R82.10 Jumbo Hotfix Take 19
|
|
Note - This Take contains all fixes from all earlier Takes. |
|
ID |
Product |
Description |
|---|---|---|
|
Take 19 Released on 26 May 2026 |
||
|
Take 19 - New Functionality
|
||
|
PRJ-66478, |
Security Management |
NEW: Policy Auditor is a policy analytics and auditing tool that provides visibility into traffic behavior within the user's network. In SmartConsole > Security Policies > Access Control, Policy Auditor presents a matrix view of the network's logical segments and the access rules defined between them. The tool allows administrators to audit these security rules and verify that they align with organizational access policies and segmentation requirements.
|
|
PRJ-65860, |
Security Management |
NEW: Now you can manage SASE Internet Access policy and HTTPS Inspection policy directly from SmartConsole. By centralizing policy management, the integration ensures consistent policy enforcement across products, streamlines governance for security policies, and consolidates operations into one trusted, management platform. |
|
PRJ-67022, |
Security Management |
NEW: Added a new Management API command to retrieve an entire Access Control Layer (including inline layers) - "export-access-rulebase". |
|
PRJ-66628, |
Security Management |
NEW: Added integration between the Security Management Server and Illumio to extend Check Point micro-segmentation capabilities. This integration enables importing Illumio Workloads and Labels into SmartConsole and using them directly in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation. |
|
Take 19 - Improvements and Resolved Issues
|
||
|
PRJ-67985, PMTR-126652 |
Security Gateway |
UPDATE: Resolved CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero. Refer to sk184981. |
|
PRJ-67840, PMTR-126457 |
Security Gateway |
UPDATE: Resolved CVE-2026-48132 - VPN process may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP. Refer to sk184982. |
|
PRJ-67875, PMTR-126538 |
Security Gateway |
UPDATE: Resolved CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion. Refer to sk184993. |
|
PRJ-67837, PMTR-126454 |
Security Gateway |
UPDATE: Resolved CVE-2026-48134 - SQL injection issue in UserCheck Web Portal when DLP is active. Refer to sk184983. |
|
PRJ-68010, PMTR-126694 |
Security Gateway |
UPDATE: Resolved CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests. Refer to sk184991. |
|
PRJ-68356, PMTR-126828 |
Security Management |
UPDATE: Resolved CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance. Refer to sk184992. |
|
- |
- |
This Jumbo Hotfix Accumulator Take includes dozens of code and functionality hardening changes. |
|
PRJ-66495, |
SSL Inspection |
UPDATE: Upgraded OpenSSL from version 3.5.4 to version 3.5.5 to fix CVE-2025-66199. |
|
PRJ-66682, |
Mobile Access |
UPDATE: The Magnific Popup JavaScript library is upgraded from the 1.1.0 version to 1.2.0. |
|
PRJ-66598, |
SSL Inspection |
UPDATE: The HSM password is now configured in the secrets_manager tool using the "secrets_manager setpassword hsm" command. This provides centralized management and improved handling after configuration. |
|
PRJ-67355, |
Security Management |
UPDATE: JRE is updated from version 8.0_8.50 to version 8.0_8.60. |
|
PRJ-66177, |
Security Management |
UPDATE: Policy installation is now accelerated after performing Global Domain Reassignment. |
|
PRJ-67101, PMTR-89328 |
Security Management |
UPDATE: Added a validation that helps to prevent assigning a single Security Gateway as both the Center and Satellite member within the same VPN Star Community. |
|
PRJ-65618, |
HCP |
UPDATE: Added a new HCP test that analyzes load balancing and NAT utilization, and suggests optimal distribution adjustments accordingly. Refer to sk171436. |
|
PRJ-66950, |
Security Gateway |
UPDATE: Added the "tap_mode" parameter to a dispatcher (fwmultik_dispatcher_in_tap_mode). This parameter puts the multi-core dispatcher into the Tap Mode for inbound traffic. Refer to sk184455. |
|
PRJ-63785, |
Security Gateway |
UPDATE: Added the ability to automatically stop kernel debugging after a specified number of seconds. See the R82 Quantum Security Gateway Administration Guide. Refer to the command "fw ctl debug -T <Number of Seconds>". |
|
PRJ-66840 |
VPN |
UPDATE: Improved the warning messages related to Tunnel Sharing behavior when transitioning between Route-Based and Domain-Based VPN community routing modes. |
|
PRJ-65823, CGNSIS-157 |
Cloud Firewall |
UPDATE: Added support for Microsoft Azure Network Adapter (MANA) driver. Refer to sk183754. |
|
PRJ-66209, HEC-2331, PRJ-66278, PRJ-66316, HEC-2296, PRJ-66648, PMTR-124220 |
Scalable Platforms |
UPDATE: Added support for reusable target profiles to the Lightshot snapshot configuration. |
|
PRJ-67871, ODU-3950 |
Automatic Updates - CPSDC |
UPDATE: Added Take 43 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414. |
|
PRJ-68136, ODU-3901 |
Automatic Updates - Policy Insights |
UPDATE: Added Take 91 of Policy Insights Release Updates. Refer to sk183421. |
|
PRJ-67868, ODU-3957 |
Automatic Updates - HCP |
UPDATE: Added Update 27 of HealthCheck Point (HCP) Release. Refer to sk171436. |
|
PRJ-67791, ODU-3852, PRJ-67787, ODU-3894, PRJ-68756, ODU-4023 |
Automatic Updates - Web SmartConsole |
UPDATE: New features and improvements are released in Take 165, Take 167, Take 170 via self-updatable package. Refer to sk170314. |
|
PRJ-68748, |
Automatic Updates - Threat Prevention |
UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109. |
|
PRJ-65163, |
Security Management |
In SmartTask-generated emails, the Sender field displays the username instead of the user's email address. |
|
PRJ-69084, PMTR-127828 |
Security Management |
Reinstallation of R82.10 Jumbo Hotfix Accumulator Take 6 may result in configuration loss. See the Critical Information section. |
|
PRJ-65037, PRHF-42720 |
Security Management |
In some scenarios, the status of a Security Gateway is incorrectly displayed in the Gateways & Servers View. |
|
PRJ-66345, |
Security Management |
The "set-checkpoint-host" Management API command with the "interfaces" field may fail with the "generic_err_invalid_parameter" error. |
|
PRJ-65448, |
Security Management |
In some scenarios, Global Domain assignment may fail with the "Failed to save the access policy assignment properties" error. |
|
PRJ-66377, |
Security Management |
In some scenarios, SmartConsole disconnects during policy installation. |
|
PRJ-64819, |
Security Management |
In some scenarios, when updatable objects are used in the policy, policy installation fails with error code "0-2-2000245". Refer to sk183844. |
|
PRJ-66607, |
Security Management |
If the MGMTCOMP-DIFF-REPORT-CLIENT process becomes suspended on the Security Management Server, the Server-side Change Report Generator fails to generate and send reports when processing a large number of changes. |
|
PRJ-66032, |
Security Management |
In some scenarios, the Management Server may generate excessive log messages, causing the cpm.elg log file to reach its size limit quickly. |
|
PRJ-66396, |
Security Management |
Upon creation of a new Domain on a Multi-Domain Security Management Server, the Domain Server's virtual IP address is not added to the Gaia database, making it inaccessible via Clish commands. Refer to sk183941. |
|
PRJ-66099, |
Security Management |
The "get interfaces" operation may fail when performed after adding a Data Center object to a VPN community. |
|
PRJ-64691, PRHF-34095 |
Security Management |
The delay may be observed during the "compiling policy" and "generating policy files" stages in SmartConsole. |
|
PRJ-65671, PRHF-43067 |
Multi-Domain Security Management |
In some scenarios, the Domain Log Management Server fails to connect to the Check Point Portal. |
|
PRJ-67039 |
CPView |
In some scenarios, CPVIEW_API_SERVICE may unexpectedly restart and generate a core dump file. |
|
PRJ-68480, PMTR-127026 |
CPView |
A race condition may occur in the CPView API Service, which may result in the CPVIEWD daemon exiting during shutdown. |
|
PRJ-68510, PRJ-68481, PMTR-127053 |
CPView |
The CPVIEWD daemon may exit during startup. |
|
PRJ-66685, |
Logging |
In SmartConsole, when exporting logs from the Logs tab to a CSV file, the "Rule" column may display only the parent rule number instead of the specific inline rule number. |
|
PRJ-66532, PRHF-44001 |
Logging |
CPView may display "N/A" values for logging-related metrics when there is insufficient free disk space in the log partition. |
|
PRJ-66652, PRHF-35509 |
Logging |
In the Connection logs, the Source Country and Destination Country fields may contain missing or incorrect values. |
|
PRJ-66843, |
Logging |
In some scenarios, non-ASCII characters may appear garbled in SmartEvent Automatic Reaction emails. |
|
PRJ-67271, |
Logging |
In HTTPS Inspection logs, some log entries may incorrectly display "Log Update" in the Software Blade field. |
|
PRJ-65333, |
Logging |
In SmartView Monitor, opened from Logs & Events > Tunnel & User Monitoring, the "SmartEvent Correlation Unit" status may be displayed as "Not running" although the CPSEMD process is running. |
|
PRJ-65365, |
Logging |
Improper memory handling within the CPD daemon may result in unexpected process restart. |
|
PRJ-65551, |
Security Gateway |
Test feed fails when testing a Network Feed object with the feed parsing format configured as JSON. Refer to sk183618. |
|
PRJ-64136, PRHF-38489 |
Security Gateway |
In rare scenarios, the FWK process may exit with core files because of a segmentation fault. |
|
PRJ-67520, |
Security Gateway |
Running the "g_tcpdump mcap" with "-C" flag fails with the file matching or captured packets merging error. |
|
PRJ-65712, |
Security Gateway |
Enabling the ForceAuth option for Remote Access VPN fails because of a typo in the saml_force_authn_override.sh script (sk182042). |
|
PRJ-64181, |
Security Gateway |
In rare scenarios, the FWK process may exit when parsing an invalid SIP packet. |
|
PRJ-66805, |
Security Gateway |
In rare scenarios, the FWK process may unexpectedly exit when the Anti-Bot Software Blade inspects a specific malformed domain. |
|
PRJ-65443, |
Security Gateway |
The SD-WAN NAT rule may not be applied when no NAT is defined in the Access Control policy. |
|
PRJ-64520, |
Security Gateway |
First packet may be delayed for around 10 seconds because of pending WSDNSD DNS lookup over TCP. Refer to sk184096. |
|
PRJ-67358, |
Security Gateway |
In rare scenarios, after an upgrade, the Security Gateway may crash because of a missing route. |
|
PRJ-66005, |
Security Gateway |
In a rare scenario, an incorrect zone assignment occurs when NAT Rule Base returns HOLD. Refer to sk184530. |
|
PRJ-64835, |
Security Gateway |
Legitimate files may be incorrectly flagged as malicious when scanned with ICAP. Refer to sk184628. |
|
PRJ-65054, |
Security Gateway |
In some scenarios, SNMPv3 monitoring fails on Data Plane when MDPS is enabled. Refer to sk184379. |
|
PRJ-66199, PRHF-43742 |
Security Gateway |
In some scenarios, when processing HTTPS traffic in the accelerated pipelined path, the FWK process may unexpectedly exit. |
|
PRJ-66360, |
Security Gateway |
The BMAC/VMAC verification for a VSX Maestro Security Group member incorrectly reports a failure on warp interfaces. |
|
PRJ-66174, |
Security Gateway |
The Security Gateway may fail to correctly handle return traffic for pass-through GRE connections in scenarios with NAT. |
|
PRJ-65269, |
Security Gateway |
In some scenarios, non-accelerated traffic from a Standby VSX Cluster member may not be routed to the correct virtual instance on the current Active member when SecureXL User Mode (UPPAK) is enabled. |
|
PRJ-65586, PRHF-43161 |
Threat Prevention |
In Smart-1 Cloud environments, the "Threat Prevention" view may display 0 in the "Logs" column under the "Top Protections" widget. Refer to sk184505. |
|
PRJ-65697, |
Identity Awareness |
In some scenarios, when Identity Sharing is configured to work with both IPv4 and IPv6 addresses, identity-based roles may not match the access roles. |
|
PRJ-66257, |
Identity Awareness |
The TLS-based Identity Sharing connection between the Policy Decision Point (PDP) and Policy Enforcement Point (PEP) may fail to establish when using IPv6 transport. |
|
PRJ-66217, |
Identity Awareness |
In some scenarios, identity sessions are not propagated to the PEP when PDP multi-process is enabled. |
|
PRJ-65790, |
Identity Awareness |
Identity Awareness AD user authentication takes a long time. Refer to sk183748. |
|
PRJ-66925, |
Identity Awareness |
In some scenarios, when PDP Multi-Process is enabled, users or machines do not match their Identity-Based policy rules. |
|
PRJ-65877, |
Application Control |
In a rare scenario, when using Dynamic URL List, updating the version file may result in a FWK process restart. |
|
PRJ-65961, |
Application Control |
Updating two or more Dynamic URL Lists may result in partial updates. |
|
PRJ-66301, |
Anti-Virus |
In some scenarios, the Security Gateway may drop DNS traffic with non-malicious Domains. |
|
PRJ-66453, |
SSL Inspection |
Several WSTLSD processes running for each Security Gateway may exhaust memory consumption. |
|
PRJ-66595, |
Mobile Access |
When Mobile Access is working in Path Translation (PT) Link Translation mode, the Citrix application may not load after an upgrade to Citrix version LTSR 2507. |
|
PRJ-67249, |
Mobile Access |
On a Check Point Firewall 3900 appliance, the CVPND process may exit while serving Citrix applications. |
|
PRJ-65902, |
ClusterXL |
After rebooting specific Security Group Members (SGMs) in a dual-site Maestro environment, PDP (Policy Decision Point) to PEP (Policy Enforcement Point) connections are not always corrected to the SMO (Single Management Object) as expected. This results in connection restarts and additional CPU load. |
|
PRJ-64917, |
ClusterXL |
After creating a High Availability ClusterXL and syncing to Smart-1 Cloud, running the "get interfaces with topology" in Smart-1 Cloud may cause the Sync interface to be removed from the Cluster object. |
|
PRJ-64091, |
ClusterXL |
When MDPS is enabled, cluster members may remain in INIT or DOWN state after reboot. |
|
PRJ-66294, |
ClusterXL |
In rare scenarios, CPHASTART, CPHACONF, and CPHAMCSET processes may intermittently unexpectedly exit. |
|
PRJ-67240, |
SecureXL |
IPv4 addresses in the SYN Defender Allow List in SmartConsole may be loaded with the address octets reversed. |
|
PRJ-67686, |
SecureXL |
Changes to the SYN Defender Allow List made in SmartConsole may not override or replace local modifications made directly on the Security Gateway. |
|
PRJ-67243, |
SecureXL |
When loading the SYN Defender Allow List from the Gateway CLI using only the "-L" parameter, the entries are merged with the existing Allow List (including those configured in SmartConsole), rather than overwriting it. |
|
PRJ-67246, |
SecureXL |
Maestro backplane interfaces may appear in the SYN Defender interface list. This is a cosmetic issue. |
|
PRJ-67252, PRHF-44552 |
SecureXL |
The USIM process may exit on Check Point Firewall 3900 appliances during IPsec VPN traffic decryption. |
|
PRJ-66368, |
SecureXL |
Local VXLAN connections may not work as expected. |
|
PRJ-66508, |
SecureXL |
In some scenarios in a VSX Maestro Security Group, when SecureXL User Mode (UPPAK) is enabled, a cluster member may incorrectly forward traffic through a Warp interface to the incorrect Virtual System. This results in traffic not being processed by the intended Virtual System, potentially causing "Out of State" drops. |
|
PRJ-66571 |
SecureXL |
When SecureXL is running in User Mode (UPPAK) on ESXi with iavf SR-IOV enabled, setting the SND core count using "cpconfig" or the queue count using "mq_mng" to a value that is not a power of two (for example, any number other than 2, 4, 8, 16, and so on) may result in the Security Gateway entering an infinite boot loop. |
|
PRJ-67078, |
SecureXL |
When using Virtio or net_iavf drivers, when configuring "mq_mng" and setting the core count to match the SND (Send) core count, a portion of network traffic may be lost. |
|
PRJ-67067, |
SecureXL |
The FWK process may exit during an upgrade if DOS/Rate limiting is active. |
|
PRJ-66172, |
SecureXL |
In some scenarios, when installing a policy fails, the Sand Blast Security Gateway becomes unresponsive and reboots automatically. The "Installation failed. Reason: Due to a timeout value of 600000 (millisecond) (port) (IP), Security Management Server aborted the connection with the peer" error is displayed in SmartConsole. |
|
PRJ-65915, |
SecureXL |
When SecureXL User Mode (UPPAK) is enabled on a VSX Security Gateway, taking down a warp interface on any Virtual System may cause all Virtual Systems connected to the same Virtual Router or Switch to lose network connectivity. |
|
PRJ-65449, |
SecureXL |
The Security Gateway with SecureXL User Mode (UPPAK) enabled may not properly update routes when bond interfaces are configured. |
|
PRJ-65918, |
Routing |
A VSX Security Gateway may drop traffic with IPv4 options or IPv6 extension headers arriving from a Virtual Switch (VSW) interface. |
|
PRJ-67174, |
Routing |
A ROUTED daemon may exit with a dump file during an OSPF route lookup on a route being redistributed between BGP and OSPF. |
|
PRJ-66409, |
Gaia OS |
The SNMPD daemon fails to restart when an interface configured with an IPv6 address is set as the SNMP agent interface. |
|
PRJ-65891, |
Gaia OS |
Custom log rotation configured using Gaia OS does not apply to SAML-related log files, so these logs are not rotated automatically. Refer to sk113241. |
|
PRJ-65890, |
Gaia OS |
Custom log rotation configured using Gaia OS does not apply to UserCheck Portal log files, so these logs are not rotated automatically. Refer to sk113241. |
|
PRJ-66752, |
Gaia OS |
Cloning groups may fail during configuration updates. Refer to sk184701. |
|
PRJ-67883, PMTR-126636 |
Gaia OS |
In a Maestro setup with MDPS enabled, the Security Gateway may crash when processing IPv6 traffic while under load. |
|
PRJ-66616, |
Gaia OS |
Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000. Refer to sk184653. |
|
PRJ-68363, PMTR-126985 |
Gaia OS |
In rare scenarios, a Check Point Firewall 3900 appliance (3950, 3970/3980 model) may fail to identify the hard disk. |
|
PRJ-64590, |
Gaia OS |
CPU spikes may occur in a cluster when SNMP is enabled. |
|
PRJ-66271, |
VPN |
During VPN IKEv2 negotiations with third-party peers that offer multiple combined encryption algorithms (both AES-GCM-128 and AES-GCM-256), the Security Gateway may not properly match the proposal, resulting in IKE failure logs and the tunnel establishment failure. |
|
PRJ-66821, |
VPN |
Multiple Entry Point (MEP) validation may be incorrectly triggered when switching a Star Community to a Route-Based community. |
|
PRJ-65544, |
VPN |
VPN participant Domains may not be automatically removed when a device is deleted from a community. |
|
PRJ-65012, |
VPN |
SSL Network Extender Portal is accessible even when it is disabled in SmartConsole. Refer to sk184344. |
|
PRJ-65827, |
VPN |
A customized Per-gateway Secure Configuration Verification (SCV) policy is not enforced for Remote Access VPN clients. Refer to sk184863. |
|
PRJ-64814, |
VPN |
When switching a VPN community from Route-Based to Domain-Based mode, the Tunnel Sharing setting may not reset to its default value. After the switch, Tunnel Sharing remains set to Per Gateway Pair instead of reverting to the Domain-Based default of Per Subnet Pair. No notification is displayed to alert about the discrepancy, which may impact performance. |
|
PRJ-65420, |
VPN |
After a Cluster failback, RDP (Routed Data Path) or DPD (Dead Peer Detection) probing may not be triggered, which can result in traffic continuing to use outdated Multiple Entry Point (MEP) Gateway selections. |
|
PRJ-66366, |
VPN |
In some scenarios, over time, prolonged VPN traffic may lead to gradual memory growth. |
|
PRJ-64081, |
VPN |
When generating a CPInfo file using the CPInfo utility, major CPU spikes may occur on the Security Gateway or Security Management Server. |
|
PRJ-66013, PMTR-117053 |
VPN |
VPN traffic from L2TP clients may fail to pass through the Security Gateway working in SecureXL User Mode (UPPAK). |
|
PRJ-68887, PRJ-68715, PMTR-127505 |
VPN |
Remote Access Endpoint Security Client may disconnect and reconnect approximately every 15 seconds. |
|
PRJ-65463, PMTR-122433 |
VPN |
Remote Access Endpoint Security Client may fail to connect. |
|
PRJ-67928, PRHF-45114 |
Multi-Portal |
In a rare scenario, a security hardening change related to Multi-Portal connections may cause an unexpected Security Gateway restart when such a connection is terminated. See the Critical Information section. |
|
PRJ-67447, |
VSX |
When a Virtual System (VS) is deleted from a VSX Security Gateway, the Dynamic Split feature does not properly recognize the removal and continues to attempt fetching data or updating CPU affinity for the deleted VS. This results in repeated errors or log entries referencing the non-existent Virtual System, and may interfere with CPU core allocation and affinity management for the remaining VSs. |
|
PRJ-66798, PRHF-41154 |
VSX |
A malformed or incorrect interface name in the "cphaprob -a if" command on VS0 triggers a fatal error in the cluster process, causing the member to go DOWN and generating a core dump. |
|
PRJ-65935, |
VSX |
The "show configuration" gClish command may fail for showing configuration for LLDP, VSNext, VSLS, SSH, and OSPF. |
|
PRJ-65674, |
VSX |
Deleting a Virtual Switch (VSW) may break connectivity for unrelated Virtual Systems (VSs). |
|
PRJ-67231, |
VSX |
Incorrect MAC address configuration on WRP interfaces in a VSNext environment leads to ClusterXL Load Sharing malfunctions and traffic correction issues. |
|
PRJ-67115, |
VSX |
When adding or deleting static routes in the huge VSX environment (more than 50 Virtual Systems and hundreds of static routes), VS creation fails with "Unable to watch directory /etc/routed-mc-enable: init: Too many open files". Refer to sk181317. |
|
PRJ-65389, |
VSNext |
In VSNext ElasticXL and VSNext Maestro, running the "cpconfig" command from Clish/gClish within a Virtual System context may trigger execution in the Global context. |
|
PRJ-65387, PMTR-122058 |
VSNext |
When the Same VMAC Mode is enabled on ElasticXL, VS0 may lose connectivity (SSH). |
|
PRJ-66386, PRHF-43223 |
Cloud Firewall |
The FWM may unexpectedly exit when attaching a license to a Security Gateway using vSEC license distribution (vsec_lic_cli). |
|
PRJ-65297, PRHF-42496 |
Cloud Firewall |
When using VSLS with Identity Sharing enabled, CloudGuard Controller may fail to send updates to Virtual Systems that have no Data Center Objects in their policy. |
|
PRJ-65014, |
Cloud Firewall |
Registration of Data Center assets with a numeric, non-UID unique identifier may fail, potentially causing performance impact on the Security Management Server. |
|
PRJ-65940, |
SD-WAN |
In rare scenarios, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) may be incomplete, causing SD-WAN rules to match traffic incorrectly. Refer to sk184814. |
|
PRJ-64736, |
SD-WAN |
A VPN IPv6 traffic outage may occur when a host/network object is defined with the Security Gateway's main IPv6 address. |
|
PRJ-66034, |
VoIP |
Real-time Transport Protocol (RTP) may not function correctly, this results in the VoIP/RTP traffic being dropped. |
|
PRJ-65801, |
VoIP |
Security Gateway may drop legitimate H323 traffic with "Illegal H.225(Q931) No Q.931 User-user IE found". Refer to sk184591. |
|
PRJ-66899, |
Scalable Platforms |
Maestro/ElasticXL policy installation may fail during a major version upgrade. |
|
PRJ-65099, |
Scalable Platforms |
In a Maestro environment with Multi-Domain Security Management and enabled MDPS, SNMP per member queries do not survive member failover. Additionally, SNMP queries to the SMO may be routed to the dplane instead of the mplane. |
|
PRJ-67016, |
Scalable Platforms |
In a Maestro setup, VXLAN tunnels may not consistently forward traffic with multiple Security Group Members. |
|
PRJ-66487, |
Scalable Platforms |
In a Maestro environment, deleting a configured VXLAN from the Security Gateway using gClish on VS0 results in a "Segmentation fault (core dumped)" error, despite successful deletion from SmartConsole. |
|
PRJ-66559, |
Scalable Platforms |
In ElasticXL setups, it may not be possible to add a second Sync interface to the bonding group. |
|
PRJ-67483, |
Scalable Platforms |
If a management interface on ElasticXL Security Gateway is a part of a bond, the license distribution mechanism may not work as expected. |
|
PRJ-67177, |
Scalable Platforms |
In ElasticXL Clusters, a new member that exits ungracefully (force shutdown, power loss, unexpected exit) may not appear in the Clish "delete cluster member" options and cannot be deleted from the cluster configuration. |
|
PRJ-66522, |
Scalable Platforms |
Rebooting an Active member in the Single Management Object (SMO) role may trigger a brief connectivity loss. |
|
PRJ-66921, |
Scalable Platforms |
After upgrading the Multi-Version Cluster to R82.10, failback to an older version may cause connection drops. |
|
PRJ-66706, |
Scalable Platforms |
After an upgrade to R82.10 of the Maestro environment, connecting using SSL Network Extender (SNX) fails. The Security Gateway drops the packets with the reason "clear text packet should be encrypted". |
|
PRJ-68246 |
Scalable Platforms |
After uninstalling the R82.10 Jumbo Hotfix Accumulator, previously installed RPM packages are not restored to their original state. |
|
PRJ-65694, |
Scalable Platforms |
In VSX setup, a configuration note may be generated after a reboot, although the configuration is synchronized. |
|
PRJ-67350, |
Scalable Platforms |
A Security Group Member may enter a continuous boot loop after the other members were upgraded. An incorrect image file (with an invalid or mismatched MD5 checksum) is presented on the Single Management Object (SMO). As a result, the problematic member fails to complete the autoclone and repeatedly reboots. |
|
PRJ-66512, |
Scalable Platforms |
Members added to an ElasticXL Security Group with the MDPS feature enabled may remain in the Down state because of a missing license. Licenses are not automatically distributed from the SMO member to newly added Security Group members. |
|
PRJ-65728, |
Scalable Platforms |
In VSNext setup, when a numbered VTI interface is created for a route-based VPN under VS0 and attached to a Virtual System, the interface appears correctly in the output of the "ifconfig" command under VS0 but becomes invisible in "ifconfig" within the assigned VS context, although it remains visible in the Clish commands output. |
|
PRJ-65996, |
Scalable Platforms |
On Maestro running VSNext, when a Virtual Switch (VSW) shares a physical interface with a Virtual System (using different VLANs), the VSW's VLAN interface may not be propagated to the Maestro Hyperscale Orchestrator (MHO). |
|
PRJ-67338, |
Scalable Platforms |
Bond interface deletion or IP address change may cause a site failover. |
|
PRJ-65685, |
Carrier Security |
The FWK process may exit when GTP Intra Tunnel Inspection is enabled. |
|
PRJ-65688, |
Carrier Security |
GTP-U intra-tunnel packets may be dropped with "Packet too short" and "Invalid IP packet" errors in Bridge Mode, preventing proper inspection of encapsulated traffic. |
|
PRJ-66715, |
Carrier Security |
A "Tunnel established" message may be printed for rejected sessions. The issue is cosmetic. |