R82.10 Jumbo Hotfix Take 36
|
|
Note - This Take contains all fixes from all earlier Takes. |
|
ID |
Product |
Description |
|---|---|---|
|
Take 36 Released on 22 July 2026 |
||
|
Take 36 - New Functionality
|
||
|
PRJ-69884, PRJ-69883 |
Security Management |
NEW: Introducing Unified Security Management from SmartConsole. SmartConsole now provides a single management plane for your organization's security - across cloud and on-premises environments. With this release, you can view the AWS firewalls and manage policies associated with your AWS firewalls directly from SmartConsole, with no need to switch between tools or consoles. Key capabilities:
This reduces operational overhead, closes visibility gaps, and ensures consistent security enforcement across your entire environment. |
|
PRJ-69898, PRJ-69899, PMTR-128616 |
Security Management |
NEW: Added integration between the Security Management Server and Nozomi to extend Check Point OT capabilities. This integration enables the import of Nozomi Assets and Tags into SmartConsole and their direct use in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation.
|
|
PRJ-69893, PRJ-69894, PMTR-129080 |
Security Management |
NEW: Added integration between the Security Management Server and Akamai Guardicore to extend Check Point micro-segmentation capabilities. This integration enables importing Akamai Guardicore Assets and Labels into SmartConsole and using them directly in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation.
|
|
PRJ-69891, PRJ-69892 PMTR-129079 |
Security Management |
NEW: ServiceNow CMDB integration allows treat ServiceNow as the single source of truth for network objects. Configuration Items and Tags import directly into SmartConsole for use in the Access Control Policy. This removes duplicate object maintenance, improves policy visibility, and enforces on the Security Gateway without an additional policy installation.
|
|
PRJ-69019, |
Security Management |
NEW: CloudGuard Controller now supports the Claroty Continuous Threat Detection (CTD) Data Center. Refer to the R82.10 CloudGuard Controller Administration Guide. |
|
PRJ-69471, |
Security Management |
NEW: Permission profiles for Access layers via the Management API are now supported. A new field, For example: |
|
PRJ-67597 |
Cloud Firewall |
NEW: Central License Utility now sends events to Events & AIOps upon license distribution failures and recoveries. Events are reported for both full distribution runs and single distribution, enabling proactive monitoring and alerting through AIOps. Refer to the Cloud Firewall Central License Tool Administration Guide. |
|
PRJ-67945, |
Scalable Platforms |
NEW: The Virtualization Screen is added to VS0 Insights, displaying Virtual Systems statistics, including Virtual Systems problem detection, alongside general environment metrics and the Resource Search tool.
|
|
PRJ-67945, |
Scalable Platforms |
NEW: Added support for integrating clean-install machines running a higher version into an existing ElasticXL environment. |
|
PRJ-69425, |
Scalable Platforms |
NEW: Added a configuration option for Maestro Orchestrator to forward Spanning Tree Protocol (STP) BPDUs to Maestro Security Group Members. Refer to sk185110. |
|
Take 36 - Improvements and Resolved Issues
|
||
|
PRJ-65590, |
Security Management |
UPDATE: In environments with thousands of Domain objects or External User Groups, the policy installation duration has been significantly improved. |
|
PRJ-70483, PMTR-129956 |
Security Management |
UPDATE: Resolved CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation. Refer to sk185152. |
|
PRJ-70932, PMTR-130686 |
Security Management |
UPDATE: Resolved CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token. Refer to sk185169. |
|
PRJ-68722, PRJ-69357, |
Gaia OS |
UPDATE: Check Point Response to CVE-2026-31431 (Copy Fail), CVE-2026-43284, CVE-2026-43500 (Dirty Frag) and CVE-2026-46300 (Fragnesia). Refer to sk184928. |
|
PRJ-69475, |
Gaia OS |
UPDATE:
|
|
PRJ-70597, PMTR-129991 |
Gaia OS |
UPDATE: Resolved CVE-2026-62145 - Local privilege escalation in Gaia Portal. Refer to sk185153. |
|
- |
- |
This Jumbo Hotfix Accumulator Take provides additional Management and Gateway hardening fixes, including VPN Site to Site and Remote Access. |
|
PRJ-68503, |
Logging |
UPDATE: In the Logs view, search performance is improved when the search term includes a Cluster. |
|
PRJ-69419, ODU-4204, PRJ-70008, ODU-4253, PRJ-70563, ODU-4316 |
Automatic Updates - Web SmartConsole |
UPDATE: New features and improvements are released in Take 171, Take 173 and Take 176 of Web SmartConsole. Refer to sk170314. |
|
PRJ-69646, ODU-4086, PRJ-70600, ODU-4337 |
Automatic Updates - Log Exporter |
UPDATE: Added Take 65 and Take 70 of Log Exporter Auto Update Deployment. Refer to sk182866. |
|
PRJ-67794, |
Security Gateway |
UPDATE: Optimized Mobile Access policy installation to improve performance in environments with a large Mobile Access Rule Base (more than 500 rules). |
|
PRJ-67086, |
Security Gateway |
UPDATE: The Security Gateway now complies with RFC-4291 by blocking the forwarding of IPv6 packets that contain link-local addresses (FE80::/10) in the source or destination fields. |
|
PRJ-67360, |
Mobile Access |
UPDATE: Resolved the Mobile Access Portal XSS vulnerability in the PHP file. |
|
PRJ-67026, PMTR-124210 |
Gaia OS |
UPDATE: Added validation for bridge ID during the bridge creation on VSNext in Gaia Portal. |
|
PRJ-69950, |
Gaia OS |
UPDATE: OpenSSL has been upgraded from version 3.5.5 to version 3.5.7 to address identified CVEs. |
|
PRJ-68784, |
Gaia OS |
UPDATE: Gaia API updates are now included in the Jumbo Hotfix Accumulator (previously were installed by AutoUpdater). See sk143612. |
|
PRJ-69643, ODU-4190 |
Gaia OS |
UPDATE: Added Take 89 and Take 90 of the AutoUpdater Utility. Refer to sk165653. |
|
PRJ-67529, |
Scalable Platforms |
UPDATE: Old SVMAC feature is now deprecated ( |
|
PRJ-64983, |
Scalable Platforms |
UPDATE: Improved warning message, user confirmation prompt, and audit logging when running the "set fcd revert" command in gClish on a Scalable Platform Security Group. |
|
PRJ-64006, |
SecureXL |
UPDATE: Improved Debug Filtering for specific flows in SecureXL User Space Mode (UPPAK) debug messages. |
|
PRJ-69640, ODU-4225, PRJ-70661, ODU-4330 |
Automatic Updates - Policy Insights |
UPDATE: Added Take 94 and Take 96 of Policy Insights Release Updates. Refer to sk183421. |
|
PRJ-69574, PRJ-70683, ODU-4351 |
Automatic Updates - HCP |
UPDATE: Added Take 93 and Take 94 of HealthCheck Point (HCP) Release. Refer to sk171436. |
|
PRJ-69585, PRJ-70141, ODU-4169 |
Automatic Updates - CPView |
UPDATE: Added Take 57 and Take 59 of CPquid (QUID) Release Updates. Refer to sk181458. |
|
PRJ-66978, |
Security Management |
The FWM process may exit because of memory exhaustion and generate large core files (up to 4GB). |
|
PRJ-64194, |
Security Management |
In some scenarios, the "show-tasks" Management API command displays incorrect results when the "from-date" and "to-date" parameters are used. Refer to sk184072. |
|
PRJ-67415, |
Security Management |
The "show-global-properties" Management API command fails when there is a database inconsistency in the "keep-hit-count-data-up-to" field. |
|
PRJ-66226, |
Security Management |
Packet mode search does not return results for Inline Layer rules in SmartConsole and Management API. Refer to sk184638. |
|
PRJ-67667, |
Security Management |
The Management API v2 command |
|
PRJ-65779, |
Security Management |
In rare scenarios, some Management API commands may fail with "Management server failed to execute command" error. |
|
PRJ-64046, |
Security Management |
In some scenarios, running the "api stats" command with the "-calc_avg_duration" flag on the Security Management Server fails with the "IndexError: list index out of range" error. Refer to sk184144. |
|
PRJ-64523, |
Security Management |
In some scenarios, opening a Security Gateway object in SmartConsole fails with "Smart Dashboard component failed to connect to a server". |
|
PRJ-65009, |
Security Management |
In some scenarios, the submit-time field in emails generated by SmartTask displays an incorrect value. |
|
PRJ-66059, |
Security Management |
Using the "get Interfaces without topology" option on a Security Gateway may remove user-defined interface comments and color settings. Refer to sk180516. |
|
PRJ-66563, |
Security Management |
Cross-domain sharing might be incorrectly configured on the PDP Security Gateway when Identity Broker is the sole enabled identity source. |
|
PRJ-67197, |
Security Management |
In some scenarios, Multi-Domain Security Management HA synchronization may fail after AI Copilot permissions are updated, until a manual synchronization is performed. Refer to sk185124. |
|
PRJ-67182, |
Security Management |
Policy installation may fail with "failed to get tls rulebases from policy id". |
|
PRJ-66162, |
Security Management |
The Security Management Server upgrade may fail during the export phase with the "Object not found - Entities can not be found" message. |
|
PRJ-69132, |
Security Management |
In some scenarios, the FWM process on the Security Management Server may unexpectedly exit when performing the "Fetch branches" action in the LDAP Account Unit properties window of SmartConsole. |
|
PRJ-67181, |
Security Management |
When adding a Shared Secret key to a VPN Community object, the operation may fail with the "Update operation failed" error. |
|
PRJ-66640, PRHF-44086 |
Security Management |
Configuration sharing from a Management Server to the Check Point Portal may fail with a "Did not get reply from Docker" error. |
|
PRJ-66947, |
Security Management |
SmartWorkflow may incorrectly show zero changes for a session, preventing the change report from being displayed. Refer to sk184779. |
|
PRJ-64102, PRJ-66380, |
Security Management |
In rare scenarios, the Security Management Server fails to start after performing the "Revert to Revision" operation. |
|
PRJ-64268, |
Security Management |
In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit, creating a core dump file. |
|
PRJ-64812, |
Security Management |
Policy installation may fail when an inline layer is used more than once in the same policy and this error is displayed "Policy installation had failed due to an internal error. If the problem persists please contact Check Point support". |
|
PRJ-67608, PRHF-44664 |
Security Management |
SmartConsole may display a generic error "Failed to save object <object_name>. Server error is: An internal error has occurred. (Code: 0x8003001D, Could not access file for write operation)" when editing interfaces on Spark Firewall. |
|
PRJ-66180, |
Security Management |
In some scenarios, accumulated open sessions can cause the Security Management Server to become unavailable. |
|
PRJ-66720, |
Security Management |
In some scenarios, on a Spark Firewall cluster, adding a cluster interface to an existing cluster member network fails with the error message "Failed to save object". |
|
PRJ-63913, |
Security Management |
In some scenarios, |
|
PRJ-65208, |
Security Management |
API login to the Security Management Server may fail with a "Null Pointer Exception" error when the session name, comment, or description is specified. |
|
PRJ-64526, |
Security Management |
Opening objects in SmartConsole may fail with the error "SmartDashboard component failed to connect to server". |
|
PRJ-66975, |
Security Management |
A SmartTask configured to send an email after policy installation may fail when the target gateway is a VSX object. |
|
PRJ-66326, |
Security Management |
In some scenarios, an API key may become invalid after editing an administrator account. |
|
PRJ-66869, |
Security Management |
SmartConsole may display the error "the user already exists" when attempting to create a new administrator with the same name as a previously deleted SAML (Identity Provider) administrator. |
|
PRJ-68294, |
Security Management |
SmartTasks may fail to send email notifications with a "send mail to <email address> failed" error when the Cc field is populated. |
|
PRJ-69281, |
Security Management |
Policy installation may fail in a Multi-Domain Security Management Server environment when the Global Policy contains a shared inline layer. |
|
PRJ-68534, |
Security Management |
In rare scenarios, the FWM process on the Multi-Domain Security Management Server may not stop after running |
|
PRJ-67192, |
Security Management |
In some scenarios, after the FWM process crashes and generates a core dump, High Availability synchronization may fail, and the Security Management Servers may appear as disconnected. |
|
PRJ-66699, PRHF-38656 |
Security Management |
In some scenarios, task notifications are not triggered for the Automatic Revisions Purge process, and the task status is not displayed correctly in SmartConsole. |
|
PRJ-68403, PRHF-39002 |
CPView |
In the VLAN interface, CPView shows the speed of the parent. |
|
PRJ-67373, |
CPView |
CPU information may not be displayed in the CPU tab in CPView for an environment with Virtual Systems. |
|
PRJ-68996, PMTR-127578 |
AIOps |
A temporary fix related to the QUID identity database (used by CPDiag and AIOps) caused issues in Maestro environments and led to degradation and occasional agent resets in AIOps, as it relies on this component as its IdentityDB. The fix has therefore been removed. |
|
PRJ-64314, |
Internal CA |
Internal CA now automatically recovers from transient database lock errors without requiring a process restart. |
|
PRJ-66039, |
Logging |
The logs maintenance is running perpetually and is not clearing disk space when the CPPCAP (Check Point Traffic Capture Tool) is enabled. |
|
PRJ-66323, |
Logging |
In some scenarios, the LOG_INDEXER process unexpectedly exits and generates a core dump. |
|
PRJ-66905, |
Logging |
High load on the LOG_INDEXER process may impact system performance. |
|
PRJ-68697, |
Logging |
SmartEvent processes may unexpectedly exit in environments containing over 1 million network objects. |
|
PRJ-66035, |
Logging |
In a Management High Availability environment, configuring threshold settings in SmartView Monitor, fails with the "Couldn't load threshold settings for the selected gateway" error. |
|
PRJ-68785, |
Logging |
In some scenarios, the SmartLog Server process may unexpectedly exit and generate a core dump. |
|
PRJ-64140, |
Security Gateway |
In a rare scenario, when handling CIFS traffic in the accelerated pipelined path, the PPE and FWK processes may exit. Refer to sk184284. |
|
PRJ-65665, |
Security Gateway |
There may be high CPU usage by the CMID process when the ICAP Client is enabled on Security Gateway. Refer to sk184524. |
|
PRJ-66433, |
Security Gateway |
The memory usage may increase over time when using the Mirror and Decrypt feature. |
|
PRJ-68595, PRHF-45113 |
Security Gateway |
In a rare scenario, the FWK process crashes when the Mirror and Decrypt feature handles large MTU frames. |
|
PRJ-65933, SMBGWY-18437 |
Security Gateway |
In rare HTTP/S inspection flows, the Security Gateway may crash if there is a parsing error. |
|
PRJ-67081, |
Security Gateway |
On ClusterXL and in Maestro Security Groups, after performing a rolling upgrade that includes a change in the CoreXL instance count, newly created firewall instances may remain in local-sync-only mode. As a result, these instances do not receive state updates from their peers, leading to intermittent connection failures and "First packet isn't SYN" drops. Refer to sk184786. |
|
PRJ-66490, |
Security Gateway |
In a rare HTTP/2 traffic scenario, a valid connection may fail. |
|
PRJ-65979, |
Security Gateway |
After an upgrade, the |
|
PRJ-67747, |
Security Gateway |
In a rare scenario, the FWD daemon may restart because of the Application Control Dynamic URL List version file. |
|
PRJ-66622, |
Security Gateway |
In rare cases, the FWK process may restart unexpectedly while the Security Gateway is processing a URL Filtering categorization response and a policy installation is running simultaneously. |
|
PRJ-65230, |
Security Gateway |
Active Streaming Layer connections become stuck, resulting in increased memory consumption over time on the Security Gateway. |
|
PRJ-68861, PMTR-127344 |
Security Gateway |
Jumbo Hotfix Accumulator installation on Security Gateways with MDPS enabled may fail with a verification error "Installation is not allowed". Refer to sk184950. |
|
PRJ-66421, |
Security Gateway |
In a rare scenario, a memory leak may occur due to a race condition between policy installation and Application Control/IPS signature updates, and persists until the next policy installation. |
|
PRJ-65630, |
Security Gateway |
The RAD daemon may unexpectedly exit when customizing RAD internal parameters ("max_flows" and "queu_max_capacity"). Refer to sk182136. |
|
PRJ-65523, |
Security Gateway |
RSH connections fail when Destination NAT is configured for the RSH server. Refer to sk184768. |
|
PRJ-65995, |
Security Gateway |
FTP transfers of files smaller than 1KB fail and result in empty files on the destination server. Refer to sk184200. |
|
PRJ-64057, |
Security Gateway |
In rare scenarios, the FWK process may unexpectedly restart when an HTTP/2 connection containing specific stream characteristics is released. |
|
PRJ-68446, |
Security Gateway |
FTP traffic does not pass through Security Gateway when using the FTP Extended Passive Mode. Refer to sk183853. |
|
PRJ-67157, |
Security Gateway |
In some scenarios related to Check Point Active Streaming (CPAS), the Security Gateway may unexpectedly crash. |
|
PRJ-66910, |
Security Gateway |
There may be log entries related to the drop optimization feature, although the dropped traffic matches a non-logging rule. |
|
PRJ-64757, |
Security Gateway |
The ICAP client does not work correctly, impacts the allowed number of characters for the ":service" field in the $FWDIR/conf/icap_client_blade_configuration.C ICAP configuration file. |
|
PRJ-66749, |
Security Gateway |
When ISP Redundancy is enabled, and the administrator changes the priority, the primary ISP may not be updated in the Security Gateway (the route is updated, but the Security Gateway continues to consider the old ISP as the primary/standby). Refer to sk184923. |
|
PRJ-64915, |
Security Gateway |
When ESP traffic is present in the environment, and the |
|
PRJ-65816, |
Security Gateway |
Some service ports may be missing in some instances, resulting in unexpected behavior for some services. |
|
PRJ-64000, |
Security Gateway |
Suspicious Activity Monitoring (SAM) rules may not function properly on a standalone device. Refer to sk184330. |
|
PRJ-64340, |
Security Gateway |
In a rare scenario, the FWD process may crash during Policy Installation because of memory corruption related to licensing. |
|
PRJ-64847, |
Security Gateway |
HTTPS inspection causes connections to fail when using a custom service with a non-standard HTTPS port (for example, TCP/9400), and the custom service object is configured with "Protocol: None". Refer to sk184294. |
|
PRJ-67492, |
Security Gateway |
In some scenarios, SmartConsole RSA SecurID administrator login fails, and the FWM process unexpectedly exits. Refer to sk184844. |
|
PRJ-67648, |
Security Gateway |
In some scenarios, internal memory mishandling in global connections may cause unexpected behavior or connectivity issues. |
|
PRJ-67506, |
Threat Prevention |
In some scenarios, enforcement of an Indicator of Compromise (IoC) feed containing mail observables may fail if the feed file includes a single malformed entry because of a parsing error. |
|
PRJ-69203, |
Threat Prevention |
In some scenarios, Zero Phishing becomes inactive during traffic inspection when Anti-Virus performs a Deep Scan on HTML or JavaScript files. |
|
PRJ-69365, |
Threat Prevention |
SSH connections may fail after enabling SSH Deep Packet Inspection (DPI). |
|
PRJ-65308, |
Threat Prevention |
In rare scenarios, the Anti-Virus fails to inspect HTTP file downloads. |
|
PRJ-68773, |
Threat Prevention |
IoC feed observables may continue to be enforced even after Anti-Virus and Anti-Bot are disabled. |
|
PRJ-68163, |
Identity Awareness |
Scaled PDP recovery was improved when specific scaled daemons crashed while Multi-Instance PDP was enabled. |
|
PRJ-65879, |
Identity Awareness |
The Microsoft Graph API access token does not renew if an authorization error occurs while working in on-demand fetch mode. |
|
PRJ-70633, PMTR-130209 |
Identity Awareness |
After upgrading an Identity Broker subscriber from R82 or earlier versions to R82.10, broker connections may fail. |
|
PRJ-64787, |
Identity Awareness |
In some scenarios, the PDPD process stops responding and users cannot authenticate through the Identity Awareness. Refer to sk184407. |
|
PRJ-69143, |
Identity Awareness |
The default role in Aruba Networks ClearPass CPPM does not match the identity sessions. |
|
PRJ-64623, |
Identity Awareness |
SNMP queries to the Security Gateway may return unexpected results: specific IP addresses or Identity Collector objects may continue to appear in SNMP outputs even after being removed from the topology configuration. Additionally, polling OIDs such as 1.3.6.1.4.1.2620.1.38.55 or 1.3.6.1.4.1.2620.1.38.53 may result in the message "No Such Instance currently exists at this OID". |
|
PRJ-67890, |
Identity Awareness |
In environments with PDP multi-process enabled, the pdpDispatchd daemon may unexpectedly exit when the Active Directory Query identity source is configured. |
|
PRJ-67951, |
SSL Inspection |
TLS Inspection and HSM statistics are not available through SNMP requests. |
|
PRJ-65580, |
SSL Inspection |
A memory leak may occur in the parsers_is TLS module when HTTPS Inspection is enabled and used to inspect non-standard TLS traffic transmitted over a proxy. |
|
PRJ-66474, |
SSL Inspection |
When HTTPS Inspection is enabled, the Security Gateway uses the global (default) outbound CA certificate, even though an outbound CA override is configured in SmartConsole. Refer to sk184880. |
|
PRJ-67376, |
IPS |
In some scenarios, the Custom Threat Prevention policy fails to enforce IPS protection overrides on rules configured with a network group in the "Install On" column. |
|
PRJ-66562, |
Application Control |
When using custom applications and SD-WAN, HTTPS traffic may be blocked with "Reason: Application Control - Internal system error" in SmartConsole log. |
|
PRJ-67580, |
URL Filtering |
In a rare scenario, the RAD request may drop when hostname header includes unsupported characters. |
|
PRJ-65134, |
URL Filtering |
An HTTPS Inspection rule that contains a custom application whose name includes spaces or certain unsupported characters does not match during policy enforcement. Refer to sk184773. |
|
PRJ-64971, |
URL Filtering |
The Resource Advisor module continues to perform categorization even when a match is found in the override category. |
|
PRJ-65025, |
Anti-Virus |
In rare scenarios, the RAD process may exit generating a core dump. |
|
PRJ-66022, |
ClusterXL |
In a ClusterXL Load Sharing Unicast configuration, the Pivot member intermittently fails to forward packets to the relevant non-Pivot cluster members. This results in packet drops, related to MAC address handling. |
|
PRJ-64061, |
ClusterXL |
When processing VPN traffic in a ClusterXL environment with "sync-to-all" enabled, the absence of sequence number updates from the active site can cause the Fast Acceleration (FnA) mechanism to become unresponsive. As a result, affected connections may be dropped, and such log entry is generated "dropped by fw_conn_inspect Reason: Frozen connection". |
|
PRJ-69330, |
SecureXL |
In some scenarios, the VSX Security Gateway passes traffic without performing proper NAT from a Virtual Router or Switch's external interface when SecureXL User Mode is enabled. |
|
PRJ-68528, |
SecureXL |
When both Quality of Service (QoS) and VPN features are enabled, memory corruption may occur in the mbuf. This can lead to an exit of the USIM process during the handling of QoS flows. |
|
PRJ-67819, |
SecureXL |
After rebooting the Security Gateway, the Allow List entry is present when viewing the list, but it is not enforced. The Deny List takes precedence, and traffic from the IP is blocked, even though it should be allowed according to the configuration. |
|
PRJ-69944, PMTR-127433 |
SecureXL |
In some scenarios, VPN packets are dropped in User Mode (UPPAK) during encryption when QoS is active. |
|
PRJ-70341, PRHF-46357 |
SecureXL |
In some scenarios, VLAN tags are stripped and MAC addresses become malformed after traffic passes through the bridge. Refer to sk185101. |
|
PRJ-65887, |
SecureXL |
PPTP/GRE traffic fails when Hide NAT is used and SecureXL runs in UPPAK mode and the "fw_pptp_enforce_protocol" parameter is enabled. Refer to sk184641. |
|
PRJ-67411, |
SecureXL |
On Check Point 3000 Series Appliances, the Multi-Queue Management utility mq_mng displays incorrect interface statistics when run in verbose mode for integrated switch ports. |
|
PRJ-66065, |
SecureXL |
The USIM process may exit with a core dump during modular configuration. |
|
PRJ-66068, |
SecureXL |
In a Cloud Firewall environment with Kernel Performance Pack (KPPAK) enabled by default, when modifying the TX queue size parameter for supported network interfaces to 2048 (2K) or 4096 (4K), reverting the setting back to the default value of 1024 (1K) is not possible. The issue is observed with these synthetic network drivers: virtio (used in GCP and KVM environments), vmxnet3 (used in VMware ESXi), and ena (used in AWS). |
|
PRJ-64175, |
SecureXL |
The "arping" command on the Security Gateway returns this output "Sent 4 probes Received 0 response" in SecureXL User Mode (UPPAK). Refer to sk184292. |
|
PRJ-65899, |
SecureXL |
Error messages are generated when running the "fwaccel dos statistics get" command, cluttering the usim_x86.elg log file. |
|
PRJ-66213, |
SecureXL |
A reference count issue in the UPPAK module can cause a USIM core dump, particularly on busy systems with long uptime. |
|
PRJ-68731, PRJ-69057, |
Routing |
On VSNext Clusters, during startup, the ROUTED daemon does not install cluster Virtual IPs (VIPs) on certain non-VS0 Virtual System (VS) routing instances. As a result, Dynamic Routing protocols (such as OSPF, BGP) fail to operate correctly on the affected instances. |
|
PRJ-69595, |
Routing |
In the VSX environment, the BGP Routed Critical Device (PNOTE) never clears after rebooting both cluster members simultaneously or during an upgrade. |
|
PRJ-66230, |
Routing |
The ROUTED daemon may exit when running the "show bgp paths" command. |
|
PRJ-67019, |
Routing |
The ROUTED daemon may exit with a pnote on Security Group Members after the Orchestrator daemon (ORCHD) stops. Refer to sk184771. |
|
PRJ-66210, |
Gaia OS |
When the nstat utility (in the iproute2 package) encounters a corrupted state file (for example, if /tmp/.nstat.u0 contains invalid data), it aborts with a core dump instead of providing an error message. |
|
PRJ-67604, |
Gaia OS |
In some scenarios, SNMP monitoring may incorrectly report 100% CPU usage. |
|
PRJ-65650, |
Gaia OS |
Excessive log entries for RADIUS users logging into Gaia Portal. Refer to sk184534. |
|
PRJ-66885, |
Gaia OS |
In rare scenarios, the CORE_UPLOADER process on Security Gateways may unexpectedly generate a core dump when the number of detected CPU cores exceeds a specific threshold. |
|
PRJ-64558, |
Gaia OS |
Unable to enter Virtual System with "virtual-system-access all" configured. Refer to sk184282. |
|
PRJ-68162, |
Gaia OS |
In a rare scenario, after several reboots, the Security Gateway restarts with an empty /etc/udev/rules.d/ rules file. As a result, the interface renaming configuration is lost, and network interfaces revert to default names, potentially disrupting network connectivity and management. |
|
PRJ-67503, |
Gaia OS |
After an upgrade, in some scenarios, two-factor authentication (2FA) may not be enforced for SSH access. This results in users are able to authenticate via SSH without the required 2FA. |
|
PRJ-68854, PRHF-45491 |
Gaia OS |
In some scenarios, VPN throughput slowness occurs on Check Point Firewall 3900 Appliances. |
|
PRJ-65948, |
Gaia OS |
Remote and local backup operations fail after installation of Jumbo Hotfix Accumulator with the "Cannot complete the backup process: not enough space in /var/log/CPbackup/backups" error. Refer to sk183767. |
|
PRJ-67026, |
Gaia OS |
In Gaia Portal, for VSNext, the Bridge Group field displays the validation error "The minimum value for this field is 1001," but does not enforce it, and it is possible to submit and create bridge object IDs with values below the minimum threshold. The fix adds validation for the bridge ID during bridge creation in VSNext. |
|
PRJ-65927, |
Gaia OS |
Clish may restart unexpectedly when running the |
|
PRJ-69113, |
Gaia OS |
After disabling Two-factor authentication (2FA) in Gaia OS, the user still requires a 2FA code on login attempts. |
|
PRJ-68251, |
Gaia OS |
For IDNS-Resolver, when the DNS server returns "TC=1", and communication should be moved to TCP instead of UDP, TCP communication does not block DNS requests. |
|
PRJ-69004, |
Gaia OS |
In Gaia Portal, bond member interfaces can be edited when they should be disabled. |
|
PRJ-65922, |
Gaia OS |
After restoring the system backup, the restored date and time are displayed incorrectly. |
|
PRJ-68683, PRHF-44285 |
Gaia OS |
The Bash Shell Logging procedure is now working in R82.10 and higher versions. Refer to sk99134. |
|
PRJ-68692, PRHF-45133 |
Gaia OS |
In some scenarios, a Security Gateway crashes because of a memory write overflow in the I/O driver. |
|
PRJ-70250, PMTR-129404 |
Mobile Access |
After hardening non-RFC-compliant HTTP requests, some Mobile VPN connections fail. Since multiple clients send bare LF requests (a specific type of non-RFC-compliant traffic), bare LF errors are now disabled by default. This behavior can be enabled using the kernel parameter |
|
PRJ-68991, PMTR-116331 |
VPN |
Added the ability to import additional .p12 certificate types as inbound and outbound certificates. |
|
PRJ-67986, |
VPN |
Automatic Security Gateway certificate enrollment using CMP with an external OPSEC PKI CA (for example, EJBCA) fails with "Internal Error" status in SmartConsole. |
|
PRJ-65678, |
VPN |
Added CA Certificate matching improvements. |
|
PRJ-70031, PMTR-129280 |
VPN |
Improved certificate validation during IKEv2 VPN negotiations to ensure VPN connections are established only after successful certificate-based authentication. |
|
PRJ-69115, |
VPN |
When IKEv2 is configured in a Remote Access community, Remote Access clients are incorrectly classified as DAIP (Dynamic Address IP) gateways during IKEv2 negotiation. This causes authentication with machine certificates to fail, preventing successful VPN client connections. |
|
PRJ-65985, |
VPN |
Remote Access IKEv2 VPN authorization may fail for LDAP Active Directory users whose Common Name (CN) in their certificate is email-based (for example, user@domain.com). When such users authenticate using an External User Certificate, they are unable to pass traffic to the Encryption Domain, resulting in dropped connections. |
|
PRJ-65327, |
VPN |
When using Capsule VPN or Endpoint Security VPN (Connect) clients in IPsec mode with IKED enabled, users can successfully authenticate and establish a VPN tunnel. However, group information received from the RADIUS server is not passed to the IKED process. As a result, security policies and access roles that rely on RADIUS group membership do not apply, and users are unable to access internal resources through the VPN. |
|
PRJ-70096, PRHF-45664 |
VPN |
In ElasticXL environments, a stale NAT-T port in the cluster sync overwrites the correct port. |
|
PRJ-69268, PRHF-45001 |
VPN |
In some scenarios, the VPN tunnel flaps every 40 seconds when the in-kernel tunnel test is enabled. |
|
PRJ-64807, |
VPN |
Traffic passing through a route-based VPN tunnel may cause high CPU usage if the traffic is fragmented. |
|
PRJ-69527, PMTR-128338 |
VPN |
Improved address validation in the VPN Remote Access proxy to correctly restrict outbound connections to internal and link-local destinations. |
|
PRJ-67353, |
VPN |
In VPN Site-to-Site environments, a memory leak in VPN-related processes may occur after a VPN driver restart, or during prolonged system runtime. |
|
PRJ-69428, PMTR-128278 |
VPN |
Improved input validation in the VPN L2TP PPP packet parser to handle malformed configuration options correctly. |
|
PRJ-64322, |
VPN |
CRL files may not be synchronized as expected in Management High Availability and Multi-Domain Security Management environments. |
|
PRJ-65322, |
VPN |
The VPND or IKED daemon may crash during IKEv2 negotiation. |
|
PRJ-66771, |
VPN |
VPN traffic outage may occur in ClusterXL environments with IKEv2 after a Cluster failover. |
|
PRJ-66468, |
VPN |
In ClusterXL environments, a VPN traffic outage of up to 60 seconds may occur after an ungraceful cluster failover. |
|
PRJ-66466, |
VPN |
VPN traffic outage may occur in ClusterXL environments with SD-WAN Overlay or Enhanced Link Selection after a Cluster failover. The new Active cluster member fails to properly handle VPN traffic because of synchronization or MAC address handling problems. |
|
PRJ-67308, |
VPN |
In a MaaS (Management as a Service) environment, VPN clients (Windows and macOS) enrolling for new certificates may encounter the "failed to enroll new certificate" error. |
|
PRJ-65668, |
VPN |
When Hub Mode is not enabled, traffic destined for dynamic objects included in the Remote Access VPN Split Tunneling Inclusion group may be incorrectly dropped. As a result, remote users may be unable to access resources defined by these dynamic objects, even though they are specified for inclusion in the split tunnel. |
|
PRJ-66430, |
VPN |
IKE negotiation fails during Phase 1 when AES-GCM encryption algorithms are used, with third-party devices as the VPN peer. This affects both Site-to-Site and Remote Access VPN scenarios. |
|
PRJ-69367, PRJ-69283 |
VSNext |
In some scenarios, on Maestro VSNext setups, a bridge is shown in a down state in the WebUI interfaces table immediately after creation in the Virtual System (VS) context. |
|
PRJ-67743, PMTR-124791 |
VSNext |
In some scenarios, on VSNext environments, Backup and Restore fails to restore a backup, causing all Virtual Systems to be in a DOWN state. |
|
PRJ-68230, |
VSX |
After deleting several Virtual Systems, stale wrpj interfaces remain attached to Virtual Switches. SmartConsole shows these orphaned interfaces with error text "Virtual System with the ID X does not exist". |
|
PRJ-67626, |
VSX |
When using VSX SmartProvisioning on Maestro, the operation fails if the VSX Gateway name includes the substring "wrp0". |
|
PRJ-69524, HEC-1792 |
VSX |
Added new SNMP OIDs to enable monitoring of physical resources per Virtual System (VS) via VS0. |
|
PRJ-67939, |
QoS |
QoS Policy installation fails when using the DiffServ class in the QoS Policy. |
|
PRJ-67684, |
SD-WAN |
In a rare scenario, the FWK process may crash when handing SD-WAN traffic. |
|
PRJ-65445, |
SD-WAN |
VPN traffic outage may occur in SD-WAN overlay environments. |
|
PRJ-65610, |
SD-WAN |
SD-WAN overlay traffic debugging is improved, enhancing visibility and troubleshooting capabilities. |
|
PRJ-64474, |
SD-WAN |
In some scenarios, SD-WAN ISP link status may fluctuate between UP and DOWN states. Reduced SD-WAN ARP probing default sensitivity to packet drops. |
|
PRJ-66778, |
SD-WAN |
In some scenarios, enabling SD-WAN Symmetric Return may lead to elevated CPU utilization on Secure Network Distributor (SND) cores. |
|
PRJ-68333, |
SD-WAN |
On the Scalable Platform Cluster, LS fragmented packets may be dropped on the receiving member with an error This may also occur with Cluster HA; however, correcting packets is negligible in such environments. |
|
PRJ-66472, |
SD-WAN |
VPN traffic outage may occur in ClusterXL environments after a Cluster failover. |
|
PRJ-66470, |
SD-WAN |
VPN traffic outage may occur in ClusterXL environments after a Cluster failover. |
|
PRJ-68797, |
Cloud Firewall |
Deleting a license pool while Cloud Firewall Gateways are still associated with it causes all licensing operations (add, distribute, remove) to continuously fail until the orphaned reference is manually cleared from the database. |
|
PRJ-69052, |
Cloud Firewall |
When a Cloud license's support contract expires, the system now keeps all gateways licensed and alerts the administrator with remediation steps, instead of silently removing their licenses. |
|
PRJ-67515, |
Cloud Firewall |
Moving Cloud licenses from one pool to another triggers license alignment: If adding a new license to CK fails, license removal will not be initiated on the Security Gateways. |
|
PRJ-65793, |
Scalable Platforms |
The unique IP address assigned to the standby site may not function correctly during a VSNext deployment. |
|
PRJ-67567, |
Scalable Platforms |
When deleting a bond in an ElasticXL environment, site failover may occur. |
|
PRJ-68832, PMTR-127137 |
Scalable Platforms |
In some scenarios, a 3950 appliance in an ElasticXL cluster fails to bring the Sync interface up because of the |
|
PRJ-67167, |
Scalable Platforms |
|
|
PRJ-65702, |
Scalable Platforms |
"TCP packet out of state" or "connection dropped due to state mismatch" messages may be seen in SmartLog or SmartView Tracker. These drops specifically occur on the sync interface, which is used for internal communication and synchronization between Security Group members. |
|
PRJ-70255, PMTR-129110 |
Scalable Platforms |
Deleting a bond may trigger a site failover because LACP negotiation resets the IPs of slave interfaces, leading to an IAC pnote and failover. |
|
PRJ-68809, |
Scalable Platforms |
When a Security Group member transitions from a down state to an active state, the synchronization process with other members in the Security Group may not complete before the recovered member becomes active. This can result in traffic drops because of incomplete state synchronization. |
|
PRJ-67822, |
Scalable Platforms |
Virtual Systems are sometimes stuck with a during_boot pnote if multiple Virtual Systems are created simultaneously. As a result, Secure Internal Communication (SIC) with the Security Management Server is not established. |
|
PRJ-67330, |
Scalable Platforms |
The Tunnel Test mechanism may incorrectly select a Sync interface IP address instead of the appropriate external interface IP. This leads to NAT drops and subsequent VPN tunnel disconnections. |
|
PRJ-67194, |
Scalable Platforms |
On Maestro appliances, /var/log/messages may be flooded with "asg_copy_capture" error messages when the system attempts to retrieve packet capture files that do not exist on remote Security Group members. |
|
PRJ-67536, |
Scalable Platforms |
A remote user may not be able to switch between Virtual Systems (VSs) in the Gaia Portal. While a local admin user is able to switch between VSs as expected. |
|
PRJ-67911, |
Scalable Platforms |
The PERFANALYZE process may exit because of an incorrect value type. As a result, SNMP performance data for the Security Group (ASG) is not updated. |
|
PRJ-67073, |
Scalable Platforms |
License commands such as "g_cplic putlic 192.0.2.15>" fails because of an incorrect calculation of member ID in ElasticXL environment, although the Sync IP address 192.0.2.15 (set up as per sk101556) exists. |
|
PRJ-67740, |
Scalable Platforms |
When adding or removing VS, if the freeze timeout ended before the VS was fully stable, the VS might still have a Critical Device (pnote), which will cause the member to go down. Refer to sk185115. |
|
PRJ-67238, |
Scalable Platforms |
In some scenarios, Anti-Spoofing generates excessive drops on ICMPv6 Neighbor Advertisement packets because traffic reaches other cluster members. |
|
PRJ-65599, |
Scalable Platforms |
Intermittent VS failover when both Maestro Hyperscale Orchestrators (MHOs) have the interface link state set to Down. Refer to sk184568. |
|
PRJ-69289, |
Scalable Platforms |
In VSLS clusters with multiple members, when a member rejoins the cluster after a reboot, an Interface Active Check (IAC) problem notification may incorrectly appear on the rejoining member, showing it in ACTIVE state. This occurs even though all interfaces are physically UP and the cluster is fully functional. |
|
PRJ-65604, |
Scalable Platforms |
In a dual-site Security Group configuration, if all members of site 1 are removed from the Security Group, the Hardware tab in SmartConsole displays an error message instead of the expected hardware information. |
|
PRJ-66761, |
Scalable Platforms |
Upgrade of a Scalable Group in the Traditional VSX / VSNext mode fails.
|
|
PRJ-65087, |
Scalable Platforms |
Added monitoring to detect connectivity failures between Dual-Site MHOs when the site-sync path is not directly connected. Refer to sk184381. |
|
PRJ-67707, |
Scalable Platforms |
After joining a VSNext ElasticXL member to a second site via automation, a pnote for the management (magg1) interface appears under vs0 in "cphaprob -a if", instead of under Virtual Switch (vswOID) as expected. |
|
PRJ-67640, |
Scalable Platforms |
In some scenarios, a Gateway that leaves the cluster is still shown as an active member to other Security Group members. This can result in the Gateway not being displayed as an available Gateway. |
|
PRJ-65992, |
Scalable Platforms |
After a Virtual System (VS) is deleted, its CTX folders are not removed. |
|
PRJ-69305, |
Scalable Platforms |
In Single Site mode, Security Groups containing more than 14 members may experience connectivity issues. |
|
PRJ-69362, |
Scalable Platforms |
The |
|
PRJ-69402, |
Scalable Platforms |
The "CliError( ) called without module or error code" error message is displayed when attempting to run VSX commands on an unsupported configuration in Clish. |
|
PRJ-65998, |
Scalable Platforms |
Added the ability for alerts to send traps to trap receiver servers using IPv6. |
|
PRJ-65098, |
Scalable Platforms |
All traps coming from a dedicated Member of a Security Group now include the hostname. For example, a trap for Member 1_4 will include the hostname (for example, hostname-s01-04), providing clearer identification than just 1_4. |
|
PRJ-65542, |
Scalable Platforms |
In Maestro or ElasticXL environments with VPN enabled, traffic may be dropped with the log message "fwha_select_should_drop_vmac". |
|
PRJ-64018, |
Scalable Platforms |
Policy installation on one Virtual System (VS) fails without a visible error message. Refer to sk184194. |
|
PRJ-67460, |
Scalable Platforms |
When performing a SIC reset after Anti-Malware (AMW) has been installed, some members may enter a "cluster-down" state with an AMW Critical Device. |
|
PRJ-66712, |
Carrier Security |
A GTPv0 tunnel fails to establish under certain conditions. |
|
PRJ-69165, |
Carrier Security |
In a rare scenario, a processed malformed GTP packet may cause the Security Gateway to crash. |