropped.

PRJ-65801,
PRHF-42758

VoIP

Security Gateway may drop legitimate H323 traffic with "Illegal H.225(Q931) No Q.931 User-user IE found". Refer to sk184591.

PRJ-66899,
PRJ-56967

Scalable Platforms

Maestro/ElasticXL policy installation may fail during a major version upgrade.

PRJ-65099,
HEC-1552

Scalable Platforms

In a Maestro environment with Multi-Domain Security Management and enabled MDPS, SNMP per member queries do not survive member failover. Additionally, SNMP queries to the SMO may be routed to the dplane instead of the mplane.

PRJ-67016,
PMTR-121790

Scalable Platforms

In a Maestro setup, VXLAN tunnels may not consistently forward traffic with multiple Security Group Members.

PRJ-66487,
PMTR-121957

Scalable Platforms

In a Maestro environment, deleting a configured VXLAN from the Security Gateway using gClish on VS0 results in a "Segmentation fault (core dumped)" error, despite successful deletion from SmartConsole.

PRJ-66559,
PMTR-121905

Scalable Platforms

In ElasticXL setups, it may not be possible to add a second Sync interface to the bonding group.

PRJ-67483,
PMTR-125457

Scalable Platforms

If a management interface on ElasticXL Security Gateway is a part of a bond, the license distribution mechanism may not work as expected.

PRJ-67177,
PMTR-120169

Scalable Platforms

In ElasticXL Clusters, a new member that exits ungracefully (force shutdown, power loss, unexpected exit) may not appear in the Clish "delete cluster member" options and cannot be deleted from the cluster configuration.

PRJ-66522,
SPC-3384

Scalable Platforms

Rebooting an Active member in the Single Management Object (SMO) role may trigger a brief connectivity loss.

PRJ-66921,
PMTR-124111

Scalable Platforms

After upgrading the Multi-Version Cluster to R82.10, failback to an older version may cause connection drops.

PRJ-66706,
PMTR-124344

Scalable Platforms

After an upgrade to R82.10 of the Maestro environment, connecting using SSL Network Extender (SNX) fails. The Security Gateway drops the packets with the reason "clear text packet should be encrypted".

PRJ-68246

Scalable Platforms

After uninstalling the R82.10 Jumbo Hotfix Accumulator, previously installed RPM packages are not restored to their original state.

PRJ-65694,
PMTR-122746

Scalable Platforms

In VSX setup, a configuration note may be generated after a reboot, although the configuration is synchronized.

PRJ-67350,
PMTR-123997

Scalable Platforms

A Security Group Member may enter a continuous boot loop after the other members were upgraded. An incorrect image file (with an invalid or mismatched MD5 checksum) is presented on the Single Management Object (SMO). As a result, the problematic member fails to complete the autoclone and repeatedly reboots.

PRJ-66512,
PMTR-122125

Scalable Platforms

Members added to an ElasticXL Security Group with the MDPS feature enabled may remain in the Down state because of a missing license. Licenses are not automatically distributed from the SMO member to newly added Security Group members.

PRJ-65728,
HEC-2236

Scalable Platforms

In VSNext setup, when a numbered VTI interface is created for a route-based VPN under VS0 and attached to a Virtual System, the interface appears correctly in the output of the "ifconfig" command under VS0 but becomes invisible in "ifconfig" within the assigned VS context, although it remains visible in the Clish commands output.

PRJ-65996,
PRJ-65903

Scalable Platforms

On Maestro running VSNext, when a Virtual Switch (VSW) shares a physical interface with a Virtual System (using different VLANs), the VSW's VLAN interface may not be propagated to the Maestro Hyperscale Orchestrator (MHO).

PRJ-67338,
PRJ-67210

Scalable Platforms

Bond interface deletion or IP address change may cause a site failover.

PRJ-65685,
PRHF-42942

Carrier Security

The FWK process may exit when GTP Intra Tunnel Inspection is enabled.

PRJ-65688,
CST-423

Carrier Security

GTP-U intra-tunnel packets may be dropped with "Packet too short" and "Invalid IP packet" errors in Bridge Mode, preventing proper inspection of encapsulated traffic.

PRJ-66715,
CST-439

Carrier Security

A "Tunnel established" message may be printed for rejected sessions. The issue is cosmetic.