R82.10 Jumbo Hotfix Take 6
|
ID |
Product |
Description |
|---|---|---|
|
Take 6 Released on 06 April 2026 |
||
|
Take 6 - New Functionality
|
||
|
PRJ-65396, |
Identity Awareness |
NEW: Added new OID (1.3.6.1.4.1.2620.1.38.55) to monitor the Identity Collector connection status in the $CPDIR/lib/snmp/chkpnt.mib file.
|
|
PRJ-64974, |
VPN |
NEW: Added support for nested groups with host/range/network objects for split tunnel on exclusion/inclusion options. Refer to R82.10 Remote Access VPN Administration Guide. |
|
PRJ-64016, |
VPN |
NEW: It is now possible to add host/network/range objects for split tunnel on exclusion/inclusion modes. Refer to R82.10 Remote Access VPN Administration Guide. |
|
Take 6 - Improvements and Resolved Issues
|
||
|
PRJ-65055, PRJ-65041 |
Security Management |
UPDATE: When connecting a Domain to the Check Point Portal, Dedicated Log Servers in the Domain are now connected automatically. |
|
PRJ-65494, |
Logging |
UPDATE: SmartEvent now supports the "system alert" log type for URL Filtering and Application Control Software Blades. |
|
PRJ-64478, ODU-3143, PRJ-64639, ODU-3259, PRJ-65289, ODU-3387, PRJ-66547, ODU-3619, PRJ-67136, ODU-3714 |
Automatic Updates - Web SmartConsole |
UPDATE: New features and improvements are released in Take 155, Take 156, Take 157, Take 163, Take 164 via self-updatable package. Refer to sk170314. |
|
PRJ-64906, PRJ-67145, ODU-3682 |
Automatic Updates - CPView |
UPDATE: Added Take 210, Take 223 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522. |
|
PRJ-64830, ODU-3235 |
Automatic Updates - Threat Prevention |
UPDATE: Added Take 27 of Autonomous Threat Prevention Management integration Release. Refer to sk167109. |
|
PRJ-64543, ODU-3199, PRJ-64744, ODU-3267 |
Automatic Updates - CPView |
UPDATE: Added Take 52, Take 53 of CPquid (QUID) Release Updates. Refer to sk181458. |
|
PRJ-67226, ODU-3738 |
Automatic Updates - HCP |
UPDATE: Added Update 26 of HealthCheck Point (HCP) Release. Refer to sk171436. |
|
PRJ-65177, ODU-3419, PRJ-66383, ODU-3435, PRJ-67189, ODU-3845 |
Automatic Updates - Policy Insights |
UPDATE: Added Take 80, Take 82, Take 87 of Policy Insights Release Updates. Refer to sk183421. |
|
PRJ-66729, ODU-3666, PRJ-67127, ODU-3803 |
Automatic Updates - Log Exporter |
UPDATE: Added Take 53, Take 60 to Log Exporter Auto Update Deployment. Refer to sk182866. |
|
PRJ-66623, ODU-3347 |
Automatic Updates - Security Management |
UPDATE: Added Update 4 of Server-Side Change Report Generator Release Updates. Refer to sk179508. |
|
PRJ-67139, ODU-3698 |
Automatic Updates - CPView |
UPDATE: Added Take 88 of CPViewExporter Release Updates. Refer to sk180521. |
|
PRJ-67229, |
Automatic Updates - Threat Prevention |
UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109. |
|
PRJ-64542, |
Security Management |
When using the "add/set data-type-weighted-keywords" and "add/set data-type-file-attributes" Management API commands, the field "description" is missing from the response. |
|
PRJ-64703, PRHF-42579 |
Security Management |
Hitcount of NAT Rule Base fails after Security Management Server upgrade. Refer to sk184336. |
|
PRJ-65810, PRHF-43517 |
Security Management |
The "show-packages" Management API command executed with "async-response" parameter may fail with "generic_err_invalid_parameter_name". |
|
PRJ-64945, PRHF-41803 |
Multi-Domain Security Management |
On Multi-Domain Security Management Servers, custom Compliance Software Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level. |
|
PRJ-65350, |
Compliance |
In some scenarios, scheduled Compliance scans are not executed after setting the intervals via the "set compliance-settings" Management API command. |
|
PRJ-64468, |
Logging |
In some scenarios, exporting logs to CSV in SmartView fails and the LOG_INDEXER process unexpectedly exits. Refer to sk184475. |
|
PRJ-65907, PMTR-122146 |
Logging |
In the "HTTPS Inspection Statistics" in SmartView, filtering by the "bypass_reason" field returns no results. |
|
PRJ-64075, |
Logging |
In some scenarios, incorrect values are shown in the "Total Bytes" field in the logs. |
|
PRJ-65820, PMTR-122907 |
Security Gateway |
When using a Security Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails. |
|
PRJ-65227, PRA-5005 |
Security Gateway |
In a rare scenario, the FWK process may restart unexpectedly when the Security Gateway processes accelerated connections. |
|
PRJ-64850, PRJ-64783 |
Security Gateway |
The FWK core dumps may be generated when the Security Gateway is processing HTTP traffic. |
|
PRJ-64079, |
Security Gateway |
In scenarios where a network connection is closed before the Anti-Virus ThreatCloud emulation or scanning response is received, the affected session may experience connectivity instability. |
|
PRJ-65781, PRHF-40380 |
Security Gateway |
When configuring NAT64 rules for specific targets, the rules may fail to apply. Return traffic may be dropped. |
|
PRJ-65924, PMTR-122717 |
Threat Prevention |
In some scenarios, External Risk Management (ERM) enrichment for SSH connections may be incomplete, resulting in only partial contextual data or risk insights associated with the SSH session. |
|
PRJ-66297, PMTR-123479 |
Threat Prevention |
In a rare scenario, the Threat Prevention Rule Base may fail to match traffic to any rule. |
|
PRJ-66142, PMTR-122910 |
Threat Prevention |
File downloads may get stuck at 100% completion when either the Anti-Virus or Threat Emulation Software Blade is actively scanning the file. |
|
PRJ-65834, PRHF-42534 |
Identity Awareness |
In a rare scenario, a Policy Decision Point (PDP) Security Gateway that acts as both an Identity Broker Subscriber and a sharing identity with a Policy Enforcement Point (PEP) may become unresponsive. |
|
PRJ-64695, PRHF-42522 |
Identity Awareness |
When the Packet Tagging feature is enabled on the Full Identity Agent, new user and machine identity sessions reported to the Identity Awareness Gateway may not be assigned the correct Access Roles. As a result, traffic from these sessions may not match Access Control Policy rules that use Access Roles with Packet Tagging enabled. |
|
PRJ-65900, PRHF-41176 |
Identity Awareness |
In a rare scenario, there may be no access to resources for identities received from the Remote Access identity source. |
|
PRJ-64765, PRJ-60821 |
Anti-Virus |
False threat alerts may appear in Anti-Virus logs for benign traffic (action: accept). This is a cosmetic issue with no security impact. |
|
PRJ-64114, PRHF-41553 |
HTTPS Inspection |
In some traffic flows, packets containing certain headers may be dropped regardless of how the non-compliant HTTP Inspection is configured. |
|
PRJ-64497, PRHF-42513 |
SSL Inspection |
Running the "show cp-trusted-ca-certificate" Management API with invalid validFrom/validTo values in the database causes an error and blocks the Trusted Certificates view. |
|
PRJ-64021, |
Mobile Access |
Mobile Access Software Blade may incorrectly terminate Guacamole-based clientless RDP/SSH sessions due to client idleness. |
|
PRJ-64023, |
Mobile Access |
In rare scenarios, Mobile Access SmartConsole Logs may not match views/queries, including the "MAC address" or "Methods" field names. |
|
PRJ-66156, |
Mobile Access |
After an upgrade, the Mobile Access Software Blade's CVPND process fails to load and the Mobile Access Portal becomes inaccessible when adding new Virtual Systems (VSs) or converting to a VSX Gateway, due to improper updates to the gateway-side configuration file cvpnd.C. Refer to sk183293. |
|
PRJ-65452, PMTR-121744 |
SecureXL |
Permanently disabling the "cphwd_enable_ecmp" global parameter on a VSX Gateway using the "-f" option of the "fwl ctl set" command may fail. |
|
PRJ-64959, PRHF-38461 |
SecureXL |
In an asymmetric UDP traffic scenario (Client-to-Site VPN and Site-to-Site VPN distributed to different members), the connection may not get accelerated. |
|
PRJ-64796, PMTR-121309, PMTR-121673 |
SecureXL |
The CX4 firmware does not update automatically as expected, and there is no error message indicating that the firmware is not the latest version. |
|
PRJ-65602, PMTR-122439 |
SecureXL |
When SecureXL works in User Mode (UPPAK) on Security Gateways with CPAC-4-10F-C interface modules, invalid Ethernet frames permanently shut down the port's transmit queue, causing complete connectivity loss. |
|
PRJ-65221, |
Gaia OS |
SNMP monitoring systems may report format errors related to the structure of the chkpnt.mib file. |
|
PRJ-65527, |
Gaia OS |
Upon logging in to the Gaia Portal, the login page accepts the credentials, briefly displays the homepage, and then automatically redirects back to the login screen. |
|
PRJ-65224, |
Gaia OS |
When integrating SNMP monitoring systems with Gaia OS, compilation of the GaiaTrapsMIB.mib file with the CHECKPOINT-MIB (chkpnt.mib) may fail. SNMP management stations or MIB browsers (such as HP OpenView, CA Spectrum, or HP Network Node Manager) return errors like "File GaiaTrapsMIB.mib failed to parse" or "ERROR : Cannot find symbol file://GaiaTrapsMIB.mib:Line XX:Column XX:multiDiskName". |
|
PRJ-65858, PMTR-122180 |
Gaia OS |
Users cannot create read-only roles, cannot modify roles by removing permissions, or assign roles with all features to specific virtual servers, and all operations fail silently without warnings. |
|
PRJ-65301, PMTR-122146 |
Gaia OS |
If multiple snapshots are stored on the Gateway server, creating a new snapshot fails with the "Cannot create snapshot, insufficient space in /boot" error, even though there is enough unpartitioned space. |
|
PRJ-66998, PRJ-67000, PRJ-67034, PMTR-124920, PRHF-44366 |
VPN, Internal CA |
Starting March 1st, 2026, newly created certificates and newly generated CRL may fail validation. Refer to sk184766. |
|
PRJ-65904, PMTR-122006 |
VSX |
During interface reallocation between Virtual Systems (VSs) on a VSX Gateway, Management access (SSH/Gaia Portal) to VS0 may be disrupted after the interface move. Returning the interface to its original VS does not recover connectivity. |
|
PRJ-65675, |
VSX |
When attempting to create a new Virtual System (VS) with management connectivity enabled, the operation may fail. This prevents the successful provisioning of the Virtual System in the environment. |
|
PRJ-66176, |
VSX |
Creating a large number of Virtual Systems (VSs) simultaneously may intermittently fail. |
|
PRJ-65243, PMTR-121780 |
VSNext |
After adding a virtual link between a Virtual System (VS) and a Virtual Switch (VSW), policy installation may fail with the "Installation failed. Reason: TCP connectivity failure [ error no. 10 ]" error. |
|
PRJ-65484, PRHF-43055 |
VSNext |
Three out of four Virtual Systems (VS) on a single site may show a "Problem" Health status in the output of the "asg stat vs all" test. This is a cosmetic issue. |
|
PRJ-65480, PMTR-122468 |
Cloud Firewall |
The Cloud Firewall Central License utility fails to distribute a single license using CLI. |
|
PRJ-65593, PMTR-122597 |
Cloud Firewall |
When a new Cloud Firewall Gateway is added to the Security Management Server, and a security policy is installed, the Security Gateway may not appear in the Central License Tool (vsec_lic_cli). As a result, the Security Gateway fails to receive a central license. |
|
PRJ-64443, PRHF-42470 |
Scalable Platforms |
Maestro Orchestrator fails to add a new Security Appliance to a Security Group when the Maestro Fastforward feature is enabled in the Security Group. Refer to sk184233. |
|
PRJ-64394, |
Scalable Platforms |
When adding a subordinate to an LACP bond, a member may go down, which triggers a site failover. |
|
PRJ-65637, PMTR-122661 |
Scalable Platforms |
After an upgrade in the Maestro and Chassis environment with multiple Virtual Systems (VSs), the disk may reach full capacity. |
|
PRJ-65501, PMTR-122485 |
Scalable Platforms |
These actions applied through the Gaia Portal are not applied to all Security Group members, but only to the SMO:
|
|
PRJ-65970, PMTR-92125 |
Scalable Platforms |
After creating a bridge interface using Gaia Portal and rebooting, the Security Gateway state is down. |
|
PRJ-66016, PMTR-123154 |
Scalable Platforms |
Using a unique IP address with the Same VMAC feature enabled may cause connections to the Standby unique IP address to fail. |
|
PRJ-65965, PMTR-120383 |
Scalable Platforms |
Link-local per-member address calculation between ElasticXL members may not be correct. |
|
PRJ-64505, |
Carrier Security |
Policy installation fails with an internal error when the Security Gateway policy includes rules that match a specific Access Point Name (APN) for GTPv0 or GTPv1 traffic. |