List of All Resolved Issues and New Features in R82 Jumbo Hotfix Accumulator

 

Review the Critical Information section before installing a new Take.

ID

Product

Description

Take 107

Released on 15 June 2026 and declared as Recommended on 21 Jun 2026

Take 107 - Improvements and Resolved Issues

 

PRJ-69648,

PMTR-128753

VPN

UPDATE:

  • Resolved CVE-2026-50751 - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange. Refer to sk185033.

  • Resolved CVE-2026-50752 VPN site-to-site certificate bypass vulnerability in deprecated IKEv1 key exchange. Refer to sk185035.

PRJ-69507,

PRHF-45889

Security Management

In rare scenarios, the CPD process may exit because of certain Secure Internal Communication (SIC) transactions.

See the Critical Information section.

Take 103

Released on 26 May 2026

Take 103 - New Functionality

 

PRJ-67316,

PRJ-65896,

PMTR-125495

Security Management

NEW: Policy Auditor is a policy analytics and auditing tool that provides visibility into traffic behavior within the user's network. In SmartConsole > Security Policies > Access Control, Policy Auditor presents a matrix view of the network's logical segments and the access rules defined between them. The tool allows administrators to audit these security rules and verify that they align with organizational access policies and segmentation requirements.

  • Requires R82 SmartConsole Build 1065 or higher.

PRJ-67021,
PMTR-124959

Security Management

NEW: Added a new Management API command to retrieve an entire Access Control Layer (including inline layers) - "export-access-rulebase".

PRJ-64780,
PMTR-124468

ElasticXL

NEW: Introduced the new Migration Tool for converting ClusterXL to ElasticXL. Refer to sk183894.

PRJ-64973,
AAD-4768

VPN

NEW: Added support for nested groups with Host/Range/Network objects for split tunnel on exclusion/inclusion options. Refer to R82 Remote Access VPN Administration Guide.

PRJ-66627,
PMTR-124234

Security Management

Cloud Firewall

NEW: Added integration between the Security Management Server and Illumio to extend Check Point micro-segmentation capabilities. This integration enables importing Illumio Workloads and Labels into SmartConsole and using them directly in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation. Refer to R82 CloudGuard Controller Administration Guide > CloudGuard Controller for Illumio Policy Compute Engine.

Take 103 - Improvements and Resolved Issues

 

PRJ-67984,

PMTR-126652

Security Gateway

UPDATE: Resolved CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero. Refer to sk184981.

PRJ-67839,

PMTR-126457

Security Gateway

UPDATE: Resolved CVE-2026-48132 - VPN process may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP. Refer to sk184982.

PRJ-67874,

PMTR-126538

Security Gateway

UPDATE: Resolved CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion. Refer to sk184993.

PRJ-67836,

PMTR-126454

Security Gateway

UPDATE: Resolved CVE-2026-48134 - SQL injection issue in UserCheck Web Portal when DLP is active. Refer to sk184983.

PRJ-68009,

PMTR-126694

Security Gateway

UPDATE: Resolved CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests. Refer to sk184991.

PRJ-68355,

PMTR-126828

Security Management

UPDATE: Resolved CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance. Refer to sk184992.

-

-

This Jumbo Hotfix Accumulator Take includes dozens of code and functionality hardening changes.

PRJ-66695,

PMTR-124314

Mobile Access

UPDATE: The Magnific Popup JavaScript library is upgraded from version 1.1.0 to 1.2.0.

PRJ-67354,

PRHF-43660

Security Management

UPDATE: JRE is updated from version 8.0_8.50 to 8.0_8.60.

PRJ-67396,
PRJ-66177

Security Management

UPDATE: Policy installation is now accelerated after performing Global Domain Reassignment.

PRJ-65271,
PRHF-42905

Security Management

UPDATE: In environments with thousands of Domain objects or External User Groups, the policy installation duration is now significantly improved.

PRJ-65116,

MGMTPROD-2359

Security Management

UPDATE: The "Test Feed" functionality in Check Point's Network Feed and IoC Feed allows administrators to validate the connectivity, parsing, and loading of Threat Intelligence feeds directly on cluster members.

PRJ-65041

Security Management

UPDATE: When connecting a Domain to the Check Point Portal, Dedicated Log Servers in the Domain are now connected automatically.

PRJ-67100,

PMTR-89328

Security Management

UPDATE: Added a validation that helps to prevent assigning a single Security Gateway as both the Center and Satellite member within the same VPN Star Community.

PRJ-65923,

PMTR-114424

Security Management

UPDATE: The Zero Phishing Software Blade improvements:

  • Changed the default Portal Accessibility configuration from "Through all interfaces" to "Through internal interfaces", including the VPN-encrypted interfaces.

  • Resolved an issue that prevented saving manual updates to internal accessibility settings. Refer to R82 Threat Prevention Administration Guide.

Requires installing R82 SmartConsole Build 1065.

PRJ-65596,

HEC-1347

HCP

UPDATE: Added a new HCP test that analyzes load balancing and NAT utilization, and suggests optimal distribution adjustments accordingly. Refer to sk171436.

PRJ-62378,
PMTR-117018

Logging

UPDATE: Added a capping status indicator to CPView and SmartConsole showing whether log sharing is actively sending logs to the Cloud or it reached its daily limit. Refer to R82 Security Management Administration Guide.

PRJ-65493,
PMTR-122413

Logging

UPDATE: SmartEvent now supports the "system alert" log type for URL Filtering and Application Control Software Blades.

PRJ-65538,

PRHF-42643

Security Gateway

UPDATE: When OCSP certificate validation fails, the Security Gateway now automatically falls back to CRL validation. Manual configuration via the Check Point Registry (described in Scenario 2 in sk179434) is no longer required.

PRJ-66949,
PRHF-44085

Security Gateway

UPDATE: Added the "tap_mode" parameter to a dispatcher (fwmultik_dispatcher_in_tap_mode). This parameter puts the multi-core dispatcher into the Tap Mode for inbound traffic. Refer to sk184455.

PRJ-64355,
PMTR-118923

Security Gateway

UPDATE: Added the ability to automatically stop kernel debugging after a specified number of seconds. See the R82 Quantum Security Gateway Administration Guide. Refer to the command "fw ctl debug -T <Number of Seconds>".

PRJ-64005,
PMTR-119902

SecureXL

UPDATE: Improved Debug Filtering for specific flows in SecureXL User Space Mode (UPPAK) debug messages.

PRJ-62990,
PMTR-118035

VSNext

UPDATE: Added an ability to automatically roll back CoreXL instance changes on a VS if the operation fails on one of the cluster members.

PRJ-65094,

PRJ-63808

Cloud Firewall

UPDATE: Azure VM sizes v2 and v3 are no longer supported. During installation of Jumbo Hotfix Accumulator or in-place upgrade, this message is now displayed: "The Azure VM size {VMsize} is deprecated for upgrade. Refer to sk183693 for details".

PRJ-65822,

CGNSIS-157

Cloud Firewall

UPDATE: Added support for Microsoft Azure Network Adapter (MANA) driver. Refer to sk183754.

PRJ-64540

Scalable Platforms

UPDATE:

  • Added support for manual FEC configuration on Maestro Orchestrator ports. This feature is intended for scenarios where FEC is not automatically detected, allowing administrators to manually set the appropriate FEC mode for optimal link performance.

  • Also, resolved an issue where -D type transceivers are incorrectly reported as not supported on Orchestrator ports.

PRJ-66546,

ODU-3619,

PRJ-67790,

ODU-3852,

PRJ-67786,

ODU-3894,

PRJ-68755,

ODU-4023

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 163, Take 165, Take 170 via self-updatable package. Refer to sk170314.

PRJ-67867,
ODU-3957

Automatic Updates - HCP

UPDATE: Added Update 27 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-66728,

ODU-3666

Automatic Updates - Log Exporter

UPDATE: Added Take 53 to Log Exporter Auto Update Deployment. Refer to sk182866.

PRJ-66382,

ODU-3435,

PRJ-68135,

ODU-3901

Automatic Updates - Policy Insights

UPDATE: Added Take 82, Take 91 of Policy Insights Release Updates. Refer to sk183421.

PRJ-67870,

ODU-3950

Automatic Updates - CPSDC

UPDATE: Added Take 43 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414.

PRJ-62809,
PRHF-40437

Security Management

Running a Packet Mode search using the Management API for a service object fails to match the correct service rules.

PRJ-61645,
PMTR-115879

Security Management

In rare scenarios, CME (Cloud Management Extension) fails to run because of the "show-simple-gateway" Management API command failure. The CME logs show such entries: "Product - CMESeverity - criticalDescription - Error during synchronization with Security Gateways. Error details: Failed to scan for gateway instances in the cloud account".

PRJ-63826,
PRHF-41884

Security Management

Best Practices may be missing or show incorrect results in the Security Best Practices view of the Compliance Software Blade. Refer to sk184239.

PRJ-63948,
PRHF-41979

Security Management

Policy installation may fail when an inline layer is used more than once in the same policy and this error is displayed "Policy installation had failed due to an internal error. If the problem persists please contact Check Point support".

PRJ-62989,
PRHF-41049

Security Management

In some scenarios, when updatable objects are used in the policy, policy installation fails with error code "0-2-2000245". Refer to sk183844.

PRJ-62087,

PRHF-40511

Security Management

In a Full High Availability (HA) ClusterXL deployment, the Check Point Portal does not display the Active Management Server as connected. As a result, Configuration Sharing is not working as expected in the Check Point Portal.

PRJ-65971,

PMTR-120900

Security Management

After an upgrading the Security Management Server, policy installation may fail with "error code - 325", "SIC general failure".

PRJ-56529,

PRHF-34095

Security Management

The delay may be observed during the "compiling policy" and "generating policy files" stages in SmartConsole.

PRJ-63437,
PRHF-41614

Security Management

In some scenarios, SmartConsole may disconnect during policy installation.

PRJ-64541,
PMTR-120942

Security Management

When using the "add/set data-type-weighted-keywords" and "add/set data-type-file-attributes" Management API commands, the field "description" is missing from the response.

PRJ-64702,

PRHF-42579

Security Management

Hitcount of NAT Rule Base fails after Security Management Server upgrade. Refer to sk184336.

PRJ-63084,
PMTR-110769

Security Management

SMB packages may not appear in the Multi-Domain Security Management "package repository list", even though they uploaded successfully.

PRJ-61595,
PRHF-40123

Security Management

After installing a policy on a Security Gateway running R81.20 or lower, the PDPD (Policy Decision Point) process on the Security Gateway fails to retrieve user information from Microsoft Entra ID (formerly Azure Active Directory).

PRJ-65162,
PRHF-42879

Security Management

In SmartTask-generated emails, the Sender field displays the username instead of the user's email address.

PRJ-63494,
PRHF-41691

Security Management

If the "Revert to Revision" operation fails:

  • Login to the Security Management Server may fail with timeout.

  • Publish operations may take a long time.

PRJ-61281,
PRHF-38623

Security Management

In rare scenarios, the /var/tmp directory may be filled up with redundant tmpUserDefineCmd_OS0*.sh files, created during Compliance Software Blade scans.

PRJ-66497,
PMTR-123464

Security Management

In some scenarios, uninstalling Threat Prevention policy on a Security Gateway fails with "An internal error has occurred".

PRJ-66046,

MLS-1482

Security Management

In some scenarios, an upgrade of the Security Management Server may fail with a "There can only be one Automatic Purge Setting for this domain. Duplicates are invalid" message.

  • The fix will only be applied if the upgrade to this Jumbo Hotfix Take is done using a Blink image or with the Advanced Upgrade method.

PRJ-65036,

PRHF-42720

Security Management

In some scenarios, the status of a Security Gateway is incorrectly displayed in the Gateways & Servers View.

PRJ-66344,
PMTR-123469

Security Management

The "set-checkpoint-host" Management API command with the "interfaces" field may fail with the "generic_err_invalid_parameter" error.

PRJ-66606,
PMTR-124200

Security Management

If the MGMTCOMP-DIFF-REPORT-CLIENT process becomes suspended on the Security Management Server, the Server-side Change Report Generator fails to generate and send reports when processing a large number of changes.

PRJ-59614,
PRHF-38392

Security Management

Upon creation of a new Domain on a Multi-Domain Security Management Server, the Domain Server's virtual IP address is not added to the Gaia database, making it inaccessible via Clish commands. Refer to sk183941.

PRJ-66376,
PRHF-43684

Security Management

In some scenarios, SmartConsole disconnects during policy installation.

PRJ-66031,
PRHF-43621

Security Management

In some scenarios, the Management Server may generate excessive log messages, causing the cpm.elg log file to reach its size limit quickly.

PRJ-65447,
PRHF-43029

Security Management

In some scenarios, Global Domain assignment may fail with the "Failed to save the access policy assignment properties" error.

PRJ-65670,

PRHF-43067

Multi-Domain Security Management

In some scenarios, the Domain Log Management Server fails to connect to the Check Point Portal.

PRJ-63590,
PMTR-119207

CPView

In some scenarios, the CPD process may exit with core dumps.

PRJ-64206,

PMTR-120236

CPView

Apostrophes used in CPView strings cause CPDiag to fail. CPView History data is not shown. Refer to sk184873.

PRJ-68509,

PRJ-68481,

PMTR-127053

CPView

The CPVIEWD daemon may exit during startup.

PRJ-65332,
PRHF-42927

Logging

In SmartView Monitor, opened from Logs & Events > Tunnel & User Monitoring, the "SmartEvent Correlation Unit" status may be displayed as "Not running" although the CPSEMD process is running.

PRJ-63974,
PRHF-41752

Logging

In SmartConsole, when exporting logs from the Logs tab to a CSV file, the "Rule" column may display only the parent rule number instead of the specific inline rule number.

PRJ-65906,

PMTR-121592

Logging

In the "HTTPS Inspection Statistics" in SmartView, filtering by the "bypass_reason" field returns no results.

PRJ-63227,

PRHF-40388

Logging

In some scenarios, disk space on the Security Management Server may increase significantly if PostgreSQL database log rotation does not function as expected.

PRJ-64074,
SL-9462

Logging

In some scenarios, incorrect values are shown in the "Total Bytes" field in the logs. Refer to sk184237.

PRJ-66531,

PRHF-44001

Logging

CPView may display "N/A" values for logging-related metrics when there is insufficient free disk space in the log partition.

PRJ-56716,

PRHF-35509

Logging

In the Connection logs, the Source Country and Destination Country fields may contain missing or incorrect values.

PRJ-59833,
PRHF-38494

Logging

In HTTPS Inspection logs, some log entries may incorrectly display "Log Update" in the Software Blade field.

PRJ-66842,
PRHF-44182

Logging

In some scenarios, non-ASCII characters may appear garbled in SmartEvent Automatic Reaction emails.

PRJ-64756,
PRHF-38664

Security Gateway

The ICAP client does not work correctly, impacts the allowed number of characters for the ":service" field in the $FWDIR/conf/icap_client_blade_configuration.C ICAP configuration file.

PRJ-63958,
PMTR-119401

Security Gateway

Changing instances on Virtual Systems may not trigger synchronization flows in some relevant directories and in the High Availability module.

PRJ-65442,
PRHF-42991

Security Gateway

The SD-WAN NAT rule may not be applied when no NAT is defined in the Access Control policy.

PRJ-67357,
PRHF-44269

Security Gateway

In rare scenarios, after an upgrade, the Security Gateway may crash because of a missing route.

PRJ-64519,
PRHF-41790

Security Gateway

First packet may be delayed for around 10 seconds because of pending WSDNSD DNS lookup over TCP. Refer to sk184096.

PRJ-66004,
PRHF-43522

Security Gateway

In a rare scenario, an incorrect zone assignment occurs when NAT Rule Base returns HOLD. Refer to sk184530.

PRJ-64834,
PRHF-42537

Security Gateway

Legitimate files may be incorrectly flagged as malicious when scanned with ICAP. Refer to sk184628.

PRJ-66804,
PRHF-44149

Security Gateway

In rare scenarios, the FWK process may unexpectedly exit when the Anti-Bot Software Blade inspects a specific malformed domain.

PRJ-62969,
PRHF-41301

Security Gateway

In rare scenarios, when deleting a subordinate interface from a bonding group, the FWK process may exit. Refer to sk183736.

PRJ-67519,
PRHF-30983

Security Gateway

Running the "g_tcpdump mcap" with "-C" flag fails with the file matching or captured packets merging error.

PRJ-64162,
PRHF-42100

Security Gateway

In rare scenarios, ElasticXL VSX Cluster Members fail over several times per day because of HTTP/2 explicit proxy process termination. Refer to sk184932.

PRJ-66891,

PMTR-113018

Security Gateway

During a ClusterXL High Availability failover, the FWK process may unexpectedly exit when processing Web Security traffic.

PRJ-63384,
PRHF-41504

Security Gateway

In rare scenarios, the FWK process may exit when parsing an invalid SIP packet.

PRJ-65053,
PRHF-42145

Security Gateway

In some scenarios, SNMPv3 monitoring fails on Data Plane when MDPS is enabled. Refer to sk184379.

PRJ-59892,

PRHF-38489

Security Gateway

In rare scenarios, the FWK process may exit with core files because of a segmentation fault.

PRJ-63235,

PRHF-41491

Security Gateway

Enabling ForceAuth for Remote Access VPN fails because of a typo in the saml_force_authn_override.sh script (sk182042).

PRJ-64976,

PRA-5005

Security Gateway

In a rare scenario, the FWK process may restart unexpectedly when the Security Gateway processes accelerated connections.

PRJ-64078,
PRHF-41256

Security Gateway

In scenarios where a network connection is closed before the Anti-Virus ThreatCloud emulation or scanning response is received, the affected session may experience connectivity instability.

PRJ-66359,
PRHF-43916

Security Gateway

The BMAC/VMAC verification for a VSX Maestro Security Group member incorrectly reports a failure on warp interfaces.

PRJ-65268,
PMTR-121815

Security Gateway

In some scenarios, non-accelerated traffic from a Standby VSX Cluster member may not be routed to the correct virtual instance on the current Active member when SecureXL User Mode (UPPAK) is enabled.

PRJ-66173,
PRHF-43692

Security Gateway

The Security Gateway may fail to correctly handle return traffic for pass-through GRE connections in scenarios with NAT.

PRJ-66198,

PRHF-43742

Security Gateway

In some scenarios, when processing HTTPS traffic in the accelerated pipelined path, the FWK process may unexpectedly exit.

PRJ-67156,

PRHF-44365

Security Gateway

In some scenarios related to Check Point Active Streaming (CPAS), the Security Gateway may unexpectedly crash.

PRJ-65585,

PRHF-43161

Threat Prevention

In Smart-1 Cloud environments, the "Threat Prevention" view may display 0 in the "Logs" column under the "Top Protections" widget. Refer to sk184505.

PRJ-66235,
TPDO-3553

Threat Prevention

In some scenarios, the IoC parser may fail to process feeds that include IPv6 observables when running on systems that do not support IPv6.

PRJ-66296,

PMTR-123479

Threat Prevention

In a rare scenario, the Threat Prevention rule base may fail to match traffic to any rule.

PRJ-65833,

PRHF-42534

Identity Awareness

In a rare scenario, a Policy Decision Point (PDP) Security Gateway that acts as both an Identity Broker Subscriber and a sharing identity with a Policy Enforcement Point (PEP) may become unresponsive.

PRJ-64694,

PRHF-42522

Identity Awareness

When the Packet Tagging feature is enabled on the Full Identity Agent, new user and machine identity sessions reported to the Identity Awareness Gateway may not be assigned the correct Access Roles. As a result, traffic from these sessions may not match Access Control Policy rules that use access roles with Packet Tagging enabled.

PRJ-64120,

PRHF-41176

Identity Awareness

In a rare scenario, there may be no access to resources for identities received from the Remote Access identity source.

PRJ-67094,

PRHF-36542

Identity Awareness

In a rare scenario, when the fetch_by_SID feature is enabled, the PDPD process repeatedly exits. Refer to sk182745.

PRJ-65868,
PRHF-43507

Identity Awareness

Skyline may not return data for part of Identity Awareness metrics described in Skyline Administration Guide.

PRJ-60571,
PRHF-39093

Content Awareness

In some scenarios, a memory leak may occur in the DLPU process. The /var/log directory on the Active Cluster member reaches critical disk usage levels.

PRJ-65960,
PMTR-123099

Application Control

Updating two or more Dynamic URL Lists may result in partial updates.

PRJ-65876,
PMTR-123004

Application Control

In a rare scenario, when using Dynamic URL List, updating the version file may result in a FWK process restart.

PRJ-63611,
PMTR-119233

IPS

In rare scenarios, the IPS update package may become corrupted. This could cause the Security Gateway to load the initial policy instead of the active security policy.

PRJ-59838,
PRHF-38433

DLP

In some scenarios, changes to the kernel parameter "dlpk_drv_default_queue_sz" may not take effect.

PRJ-64751,
PRHF-42607

Anti-Virus

In some scenarios, a memory leak may occur in the Anti-Virus Software Blade process when the Security Gateway is configured as a proxy.

PRJ-66185,
PRHF-43831

Anti-Virus

In some scenarios, the Security Gateway may drop DNS traffic with non-malicious Domains.

PRJ-66452,
PMTR-121764

SSL Inspection

Several WSTLSD processes running for each Security Gateway may exhaust memory consumption.

PRJ-58810,
PRJ-58737

Mobile Access

After an upgrade, the Mobile Access Software Blade's CVPND daemon fails to load and the Mobile Access Portal becomes inaccessible when adding new Virtual Systems or converting to a VSX Gateway, due to improper updates to the gateway-side configuration file cvpnd.C. Refer to sk183293.

PRJ-66594,
PRHF-44051

Mobile Access

When Mobile Access is working in Path Translation (PT) Link Translation mode, the Citrix application may not load after an upgrade to Citrix version LTSR 2507.

PRJ-62167,
PRHF-40663

ClusterXL

Connections with fragmented packets drop on Scalable Platform/Maestro when there are multiple active Security Group Members (SGMs) on the site. Refer to sk182559.

PRJ-64090,
PRA-5003

ClusterXL

When MDPS is enabled, cluster may get stuck in "Init" state with FullSync pnote because of a failure to bind to a socket.

PRJ-64916,
PRHF-42671

ClusterXL

After creating a High Availability ClusterXL and syncing to Smart-1 Cloud, running the "get interfaces with topology" in Smart-1 Cloud may cause the Sync interface to be removed from the Cluster object.

PRJ-59711,
PRHF-37976

ClusterXL

The "cphaconf failover_bond <bond_name>" command fails with Management Data Plane Separation (MDPS). Refer to sk183935.

PRJ-66293,
PMTR-123321

ClusterXL

In rare scenarios, CPHASTART, CPHACONF, and CPHAMCSET processes may intermittently unexpectedly exit.

PRJ-65901,
PMTR-123186

ClusterXL

After rebooting specific Security Group Members (SGMs) in a dual-site Maestro environment, PDP (Policy Decision Point) to PEP (Policy Enforcement Point) connections are not always corrected to the SMO (Single Management Object) as expected. This results in connection restarts and additional CPU load.

PRJ-67239,
PRHF-44218

SecureXL

IPv4 addresses in the SYN Defender Allow List in SmartConsole may be loaded with the address octets reversed.

PRJ-67245,
PRHF-44550

SecureXL

Maestro backplane interfaces may appear in the SYN Defender interface list. This is a cosmetic issue.

PRJ-67685,
PMTR-125951

SecureXL

Changes to the SYN Defender Allow List made in SmartConsole may not override or replace local modifications made directly on the Security Gateway.

PRJ-67242,
PRHF-44335

SecureXL

When loading the SYN Defender Allow List from the Gateway CLI using only the "-L" parameter, the entries are merged with the existing Allow List (including those configured in SmartConsole), rather than overwriting it.

PRJ-67933,
PMTR-119508

SecureXL

When using DoS Deny List and running "cpstop", an error message may be displayed, and a memory leak may occur.

PRJ-67066,
PMTR-124718

SecureXL

The FWK process may exit during an upgrade if DOS/Rate limiting is active.

PRJ-67241,
PMTR-114101

SecureXL

A failed Access Control policy installation may block future installs until the Security Gateway is rebooted, even after the original issue is resolved.

PRJ-64147,
PMTR-120207

SecureXL

The Security Gateway with SecureXL User Mode (UPPAK) enabled may not properly update routes when bond interfaces are configured.

PRJ-66171,
PRHF-43757

SecureXL

In some scenarios, when installing a policy fails, the Sand Blast Security Gateway becomes unresponsive and reboots automatically. The "Installation failed. Reason: Due to a timeout value of 600000 (millisecond) (port) (IP), Security Management Server aborted the connection with the peer" error is displayed in SmartConsole.

PRJ-65914,
PMTR-122248

SecureXL

When SecureXL User Mode (UPPAK) is enabled on a VSX Security Gateway, taking down a warp interface on any Virtual System may cause all Virtual Systems connected to the same Virtual Router or Switch to lose network connectivity.

PRJ-63692,
PMTR-118658

SecureXL

In some scenarios, the USIM_X86 process may become unresponsive.

PRJ-63079,
PRHF-41393

SecureXL

GRE tunnels fail after upgrade to R82 when SecureXL is enabled on the Security Gateway. Refer to sk184007.

PRJ-63124,
PMTR-118217

SecureXL

The USIM process may exit with core dumps when debug information is collected.

PRJ-62251,
PMTR-116638

SecureXL

SYN Defender (Synatk) does not recognize or enforce protections on bridge interfaces.

PRJ-62198,
PMTR-114719

SecureXL

When the Security Gateway is working with SecureXL in User Mode (UPPAK) mode, in some scenarios, the USIM process may exit and not restart, although it should.

PRJ-66163,

PRJ-66223

SecureXL

A vmcore dump may occur when enabling kernel debugs in Kernel Mode (KPPAK) while processing multicast traffic.

PRJ-61390,
PRHF-42606

SecureXL

When configuring PIM in Sparse Mode across multiple Virtual Systems on a VSX Security Gateway, the Security Gateway may crash, resulting in loss of connectivity.

PRJ-64318,
PMTR-120376

SecureXL

When SecureXL is working in User Mode (UPPAK) mode, some packets may sometimes appear twice in the output of the "tcpdump" command.

PRJ-65106,
PRJ-61338

SecureXL

When SecureXL User Mode (UPPAK) mode may be disabled if some scripts are incorrectly edited.

PRJ-65451,

PMTR-121744

SecureXL

Permanently disabling the "cphwd_enable_ecmp" global parameter on a VSX Gateway using the "-f" option of the "fwl ctl set" command may fail.

PRJ-65601,

PMTR-122439

SecureXL

When SecureXL works in User Mode (UPPAK) on Security Gateways with CPAC-4-10F-C interface modules, invalid Ethernet frames permanently shut down the port's transmit queue, causing complete connectivity loss.

PRJ-64616,
PMTR-121035

Routing

When a routemap rule is configured to match a specific BGP community, it incorrectly matches routes that have no community set at all, instead of excluding them.

PRJ-67173,
PRHF-44146

Routing

A ROUTED daemon may exit with a dump file during an OSPF route lookup on a route being redistributed between BGP and OSPF.

PRJ-62566,
PMTR-117103

Routing

When SecureXL runs in User Mode (UPPAK), local IGMP and MLD multicast groups are not added to listener reports. This causes the output of the "show igmp groups" command to miss expected local group memberships. Additionally, the router does not send MLD reports for IPv6 multicast groups, breaking IPv6 Dynamic Routing.

PRJ-65917,
PMTR-122434

Routing

A VSX Security Gateway may drop traffic with IPv4 options or IPv6 extension headers arriving from a Virtual Switch (VSW) interface.

PRJ-66408,
PRHF-43907

Gaia OS

The SNMPD daemon fails to restart when an interface configured with an IPv6 address is set as the SNMP agent interface.

PRJ-65154,
PMTR-116969

Gaia OS

When MDPS routing separation is enabled, Link Layer Discovery Protocol (LLDP) fails to be enabled from Gaia Portal.

PRJ-65220,
PRHF-42915

Gaia OS

SNMP monitoring systems may report format errors related to the structure of the chkpnt.mib file.

PRJ-62338,
PRHF-40826

Gaia OS

LLDP data formatting issues when querying using SNMP. Refer to sk183733.

PRJ-65223,
PRHF-42944

Gaia OS

When integrating SNMP monitoring systems with Gaia OS, compilation of the GaiaTrapsMIB.mib file with the CHECKPOINT-MIB (chkpnt.mib) may fail. SNMP management stations or MIB browsers (such as HP OpenView, CA Spectrum, or HP Network Node Manager) return errors like "File GaiaTrapsMIB.mib failed to parse" or "ERROR : Cannot find symbol file://GaiaTrapsMIB.mib:Line XX:Column XX:multiDiskName".

PRJ-61179,

PRHF-33954

Gaia OS

On a Scalable Platform Security Group, although an SHA hash type was configured for Gaia OS passwords with the Gaia Global Clish command "set password-controls password-hash-type", the Gaia Global Clish command "set expert-password" saves the password as an MD5 hash in the Gaia OS database. Refer to sk182339.

PRJ-65857,

PMTR-122180

Gaia OS

Users cannot create read-only roles, cannot modify roles by removing permissions, or assign roles with all features to specific virtual servers, and all operations fail silently without warnings.

PRJ-63238,

PRHF-41507

Gaia OS

The SSHD process unexpectedly exits on the Multi-Domain Log Server (MLM) after an SSH session ends. Refer to sk183972.

PRJ-65026,

PRHF-42775

Gaia OS

"No Such Instance currently exists at this OID" message is displayed when querying the OID tree 1.3.6.1.4.1.2620.1.48 on a Maestro Security Group. Refer to sk184363.

PRJ-65526,
PRHF-43016

Gaia OS

Upon logging in to the Gaia Portal, the login page accepts the credentials, briefly displays the homepage, and then automatically redirects back to the login screen.

PRJ-65857,

PMTR-122180

Gaia OS

Users cannot create read-only roles, cannot modify roles by removing permissions, and cannot assign roles with all features to specific virtual servers, with all operations failing silently without warnings.

PRJ-57484,
PRHF-30690

Gaia OS

Custom log rotation configured using Gaia OS does not apply to SAML-related log files, so these logs are not rotated automatically. Refer to sk113241.

PRJ-57485,
PRHF-34965

Gaia OS

Custom log rotation configured using Gaia OS does not apply to UserCheck Portal log files, so these logs are not rotated automatically. Refer to sk113241.

PRJ-66751,
PRHF-44108

Gaia OS

Cloning groups may fail during configuration updates. Refer to sk184701.

PRJ-67944,
PRJ-67883,

PMTR-126636

Gaia OS

In a Maestro setup with MDPS enabled, the Security Gateway may crash when processing IPv6 traffic while under load.

PRJ-66465,
AAD-8776,

PMTR-123351,

PRHF-44661

VPN

VPN traffic outage may occur in ClusterXL environments with SD-WAN Overlay or Enhanced Link Selection after a Cluster failover. The new Active cluster member fails to properly handle VPN traffic because of synchronization or MAC address handling problems.

PRJ-65321,
PRHF-42883

VPN

The VPND or IKED daemon may unexpectedly exit during IKEv2 negotiation.

PRJ-65011,
PRA-5001

VPN

SSL Network Extender Portal is accessible even when it is disabled in SmartConsole. Refer to sk184344.

PRJ-63552,
PRHF-41687

VPN

CRL files may not be synchronized as expected in Management High Availability and Multi-Domain Security Management environments.

PRJ-66855,
PRHF-44039

VPN

The VPND daemon intermittently exits after a downgrade.

PRJ-68715,

PMTR-127505

VPN

Remote Access Endpoint Security Client may disconnect and reconnect approximately every 15 seconds.

PRJ-68992,

PMTR-122433

VPN

Remote Access Endpoint Security Client may fail to connect.

PRJ-63829,
PRHF-41901

VPN

When generating a CPInfo file using the CPInfo utility, major CPU spikes may occur on the Security Gateway or Security Management Server.

PRJ-67110,
PRHF-44004

VPN

The VPND and IKED daemons keep restarting after upgrading to R82 in an environment with multiple VTI interfaces. Refer to sk184895.

PRJ-66467,
AAD-9083

VPN

In ClusterXL environments, a VPN traffic outage of up to 60 seconds may occur after an ungraceful cluster failover.

PRJ-66365,
PMTR-123613

VPN

In some scenarios, over time, prolonged VPN traffic may lead to gradual memory growth.

PRJ-65826,
PRHF-43529

VPN

A customized Per-gateway Secure Configuration Verification (SCV) policy is not enforced for Remote Access VPN clients. Refer to sk184863.

PRJ-66770,
AAD-9554

VPN

VPN traffic outage may occur in ClusterXL environments with IKEv2 after a Cluster failover.

PRJ-64249,
PMTR-120380

VPN

After an upgrade of the Security Management Server to R82.10, after starting SmartConsole, a validation error "DYNAMIC MESSAGE" is displayed, and VPN Community shows a warning "R82 gateways use the deprecated Kyber algorithm, for PQC. It is recommended to use R8210 and above gateways that use standard PQC algorithms. See sk184080 for details".

PRJ-65419,
PMTR-121924

VPN

After a Cluster failback, RDP (Routed Data Path) or DPD (Dead Peer Detection) probing may not be triggered, which can result in traffic continuing to use outdated Multiple Entry Point (MEP) Gateway selections.

PRJ-66012,

PMTR-117053

VPN

VPN traffic from L2TP clients may fail to pass through the Security Gateway working in SecureXL User Mode (UPPAK).

PRJ-58820,

PMTR-110326,

AAD-3140

VPN

In environments where all Security Gateways are configured with IPv6 addresses only, Site-to-Site VPN connectivity may be disrupted when Enhanced Link Selection is enabled.

PRJ-63074,
AAD-7010,

PMTR-118391

VPN

IPv6 traffic disruption may occur on Security Gateways when Enhanced Link Selection is enabled and VPN links are directly connected interfaces.

PRJ-65740,

PMTR-122271

VPN

The IKED process may exit when the traffic is passing through IKEv2 tunnels.

PRJ-62344,
PRHF-40386

VPN

In some scenarios, only a partial list of traffic selectors may be sent during tunnel negotiation for Remote Access IKEv2 tunnels.

PRJ-62763,
PMTR-117325

VPN

Enhanced Link Selection configured with Auto Next Hop uses invalid IP addresses, preventing tunnel initiation.

PRJ-60957,
PRHF-38401

VPN

High CPU utilization on single core because of excessive VPN probing and SEP correction in ClusterXL HA Mode. Refer to sk183814.

PRJ-62055,
PRHF-40518

VPN

IKE daemons may fail to start on Cluster members without generating dump files.

PRJ-62491,
PMTR-114891

VPN

Policy installation fails in a Remote Access community with only R82 Security Gateways when SHA-384 or SHA-512 are enabled, although failure should occur only if lower Security Gateway versions are part of the community.

PRJ-62774,

PRHF-41154

VSX

A malformed or incorrect interface name in the "cphaprob -a if" command on VS0 triggers a fatal error in the cluster process, causing the member to go DOWN and generating a core dump.

PRJ-65191,
PMTR-122006

VSX

During interface reallocation between Virtual Systems on a VSX Gateway, Management access (SSH/Gaia Portal) to VS0 may be disrupted after the interface move. Returning the interface to its original VS does not recover connectivity.

PRJ-65232,
PMTR-121783

VSX

After upgrading the firmware, the interface on one of the VSX cluster members may go down.

PRJ-67230,
PMTR-125258

VSX

Incorrect MAC address configuration on WRP interfaces in a VSNext environment leads to ClusterXL Load Sharing malfunctions and traffic correction issues.

PRJ-65673,
PMTR-122609

VSX

Deleting a Virtual Switch (VSW) may break connectivity for unrelated Virtual Systems (VSs).

PRJ-64608,
PMTR-118702

VSX

The number of IPv6 instances remains "0" on VS1 after enabling IPv6 state on it through Clish and performing a reboot.

PRJ-61255,
HEC-574

VSX

The Netscout feature may not monitor network connectivity to remote known hosts on VSs other than VS0.

PRJ-65479,
PMTR-122185

VSX

When attempting to create a new Virtual System (VS) with management connectivity enabled, the operation may fail. This prevents the successful provisioning of the Virtual System in the environment.

PRJ-67114,
PMTR-123775

VSX

When adding or deleting static routes in the huge VSX environment (more than 50 Virtual Systems and hundreds of static routes), VS creation fails with "Unable to watch directory /etc/routed-mc-enable: init: Too many open files". Refer to sk181317.

PRJ-65934,
HEC-2260

VSX

The "show configuration" gClish command may fail for showing configuration for LLDP, VSNext, VSLS, SSH, and OSPF.

PRJ-65388,
PMTR-122044

VSNext

In VSNext ElasticXL and VSNext Maestro, running the "cpconfig" command from Clish/gClish within a Virtual System context may trigger execution in the Global context.

PRJ-65242,

PMTR-121780

VSNext

After adding a virtual link between a Virtual System (VS) and a Virtual Switch (VSW), policy installation may fail with the "Installation failed. Reason: TCP connectivity failure [ error no. 10 ]" error.

PRJ-63697,

PMTR-119366

VSNext

When capturing packets on a warp interface in a Virtual System (VS) of a VSX Security Gateway with SecureXL User Mode (UPPAK) enabled, certain reply packets may not be captured, for example, ICMP Echo Replies to traffic directed at the Security Gateway.

PRJ-65483,

PRHF-43055

VSNext

Three out of four Virtual Systems (VS) on a single site may show a "Problem" Health status in the output of the "asg stat vs all" test. This is a cosmetic issue.

PRJ-65386,

PMTR-122058

VSNext

When the Same VMAC Mode is enabled on ElasticXL, VS0 may lose connectivity (SSH).

PRJ-65592,

PMTR-122597

Cloud Firewall

When a new Cloud Firewall Gateway is added to the Security Management Server, and a security policy is installed, the Security Gateway may not appear in the Central License Tool (vsec_lic_cli). As a result, the Security Gateway fails to receive a central license.

PRJ-66385,

PRHF-43223

Cloud Firewall

The FWM may unexpectedly exit when attaching a license to a Security Gateway using vSEC license distribution (vsec_lic_cli).

PRJ-65296,

PRHF-42496

Cloud Firewall

When using VSLS with Identity Sharing enabled, CloudGuard Controller may fail to send updates to Virtual Systems that have no Data Center Objects in their policy.

PRJ-65013,
PRHF-42642

Cloud Firewall

Registration of Data Center assets with a numeric, non-UID unique identifier may fail, potentially causing performance impact on the Security Management Server.

PRJ-63858,
PMTR-119378

SD-WAN

When VPN Enhanced Link Selection is configured and SD-WAN is enabled, pushing a new SD-WAN policy may result in loss of connectivity.

PRJ-66471,
AAD-9375,

PRJ-66469,
AAD-9373

SD-WAN

VPN traffic outage may occur in ClusterXL environments after a Cluster failover.

PRJ-64070,

PRHF-41754

SD-WAN

In an SD-WAN overlay environment when there is no matching rule, the /var/log/messages directory may contain many "could not find rule uuid for connection", "invalid return value from callback" errors.

PRJ-64871,
PRHF-42485

SD-WAN

In rare scenarios, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) may be incomplete, causing SD-WAN rules to match traffic incorrectly. Refer to sk184814.

PRJ-66033,
PMTR-109757

VoIP

Real-time Transport Protocol (RTP) may not function correctly, this results in the VoIP/RTP traffic being dropped.

PRJ-65800,
PRHF-42758

VoIP

Security Gateway may drop legitimate H323 traffic with "Illegal H.225(Q931) No Q.931 User-user IE found". Refer to sk184591.

PRJ-67482,
PMTR-125457

Scalable Platforms

If a management interface on ElasticXL Security Gateway is a part of a bond, the license distribution mechanism may not work as expected.

PRJ-64407,
HEC-1552

Scalable Platforms

In a Maestro environment with Multi-Domain Security Management and enabled MDPS, SNMP per member queries do not survive member failover. Additionally, SNMP queries to the SMO may be routed to the dplane instead of the mplane.

PRJ-64704,
PMTR-121141

Scalable Platforms

When working in the VSnext setup, creating Virtual Systems, deleting them, and recreating them may fail with an error.

PRJ-67349,
PMTR-123997

Scalable Platforms

A Security Group Member may enter a continuous boot loop after the other members were upgraded. An incorrect image file (with an invalid or mismatched MD5 checksum) is presented on the Single Management Object (SMO). As a result, the problematic member fails to complete the autoclone and repeatedly reboots.

PRJ-67176,
PMTR-120169

Scalable Platforms

In ElasticXL Clusters, a new member that exits ungracefully (force shutdown, power loss, unexpected exit) may not appear in the Clish "delete cluster member" options and cannot be deleted from the cluster configuration.

PRJ-66015,
PMTR-123154

Scalable Platforms

Using a unique IP address with the Same VMAC feature enabled may cause connections to the Standby unique IP address to fail.

PRJ-65524,
PMTR-122125

Scalable Platforms

Members added to an ElasticXL Security Group with the MDPS feature enabled may remain in the Down state because of a missing license. Licenses are not automatically distributed from the SMO member to newly added Security Group members.

PRJ-65135,
PMTR-121831

Scalable Platforms

In DNS per-Virtual System (per-VS) mode, the DNSMASQ process may allocate ports outside the defined local port pool, potentially resulting in dropped DNS traffic.

PRJ-66511,

PMTR-121748

Scalable Platforms

When MDPS Resource Separation is enabled, pushing policy under load may cause Single Management Object (SMO) to become unresponsive.

PRJ-65993

Scalable Platforms

When an upgraded site holds the initial connection, subsequent site failovers may cause out-of-state packet drops.

PRJ-62900,
PMTR-118072

Scalable Platforms

In rare scenarios, enabling interface monitoring may cause the FWK process to exit.

PRJ-64701,
PMTR-121215

Scalable Platforms

When "g_ClusterXL admin up" is triggered from a non-VS0 member (for example, VS1), the command fails and the upgraded site remains down with a pnote.

PRJ-66122,
PRHF-41852

Scalable Platforms

BGP Sessions may fail to re-establish after SMO failover because of physical link failure. Refer to sk184371.

PRJ-65767,
HEC-2146

Scalable Platforms

After creating a light snapshot locally, the snapshot appears in the output of "show lightshots", but the /mnt/lightshot directory is empty. When attempting to export the snapshot using the "set snapshot-onetime export <Snapshot-Name> target local path <Local-Path>" command, the operation fails with the "General Rsync failure" error.

PRJ-64393,
PMTR-119685

Scalable Platforms

When adding a subordinate to an LACP bond, a member may go down, which triggers a site failover.

PRJ-65969,

PMTR-92125

Scalable Platforms

After creating a bridge interface using Gaia Portal and rebooting, the Security Gateway state is down.

PRJ-63868,
PRJ-62493

Scalable Platforms

In a Maestro Security Group with a Threat Prevention policy applied, performing an SIC reset may cause non-Single Management Object (non-SMO) Security Group members to enter a Down state. The affected members display an Anti-Malware pnote as the reason for the state change.

PRJ-65500,

PMTR-122485

Scalable Platforms

These actions applied through the Web Portal are not applied to all Security Group members, but only to the SMO:

  • create/delete/edit scheduled backup

  • edit mail-address/notification-level for mailing

  • delete backup

PRJ-64390,
PMTR-120706

Scalable Platforms

In a Maestro deployment, the file $PPKDIR/conf/adpkern.conf may not be synchronized between Security Group members.

PRJ-65545,

PRHF-43121

Scalable Platforms

In a rare scenario, when a VPN-corrected packet is dropped, the packet truncation warning "14 bytes missing" may be seen in the "tcpdump" output.

PRJ-64316,

PRHF-42296

Scalable Platforms

When changing IP addresses according to sk179028, the ORCHD daemon may restart and cause communication issues.

PRJ-65118,
PMTR-121584

Scalable Platforms

OSPF adjacencies repeatedly disconnect in a VSNext Cluster. Refer to sk184396.

PRJ-65693,
PMTR-122746

Scalable Platforms

In VSX setup, a configuration note may be generated after a reboot, although the configuration is synchronized.

PRJ-62049,

PMTR-116460

Scalable Platforms

On a Maestro dual-site environment, the sgm_pmd core dump file may be generated after the Jumbo Hotfix Accumulator installation. There is no functional impact.

PRJ-65727,
HEC-2236

Scalable Platforms

In VSNext setup, when a numbered VTI interface is created for a route-based VPN under VS0 and attached to a Virtual System, the interface appears correctly in the output of the "ifconfig" command under VS0 but becomes invisible in "ifconfig" within the assigned VS context, although it remains visible in the Clish commands output.

PRJ-67210

Scalable Platforms

Bond interface deletion or IP address change may cause a site failover.

PRJ-65903

Scalable Platforms

On Maestro running VSNext, when a Virtual Switch (VSW) shares a physical interface with a Virtual System (using different VLANs), the VSW's VLAN interface may not be propagated to the Maestro Hyperscale Orchestrator (MHO).

PRJ-66558,
PMTR-121905

Scalable Platforms

In ElasticXL setups, it may not be possible to add a second Sync interface to the bonding group.

PRJ-66521,
SPC-3384

Scalable Platforms

Rebooting an Active member in the Single Management Object (SMO) role may trigger a brief connectivity loss.

PRJ-67595,
PRHF-45019

Scalable Platforms

After joining a VSNext ElasticXL member to a second site via automation, a pnote for the management (magg1) interface appears under vs0 in "cphaprob -a if", instead of under Virtual Switch (vswOID) as expected.

PRJ-65684,
PRHF-42942

Carrier Security

The FWK process may exit when GTP Intra Tunnel Inspection is enabled.

PRJ-65687,
CST-423

Carrier Security

GTP-U intra-tunnel packets may be dropped with "Packet too short" and "Invalid IP packet" errors in Bridge Mode, preventing proper inspection of encapsulated traffic.

PRJ-66714,
CST-439

Carrier Security

A "Tunnel established" message may be printed for rejected sessions. The issue is cosmetic.

PRJ-60645,
PRHF-21006

Carrier Security

GTPv1 traffic may be dropped with code description "Invalid IE length value", "GTP info: Parsing IE type 133 failed".

Take 91

Released on 31 March 2026 and declared as Recommended on 19 April 2026

Take 91 - Improvements and Resolved Issues

 

PRJ-66619,

ODU-3347

Automatic Updates - Security Management

UPDATE: Added Update 4 of Server-Side Change Report Generator Release Updates. Refer to sk179508.

PRJ-67135,

ODU-3714

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 164 via self-updatable package. Refer to sk170314.

PRJ-67144,

ODU-3682

Automatic Updates - CPView

UPDATE: Added Take 223 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.

PRJ-67138,

ODU-3698

Automatic Updates - CPView

UPDATE: Added Take 88 of CPViewExporter Release Updates. Refer to sk180521.

PRJ-67126,

ODU-3803

Automatic Updates - Log Exporter

UPDATE: Added Take 60 to Log Exporter Auto Update Deployment. Refer to sk182866.

PRJ-67188,

ODU-3845

Automatic Updates - Policy Insights

UPDATE: Added Take 87 of Policy Insights Release Updates. Refer to sk183421.

PRJ-67225,

ODU-3738

Automatic Updates - HCP

UPDATE: Added Update 26 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-67228,
ODU-3467

Automatic Updates - Threat Prevention

UPDATE: Added Update 28 of Autonomous Threat Prevention Management Integration Release. Refer to sk167109.

PRJ-66141,

PMTR-122910

Threat Prevention

File downloads may get stuck at 100% completion when either the Anti-Virus or Threat Emulation Software Blade is actively scanning the file.

See the Critical Information section.

PRJ-66997,

PRJ-66999,

PRJ-67033,

PMTR-124920,

PRHF-44366,

PMTR-124980

VPN, Internal CA

Starting March 1st, 2026, newly created certificates and newly generated CRL may fail validation. Refer to sk184766.

Take 73

Released on 17 February 2026

Take 73 - New Functionality

 

PRJ-64015,
PMTR-119998

VPN

NEW: It is now possible to add host/network/range objects for split tunnel on exclusion/inclusion modes. Refer to R82 Remote Access VPN Administration Guide > Dynamic Split Tunneling for SaaS Using Updatable Objects.

PRJ-65355,
PMTR-116780

CPView

NEW: Added the new Skyline metric "system.traffic.templates". Refer to the Skyline Administration Guide > Skyline Metrics Repository > System > Traffic.

PRJ-65719

Security Management

NEW: Now you can manage Harmony SASE Internet Access policy and HTTPS Inspection policy directly from SmartConsole. By centralizing policy management, the integration ensures consistent policy enforcement across products, streamlines governance for security policies, and consolidates operations into one trusted, management platform.

Take 73 - Improvements and Resolved Issues

 

PRJ-62103,

PMTR-116716

Harmony Endpoint

UPDATE: Check Point response to Apache Tomcat CVEs on Harmony Endpoint Security Management Server - CVE-2025-31651 and CVE-2025-31650. Refer to sk183615.

PRJ-64185,
PMTR-118961

Security Management

UPDATE: JRE is updated from version 8.0_8.35 to version 8.0_8.50

PRJ-62361,
PRHF-40849

Security Management

UPDATE: Policy verification error messages are now improved for scenarios when verification fails because of updatable objects, dynamic objects, and Domain objects in a Remote Access VPN community.

PRJ-64531,
PRHF-42420

Security Management

UPDATE: In environments with hundreds of users and user groups, policy installation duration is significantly improved.

PRJ-63719,

PMTR-119125

Gaia OS

UPDATE: Added ability to use the '.', '@', '~', ',' characters for non-local users using the Clish command "set aaa allow-unsanitized-username enable <all/dot/at/comma/tilde>". Refer to sk183201.

PRJ-63580,
PRHF-41198

Harmony Endpoint

UPDATE:

  • Directory scanner improvements for large environments.

  • Emon JSON data payload management improvements.

PRJ-66208,

HEC-2331,

PRJ-66315,

PRJ-66277,

HEC-2296,

PRJ-66739,

PMTR-124220

Scalable Platforms

UPDATE: Added support for reusable target profiles to the Lightshot snapshot configuration.

PRJ-63723

Scalable Platforms

UPDATE: Added the LogHub feature to the Insights tool.

PRJ-63218,
PMTR-118534

Scalable Platforms

UPDATE: Added ElasticXL support for Virtual Machines on Mixed Appliances. Refer to sk183513.

PRJ-65288,

ODU-3387

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 157 via self-updatable package. Refer to sk170314.

PRJ-59091,
PRHF-37685

Security Management

Administrators with LSM write permissions cannot delete LSM Gateway objects without also having write permissions for Others/Common Objects.

PRJ-60654,
PMTR-114622

Diagnostics

The Security Gateway freezes or crashes without generating a core dump, and the message "Global htab id 100020 out of range!" appears in the $FWDIR/log/fwk.elgfile, when running CPDiag. Refer to sk183538.

PRJ-62532,
PRHF-40750

Security Management

Importing a large policy package fails with validation and API errors on the Multi-Domain Security Management Server. Refer to sk183697.

PRJ-64885,

PRHF-42660

Security Management

In rare scenarios, login using Management API fails with a timeout and the "api status" command returns "API readiness test failed" message. Refer to sk184342.

PRJ-60489,
PRHF-39032

Security Management

In some scenarios, when Configuration Sharing is enabled, audit logs may show failed login attempts to the CPM Server after publishing changes.

PRJ-61809,
PRHF-40205

Security Management

When a user with read-only permissions for Global Domains (for example, a user with the Global Manager profile) connects to the System Domain in SmartConsole, the SmartConsole status bar incorrectly displays the user as having read-write permissions.

PRJ-59516,
PRHF-37612

Security Management

In rare scenarios, after an IPS update, all protections are set to Staging mode in Threat Profiles configured with "Set activation as Staging mode".

PRJ-61328,
PRHF-39881

Security Management

In rare scenarios, an IPS update fails because of duplicate objects.

PRJ-59751,
PRHF-38490

Security Management

In some scenarios, creating a Standby Domain Security Management Server fails with a "You do not have the permissions to complete this action" message.

PRJ-62555,

PRHF-40800

Security Management

In SmartConsole, if the Task pane has no tasks to show, the Task pane incorrectly shows an "Error retrieving results" message.

PRJ-60375,

PRHF-38836

Security Management

VMcore crashes may occur with core dumps of the LOG_INDEXER, LOG_EXPORTER, and JAVA processes on the Security Management Server, causing high CPU utilization.

PRJ-62551,

PMTR-117467

Security Management

In rare scenarios, the Security Management Server fails to start after performing a "Revert to Revision" operation.

PRJ-60527,

PRHF-38743

Security Management

When running the "mgmt_cli -r true gaia-api/set-ntp target pocsms enabled true --format json" Management API command, the output is not the same as running it directly from Gaia API. Refer to sk184510.

PRJ-62195,

PMTR-116551

Security Management

When using the "set-threat-protection" Management API command, overriding either the packet-capture or track values also overrides the action field and sets it to "inactive".

PRJ-56730,

PRHF-35654

Security Management

In some scenarios, Compliance Software Blade presents the results of Firewall Best Practices as "N/A".

PRJ-65809,

PRHF-43517

Security Management

The "show-packages" Management API command executed with "async-response" parameter may fail with "generic_err_invalid_parameter_name".

PRJ-63793,

PRHF-41803

Multi-Domain Security Management

On Multi-Domain Security Management Servers, custom Compliance Software Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level.

PRJ-65236,

PMTR-121265

Multi-Domain Security Management

In certain scenarios, an upgrade of the Multi-Domain Security Management Server may fail with a "During synchronization a new object was found through a relationship that was not marked cascade PERSIST" message.

  • The fix will only be applied if the upgrade to this Jumbo Hotfix Take is done using a Blink image or with the Advanced Upgrade method.

PRJ-56359,

PRHF-34777

CPView

CPView may display incorrect concurrent connection statistics (negative values) because of improper aggregation of connection data during a Cluster failover.

PRJ-55405,

PRHF-34152

Logging

In rare scenarios, the description of IPS Logs in the Logs view may be unclear. Refer to sk182386.

PRJ-64465,

PRHF-42386

Logging

In some scenarios, exporting logs to CSV in SmartView fails and the LOG_INDEXER process unexpectedly exits. Refer to sk184475.

PRJ-65364,

PMTR-122317

Logging

Improper memory handling within the CPD process may result in unexpected process restart.

PRJ-62132,

PRHF-40631

Security Gateway

The FWK memory leak may occur during FTP connections with high file volume. Refer to sk183662.

PRJ-56833,

PRHF-35857

Security Gateway

Potential memory leak in the CPD process.

PRJ-64397,
PMTR-120304

Security Gateway

When changing the CoreXL configuration (for example, adjusting the number of SND and FW instances), a network interface may unexpectedly go down. This can cause traffic disruption.

PRJ-64493,
PMTR-120932

Security Gateway

The Security Gateway may drop packets and potentially crash because of memory allocation issues.

PRJ-59735,
PMTR-110282

Security Gateway

In some scenarios, when SecureXL is working in User Mode (UPPAK) mode, QoS service is unable to start, displaying the "QoS is not responding. Verify that QoS is installed on the gateway" error. Refer to sk183752.

PRJ-62920,
PMTR-117427

Security Gateway

Infinite routing loop may occur because of TTL handling in SecureXL Medium Path. Refer to sk183728.

PRJ-65819,

PMTR-122907

Security Gateway

When using a Security Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails.

See the Critical Information section.

PRJ-63942,
PRHF-41674

Security Gateway

In a Maestro VSX environment, Layer 2 MAC address table in Bridge Mode (Bridge Forwarding Database) entries may be incorrectly deleted, causing connectivity issues.

PRJ-65131,

PMTR-108249

Security Gateway

A PYTHON3.11 zombie process may be running in the background without impact on system performance.

PRJ-64496,

PRHF-42513

SSL Inspection

Running the "show cp-trusted-ca-certificate" Management API with invalid validFrom/validTo values in the database causes an error and blocks the Trusted Certificates view.

PRJ-66542,

PMTR-123417

SSL Inspection

SSL Network Extender (SNX) package installation fails with a verification error.

PRJ-62837,
PRHF-39978

Mobile Access

Mobile Access Software Blade may incorrectly terminate Guacamole-based clientless RDP/SSH sessions due to client idleness.

PRJ-60482,

PMTR-110991

Mobile Access

Mobile Access SSL Network Extender (SNX) remote users with Windows 11 24H2 fail to connect. Refer to sk182923.

PRJ-62831,
PRHF-41229

Mobile Access

In rare scenarios, Mobile Access SmartConsole Logs may not match views/queries, including the "MAC address" or "Methods" field names.

PRJ-58680,
PMTR-110608

SecureXL

Concurrent NAT64 and NAT46 operations may cause packet processing threads to become unresponsive because of improper issue handling in the SIM v6 kernel module.

PRJ-64334,
PMTR-120460

SecureXL

Potential USIM process exit when using virtio devices and changing the MTU value.

PRJ-64457,
PMTR-120707

SecureXL

Traffic may be disrupted when reconfiguring the virtual hardware interfaces.

PRJ-61312,
PMTR-115500

SecureXL

In some scenarios, the VSX Security Gateway may not route traffic correctly for non-accelerated connections and accelerated connections that require Active or Passive Streaming when SecureXL User Mode (UPPAK) is enabled.

PRJ-61616,
PMTR-116026

SecureXL

The USIM process may exit when multiple routes are using the same nexthop and the nexthop is not yet resolved

PRJ-62960,
PMTR-117546

SecureXL

The USIM process may exit when viewing the fg_conn table using the "fwaccel tab -t" command.

PRJ-62908,
PMTR-118106

SecureXL

The USIM process may exit during the FWK restart.

PRJ-57694,
PMTR-109360

SecureXL

Multiple "radix_get_value" messages may appear in fwk.elg log files.

PRJ-63632,
PMTR-118835

SecureXL

The USIM process may exit while configuring a PPPoE interface using Gaia Portal.

PRJ-64881,
PRHF-42050

SecureXL

When a VLAN interface is configured as the synchronization interface for the VSX cluster and SecureXL User Mode (UPPAK) is enabled, Virtual Systems on non-active members cannot forward traffic to Virtual Systems on the active member through a warp interface.

PRJ-64613,
PMTR-121137

SecureXL

Multiple threads may be performing a routing next hop lookup for the same next hop at the same time, causing a rare race condition and USIM-related processes to exit.

PRJ-61827,
PRHF-40390

SecureXL

Interface cards are not displayed in the output of the "show asset network" command when SecureXL User Mode (UPPAK) and MDPS are enabled. Refer to sk184218.

PRJ-64143,

PMTR-120092

SecureXL

In a Maestro setup, the USIM process may exit under high load when handling encrypted VPN traffic with the other Security Gateway.

PRJ-60845,

PRHF-39251

SecureXL

In some scenarios, the Security Gateway may crash when IoC feed contains an IPv6 address.

PRJ-62421,

PMTR-115630

SecureXL

In some scenarios, the Security Gateway may crash.

PRJ-61623,

PMTR-116027

SecureXL

Rate Limiting policy installation (when the Rate Limiting policy is updated or country code data is updated) may take a long time.

PRJ-59396,

AAD-4359

VPN

VPN traffic outage may occur in ClusterXL environments after a Cluster failover.

PRJ-58822,

AAD-3662

VPN

IPv6 Site-2-Site connectivity may not be stable in Enhanced Link Selection configuration on ClusterXL environments.

PRJ-63346,

PMTR-104766

VPN

A race condition may cause the PROBEMOND process to exit during policy installation when VPN network probes are removed/added.

PRJ-59231,

AAD-4299

VPN

IPv6 traffic outage in Enhanced Link Selection configuration after tunnel deletion on one side during tunnel renegotiation.

PRJ-63020,
PRHF-40410

VSX

Services fail after Virtual System failover in Maestro dual-site environment using the Same Virtual MAC feature. Refer to sk183956 and sk184194.

PRJ-64573,

PMTR-120689

VSX

In an ElasticXL Cluster in the VSNext Mode, when physical interfaces are configured as management interfaces on Virtual Systems, these interfaces are down after reboot.

PRJ-63757,

PMTR-119447

VSX

In a Maestro environment, Security Group member may not be in the ACTIVE state with an Active Distutil PNOTE raised.

PRJ-62535,

PRHF-40972

Gaia OS

Gaia Portal Session Cookie missing the SameSite attribute. Security scanners and penetration tests flag the missing SameSite attribute as a vulnerability. Refer to sk183645.

PRJ-63262,
PRHF-29936

Gaia OS

The LLDP Clish "lldpneighbors" command may have a corrupted output in case of extensive data. Refer to sk182065.

PRJ-60766,
PRHF-39354

Gaia OS

DHCP traffic peaks may cause high utilization, potentially impacting connectivity.

PRJ-62041,
PRHF-40558

Gaia OS

The MONITORD process unexpectedly exits on Security Gateways. Refer to sk184076.

PRJ-62466,
PRHF-40902

Gaia OS

SNMP Power Supply trap reports false "Down" status. Refer to sk183702.

PRJ-63423,

PMTR-118146

Gaia OS

Restoring backup using Gaia Portal (or gClish) when there is a single member in the Security Group fails.

PRJ-59019,

PMTR-110956

Gaia OS

LACP bonds may continue passing traffic when running SecureXL User Space Mode and the value drops below the configured minimum number of links, although the bond interface should stop passing traffic.

PRJ-59519,

PMTR-111921

SD-WAN

A Virtual System may lose connectivity on the Backup and the Standby member when route-based traffic is configured with specific SD-WAN configurations in VSX environments.

PRJ-63462,
EPS-60858

Harmony Endpoint

Full Disk Encryption user update password fails with auth_type 3 (certificate and password).

PRJ-61893,
PRHF-39789

Harmony Endpoint

Posture Management scans initiated manually or automatically remain stuck at the "Scan initialize" status. This issue affects all devices with Endpoint Security installed.

PRJ-63038,
EPS-60640

Harmony Endpoint

After upgrading the Endpoint Security Client from a non-compliant version to E88.62 on Azure AD devices (protected by Full Disk Encryption), multiple clients may enter a disconnected state.

PRJ-61896,
PRHF-39851

Harmony Endpoint

Security Management Server and Policy Server may lose connectivity after uploading production licenses. Running "cplic print -x" on the Policy Server shows no output, while the Security Management Server output is uploaded for review.

PRJ-65469,

PRJ-65480

CloudGuard Network

The CloudGuard Network Central License utility fails to distribute a single license using CLI.

PRJ-61275,
PMTR-112270

QoS

Security Gateway cannot fetch the QoS policy from Security Management. Refer to sk183709.

PRJ-63694,
PMTR-120767

Scalable Platforms

Members added to a Security Group with the MDPS feature enabled may stay in the Down state because of a missing license (licenses are not distributed from the SMO member to the added Security Group members).

PRJ-65088,

PRJ-65089,

PRHF-42654

Scalable Platforms

Traffic impact on a Maestro Gateway with the MDPS feature enabled during a major version upgrade to R82.

PRJ-64436,
PRHF-42470

Scalable Platforms

Maestro Orchestrator fails to add a new Security Appliance to a Security Group when the Maestro Fastforward feature is enabled in the Security Group. Refer to sk184233.

PRJ-64818

Scalable Platforms

The "hcp -r" Orchestrators Ports Link Integrity test does not report link integrity issues when there is a bad signal on the MHO physical ports.

PRJ-64123,
PMTR-120049

Scalable Platforms

In an ElasticXL Cluster in the VSNext Mode, it is not possible to configure more than 32 CoreXL IPv4 / IPv6 Firewall instances in a Virtual Gateway in the CLI. The Gaia gClish command "set vsnext corexl-instances virtual-gateway ID ipv4-instances Value" fails with the "CLINFR0409 Invalid number: Value. Not in range 1..32." error.

PRJ-64062,
PRJ-62567

Scalable Platforms

When Maestro Fastforward feature is enabled, policy installation may fail with "Maestro acceleration (MXL) failed, reason: General error. Please check /var/log/acl_cli.log on the security group SMO for more details" instead of indicating that it is a policy parser issue.

PRJ-60421,
PMTR-113626

Scalable Platforms

In a VSNext environment with a Virtual Switch (VSW), SNMP data for ASG branches may not be collected.

PRJ-64345,
PMTR-120231

Scalable Platforms

After an upgrade, a local connection from Standby members on the VS management interface fails.

PRJ-65636,

PMTR-122661

Scalable Platforms

In the Maestro and Chassis environment with multiple Virtual Systems (VSs) and updatable objects, the disk may reach full capacity. Refer to sk184576.

See the Critical Information section.

PRJ-64593,

PMTR-121110

Scalable Platforms

In rare scenarios, in a Maestro setup, traffic interruption may occur after Security Gateway reboots when the Gaia Database is corrupted.

PRJ-62818,

PRHF-41165

Scalable Platforms

In a Maestro VSX VSLS Cluster, after setting the kernel parameters "fwha_monitor_all_vlan=1" and "fwha_enable_if_probing=1", memory consumption may immediately increase to 100% and cause an outage.

PRJ-63476,

PMTR-119026

Scalable Platforms

Installing policy to the Maestro Security Group under extreme load with Resource Separation may fail.

PRJ-64632,

PRHF-41710

Scalable Platforms

The "Invalid property name for chassis" error is displayed when changing the "alert_threshold packet_rate_total_threshold_low_ratio" value.

PRJ-64504,
CST-399

Carrier Security

Policy installation fails with an internal error when the Security Gateway policy includes rules that match a specific Access Point Name (APN) for GTPv0 or GTPv1 traffic.

PRJ-56452,
PRHF-31961

Carrier Security

SAM rules fail to gracefully terminate PDP context when the timer expires.

PRJ-56448,

PRHF-31901

Carrier Security

Running to "snmpwalk" or "stattest" command for any of GX OIDs results in the "No Such Instance currently exists at this OID" error.

Take 60

Released on 29 December 2025 and declared as Recommended on 19 January 2026

Take 60 - Improvements and Resolved Issues

 

PRJ-63742,
PMTR-119534

Gaia OS

UPDATE: Check Point response to CVE-2019-6109, CVE-2019-6110, CVE-2019-6111. Refer to sk65269.

PRJ-63364,
MGMTTECH-621

Security Management

UPDATE: Enhanced packet search in SmartConsole with three IP address modes:

  • "Exact": Returns rules where the IP address/network in the rule is exactly the same as the IP address/network in the search.

  • "Containing": Returns rules where the IP address/network you searched for contains the IP address/network of the rule.

  • "Contained in": Returns rules where the IP address/network you searched for is contained within the IP address/network of the rule.

PRJ-63473,

PMTR-117101

Security Management

UPDATE: SmartTasks are now supported in the System Domain of Multi-Domain Security Management. This feature enables the automation of system-domain operations, reducing manual tasks and enhancing reliability. Refer to R81.20 Quantum Security Management Administration Guide > Preferences and Management Settings > SmartTasks.

PRJ-63736,
PMTR-119349

Security Gateway

UPDATE: Added a new kernel parameter "up_rulebase_run_implied_rules" (enabled by default - "1"). Setting to "0" disables execution of implied rules in the Access Control Rule Base.

PRJ-61019,
FMW-5200

Security Gateway

UPDATE: Improved shared memory packet flow and performance.

PRJ-62396,
PMTR-116872

Scalable Platforms

UPDATE: Deleting Virtual System 0 (VS0) from the Gaia Portal causes loss of connection with the cluster. Virtual Systems 0 and 500 are now blocked from deletion in the Gaia Portal to prevent this issue.

PRJ-64247,

ODU-3159,

PRJ-64545,

ODU-3225,

PRJ-65176,

ODU-3419

Automatic Updates - Policy Insights

UPDATE: Added Take 77, Take 78 and Take 80 of Policy Insights Release Updates. Refer to sk183421.

PRJ-64477,

ODU-3143,

PRJ-64638,

ODU-3259

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 155 and Take 156 via self-updatable package. Refer to sk170314.

PRJ-64548,

ODU-3175

Automatic Updates - HCP

UPDATE: Added Update 24 of HealthCheck Point (HCP) Release. Refer to sk171436.

PRJ-64586,
ODU-3199,

PRJ-64743,

ODU-3267

Automatic Updates - CPView

UPDATE: Added Take 52 and Take 53 of CPquid (QUID) Release Updates. Refer to sk181458.

PRJ-64905,
ODU-3275

Automatic Updates - CPView

UPDATE: Added Take 210 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.

PRJ-64829,
ODU-3235

Automatic Updates - Threat Prevention

UPDATE: Added Update 27 of Autonomous Threat Prevention Management integration Release. Refer to sk167109.

PRJ-60644,
PRHF-39082

Security Management

In some scenarios, the warning "Threat Prevention Policy: For better performance, blade exception rules with the action 'Inactive' should be placed above other exception rules" appears in SmartConsole even though no exception rules violate the recommended configuration.

PRJ-62993,
PRHF-41249

Security Management

Regenerating a token on a Security Gateway Smart-1 Cloud may fail with an unclear validation message "No error in result from fwm command: [gen-pki-cert-req]".

PRJ-62778,
PRHF-41168

Security Management

In rare scenarios, High Availability synchronization may fail with a connectivity error.

PRJ-64740,

PMTR-121337

Security Management

When the Dynamic URL List feature is enabled, Security Gateway may crash during policy installation.

See the Critical Information section.

PRJ-63544,
PMTR-119007

Multi-Domain Security Management

On the Multi-Domain Security Management Server, when staging is cleared for an IPS protection in the Global Domain, any staging configuration for the same protection in the local Domain (within a Global profile) remains unchanged during policy assignment.

PRJ-63502,
PMTR-118861

Multi-Domain Security Management

In a rare scenario, the FWM process exits during a vsx_util upgrade.

PRJ-63541,
PRHF-41609

Multi-Domain Security Management

In a Multi-Domain Security Management environment, when opening the License tab of a Security Gateway object in SmartConsole, the "Security Gateway was not found" error may be shown.

PRJ-62388,
PMTR-112519

Multi-Domain Security Management

Scheduled automatic purge revisions may result in duplicate purge revisions tasks after restart of a Multi-Domain Security Management Server.

PRJ-64105,

PMTR-120043

Multi-Domain Security Management

The Configuration Sharing feature does not work as expected with VSX Gateways on a specific Domain.

PRJ-63314,
PRHF-41539

Security Gateway

The RAD daemon may unexpectedly exit.

PRJ-62826,
PMTR-117944

Security Gateway

When the Gaia Portal accessibility is configured as "According to Firewall policy", access may be denied because of a match on an implied rule with the "Accept" action.

PRJ-64783

Security Gateway

The FWK core dumps may be generated when the Security Gateway is processing HTTP traffic.

PRJ-63379,

PRHF-41472

Security Gateway

Threat Emulation on ICAP Server fails with "There was an Unexpected Internal error, Please try again later". Refer to sk184228.

PRJ-63088,

PRHF-40865

Security Gateway

HTTP parsing fails with the "Illegal header format detected: Invalid header field" error.

PRJ-62883,
PRHF-41266

Security Gateway

In some scenarios, when HyperFlow is enabled, websites that use HTTP2 protocol do not load properly.

PRJ-63487,
PRHF-41690

Security Gateway

Mirror and Decrypt feature may not function as expected when HyperFlow is enabled.

PRJ-63821,

PRHF-41922

Security Gateway

When a Security Gateway is configured in Bridge Mode, a memory leak may occur.

PRJ-63030,

PMTR-117588

Security Gateway

Web browsing is slow, or pages freeze after an upgrade when using Security Gateway as an HTTP/HTTPS Proxy. Refer to sk184683.

PRJ-61197,
PRHF-39537

Threat Prevention

In rare scenarios, the Anti-Virus Software Blade fails to fetch the external intelligence feed because of an authentication failure.

PRJ-63859,

PMTR-113368,

TPDO-3593

Threat Prevention

In a rare scenario, SmartConsole does not display a notification when the IP reputation feed for the Anti-Bot Software Blade fails to load.

PRJ-63841,
PRHF-32655

Identity Awareness

In Azure Active Directory, access role assignment only evaluates the first 100 group memberships for a user. Group memberships beyond this limit are ignored when determining access roles. Refer to sk183328.

PRJ-56755,
PRHF-33776

Identity Awareness

In a rare scenario, the PDPD daemon may unexpectedly exit while updating identity session timers.

PRJ-63432,

PMTR-118983

URL Filtering

In rare scenarios, IoC resources are not loaded or distributed as expected.

PRJ-63886,
PRHF-41980

Application Control

In the Application Layer, an "any-any" rule (from any source to any destination, using any service) with long-lived connections may cause excessive memory usage. Refer to sk184196.

PRJ-61474,

PMTR-115790

IPS

In some conditions, the Packet Capture may be missing from IPS logs in SmartConsole.

PRJ-63325,

PRHF-41553

HTTPS Inspection

In some traffic flows, packets containing certain headers may be dropped regardless of how the non-compliant HTTP Inspection is configured.

PRJ-64330,
PMTR-120628

SecureXL

When using MDPS with IPv6 disabled on the Security Gateway side, the Security Gateway may leak IPv6 packet buffers instead of dropping them. Refer to sk184419.

PRJ-59483,

PRHF-37901

SecureXL

When using DoS Deny List, CPU usage may increase.

PRJ-63602,

PMTR-119184

SecureXL

Security Gateway unexpectedly crashes with kernel logs showing segmentation faults in the USIM_86 process. Refer to sk184340.

PRJ-59480,

PRHF-38329

SecureXL

When using DoS Deny List, a firewall kernel module memory leak may occur.

PRJ-61341,
PMTR-115628

SecureXL

In some scenarios, there is significant latency when passing traffic through bridge interfaces configured on a Security Gateway when SecureXL User Mode is enabled.

PRJ-60965,
PMTR-114558

SecureXL

Significant latency on a VSX Security Gateway when transmitting non-accelerated or accelerated traffic with Active or Passive Streaming, through multiple Virtual Systems connected by Virtual Switches when SecureXL User Mode is enabled.

PRJ-63415,
PMTR-118686

SecureXL

In a rare scenario, packets with malformed message headers cause the Security Gateway to crash.

PRJ-62489,
PMTR-111667

SecureXL

In some scenarios, the Security Gateway delays offloading a connection to the Quantum LightSpeed hardware accelerated card when SecureXL User Mode (UPPAK) is enabled.

PRJ-63471,

PMTR-118999

SecureXL

In some scenarios, a VSX Gateway may not optimally pass traffic from a Virtual System to a Virtual Router or Virtual Switch when connections are accelerated in SecureXL.

PRJ-62914,
PMTR-118130

SecureXL

In some scenarios, after an update of the OS route configuration, there may be a significant delay in traffic passing through the Security Gateway when SecureXL works in the User Mode (UPPAK). Refer to sk182740.

PRJ-63857,
PMTR-119616

SecureXL

When tunnel is established and traffic is running, the USIM process may exit every 15-20 minutes and cause a failover of the second member.

PRJ-63777,

PMTR-119562

SecureXL

VPN cluster members may crash after a cluster failover with BGP enabled and the exit of the USIM process.

PRJ-63172,
PMTR-118518

SecureXL

In some scenarios, when a Security Gateway, running in SecureXL User Mode (UPPAK), receives IPv6 Neighbor Discovery Protocol (NDP) packets from the network, it may not properly forward or process them correctly.

PRJ-61977,
PRHF-40429

Gaia OS

When taking snapshots of the Security Group Members, some of the Members may crash, the dmesg_dumps shows multiple messages occurred before the crash "the active connections feature is currently enabled in the SmartView Tracker and due to high load it is making sync too slow to function properly. Therefore, 319489 active connection updates were dropped and no sync updates were lost".

PRJ-64107,
PMTR-120125

Routing

Running the "set igmp interface <ifname> last-member-query-interval <value>" command may fail with a syntax error.

PRJ-62457,
PMTR-117209

VPN

An unprintable character symbol may appear next to the username in the "Log In" logs when connecting with the configured "Fetch Username from Subject DN.CN" parsing.

PRJ-61385,
PMTR-113498

VSX

In a VSX setup, when Dynamic Balancing is enabled and an Elephant Flow is running, only one firewall instance may remain active to handle the rest of the traffic.

PRJ-63936,
PRHF-42049

VSX

When installing a new policy on Virtual Systems, the installation succeeds, although the error "VSX INSTALL ERROR: Failed to extract FW1 policy details! Skipping state directory overwrite" is displayed.

PRJ-64096,

PRHF-38127

VSX

In large scale environments, the "cpstat vsx" commands sometimes take a long time to execute or fail.

PRJ-62886,
PMTR-117998

VSX

In rare scenarios, policy installation may fail after an upgrade in VSX environments.

PRJ-64281,

PMTR-120135

VSNext

The FWK process may exit with core dumps during VS creation or deletion.

PRJ-65178,

PMTR-121938

VSNext

When deploying a Check Point ElasticXL Cluster in VSNext mode, Virtual System Load Sharing may assign the same MAC address to multiple Virtual System WRP interfaces, causing network connectivity issues or MAC address conflicts.

PRJ-64052,

PMTR-118935

VSNext

On VSNext ElasticXL setups with more than one Virtual System and IPv6 enabled, SSH disconnections occur because of wrong MAC address assignment to WRP interfaces.

PRJ-65193,

HEC-2089

VSNext

Modifying the number of CoreXL Firewall instances on a Virtual System (VS) or VSX Gateway may result in Security Policy installation issues or loss of policy configuration.

PRJ-63508,
PRHF-41452

CloudGuard Network

Registration of an updated Data Center asset to the Security Management Server may fail.

PRJ-62008,

SDWANGW-4494

SD-WAN

In rare scenarios, policy installation causes traffic matched by the "prefer local breakout" rule to be incorrectly routed through the underlay private link instead of the overlay.

PRJ-62762,

PMTR-117824,

SDWANGW-4233

SD-WAN

In rare scenarios, new connections may continue matching "Prioritize Local Breakout" despite low ISP quality that should trigger a switch to backhaul.

PRJ-62652,
PMTR-118499

Scalable Platforms

When running the "fw ctl iflist" command, there is a discrepancy between the expected network interfaces and what the kernel actually detects. This may lead to connectivity issues.

PRJ-62622,
PMTR-117580,

PRHF-42228

Scalable Platforms

OTV switches drop unknown unicast packets (packets with destination MAC addresses not present in the MAC address table) instead of forwarding them, resulting in traffic loss.

PRJ-63905,
PMTR-119823

Scalable Platforms

When multiple subordinate interfaces in the Sync bond are not dedicated Sync interfaces, MAC address duplicates may occur, causing communication failures between cluster members.

PRJ-60967,
PRHF-39103

Scalable Platforms

In rare scenarios, "asg stat -i chassis_monitor" returns "0" even when the cluster did not start, causing "distutil" to incorrectly update the MHO topology. This can result in a traffic impact when a cluster member recovers from a FWK process exit.

PRJ-59668,
PRHF-38432

Scalable Platforms

After enabling Maestro Fastforward on a Security Group, traffic matching relevant rules is routed to the default Security Gateway instead of the correct nexthop because the static route is missing from /etc/mlx_routing.json on the Maestro Orchestrator. The Orchestrator shows 200 routes and fails to pick up the interface's routes, despite the interface topology is configured as "according to routes" in SmartConsole.

PRJ-64036,
HEC-1931

Scalable Platforms

The Insights tool may not represent data on Virtual Systems.

PRJ-62924,
HEC-1486

Scalable Platforms

Scalable Platforms in the VSNext mode do not support Cluster Load Sharing (two or more Security Group Members on the same Site).

PRJ-64117,
PMTR-120059,

PMTR-120412

Scalable Platforms

On VSNext ElasticXL setups with IPv6 enabled, multiple WRP interfaces may be assigned the same link-local address, potentially causing network connectivity issues and routing failures.

PRJ-63786,

PMTR-110923

Scalable Platforms

When running the "show asset all" command on setups with ElasticXL enabled, Disk Model, Serial, and Capacity outputs are not displayed.

PRJ-63556,
PRHF-41584

Scalable Platforms

Running the command "ccutil ssm_exec 1 'show system uptime'"generates no output.

PRJ-64495,
PMTR-120972

Scalable Platforms

The gClish command "set cluster configuration image auto-clone state" may not be propagated to Security Group Members.

PRJ-63853,
PRHF-31869

Carrier Security

GTP traffic may not be well balanced, some CPU cores may be overloaded while others are underutilized, leading to performance issues.

Take 44

Released on 05 November 2025 and declared as Recommended on 23 November 2025

Take 44 - New Functionality

 

PRJ-62668,
PMTR-116161

Gaia OS

NEW: Hardened the authentication in the Gaia Cloning Group.

Important - After the installation of this Jumbo Hotfix Accumulator Take, you must follow these steps in each current Cloning Group:

  1. Make sure this Jumbo Hotfix Accumulator Take is installed on each Cloning Group Member

  2. On each of the Cloning Group Members, enter a Cloning Group password - enter the current password again or a new password.

  3. On each Cloning Group Member, re-synchronize the Cloning Group.

For more information, see the Gaia Administration Guide > Chapter "System Management" > Section "Cloning Group".

PRJ-62143,
PMTR-116780

CPView

NEW: Added the new Skyline metric "system.traffic.templates". Refer to the Skyline Administration Guide > Skyline Metrics Repository > System > Traffic.

Take 44 - Improvements and Resolved Issues

 

PRJ-63003,
PMTR-117744

Gaia OS

UPDATE: Check Point response to CVE-2025-32728 - The SSH directive "DisableForwarding" fails to disable "X11 Forwarding" and "Agent Forwarding". Refer to sk183394.

PRJ-63322,
MGMTTECH-2142

Security Management

UPDATE: A Security Management Server/Domain Management Server can now manage up to 1500 Security Gateways/Cluster members, allowing concurrent policy installation on all Security Gateways/Cluster members at once.

PRJ-59094,
PRHF-37840

Security Management

UPDATE: It is possible now to run the "show-packages" Management API command asynchronously using the "async-response" parameter.

PRJ-62339,
PMTR-115295

CPUSE

UPDATE: Added an HCP test to check whether the CPAC-2-100/25F, CPAC-2-100/25F-B, CPAC-2-40F-B, or CPAC-2-40F-C FW firmware is safe to update from R81.10 to a higher version. Refer to sk182403.

PRJ-62729,
PMTR-117738

Logging

UPDATE: Improved the design of the Security Checkup report in SmartView.

PRJ-62347,

PMTR-117114

Logging

UPDATE: The "tops" calculation method is now consistent between SmartConsole and Management CLI (mgmt_cli), so both tools produce matching results.

PRJ-61802,
PRHF-39531

Logging

UPDATE: The SOLR process (listening on port 8211) no longer accepts connections using the TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA cipher suite. Refer to sk181683.

PRJ-62730,
PMTR-117759

Security Gateway

UPDATE: ISP Redundancy is now supported in VSNext Mode.

PRJ-62857,
PMTR-117982

Security Gateway

UPDATE: ICAP Server is now supported in VSNext Mode.

PRJ-62310

Identity Awareness

UPDATE: Added Identity Awareness metrics to Skyline. Refer to the Skyline Metrics Repository.

PRJ-62473,
PMTR-117312

IPS

UPDATE: HTTP/1.1 requests missing host headers are now processed by the non-compliant HTTP Protection feature (Strict Parsing option). Previously, such requests were dropped immediately. Refer to sk183569.

PRJ-60142,
PMTR-87460,

PRJ-60464,

PMTR-114416

SecureXL

UPDATE: SecureXL Rate Limiting rules for DoS Mitigation now support these parameters with automatic IP range updating enabled by default:

  • "cc:<COUNTRY_CODE>"

  • "asn:<AUTONOMOUS_SYSTEM_NUMBER>"

Refer to sk112454.

PRJ-61325,
PRHF-39697

CloudGuard Network

UPDATE: Updated supported regions in OCI (Oracle Cloud Infrastructure) data centers and changed the fetching domain logic.

PRJ-62731,
PMTR-117699

Scalable Platforms

UPDATE: CPView now monitors the Quantum Maestro backplane interfaces, Sync, and Chassis Internal Network (CIN) interfaces.

PRJ-61404,
PMTR-112536

Scalable Platforms

UPDATE: Increased the maximum supported number of Uplink interfaces from 64 to 99 on Maestro Orchestrator MHO-175. It is now supported to configure Ports 17 - 30 as Uplink. Refer to the Quantum Maestro Getting Started Guide.

PRJ-63900,
ODU-3127

Automatic Updates - CPView

UPDATE: Added Take 50 of CPquid (QUID) Release Updates. Refer to sk181458.

PRJ-63518,
ODU-3040

Automatic Updates - CPView

UPDATE: Added Take 201 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.

PRJ-63522,

ODU-3064,

PRJ-63713,

ODU-3111

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 149 and Take 150 via self-updatable package. Refer to sk170314.

PRJ-63782,

ODU-3095

Automatic Updates - Policy Insights

UPDATE: Added Take 76 of Policy Insights Release Updates. Refer to sk183421.

PRJ-62244,
PMTR-116383

Security Management

In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit, creating a core dump file because of the incorrect license update.

PRJ-61899,

PRHF-40211

Security Management

After editing an Interoperable Device object, the number of changes of the current session presented in SmartConsole may be inaccurate.

PRJ-57302,
PRHF-35813

Security Management

In rare scenarios, the User Check policy is not updated during the Accelerated Policy installation.

PRJ-62665,
PRHF-41094

Security Management

When Global Domain Assignment removal fails with the "Global Domain Assignment failed: object XXX could not be deleted because it is referenced by other objects" error, only a partial list of the referencing objects is displayed in the error message.

PRJ-59982,
PRHF-38312

Security Management

When migrating a Security Management Server to a Multi-Domain Security Management Server more than once, the operation fails with the "got at least one duplicate UID in requested list" error.

PRJ-63200,
PMTR-118466

Security Management

In rare scenarios, the FWM process may not start automatically after an unexpected exit.

PRJ-63490,
MGMTTECH-516

Security Management

Security Management Server upgrade may fail when running out of memory.

PRJ-62638,
PRHF-40995

Security Management

After an IPS update, reassigning global policies may take a long time.

PRJ-61806,
PRHF-40186

Security Management

In rare scenarios, discarding an old session fails with an "An internal error has occurred" message.

PRJ-60214,
PRHF-38893

Multi-Domain Security Management

In rare cases, Security Gateway licenses are not displayed in SmartUpdate when connected at the Multi-Domain Security Management level, despite being visible at the Domain level.

PRJ-61169,
PMTR-107107

SmartProvisioning

When updating a VSX cluster configured as a Central Office Gateway through SmartProvisioning, the SmartProvisioning application displays "Server is disconnected. SmartProvisioning will be terminated" and crashes.

PRJ-63721,

SMBGWY-12611

SmartProvisioning

In the SmartProvisioning application, the hardware for 2530, 2550, 2560, 2570, 2580 Quantum Spark appliances is displayed as 1100 appliances instead of their actual hardware. This may lead to policy installation failures.

PRJ-58825,

PRHF-29330

CPView

In CPView, under Network > Traffic in Concurrent Connections table, the amount of non-TCP connections is higher than shown in the output of the "fw ctl pstat" and "fw tab -t connections -s" command. The issue is cosmetic only.

PRJ-60005,
PRHF-38733

Security Gateway

Policy installation may fail when an updatable object is processed incorrectly.

PRJ-57689,
PRHF-29290

Security Gateway

Intermittent drops of transmission packets for "Streaming Engine: TCP Invalid Retransmission" causing HTTP loading issues. Refer to sk181282.

PRJ-61859,
PRHF-40380

Security Gateway

When configuring NAT64 rules for specific targets, the rules may fail to apply. Return traffic may be dropped.

PRJ-62017,
PRHF-40483

Security Gateway

The RAD daemon may unexpectedly exit on VSX Gateways.

PRJ-59451,
PRHF-38172

Security Gateway

An application may fail to match correctly when URL Filtering is configured in Hold Mode.

PRJ-61437,
PRHF-39815

Security Gateway

In Maestro Dual Site in the VSX VSLS mode, although CoreXL Dynamic Balancing is enabled, CoreXL does not change the number of Firewall instances and SND instances during traffic load. Refer to sk183485.

PRJ-62563,
PRHF-41025

Security Gateway

ICAP Server may fail to process multipart HTTP requests (when request body is split into multiple parts, each with its own headers and content).

PRJ-62895,
PRHF-41242

Security Gateway

HTTP/2 connection may fail when Threat Prevention Software Blades are enabled with Deep Inspection because of a protocol error. Refer to sk183822.

PRJ-58194,
PRHF-37156

Threat Prevention

In some scenarios, the Anti-Virus Software Blade fails to parse and load external IoC observables of type IPv6. Refer to sk182947.

PRJ-63023,
PMTR-117719

Threat Prevention

In a rare scenario, the DLPU process may exit during traffic inspection when holding a connection.

PRJ-61619,
PRHF-40065

Threat Prevention

The testing of external IoC feed connectivity from SmartConsole fails because of improper retrieval of configuration values.

PRJ-60587,
PRHF-38756

Identity Awareness

Users on shared Servers (MUH v1 and v2) cannot access resources they should have permission to use. When this happens, the Security Gateway fails to recognize the user's identity and does not apply the correct access permissions. Refer to sk183268.

PRJ-60983,
PRHF-39261

Identity Awareness

Entra ID (Azure ID) authorization may fail when more than one tenant is configured for authorization and the "fetch-user-group"s or "fetch-machine-groups" mode is enabled.

PRJ-58059,
PRHF-36813

IPS

In rare scenarios, the source IP shown in the IPS detection log is invalid. Refer to sk182914.

PRJ-62812,
PRHF-41088

IPS

When using Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails.

PRJ-61303,
PRHF-39517

Anti-Virus

In a rare scenario, the memory consumption of the DLPU process continuously increases.

PRJ-63062,
PMTR-118347

Anti-Virus

In a rare scenario, the Security Gateway may crash during traffic inspection.

PRJ-63026,

PMTR-116661

Anti-Virus

In some scenarios, the Anti-Virus Software Blade reaches a timeout when inspecting Domains because of latency in the RAD daemon.

PRJ-62687,
PRHF-40994

ClusterXL

Modifying the number of CoreXL instances in a VSLS cluster containing three or more members causes traffic interruption on the updated Virtual System.

PRJ-60349,
PMTR-113063

ClusterXL

In cluster environments using Bonds and VLANs, the ClusterXL Monitoring command "cphaprob stat" (Expert Mode) and the Clish command "show cluster state" may display an incorrect failover reason when an interface disconnects or a link goes down.

PRJ-59745,
PRHF-38554

ClusterXL

In a ClusterXL setup, a rare performance issue may be caused by policy installation failure.

PRJ-61110,
PMTR-115083

ClusterXL

A rare race condition occurs during "cpstart" command execution in VSX environments that prevents proper sync interface installation, specifically in the cluster flow process, causing synchronization problems between cluster members.

PRJ-61740,
PMTR-115808

ClusterXL

An FWK core file is generated when configuring a Bridge Group with more than two interfaces.

PRJ-61583,
PMTR-115396

ClusterXL

6in4 tunnels are shown in Down state when monitored using the "cphaprob -a if" command.

PRJ-62302,

PMTR-115027

ClusterXL

In ClusterXL High Availability (HA), in some scenarios, the Active cluster member stops sending Cluster Control Protocol (CCP) heartbeats, and the Standby member may misinterpret this as an Interface Active Check (IAC) failure.

PRJ-62201,
PMTR-116890

SecureXL

SecureXL does not immediately send packets to the appropriate handler when it receives packets from a Virtual Router or Virtual Switch and fails to forward them to the connected Virtual System. This delay causes significant routing delays and potential routing errors on VSX Security Gateways.

PRJ-62395,
PMTR-117108

SecureXL

The Security Gateway can take a significant amount of time to boot up when SecureXL User Mode (UPPAK) is enabled.

PRJ-63054,
PMTR-118395

SecureXL

The link on the 4-Port 10/25GbE CX7 Lightspeed Network Interface Card may fail to establish when multiple 4-port CX7 Lightspeed Network Interface Cards are installed.

PRJ-60628,
PMTR-114633

SecureXL

Memory corruption may occur in rare VPN routing scenarios.

PRJ-60897,
PMTR-111305

SecureXL

When SecureXL User Mode (UPPAK) is enabled, there can be a significant latency on a Security Gateway when opening an FTP data connection.

PRJ-62888,
PRHF-40086

SecureXL

In cluster environments, on the Active member, the USIM_x86 process may experience frequent core dumps, causing Security Gateway instability.

PRJ-62576,
PMTR-109269

SecureXL

The USIM core file may be generated when rebooting the Security Gateway.

PRJ-62588,
PRHF-41038

CoreXL

In rare scenarios, CoreXL Firewall instances may become fully utilized because of resource contention from the Parallel Processing Engine (PPE). Refer to sk184183.

PRJ-62851,
PRHF-31534

Routing

In a specific scenario, where SSM static groups are configured on an interface, after a failover, these IP addresses do not appear as Outgoing Interfaces (OIFs).

PRJ-63118,
PRHF-41346

Routing

ASE LSAs for routes sharing the same prefix but having different mask lengths may not be re-originated correctly when a topology change restores previously unreachable routes to a reachable state.

PRJ-60970,

PMTR-117291

VPN

IKEv2 negotiation and Child SA re-keying processes may experience instability during Remote Access VPN connections.

PRJ-61918,
PRHF-40237,

PMTR-116423

VPN

In VSX environments with VS and VR configurations, when Policy-Based Routing (PBR) is configured on the Virtual Router, Remote Access VPN traffic bypasses the PBR table and uses the default route instead.

PRJ-62228,
PMTR-110683

VSX

The "vsx-provisioning-tool" CLI command returns asynchronous task IDs before it is ready for monitoring, causing Terraform and similar automation tools to immediately fail when attempting to track task status.

PRJ-63818

VSX

In a rare scenario, the FWM process may exit on the Security Management Server managing VSX Gateways/Clusters.

PRJ-63287

VSNext

After installing a Jumbo Hotfix Accumulator R82 Take 14 and higher, assigning an IPv6 address to the SMO interface fails.

PRJ-61593,
PRHF-40115

Gaia OS

  • The sysLocation OID (1.3.6.1.2.1.1.6.0) returns "UNKNOWN", even though the value is configured in the SNMP settings and exists in the Gaia database (/config/active).

  • When editing sysLocation or sysContact using the SNMP configuration interface, the Gaia database is updated, but the SNMP configuration file is not updated.

PRJ-62735,
PMTR-117714

Gaia OS

When using Resource Separation on MDPS on Maestro, and the Security Gateway is under extreme load, policy installation fails, although the Resource Separation should handle the load.

PRJ-62585,
PRHF-41027

Gaia OS

The Security Management Server hangs during a Backup operation because of endless SSH handshake retry, making it impossible to access via SSH or CLI.

PRJ-63279

Gaia OS

The "See more information in Gaia updates" link in CPUSE is broken.

PRJ-59688,
PRHF-38276

Gaia OS

HealthCheck Point (HCP) reports "rx_length_errors" for Security Group Members. Refer to sk183040.

PRJ-63584,

PRHF-41381

Gaia OS

SNMP query for "vsxStatusInterfaceRxBytes" and "vsxStatusInterfaceTxBytes" OIDs returns "0". Refer to sk183871.

PRJ-62997,

PRHF-41344

Gaia OS

The "show syslog logs" Clish command returns the "cat: /var/log/messages*: No such file or directory" error even though these files exist.

PRJ-61994,
PRHF-39856

CloudGuard Network

In rare scenarios, in a VSX Cluster running in VSLS Mode with Identity Sharing configuration, CloudGuard Controller may send identities to the VS IP address and not the Cluster IP address, causing Security Gateway update failures.

PRJ-62798,
PRHF-41139

CloudGuard Network

In the Smart-1 Cloud environment, in the Gateways & Servers view, newly provisioned CloudGuard Autoscaling Security Gateways may be shown as disconnected.

PRJ-63452,

PRHF-41488

SD-WAN

In rare scenarios, after an upgrade, installing an Access Control policy in an SD-WAN cluster environment causes the Standby member to transmit probes and may cause traffic disruption.

PRJ-61793,

SDWANGW-4359

SD-WAN

In rare scenarios, after an upgrade or "cpstop;cpstart", SD-WAN policy installation fails with "Error code: 2-4-2000279".

PRJ-58056,

PRHF-37015

Scalable Platforms

When handling multiple shared uplinks across numerous interfaces, errors related to LACP bond uplink updates may be printed in logs.

PRJ-59278,
PMTR-111692

Scalable Platforms

Gaia database lock on a Maestro Security Group configured with Management Aggregation (MAGG) is lost when using API or Gaia gClish to add a new Management interface to the Security Group. Refer to sk183031.

PRJ-58671,
PMTR-110323

Scalable Platforms

When the Maestro Fastforward feature is enabled, rebooting a member may cause the member to be down because of the policy installation failure and the "Site HA module not started" error may be displayed.

PRJ-59845,
PRHF-38430

Scalable Platforms

In a Security Group in VSX mode, if an interface's link state changes during boot, there may be a delay in updating the link state. This delay can cause traffic interruption on that interface.

PRJ-62409,
PMTR-117173

Scalable Platforms

Security Group members may reboot because of cp-nano database entries. The /var/log/configuration_reboot_reason.log may show "process:cp-nano-watchdog" when database entries exist only on the local member or only on the SMO member.

PRJ-62804,
PMTR-117683

Scalable Platforms

In Maestro Security Group or Scalable Chassis Security Group with VSX with many Virtual Systems (VSs), boot may take a long time when the database file (/config/active) is very large (200,000 lines or more).

PRJ-63208,
PMTR-118598

Scalable Platforms

During an upgrade process, a member gets stuck in the DOWN(TpPolicy) state although Threat Prevention is not configured in the environment.

PRJ-59791,
PMTR-105687

Scalable Platforms

On the Mobile Access Portal, SAML authentication does not display the login fields in a Maestro Security Group in the VSX. Refer to sk182548.

PRJ-59581,
PMTR-112587

Scalable Platforms

The minimum and maximum thresholds are incorrectly reported (the values are flipped) for PMIC-3 1V sensor readings in MHO-175.

PRJ-62759,
PMTR-117801

Scalable Platforms

Unnecessary reboots may be caused by differences in the database's scheduled backup entries (creation and update time) between the Security Group members.

PRJ-63448,
PRHF-23287

Scalable Platforms

After adding a custom command in Gaia gClish with the "add command", the custom command is available only on the Single Management Object (SMO). Refer to sk178671.

PRJ-58146,
PMTR-98993

Scalable Platforms

In ElasticXL, each Security Group Member allocates only 1785 ports for Hide NAT instead of approximately 16600 ports. Refer to sk183481.

PRJ-63944,

PMTR-119974

Scalable Platforms

Quantum Maestro Orchestrator Gaia Portal may become inaccessible after installing R82 Jumbo Hotfix Accumulator Take 41 or Take 43.

See the Critical Information section.

PRJ-58127,

PMTR-109620

Scalable Platforms

In rare scenarios, authentication between MHOs is not established. Trying to establish authentication manually fails with the "TrustEstablishmentError: Failed to set up communication user on host 1_1: invalid literal for int() with base 10" error.

PRJ-59939,
PRHF-38620

Carrier Security

Security Gateway drops GTP traffic with the log "Message includes unexpected information element type". Refer to sk106469.

Take 43

Released on 19 October 2025 and declared as Recommended on 29 October 2025

Take 43 - Improvements and Resolved Issues

 

PRJ-63625,
PMTR-119268

Logging

UPDATE: Resolved CVE-2025-2028. Lack of TLS validation when downloading a visualization support data file. Refer to sk183349.

PRJ-62739,

ODU-2594

Automatic Updates - Threat Prevention

UPDATE: Added Update 26 of Autonomous Threat Prevention Management integration Release. Refer to sk167109.

PRJ-63918,

PRHF-41964

Security Gateway

Certain User Space processes (for example, PDPD) become unresponsive when working in Firewall Kernel Space Mode. Refer to sk184028.

See the Critical Information section.

Take 41

Released on 03 September 2025

Take 41 - New Functionality

 

PRJ-62356

Security Management

NEW: Web SmartConsole now supports Quantum Spark Gateways and Security Gateways with a Dynamic IP Address (DAIP).

PRJ-60279,
PMTR-114156

Application Control

NEW: This Take introduces the Dynamic URL List feature is an enhancement to the Custom Applications / Sites object (sk165094), allowing to maintain a dynamic list of URLs based on a feed file.

Refer to R82 Security Management Administration Guide > Topic "Creating Application Control and URL Filtering Rules".

Take 41 - Improvements and Resolved Issues

 

PRJ-63329,

PRHF-41560

HTTPS Inspection,

VPN

UPDATE: Updated CRL and OCSP validation in Remote Access VPN, Site-to-Site VPN, and HTTPS Inspection to use HTTP/1.1 instead of HTTP/1.0. This ensures continued compatibility with DigiCert's updated requirements and prevents certificate validation failures. Refer to sk183884.

PRJ-63136,

PMTR-116712

Security Management

UPDATE: Added a new Clish command "cplic ignore_expired_ngtx 1" that allows administrators to disable license status monitoring for expired Next Generation Threat Extraction (NGTX) licenses in SmartConsole. Run the "cplic ignore_expired_ngtx 1" command on each Cluster Member or Virtual System that reports an error and restart with the "cpstop;cpstart" command.

PRJ-62387,
PMTR-117127

Security Management

UPDATE: Added a new API version (2.0.1). Refer to the Management API Reference.

PRJ-62454,
MGMTPROD-1952

Security Management

UPDATE: Added new Management API commands to configure synchronization with User Center: "show sync-with-user-center" and "set sync-with-user-center" which was previously only configurable through the SmartConsole GUI. Refer to sk94064.

PRJ-61286,
PRHF-39744

Security Management

UPDATE:  The upgrade duration for the Security Management Server and Multi-Domain Security Management Server has been reduced by up to 60%.

  • The fix will only be applied if the upgrade to R82 Jumbo Hotfix Accumulator Take 41 or higher is done using a Blink image or the Advanced Upgrade method.

PRJ-59285,
PRHF-38115

Security Management

UPDATE: JRE is updated from version 8.0_8.26 to version 8.0_8.35.

PRJ-62308,
PMTR-117039

Security Management

UPDATE: Added the "show-only-local-domain" field to API queries to return only objects from the current local Domain.

PRJ-61672,
PMTR-89079

Security Management

UPDATE: Improved the "fw tab" CLI command help by adding descriptive explanations for each option.

PRJ-62157,
PMTR-116839

Logging

UPDATE: Extended the "show logs" API to support Infinity Copilot queries in on-premises logs.

PRJ-61188,

FMW-3427

URL Filtering

UPDATE: URL Filtering provides now better categorization for non-inspected HTTPS connections by proactively re-validating certificates before the "Categorize-HTTPS" cache entry expires.

PRJ-61816,

PRHF-20323

VPN

UPDATE: Modified the default behavior of the legacy Policy Server daemon (DTPSD). By default, this daemon now starts in the "DOWN" state unless explicitly configured otherwise. Refer to sk183803.

PRJ-61642,
PMTR-115412

Gaia OS

UPDATE: In the Gaia Portal login, added support for the period character (".") in RADIUS and TACACS usernames. This feature is disabled by default. Refer to sk183201.

PRJ-62423,
VSECPC-10838

CloudGuard Network

UPDATE: Added support for GCP NSI (Google Cloud Platform Network Security Integration) solution.

PRJ-59472,
PMTR-109854

Scalable Platforms

UPDATE: Added option to use the local IP address 127.0.0.1 for license creation for Maestro Security Group members.

PRJ-61577,
HEC-1383

Scalable Platforms

UPDATE:

Added ElasticXL support for Virtual Machines with Virtual Machines. Refer to sk183513.

Additionally, in the Insights tool:

  • Added support for the Insights tool, which was previously only available on Scalable Platforms. Use the "insights --activate" command to activate the tool in non-scalable environments.

  • Added Virtualization table (a VSX feature) when running Insights from VS0.

  • The Performance widget is now also accessible with the "show cluster info performance" Clish command.

PRJ-62023,
PRHF-40184

Security Management

In SmartConsole, deleting a license in the Licenses tab of a Security Cluster object fails with the "Domain Management Server licenses cannot be removed from the Domain Management Server level" error.

PRJ-61293,
PRHF-39777

Security Management

The $MDS_FWDIR/log directory may contain multiple api_status_UUID.json files.

PRJ-61290,
PRHF-39256

Security Management

In rare scenarios, login to the Security Management Server may fail with timeout.

PRJ-58577,
PRHF-36096

Security Management

In some scenarios, the PostgreSQL database fully utilizes disk space on the Security Management Server.

PRJ-59085,
PRHF-37999

Security Management

Policy installation is delayed because of the FWM process load. Refer to sk183563.

PRJ-63369,

PRHF-41564

Security Management

Backup file size on the Security Management Server grows after an upgrade. Refer to sk183835.
See the Critical Information section.

PRJ-61322,
PRHF-39817

Security Management

Reassigning Global Policy takes a few hours after updating IPS Snort protections.

PRJ-59928,
PRHF-38237

Security Management

In some scenarios, the Changes Report is not attached to the email sent by the SmartTask configured with the "After Publish" trigger and the "Send Mail" action.

PRJ-62184,
PMTR-116869

Security Management

SAML authentication fails for Web SmartConsole on port 4434, redirecting to an invalid URL (https://localhost:4434:4434/smartconsole/transport) and preventing SSO login, while SmartConsole GUI authentication works normally.

PRJ-61669,
PRHF-39885

Security Management

In some scenarios, SmartConsole disconnects when installing policy if there are 50 installation targets or more.

PRJ-59666,
PRHF-37860

Security Management

Compliance scan finishes successfully but does not show any data in SmartConsole.

PRJ-62138,
PMTR-115488

Security Management

Running the Management API "show-object on access-role object" command may fail with "generic_server_error".

PRJ-59760,
PMTR-108985

Security Management

The Management API command "add-custom-ca-certificate" may fail with a "general error" if the administrator does not provide the Base64-certificate parameter.

PRJ-62230,
MGMTPROD-436

Security Management

When adding an application to an Access Control rule with service set to "None" and track set to "Log", the "set-access-rule" Management API command triggers an error: "You must enable the Granularity option 'Session' for the Track option 'Log' if the rule specifies an application or a Contact Type".

PRJ-57314,
PRHF-36228

Security Management

In some scenarios, the "where-used" Management API command with details-level set to "full" may fail with a "generic_internal_error" message, if the queried object is part of a Threat Prevention Exception Group.

PRJ-62093,
PRHF-40268

Security Management

In SmartConsole, when viewing the License tab of a Security Gateway object, multiple duplicated VSEC licenses with the same signature may be shown.

PRJ-62314,
PRHF-40748

Security Management

The FWM daemon may leak and then exit.

PRJ-60678,
PMTR-114726

Security Management

The "add-lsm-gateway" or "add-lsm-cluster" Management API commands may report success even when IKE certificate creation fails.

PRJ-61533,
PRHF-39869

Security Management

In the Compliance view, when clicking the picker in the "Source" or "Destination" columns while creating a custom Firewall Best Practice, the network objects list shows "Loading" and loads slowly.

PRJ-63105,
PMTR-118295

CPView

In a VSX environment, the CPVIEWD daemon may exit and produce a core dump file.

PRJ-59194,
PRHF-38042

Logging

When viewing certain reports in SmartView, the "No data found" error may appear even when matching logs exist.

PRJ-58762,
PRHF-37638

Security Gateway

Incorrect bonds may be shown in the Data Plane when using MDPS and running the "show configuration bonding" command.

PRJ-61352,
PMTR-115638

Security Gateway

In the CPView > Network > Templates > Accept-Templates, the concurrent templates may have a bogus value such as 18,466,744,073,709,551,585.

PRJ-60754,
PRHF-39368

Security Gateway

Non-HTTP connections may be incorrectly dropped because of a missing Host header when the Gateway operates as a proxy.

PRJ-61909,
PMTR-116366

Security Gateway

Missing cleanup when template connection creation fails prevents the system from exiting new connection context mode, causing subsequent connection operations to write incorrectly to the cache instead of the connection table.

PRJ-60900,
PRHF-39414

Security Gateway

Traffic is dropped with a"Matched Optimized Drop" message, although it is allowed by configurations in the Rule Base. Refer to sk183443.

PRJ-61425,
FMW-4633

Security Gateway

VSEC licenses may be automatically deleted and re-added on the Security Management Server (SmartCenter in Azure), creating duplicate license strings with mismatched signatures and causing intermittent "License with CK already exists" errors.

PRJ-59546,
PRHF-38154

Security Gateway

In some scenarios, the "Use of undefined constant session" warning is frequently printed in the SAML Portal's error_log file.

PRJ-61865,
PRHF-40249

Security Gateway

In rare scenarios, the WSDNS daemon may exit instead of shutting down gracefully.

PRJ-57282,
PRHF-36273

Security Gateway

The update_license_conf script incorrectly parses the allowed cores count, setting "ALLOWED_CORES=-1" and causing Check Point Virtual Machine system corruption and daemon failures when CPU increases.

PRJ-62107,
PRHF-40509

Security Gateway

The Clone Policy Package task in SmartConsole fails with the "The object name must not contain whitespace characters at the beginning or the end" error. Refer to sk161294.

PRJ-62462,
PRHF-27185

Security Gateway

Stability issues for Data connections (RDP / RTP / FTP/ETC). Refer to sk179651.

PRJ-62121,
PRHF-40597

Security Gateway

The SAML authentication flow may fail on a VSX Gateway.

PRJ-62418,
PRHF-31491

Security Gateway

Unexpected cluster flapping may occur during signature load.

PRJ-61012,
PRHF-39339

Security Gateway

After upgrading the Security Gateway to R81.20 Jumbo Hotfix Accumulator Take 92, Remote Access IPSec VPN connections using Endpoint Security VPN E88.60 fail. Authentication succeeds, but all client connections through the Security Gateway are dropped by the Cleanup Rule.

PRJ-61053,
PRHF-39655

Security Gateway

After a system restarts (for example, reboot or cprestart), FWD-related sub-processes such as VPND and PDP may not run. Refer to sk183446.

PRJ-60757,

PMTR-114362

Security Gateway

In rare scenarios, the local connection route may be incorrect when the ICAP client is active.

PRJ-62867

Security Gateway

In certain scenarios, the $SAMLPORTAL_HOME/logs/error_log file may continuously grow, potentially consuming a significant amount of disk space.

PRJ-57055,
PRHF-28783

Content Awareness

Disk space may not be cleared as expected when Content Awareness is the only enabled Software Blade.

PRJ-62792,
PMTR-115931

URL Filtering

The FW_FULL process may exit in the Dynamic URLs list update flow.

PRJ-62257,
PMTR-116639

URL Filtering

In rare scenarios, the FWK process may crash when the URL Filtering Software Blade is enabled.

PRJ-62443,
PRHF-40727

IPS

Security Gateway blocks the download of files larger than 4 GB with the log "Application Control - HTTP parsing error occurred" in SmartConsole. Refer to sk183681.

PRJ-60271,
PMTR-113602

DLP

A potential memory leak because of many DLP/FILE_CONVERT processes spawned.

PRJ-60840,

PRJ-60821

Anti-Virus

False threat alerts may appear in Anti-Virus logs for benign traffic (action: accept). This is a cosmetic issue with no security impact.

PRJ-57445,
PRHF-36348

ClusterXL

Virtual System in a VSX VSLS Cluster does not fail over when a cluster interface goes down. Refer to sk182734.

PRJ-62145,
PMTR-116446

SecureXL

After an upgrade, the USIM process may exit.

PRJ-62691,

PMTR-117113

SecureXL

When the Security Gateway runs in User Mode SecureXL (UPPAK), removing a VLAN impacts connectivity on other VLANs in Bridge mode that share the same physical interface.

PRJ-63052,

PRHF-41230

SecureXL

When there are a large number of SNDs operating with Intel NICs, the system could run low on available jumbo mbufs, leading to connectivity issues. Refer to sk183771.

See the Critical Information section.

PRJ-59180,
PRHF-37771

Routing

The multicast stream may not resolve correctly in VSX topologies. Packets are dropped with the "IP multicast routing failed (missing OS route)" message.

PRJ-59305,
PMTR-111436

VPN

IKE related core files may be generated when passing traffic through a VPN tunnel.

PRJ-60073,
AAD-5014

VPN

Rare VPN connectivity issues caused by Encryption Domain overrides in communities with third-party Gateways.

PRJ-61969,
PRHF-40481

VPN

The VPND or IKED daemon may exit during IKEv2 negotiation.

PRJ-62486,

PMTR-117252

VSX

In some scenarios, the FWM process exits during VSX provisioning, and the VSX Provisioning operation fails. Refer to sk184502.

PRJ-60693,
PMTR-114063

VSX

In rare scenarios in a VSX environment, after a Virtual System (VS) starts, it becomes stuck in Down state with a "FullSync" pnote.

PRJ-62379,

PMTR-117339

VSNext

The Security Gateway may crash when recreating a Virtual Gateway.

PRJ-61295,
HEC-1345

VSNext

In the VS0 context, physical resources per VS may not be visible when using the "cpview -m" command, although they are available in the CPView tool.

PRJ-59657,

PRHF-38449

Gaia OS

The 1.3.6.1.4.1.2620.1.6.7.5.1.5 SNMP OID (multiProcUsage) reports wrong values when HyperFlow is enabled.

PRJ-61756,
PMTR-115846

Gaia OS

Traffic routing may fail between the host and PPPoE / DNS Server through the Security Gateway, even though host-to-gateway and gateway-to-DNS connections work as expected.

PRJ-61814,
PRHF-40409

Gaia OS

SNMP Agent may report a wrong value for VLAN Interface Speed.

PRJ-62384,
PRHF-40893

Gaia OS

SNMP data types under the ASG MIB tree ( for Scalable Platform Security Groups) may be incorrect.

PRJ-62222,
PRHF-40517

CloudGuard Network

If the User Center connection fails, contracts may be retrieved incorrectly, resulting in erroneous contracts getting pushed to the Security Gateway.

PRJ-61980,
PRHF-40203

CloudGuard Network

Changes made to the JSON file of a Generic Data Center object may take a long time to appear in SmartConsole or Management API, although enforcement on the Security Gateway functions as expected.

PRJ-62129,
PMTR-116761

Scalable Platforms

In Gaia Portal, there is a hardcoded maximum limit of 32 firewall instances for CoreXL configuration, although the correct maximum should be based on the actual number of CPU cores available on the machine.

PRJ-59366,
HEC-1235

Scalable Platforms

Redundant logs from "Alerts Events" in the Insights tool. The issue is cosmetic only.

PRJ-59780,
PMTR-111817

Scalable Platforms

Policy installation may fail on newly added Security Group members because an updatable object package is missing.

PRJ-61345,
PRHF-39863

Scalable Platforms

The "asg diag verify" command reports inconsistent OSPFv3 routes for Security Gateway Modules on Quantum Maestro. Refer to sk179931.

PRJ-62519,
PMTR-117435

Scalable Platforms

The CPVIEWD daemon may exit on a VSX Gateway.

PRJ-62574,
PMTR-117483

Scalable Platforms

Security Group members changing from ACTIVE state to READY state may cause traffic impact.

PRJ-59056,
PRHF-37439

Carrier Security

The Security Gateway may crash after dropping corrupt GTP-C (control traffic) packets.

Take 39

Released on 27 August 2025 and declared as Recommended on 07 September 2025

Take 39 - Improvements and Resolved Issues

 

PRJ-62598,

PRHF-41141

Logging

In some scenarios, SmartConsole does not display logs from the Multi-Domain Log Server and Multi-Domain Log Modules after an upgrade to R82. Refer to sk183783.

See the Critical Information section.

PRJ-63299,

PRHF-41389

CloudGuard Network

The CloudGuard Network Central License utility fails to distribute the license, if there are duplicate entries of the license on the Security Management Server. Refer to sk183832.

See the Critical Information section.

Take 36

Released on 31 July 2025

Take 36 - New Functionality

 

PRJ-60966,
PMTR-90911

Security Management

NEW: In SmartConsole, the CSV export file of Access Control Policy NAT rules now contains the hit count data: "Hits", "First Hits" and "Last Hits" columns.

PRJ-60497,
PMTR-114492

Security Management

NEW: Added statistics for Top Matched Access Control Rules and Top Log Types in the Logs view of SmartConsole and in the response of the "show logs" Management API command. This allows to identify the rules that generate a high volume of logs.

PRJ-62732,

SMBGWY-12611

Security Management

NEW: Added support for the Quantum Spark 2500 appliances (2530, 2550, 2560, 2570, and 2580) in the EA (Early Availability) program.

Take 36 - Improvements and Resolved Issues

 

PRJ-60718,
PMTR-114504

Logging

UPDATE: Resolved CVE-2025-2028. Lack of TLS validation when downloading a visualization support data file. Refer to sk183349.

PRJ-59425,
PMTR-112077

Mobile Access

UPDATE: Resolved CVE-2024-52885. Mobile Access File Share applications are vulnerable to directory traversal attacks. Refer to sk183137.

PRJ-59537,
MGMTPROD-1385

Security Management

UPDATE: In SmartConsole and Management API, Access and NAT Policies now support Rule Base search for hitcount values.

PRJ-62283,
PMTR-114192

Security Management

UPDATE: Updated the "show asset" command output with the correct details for the X7 4-port card (CPAC-4-10/25F-DA model).

PRJ-61388,
PRHF-39859

Security Management

UPDATE: On Security Management Servers, environment variables set using the override_server_setting.sh script now apply to all processes. Refer to sk165938.

PRJ-60245,

PMTR-110297

Logging

UPDATE: Log Exporter is now delivered as an autoupdatable package, replacing the maintrain-based deployment. This approach shifts from version-based to component-level updates, enabling a more granular and agile update mechanism. Refer to sk182866.

PRJ-60790

Logging

UPDATE: In SmartConsole > Logs & Monitor > Logs, added information to the "Per Session" logs:

  • NAT fields

  • Dynamic object name

  • Updatable object name

  • Network feed object name

  • Destination Domain Name field

PRJ-59881,
PRHF-38023

Security Gateway

UPDATE: Improved processing of ICMP packets in the Security Gateway.

PRJ-61680

Security Gateway

UPDATE: Quantum Force 9400 and 9300 appliances with Standalone configuration now run in User Space Firewall (USFW) Mode by default.

PRJ-60047,
PMTR-110330

Security Gateway

UPDATE: Added an out-of-the-box package for updatable objects that is included with clean installations or Jumbo Accumulator Hotfix Takes (when no other package exists). If the out-of-the-box package is present during policy installation, an update is now initiated in addition to the automatic update.

PRJ-61470,
PMTR-116355

VPN

UPDATE: Added the "inclusions" feature to the Split Tunnel Remote Access functionality. Refer to the R82 Remote Access VPN Admin Guide > Dynamic Split Tunneling for SaaS Using Updatable Objects.

PRJ-61795,
PRHF-40060

Scalable Platforms

UPDATE: The "fwha_allow_different_corexl_instances" kernel parameter is now added to prevent cluster members from entering a Down state because of firewall instance count mismatches.

PRJ-60352,
PMTR-114300

Diagnostics

An FD (file descriptor) memory leak may occur when creating a new object in SmartConsole.

PRJ-60500,
PMTR-114274

Security Management

VPN certificate renewal may generate certificates with 2K key sizes instead of the 3K size specified in Global Properties.

PRJ-61469,
PMTR-109056

Security Management

The "Management rejected fetch for this module - version matching problem" error is displayed when running the "fw vsx fetch" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server. Refer to sk183298.

PRJ-61359,
PRHF-39806

Security Management

In some scenarios, a cluster object may not be listed in the "Uninstall Threat Prevention Policy" window.

PRJ-61318,
PRHF-39827

Security Management

Fetching branches from an LDAP Server fails with "Failed to connect to LDAP Server. Please ensure that the administrator's credentials are correct and try again" when the LDAP Server does not support anonymous bind (when a client connects to an LDAP server without providing any credentials). To enable the ability, refer to sk183461.

PRJ-61477,
PRHF-40016

Security Management

In rare scenarios, the CPRLIC process may exit with core files generated to the /var/log/dump/usermode/ directory on the Security Management Server.

PRJ-60470,
PRHF-38859

Security Management

Deleting a user that is used in a user group with more than 1000 users may cause SmartConsole to time out.

PRJ-60433,
PRHF-38563

Security Management

Virtual System routes and interfaces may not be synchronized to the Standby Security Management Servers.

PRJ-59100,
PRHF-33411

Security Management

In some scenarios, when exporting the Gateways and Servers View to CSV, the resulting file may contain an extra empty column. Refer to sk182233.

PRJ-60961,
PRHF-38808

Security Management

In rare scenarios, in multi-site Multi-Domain Security Management environments, operations across two or more Servers, such as Global Domain Assignment, IPS and Application Control update may fail.

PRJ-58352,
PRHF-37197

Security Management

In some scenarios, policy installation fails with the "/opt/<xxxxx>-R81.20/conf/Policy-name.pf" line N: ERROR: syntax error Error compiling IPv6 flavor. Operation ended with errors" error.

PRJ-60699,
PRHF-39297

Security Management

The Management API command "set simple-gateway name 'XXX' usercheck-portal-settings.enabled {false|true}" fails to properly enable or disable User Check for Security Gateway objects. When running this command, the change is not applied to the Security Gateway configuration, and the "Enable UserCheck for active blades" setting in SmartConsole remains unchanged.

PRJ-61043,
PRHF-39465

Security Management

In rare scenarios, accelerated policy installation fails to initialize, the full Access Control Policy installation is executed instead and it may take up to 20 minutes.

PRJ-56522,

PRHF-35230

Security Management

In rare scenarios, the first packet of a connection is incorrectly dropped when a non-FQDN object is used in the Rule Base.

PRJ-58202,
PRHF-34401

Security Management

The "vsx-run-operation" Management API command may fail on the Multi-Domain Security Management Server. Refer to sk182524.

PRJ-60762,
PRHF-39098

Security Management

In rare scenarios, after deleting Data Center objects:

  • Login to the Security Management Server may fail with timeout.

  • Publish operations may take a long time.

PRJ-57975,
PRHF-36695

Security Management

In some scenarios, the Postgres database on the Standby Security Management Server is growing after every High Availability synchronization. Refer to sk182868.

PRJ-61585,
PRHF-37905

Security Management

Access Control policy installation may take a long time when updatable objects are used in the policy.

PRJ-59370,
PMTR-110008

Security Management

The "show lsm-gateway" and "show lsm-gateways" Management API commands may return an empty "version" field.

PRJ-60013,
PMTR-114030

Security Management

In rare scenarios, policy installation may get stuck at 99%.

PRJ-59625,
PRHF-38414

Multi-Domain Security Management

In rare scenarios, Domain creation fails with "Failed to create Domain server '<Domain Server Name>'. The connected administrator has no permission to create a Domain-Server on the specified Domain".

PRJ-60660,
PMTR-114305

SmartProvisioning

In SmartProvisioning application:

  • Performing "push policy" on a Gaia LSM Cluster fails with the "local failure of CPRID" error.

  • The "Get Gateway Data" operation fails with "Execution error Error: Unspecified error".

  • The "cphaprob stat" command returns a core dump file.

PRJ-61987,

PMTR-116260

CPView

CPView history may be corrupted.

PRJ-61489,
PRHF-39983

Security Gateway

In a rare scenario, the FWK process may restart unexpectedly.

PRJ-60129,
PRHF-38666

Security Gateway

When the Mirror and Decrypt feature is enabled, the SKB memory leak may occur.

PRJ-60126,
PRHF-38574

Security Gateway

When Mirror and Decrypt features are enabled, the Security Gateway may experience unexpected reboots. The crashes are caused by "put_cred_rcu()" errors with negative usage values and memory leaks in the ARP cache.

PRJ-60949,

PRHF-39471

Security Gateway

In a rare scenario, the CPD daemon may exit on the Security Gateway.

PRJ-61309,

PMTR-115595,

HEC-371

Security Gateway

ElasticXL members communicating with the pivot cluster member may transition to DOWN state when synchronization between the pivot and other members is lost. Refer to sk183434.

PRJ-60579,
PRHF-38995

Security Gateway

In rare cases, failovers may occur because the FWK process unexpectedly exits.

PRJ-59157,
PRHF-37774

Security Gateway

Security Gateways with default MDPS task settings using proxy can fetch CPUSE updates and licenses successfully. On MPLANE updatable objects are not updated while everything works on DPLANE.

PRJ-61449,
PRHF-39840

Security Gateway

When handling interface statistics, the CPD or FWK processes may unexpectedly restart with an error related to IOCTL printed in logs. Refer to sk183544.

PRJ-60455,
PMTR-114419

Security Gateway

Enabling debugging in Quick UDP Internet Connections (QUIC) flows may cause an FWK process crash.

PRJ-62174,

PRJ-59649

Security Gateway

In rare scenarios, the FWK process may unexpectedly exit when stopping the Security Gateway using the "cpstop" command while a packet capture tool is running.

PRJ-60669,

PMTR-114653

Security Gateway

In rare scenarios, downloading large files over HTTPS may get stuck.

PRJ-60427,
PMTR-114342

Security Gateway

In rare scenarios, the FWK process may unexpectedly exit when the IPS Software Blade logs triggered protections.

PRJ-60539,
PRHF-38647

Security Gateway

In a rare scenario, after an upgrade, the Security Gateway may crash with a vmcore.

PRJ-59895,
PRHF-38438

Security Gateway

The VSX Security Gateway may crash when an external interface connected to the Virtual Router or Virtual Switch starts flapping.

PRJ-60446,
PRHF-38975

Security Gateway

RADIUS authentication fails when a response packet contains the Message-Authenticator attribute. Refer to sk183244.

PRJ-60216,
PRHF-34528

Threat Prevention

In some scenarios, external IoC feeds are not correctly fetched in VSX environments after a reboot.

PRJ-57978,
PRHF-36739

Threat Extraction

In a rare scenario, a script related to CPView may take a long time to execute and the SCRUBD process becomes unresponsive.

PRJ-58005,
PRHF-36322

Anti-Virus

In rare scenarios, Security Gateways with the Content Awareness Software Blade enabled may fail to properly process certain .zip file formats, resulting in "Failed to process files" errors during the Anti-Virus inspection.

PRJ-59857,
PRHF-38565

Anti-Virus

In some failure scenarios, the Anti-Virus Software Blade does not report the failure in a SmartConsole log.

PRJ-60663,

PMTR-114734

Anti-Bot

In rare scenarios, the RAD process may unexpectedly exit.

PRJ-60616,
PRHF-39184

Mobile Access

The Mobile Access Portal hosted on a Security Gateway R81.20 or lower becomes unresponsive, and CVPND core files are generated after the Security Management Server is upgraded to version R82.

PRJ-60700,
PMTR-108872

SSL Inspection

The "HTTPS Inspection Statistics" view in Demo Mode of SmartView in SmartConsole shows " No data found". The issue is cosmetic only.

PRJ-59766,
PRHF-38539

ClusterXL

If both bond subordinate interfaces are down, the output of "cphaprob show_bond bond" command is corrupted.

PRJ-60780,
PMTR-110618

ClusterXL

The ROUTED daemon may incorrectly initialize as Subordinate rather than Master after a "cpstop;cpstart" command when executed on the sole Active member in a cluster configuration.

PRJ-58336,
PRHF-36801

ClusterXL

A Multi-Version Cluster (MVC) member with VPN enabled may crash when performing an upgrade from R80.40.

PRJ-59213,
HEC-1195

ClusterXL

In High Availability Bridge Mode ClusterXL environments, the management interface of a Standby member becomes inaccessible. Refer to sk183124.

PRJ-57369,
PRHF-36165

ClusterXL

In VSX environments, deleting a Virtual System interface through SmartConsole fails to remove certain bindings, causing the interface to be automatically re-added.

PRJ-60378,
PMTR-114234

SecureXL

When printing the Deny list on a Security Gateway during Threat Prevention policy installation after deleting a large IoC feed from Security Management, an uninformative IOCTL error is displayed instead of a proper error message. The issue is cosmetic only.

PRJ-61467,
PMTR-111760

SecureXL

The USIM process to exit during error logging.

PRJ-60592,
PMTR-113834

SecureXL

In a rare scenario, no traffic is passed in the 6in4 tunnel and the two hosts cannot reach each other. The output for the "tcpdump" command in the tunnel shows "ip: unknown ip 0".

PRJ-61966,

PRJ-61915

SecureXL

The USIM process may crash during route updates when the Hardware Acceleration offloading connection is active.

PRJ-61021,
PMTR-115089

SecureXL

In rare scenarios, when SecureXL works in User Mode, running the "reset_gw" or "vsx_util reconfigure" commands may cause the Security Gateway to crash.

PRJ-59503,
PRHF-38095

ClusterXL

In rare scenarios, after enabling Bridge Mode, a cluster member may stuck in a boot loop.

PRJ-61182,
PRHF-39695

SecureXL

Multicast traffic is dropped when the Packet-Broker operates in Monitor Mode with Promiscuous Mode disabled.

PRJ-60722,
PMTR-114790

SecureXL

The Security Gateway may crash when connected to the Smart-1 Cloud Management Server and a maas_tunnel interface is repeatedly added and deleted.

PRJ-60999,

PMTR-115074

SecureXL

After MTU for Jumbo Frames is configured on a physical interface for the first time, until the Security Gateway is rebooted, there may be potential packet drops.

PRJ-59988,

PRHF-38501

Gaia OS

Multiple SNMP OIDs return incorrect data types. Refer to sk183166.

PRJ-62065,
PRHF-40577

Gaia OS

Stability issue on Quantum Force appliances 9300 and 9400. Refer to sk183438.

PRJ-58413,

PRHF-37416

Gaia OS

Exporting logs using the "backup -l" command may fail.

PRJ-58040,

PRHF-36803

Gaia OS

SNMP OID .1.3.6.1.4.1.2620.1.6.7.5.1.5.X falsely reports high CPU due to malformed calculation. Refer to sk182784.

PRJ-59922,
PRHF-38669

Gaia OS

In rare scenarios, users may be disconnected from SmartConsole, and an FWM process core dump is generated.

PRJ-60162,
PRHF-38736

Routing

The ROUTED daemon core dump file may be generated because of an assertion failure in the OSPF code.

PRJ-61331,
PMTR-115613

Routing

When working in User Mode (UPPAK), SecureXL may crash when multiple SND cores perform simultaneous next hop lookup for the same next hop.

PRJ-60813,
PMTR-114871

Routing

In a rare scenario, a Security Gateway crash and temporary loss of routing adjacency occur when the cluster messaging system attempts to process a deletion request for a BFD session that no longer exists.

PRJ-59742,
PRHF-37444

Routing

The ROUTED daemon may exit when processing OSPF network updates in a cluster environment. This occurs because of a timing issue in the routing protocol synchronization process.

PRJ-61214,
PMTR-115308

Routing

If BFD (Bidirectional Forwarding Detection) timing parameters, such as "min-rx-interval", are modified during an active BFD session deletion process, and a new BFD session is established before the deletion fully completes (deletion typically requires up to 2 hours), the newly created session inherits the previous timing configuration rather than applying the updated timing settings.

PRJ-60776,
PMTR-114870

Routing

In some scenarios, the ROUTED daemon may exit with a core dump file.

PRJ-60745,
PMTR-114835

Routing

In some scenarios, BGP routing updates may not be processed properly.

PRJ-62111,

PRHF-40540

Routing

A memory leak occurs in the ROUTED daemon when CoreXL is running OSPF and handling large numbers of LSAs combined with frequent route flaps.

PRJ-58688,
PMTR-110631

Gaia OS

NFS mount does not support hyphen "-".

PRJ-59137,
PMTR-110490

Gaia OS

When deleting a bond interface with slaves still attached while maintaining both Gaia Portaland SSH sessions, the deletion succeeds but generates "unregister_netdevice" syslog messages and terminates the Gaia Portal session. The issue occurs because local connections to the Gateway cause slow bond interface deletion, leading to Gaia Portal timeout.

PRJ-57175,
PRHF-36109

Gaia OS

In rare scenarios, when using IP Aliasing, deleting an interface by IP address reference may incorrectly delete the wrong IP address because of incorrect error handling.

PRJ-61371,
PMTR-115542

VPN

In rare scenarios, VPN traffic connectivity may be lost during policy installation.

PRJ-58955,
PMTR-111093

VPN

VPN connection may be unstable because of packet fragmentation issues.

PRJ-61225,
PRHF-39785

VPN

In a rare scenario, the FWK process may exit during VPN traffic decryption and routing when the PPPoE interface is enabled.

PRJ-58320,
PRHF-37066

VSX

Virtual Router advanced routes may be assigned incorrect priorities in policy-based routing configurations.

PRJ-58334,
PRHF-37228

VSX

The "fw stat" command output may not display the correct policy name for a Virtual System.

PRJ-58791,

PRHF-37719

VSX

The "vsx_util view_vs_conf" command output may show "N/A" for a Gateway when an object in the Domain shares the same name as the Virtual System object.

PRJ-57350,
PRHF-36278

VSX

A static route to 0.0.0.0, regardless of the subnet mask, is incorrectly treated as the default route (0.0.0.0/0) and does not appear in the VSX Gateway's routing table. Refer to sk182742.

PRJ-59033,

PMTR-111124,

HEC-953

VSNext

In a large scale VSNext environment, creating over 50 Virtual Systems (VSs) fails.

PRJ-60961,

PMTR-115016

SD-WAN

SD-WAN fails to obtain next hop address automatically from the DHCP Server.

PRJ-59427,

PRHF-38271

SD-WAN

SD-WAN policy installation may fail during the configuration of MDPS on the Security Gateway.

PRJ-60748,

PMTR-114442

SD-WAN

In rare scenarios, SD-WAN policy installation hangs indefinitely.

PRJ-58304,
PRHF-37070

Scalable Platforms

In a Maestro environment, migrating a Virtual System between Security Groups may cause a member to crash.

PRJ-56586,
PRHF-35421

Scalable Platforms

Connections with fragmented packets drop with the "Virt Defrag Timeout" error. Refer to sk182559.

PRJ-60448,
HEC-914

Scalable Platforms

After a reboot, IPv6 addresses configured on data interfaces disappear from the "ifconfig" output when the Same VMAC feature is enabled in SmartConsole.

PRJ-59499,
FMW-3594

Scalable Platforms

In rare scenarios, the connection between the Security Gateway (acting as a proxy) and the Security Management Server is not closed correctly.

PRJ-60672,
PRHF-38834

Scalable Platforms

Running "cpstop" on a specific Virtual System may cause traffic interruption in dual site deployments.

PRJ-61502,
PRHF-39967

Scalable Platforms

A cluster member may crash when performing a manual site failover and the deployment is using "Interface Active Check" with IPv6 enabled.

PRJ-60052,

PRHF-38689

Scalable Platforms

One member in a Maestro Security Group may be reported as down and inaccessible, the /var/log/messages and fwk.elg logs indicate:

  • "State change: ACTIVE -> DOWN | Reason: VSX PNOTE due to problem in Virtual System X",

  • "used greatest stack depth: 9544 bytes left",

  • Errors related to unknown/invalid parameters and kernel policy copy failures.

Take 34

Released on 23 July 2025 and declared as Recommended on 27 July 2025

Take 34 - Improvements and Resolved Issues

 

PRJ-62606,

PRJ-62595,

PMTR-117551

Routing

DHCP broadcast packets are not visible on the intended VLAN when working in SecureXL User Mode (UPPAK). Refer to sk183675.

PRJ-62608,

PRHF-41064

CloudGuard Network

After an upgrade to R82 Jumbo Hotfix Accumulator Take 25, CloudGuard Network for AWS Gateway may crash with a vmcore. Collecting the CPInfo statistics also triggers a crash with a reboot.

Take 33

Released on 08 July 2025 and declared as Recommended on 16 July 2025

Take 33 - Improvements and Resolved Issues

 

PRJ-62112,

PMTR-116903

VSNext

In a VSNext setup, Virtual Gateways (except VS0) cannot establish SIC connectivity with the Security Management Server.

See the Critical Information section.

PRJ-62374,

PRHF-40338

Scalable Platforms

The CPD process may exit during policy installation on a Scalable Platforms cluster on Quantum Force 29000 appliances.

PRJ-59589,

PMTR-114423

Scalable Platforms

R81.20 / R81.10 / R81 Security Gateways, Cluster Members, and Scalable Platform Security Groups may fail to fetch the Threat Prevention policy from their R82 Security Management Server / Multi-Domain Security Management Server. See sk183602.

Take 25

Released on 15 June 2025

Take 25 - New Functionality

 

PRJ-59495

Hardware

NEW: Added support for Quantum Smart-1 700-S, 700-M, 7000-L, 7000-XL, 7000-UL. Refer to sk182601.

PRJ-57860,

PMTR-112034

SD-WAN

NEW: SD-WAN functionality now supports AWS Cross Availability Zone and traffic steering with configurable multi-target probing.

PRJ-58894,
PRHF-31058

SSL Inspection

NEW: This Take introduces a fail-open mechanism for HTTPS Inspection with Hardware Security Module (HSM) integration. If the HSM becomes unavailable, TLS connections now automatically bypass HTTPS Inspection, ensuring continuous network connectivity.

Take 25 - Improvements and Resolved Issues

PRJ-59936,
PMTR-113250

Gaia OS

UPDATE: A patch on top of OpenSSL 1.1.1w to fix CVE-2024-13176. Refer to sk183168.

PRJ-60772,

HEC-868,

PMTR-114867

Diagnostics

UPDATE: Added the ability to monitor the CPU cores that run CoreXL SND (Secure Network Dispatcher) instances separately from the CPU cores that run CoreXL Firewall instances. The monitoring of CPU cores handling CoreXL SND instances was improved. It is possible now to:

  • view the exact number of CPU cores running SND instances that are under load, instead of seeing it as a percentage of total CPU cores.

  • configure the load threshold for CPU cores running CoreXL SND instances.

  • configure the load duration for SND CPU cores.

When these parameters are configured, the load on SND CPUs triggers a failover at a different time and under different load conditions compared to Firewall CPUs. Refer to the R82 ClusterXL Administration Guide > Advanced Features and Procedures > ClusterXL Failover based on the Load on ClusterXL SND Instances.

PRJ-59727,
PMTR-112995

Security Management

UPDATE: Added the "Type" and "Resource" columns to the HTTPS Inspection Logs table under Logs & Events.

PRJ-58951,
PMTR-110805

Security Management

UPDATE: Management upgrade performance is improved by up to 15%.

  • The fix will only be applied if the Management Server upgrade is performed using either the Blink image of the current Jumbo Hotfix Accumulator Take or the Advanced Upgrade method (where the current Jumbo Hotfix Accumulator Take is installed on the target Management Server).

PRJ-57995,
PMTR-112672

Security Management

UPDATE: Added support for using Network Groups in the "Install On" column of the NAT Policy. Refer to sk176846.

PRJ-60049,
FMW-4284

CPView

UPDATE: CPView and SNMP can now show Hide NAT statistics for up to 200 top NAT IP Pools (the default is 3 top NAT IP Pools). Configure the required value for the kernel parameter "fwx_alloc_top_pools_num" with the CLI command "fw ctl set -f int fwx_alloc_top_pools_num <integer from 1 to 200>".

PRJ-60364,
PMTR-108410

Logging

UPDATE: Added a count of Session and Connection logs to the "cpstat" command output.

PRJ-58669,

PMTR-110592

Security Gateway

UPDATE: Added multi-interface packet fragment reassembly support to prevent drops in Equal Cost Multipath (ECMP) environments.

PRJ-58552,
FMW-2292,

PMTR-110440

Security Gateway

UPDATE: Support TLS 1.3 for the RAD process requests. To activate it, change the TLS version to "TLSv1_3". Refer to sk178505.

PRJ-57079,
PRHF-35181

Security Gateway

UPDATE: RAD extended flow information is now logged into a cyclic CSV file - $FWDIR/log/rad_events/rad_flows.csv. This enhancement provides visibility into RAD connections, helping to monitoring and troubleshooting. Refer to sk183108.

PRJ-58815,
PRHF-37100

Security Gateway

UPDATE: Added a kernel parameter "domo_reverse_lookup_disabled" to disable reverse DNS lookups to avoid rare incorrect matches in scenarios involving non-Fully Qualified Domain Name (non-FQDN) Domains.

  • "domo_reverse_lookup_disabled 1" to disable reverse DNS lookups.

  • "domo_reverse_lookup_disabled 0" to enable reverse DNS lookups (the default value).

Refer to sk120633.

PRJ-57317,

PMTR-108735

Threat Prevention

UPDATE: Improved Threat Prevention Software Blades performance by 15%-25% on Quantum Force 9000, 19000 and 29000 appliances.

PRJ-54144,
PRHF-31274

SSL Inspection

UPDATE: HTTPS Inspection statistics are now available through SNMP requests.

PRJ-59774,
PMTR-113092

SSL Inspection

UPDATE: In SmartConsole, added a new section "Application/Site" to the HTTPS Inspect log details. It provides details on resource and categorization matching.

PRJ-58754,
PRHF-36873

Mobile Access

UPDATE: Added support for the Mobile Access Portal "WebSocket" applications to work in environments with asymmetric network bandwidth (the download speed is faster than the upload speed) between external and internal networks. Refer to sk95311.

PRJ-60000,
PMTR-111169

ClusterXL

UPDATE: SecureXL User Mode (UPPAK) is now blocked in Active-Active cluster configurations, as this combination is not supported.

PRJ-58673,

SDWANM-2809

SD-WAN

UPDATE: Added selection of specific Security Gateways to onboard to the Infinity Portal, and the ability to disable the feature completely. Refer to sk180557.

PRJ-57542,
PMTR-110262

VSX

UPDATE: Implemented a validation in Clish to restrict virtual switch (VSW) configuration to a single interface, preventing setup disruption.

PRJ-59233,

PMTR-111643

VSNext

UPDATE: In the Clish API, added the comprehensive VSNext task monitoring capabilities, previously available only in the Gaia Portal.

PRJ-59274,

HEC-915

VSNext

UPDATE: The "add-virtual-gateway" Management API is updated: added the option to not connect the new VS to the virtual switch.

PRJ-60148,

PMTR-113933

VSNext

UPDATE: Rather than using the management switch, it is now possible to choose a different management interface for each virtual system (VS).

PRJ-59121,
PMTR-110666

VSNext

UPDATE: Improved debuggability for the "cpstart" command in a large scale VSNext environments.

PRJ-57224,

PMTR-110740

CloudGuard Network

UPDATE: Traffic between an external network host and an internal network host is now accelerated when a static NAT is configured to translate a cluster member's IP address or specific high port to an internal host IP address or specific service port. This scenario is relevant in Check Point CloudGuard Network Security Azure High Availability deployments, where traffic passes through a Load Balancer.

  • To enable acceleration, add this kernel parameter to the $FWDIR/boot/modules/fwkern.conf file - "accel_dnat_to_cluster=1".

  • The change can also be applied immediately to the running FW1 process without requiring a reboot: "fw ctl set int accel_dnat_to_cluster 1".

PRJ-57795,
PMTR-109576

CloudGuard Network

UPDATE: CloudGuard Network for AWS Gateway Load Balancer Auto Scaling Group now supports inspection of IPv6 traffic encapsulated with GENEVE IPv4 headers.

PRJ-56783,

PRHF-35847

Diagnostics

In SmartConsole, in the Gateways & Servers view, under Device & License Information of a Security Gateway or Cluster object, or in CPView and SNMP traps, the value of "new connection rate" for OID .1.3.6.1.4.1.2620.1.1.26.11.6.0 is incorrect.

PRJ-58243,
PMTR-110065

Diagnostics

After rebooting a Multi-Domain Security Management Server, the CPView (sk101878) and Skyline (sk178566) tools do not return data (for example, when running the "cpview -m", "cpview -t", "cpview -s" commands).

PRJ-58851,
PRHF-37388

Security Management

In rare scenarios, a core file of the CPRLIC process is generated.

PRJ-56974,
PRHF-36032

Security Management

Using the "set simple-cluster" command without the "members.add" option to add cluster members may result in recreating existing cluster members and potential loss of SIC.

PRJ-60696,

PRHF-39191,

PMTR-114757

Security Management

Login using a TACACS Server created with the "add tacacs-server" Management API command, fails with "authentication to server failed".

PRJ-59097,

PRHF-37788

Security Management

Management Server operations may be slow because of some API commands, and multiple core dumps may be generated.

PRJ-58472,
PRHF-37430

Security Management

Creating a Threat Prevention Exception from a log fails with the "Failed to add exception" error when the "File Name" field in the log contains a Windows directory separator ("\").

PRJ-58718,
PRHF-37561

Security Management

Changes to a SmartConsole administrator's Authentication Server (RADIUS or TACACS) may occasionally fail to take effect.

PRJ-57818,
PMTR-107227

Security Management

In some scenarios, Web SmartConsole session gets disconnected after several minutes.

PRJ-58448,
PRHF-37393

Security Management

In rare scenarios, Revert to Database Revision is stuck at 10%.

PRJ-57397,
PRHF-36340

Security Management

In rare scenarios, when more than one Security Blade is enabled on the Security Gateway, Presets for policy installation may fail after purging all revisions.

PRJ-59308,
PRHF-38068

Security Management

In some scenarios, the "Log Servers" tab in the Logs and Events view of SmartConsole is not visible. Refer to sk183154.

PRJ-59059,
PRHF-37185

Security Management

When using SmartWorkflow on a Security Management Server with more than 200 administrators, requests may stall or cause SmartConsole crashes during submission.

PRJ-57721,
PRHF-36549

Security Management

Inserting the "\n" character in the name of a rule fails with an unclear error message not indicating the cause of the failure.

PRJ-59023,
PRHF-37832

Security Management

Access Control Policy installation may take a long time when updatable objects are used in the policy.

PRJ-58524,
PRHF-37446

Security Management

In rare scenarios, login to SmartConsole may fail with the timeout.

PRJ-58341,
PRHF-37251

Security Management

In rare scenarios, login to SmartConsole using LDAP, TACACS or RADIUS authentication fails with a timeout.

PRJ-58901,
PRHF-37631

Security Management

After an IPS update, reassigning global policies may take a long time.

PRJ-58574,
PRHF-37436

Security Management

Global Policy Reassignment fails with the "org.postgresql.util.PSQLException: ERROR: more than one row returned by a subquery used as an expression" error printed in the cpm.elg file.

PRJ-57917

Security Management

In rare scenarios, the CPD process may unexpectedly exit and create a core dump file. Refer to sk182787.

PRJ-58920,
PRHF-37819

Security Management

In rare scenarios, policy installation fails with "Policy installation had failed due to an internal error".

PRJ-57630,
PRHF-36614

Security Management

In rare scenarios, Infinity Portal shows the "Failed to update Infinity Portal with objects from your on-premises Management Server. Contact Check Point Support" error.

PRJ-57323,
PRHF-36147

Security Management

When modifying the URL definition type in an Application Site object using the "set application-site" Management API command with the "urls-defined-as-regular-expression" parameter, the type of pre-existing URLs remains unchanged.

PRJ-58503,
PRHF-37445

Security Management

Renaming a Secondary Security Management Server that was promoted to Primary fails.

PRJ-58527,
PRHF-37141

Security Management

In some scenarios, policy state directories are synchronized between Active and Standby Security Management Servers, leading to high disk space usage.

PRJ-58917,

PRHF-37822

Security Management

Policy Installation may not be accelerated after modifying a host in a rule with the inline layer action.

PRJ-58686,

PMTR-110626

Security Management

Duplicated licenses on the Security Management Server may impact the vsec_lic_cli utility.

PRJ-59700,
PRHF-38273

Security Management

The Compliance Software Blade incorrectly reports Gaia Best Practices as insecure for cluster members.

PRJ-59433,
PRHF-38264

Security Management

In some scenarios, opening a specific VPN community in SmartConsole fails and the "Unable to load page" message is printed, while other communities can be opened.

PRJ-59600,
PRHF-38330

Security Management

In rare scenarios, Global Policy Assignment fails with an "IPS update is currently running in local domain" message, although IPS update is not running in that Domain.

PRJ-57307,
PRHF-36241

Security Management

If a custom login message exceeds 1000 characters, the login output file, which contains the sid and other session data, cannot be parsed as expected. Using the "mgmt_cli" with the "-s" parameter results in the "Failed to parse login output file" error.

PRJ-57139,

PRHF-36149

Security Management

In some scenarios, the Security Management Server with a proxy configured is unable to connect to Infinity Portal after changing the proxy settings.

PRJ-59341,
PMTR-111778

Security Management

When a Security Gateway object is deleted, its license may still appear as attached even though the Security Gateway Object no longer exists.

PRJ-58606,
PRHF-34898

Security Management

Packet mode search or search within Object Explorer for IP address ranges may not work correctly on the Standby Security Management Server.

PRJ-59631,
PRHF-38384

Security Management

In a rare scenario, December date comments in the IPS User Settings view may display incorrect year.

PRJ-60151,
PRHF-38525

Security Management

In some scenarios, Virtual Security Gateways lose their licenses. This causes Site to Site VPN and Remote Access VPN services to go down, while general internet access remains functional. SmartUpdate may not load.

PRJ-57440,
PRHF-23903

Multi-Domain Security Management

In a Multi-Domain Security Management environment, RADIUS authentication may be sent with an incorrect IP address. Refer to sk180723.

PRJ-58777,
PRHF-37360

Multi-Domain Security Management

In a Multi-Domain Security Management environment, an audit log is not created after changing the "Parent rule for Domain's policy" Domain layer.

PRJ-58847,
PRHF-34721

Multi-Domain Security Management

In a Multi-Domain Security Management environment with a VSX Gateway, such operations as login to SmartConsole, Global Domain Assignment, Domain creation or deletion may take longer than expected or fail with a timeout message "Task failed".

PRJ-58969,
PRHF-37258

Multi-Domain Security Management

In rare scenarios, the "mdsstat" command shows that the CPD process is down even though it is up and running.

PRJ-58874,
PRHF-37752

Multi-Domain Security Management

In certain scenarios, when Cluster objects are used in a Multi-Domain Security Management Server with Domains that have Global Domain Assignments, an upgrade may fail with "Tried to persist object OBJ_ID with domain 1e294ce0-367a-11e3-aa6e-0800200c9a66 while active domain is DOMAIN_ID".

  • The fix will only be applied if the upgrade to this Jumbo Hotfix Take is done using a Blink image or with the Advanced Upgrade method.

PRJ-56977,
PRHF-35998

Multi-Domain Security Management

In some scenarios, in the Multi-Domain Security Management Server, certain previously utilized global objects may remain hidden from both the SmartConsole's Object Explorer View and the "show unused-objects" Management API command.

PRJ-59215,
PRHF-38104

Multi-Domain Security Management

Policy installation fails on all Domains on the Multi-Domain Security Management Server with "Layer '<LAYER NAME>': Verification failed due to an internal error" if an Externally Managed Security Gateway object with IPsec enabled does not have an encryption Domain. Refer to sk183003.

PRJ-58981,
PRHF-37890

Multi-Domain Security Management

In some scenarios, the "SIC Error for EntitlementManager: Peer sent wrong DN" error is printed in cpd.elg on a VSX Gateway.

PRJ-60322,

PMTR-114256

Multi-Domain Security Management

Multiple errors "T_get_event: cannot register socket %d (%d sockets already registered for %s)" are printed in $MDSDIR/log/ in.msd.

PRJ-59767,
PMTR-112934

Compliance

In rare scenarios, the "Blades" widget in the Compliance Software Blade Overview page is blank.

PRJ-58260,

PMTR-110658

CPView

Interfaces with VLAN are not visible in CPView stats.

PRJ-59348,
PMTR-111094

Logging

In the cloud environments (Smart-1 Cloud and EPMaaS), logs query may fail because of the AWS certificate change.

PRJ-59591,
PRJ-59592

Logging

When opening a log card in the Logs View, duplicate values may appear in the "Resource" and "Reason" fields.

PRJ-60574,
PMTR-106428

Logging

When disconnecting the Security Management Server from the Infinity Portal and connecting to a different region, log sharing from Log Servers does not work until the Log Server restarts.

PRJ-57787,
PMTR-100187

Security Gateway

The "fileapp_parser_get_attribs: call orig_get_attrib failed" error is printed in the $FWDIR/log/fwk.elg file.

PRJ-57256,
PRHF-25598

Security Gateway

When a NAT-T tunnel is set up between VPN peers, packets having UDP encapsulation added to the headers are not transmitted out of the PPPoE interface as they should be. VPN connection appears to be established but does not actually pass traffic.

PRJ-57513,
PRHF-32506

Security Gateway

VoIP H.323 calls are dropped with reason "Handler 'h323_h245_code' reject". Refer to sk182835.

PRJ-59131,
PRHF-38022

Security Gateway

The DHCPv6 relay drops reply messages from the DHCPv6 server rather than forwarding them to the clients.

PRJ-58744,
PRHF-37487

Security Gateway

In a rare scenario, when the Anti-Virus Software Blade and the ICAP Server are enabled, there may be high CPU usage.

PRJ-60804,

PRHF-38473

Security Gateway

The FWK process exits with core dumps and error messages in $FWDIR/log/fwk.elg:"malware_res_rep_match_dns_response: check_dns_response_activate() failed".

PRJ-57740,

PRHF-36496

Security Gateway

Local connections originating from the Security Gateway may fail to refresh their timeout values.

PRJ-60290,

PRHF-38919

Security Gateway

Memory handling issue, causing the FWK process to unexpectedly restart.

PRJ-60286,

PRHF-38898

Security Gateway

In rare scenarios, HTTPS inspection may block the downloading and uploading of PDF files to and from the Web Server.

PRJ-59786,

PRHF-38340

Security Gateway

The FWK process may unexpectedly restart when running the memory detection leak procedure.

PRJ-59607,

PRHF-38380

Security Gateway

In a specific scenario, file downloads intermittently stop until resumed manually because of HTTP parsing issues and Content Awareness parsing failures.

PRJ-58628,

PRHF-36742

Security Gateway

In a Maestro environment with configured Virtual System Load Sharing (VSLS) Mode, one of the Security Gateways on an SGM may be unresponsive until it is restarted several times.

PRJ-58390,

PRHF-36744

Security Gateway

The DSD process (Dynamic Split Daemon) may exit when the "affinity" command input is large.

PRJ-61165,

PRHF-39691

Security Gateway

A rare issue in HTTP/2 multiplexing may lead to traffic disruption. Refer to sk183441.

PRJ-56438,
PRHF-35363,

PRJ-58861,
PMTR-110741,

PRJ-59203,

PRHF-37975

Security Gateway

In a rare scenario, the FWK process may unexpectedly exit and bring down the Security Gateway.

PRJ-58393,
PRHF-36652

Security Gateway

In some scenarios, a memory leak may occur in the FWK process.

PRJ-60946,

PRHF-39464,

PRJ-61452,

PRHF-39847

Security Gateway

  • The CPD or FWK process may unexpectedly restart when handling the interface statistics.

  • The CPVIEW_SERVICES, RAD, SNMPD and VPN processes may exit with a core dump file because of memory corruption.
    Refer to sk183544.

PRJ-59353,
PRHF-37361

Security Gateway

In a rare scenario, an outage may occur in an Azure environment after one cluster member crashes and recovers.

PRJ-58217,
PRHF-37208

Security Gateway

A rare race condition may cause a Security Gateway to restart when updating the statistics.

PRJ-59114,
PRHF-37640

Security Gateway

Some Access Control Rule Base flows may increase CPU utilization .

PRJ-57932,
PRHF-36685

Security Gateway

In rare scenarios, Security Gateway may crash when running the "ethtool -x" or the "ethtool -X" command for an interface that uses the AWS ENA network driver.

PRJ-59816,
PRHF-38598

Security Gateway

In rare scenarios, the CPD process may unexpectedly exit, generating a core dump.

PRJ-59151,
PRHF-37843

Security Gateway

After enabling Security Zones in NAT Rule Base, wrong IP address is shown in logs and NAT is performed incorrectly. Refer to sk183088.

PRJ-59619,
PMTR-111544

Security Gateway

In a rare scenario, if the USIM process exits during firewall memory mapping, it can result in a Security Gateway crash.

PRJ-58631,
PRHF-36749

Security Gateway

In a rare scenario, the FWK process may exit because of memory corruption.

PRJ-60412,

PRHF-39061

Security Gateway

Policy installation fails with the error message: "All the rules in layer "<Name of Layer>" contain only expired time objects. See sk155253 for more details".

PRJ-58445,
PMTR-109929

Security Gateway

In a rare scenario, Security Gateway may crash with vmcore when working in Kernel Mode Firewall (KMFW).

PRJ-59119,
PMTR-110235

Security Gateway

In a rare scenario, the RAD daemon may exit during large memory allocation operations.

PRJ-57676,
PRHF-36647

Security Gateway

A stability issue where the ICAP Server may unexpectedly restart when processing traffic from a Security Gateway with Threat Emulation enabled.

PRJ-60536,
PRHF-38638

Security Gateway

In some scenarios, in a cluster environment, when URL Filtering is enabled, there may be traffic disruption.

PRJ-60203,
PRHF-38844

Security Gateway

In a rare scenario, VoIP Traffic fails after the initial call when SecureXL operates in User Mode (UPPAK). Refer to sk183218.

PRJ-60530,
PRHF-38547

Security Gateway

In a rare scenario, the Security Gateway may crash during email inspection.

PRJ-60548,
PRHF-38708

Security Gateway

Incorrect memory handling may cause the FWK process to unexpectedly exit.

PRJ-56340,
PRHF-35382

Internal CA

In some scenarios, a VPN outage may occur after an ICA renewal.

PRJ-57869,
AAD-2659

Threat Prevention

In rare scenarios, SSH connections may be dropped when SSH Deep Packet Inspection (SSH DPI) is activated on the Security Gateway.

PRJ-59994,
PRHF-33276

Threat Emulation

In rare scenarios, the Threat Emulation Software Blade may fail to correctly classify the file type.

PRJ-61767,

PMTR-116315

Threat Extraction

The Threat Extraction Software Blade may inadvertently delete some system files on the Security Gateway. Refer to sk183512.

PRJ-61981

Threat Extraction

A memory leak can occur in the Threat Extraction file inspection process for HTTP/S protocols. When memory consumption reaches the maximum allowed allocation, it causes the process to crash and automatically restart.

PRJ-60243,

PRHF-38820

Identity Awareness

PDP to PEP Identity synchronization may fail on the PDP side if an alternative IP address for PEP communication is configured, as described in sk60701.

PRJ-59252,
PMTR-111703

Identity Awareness

In a rare scenario, the PDPD process may unexpectedly exit during a cluster failover.

PRJ-57645,
PRHF-36542

Identity Awareness

In a rare scenario, when fetch_by_SID is enabled, the PDPD process repeatedly exits. Refer to sk182745.

PRJ-58460,
PRHF-37149

Application Control

HTTP traffic dropped by PSL because of missing Host header. Refer to sk183569.

PRJ-59611,
PRHF-38383

Application Control

If the Access Rule Base does not contain Extended/Detailed Log Tracking options, category override functionality fails when the "partial load" feature is enabled.

PRJ-59617,
PRHF-38387

Application Control

Some custom applications in the HTTPS Inspection policy are not matched if they are part of a Group object. Refer to sk183176.

PRJ-57182,

PRHF-36126

URL Filtering

URL Filtering may not classify a site in a specific rare scenario when the Security Gateway is configured as a proxy.

PRJ-58757,
PRHF-37462

URL Filtering

In some scenarios, when URL Filtering Software Blade analyzes web requests, the RAD error may appear in /var/log/messages: "rad_kernel_urlf_request_serialize: string len =XXXX bigger than max 4096".

PRJ-56476,
PRHF-35174

IPS

In some scenarios, a Security Gateway is not listed as an option for the Threat Prevention uninstall, even though the Threat Prevention Software Blade is disabled on the Security Gateway object.

PRJ-60940,
PRHF-38863

IPS

The FWK process may unexpectedly exit during HTTPS inspection flow which requires the RAD service categorization.

PRJ-56517,
PRHF-35504

DLP

DLP policies may not correctly block password-protected and unprotected files during Google Drive uploads, despite the Content Awareness Software Blade configuration.

PRJ-59500,
PRHF-30036

Anti-Virus

When Anti-Virus is enabled, files are not downloaded with the "Failed writing the file" error printed in logs, and the block page is not displayed.

PRJ-58656,

PRHF-37376

Anti-Virus

RAD queries fail, generating "wrong status code in reply" errors logged in $FWDIR/log/rad_events/Error/* files. Refer to sk183009.

PRJ-60011,

PMTR-113461

Anti-Bot

In some scenarios, the Anti-Bot Software Blade fails to parse external IoC feeds with IP address observables.

PRJ-58841,

PMTR-105936

Anti-Bot

When the Security Gateway with FIPS mode is enabled, running the Anti-Virus and Anti-Bot Software Blades updates with the "fw update -b AB -b AV -f" command fails.

PRJ-59224,

PRHF-38081

Anti-Bot

In some scenarios, a SmartConsole log with the Anti-Bot Software Blade entries may appear when the Anti-Bot Software Blade is disabled in the profile.

PRJ-58804,
AAD-3331,

PMTR-110853

SSL Inspection

The "Detect" logs for Client's TLS alerts are not aligned with the Server's TLS alerts logs. This is a cosmetic issue.

PRJ-57461,
PMTR-109067,

PRJ-58871,
PMTR-110943

SSL Inspection

When a TLS connection is rejected because of no shared key exchange between the client and the Security Gateway, no log is generated to inform the administrator.

PRJ-59777,

PMTR-113097

SSL Inspection

The "HTTPS Inspection Rule ID" and "HTTPS Inspection Rule Name" fields are seen in the "Bypass Under Load" and "Learning Mode" bypasses logs although they should not be printed.

PRJ-60106,
PRHF-38755

Mobile Access

The HTTPD process periodically exits when accessing the Mobile Access Software Blade Citrix application because of the memory leak in the Citrix proxy implementation.

PRJ-60391,
PMTR-114281

ClusterXL

The CPHAPROB process may exit with a core dump file.

PRJ-60533,
PRHF-38566,

PRJ-60545,
PRHF-38704

ClusterXL

In ClusterXL High Availability setup, a crash may occur on both the primary and secondary members, causing network outages.

PRJ-59391,
PMTR-110959

ClusterXL

Running the "cphaprob -a if <interface name>" command in the VSX Cluster may cause the FWK process to exit.

PRJ-59874,

PRJ-59583

ClusterXL

The FWK process may exit after enabling or disabling the "Same VMAC" feature. Refer to sk165674.

PRJ-60293,

PRHF-38847

ClusterXL

A race condition may occur during startup when the ROUTED daemon does not receive all cluster Virtual IP addresses, causing static routes to disappear.

PRJ-59565,
PMTR-112079

ClusterXL

ClusterXL drops traffic that is sent to its IPv6 Virtual IP Address that is configured with the Unicast Link-Local scope (/64). Refer to sk183104.

PRJ-58081,
PMTR-68784

SecureXL

Packet drops may occur if the same multicast packet is received on multiple interfaces.

PRJ-57037,
PRHF-32840

SecureXL

High volumes of RST packets may cause CPU spikes, resulting in incoming network packet drops on SND instances.

PRJ-60686,

PRHF-39209

SecureXL

The packets may not be accelerated because of a routing issue.

PRJ-60568,

PMTR-113304

SecureXL

In a rare scenario, the Security Gateway may become unresponsive during extended high memory utilization.

PRJ-60256,

PMTR-113688

SecureXL

SecureXL in User Mode (UPPAK) may restart when the Security Gateway is under high load and cpWatchDog triggers a reboot.

PRJ-60606,

PMTR-114373

SecureXL

The Hardware Acceleration offloaded connection may break when the route is updated, affecting the offload flow and slowing down operations.

PRJ-60070,
PMTR-111505

SecureXL

Running the "tcpdump" command on all interfaces (for example, "tcpdump -peni any") on machines with SecureXL in User Mode (UPPAK) while under heavy traffic load may cause the system to hang. Refer to sk183222.

PRJ-59363,
PMTR-111468

SecureXL

When SecureXL works in User Mode (UPPAK), in a VSX environment with many virtual systems, the Gaia Portal may not be accessible when it reaches its internal connection limit.

PRJ-60310,

PMTR-114110

SecureXL

The USIM_x86 process may potentially exit because of a race condition when a route is simultaneously used by multiple SND cores.

PRJ-59969,

PMTR-113266

SecureXL

A warning message "adp_rt4_delete: rt entry .... does not exist for slot 1" may be printed in the /var/log/dmesg file while VPN connection remains active.

PRJ-60257,

PMTR-113479

SecureXL

In some scenarios, the Security Gateway may crash while running "cpstop" or disabling MDPS when SecureXL works in User Mode (UPPAK).

PRJ-61217,

PRHF-39512

SecureXL

The Security Gateway with SecureXL in User Mode (UPPAK) may crash under load during bond interface state flapping.

PRJ-61107,

PMTR-108077

SecureXL

SecureXL in User Mode (UPPAK) may be incorrectly enabled or disabled during runtime or Jumbo Hotfix Accumulator installation.

PRJ-59017,
PMTR-111199

SecureXL

Memory allocation issue when handling Jumbo Frames.

PRJ-60384,
PRHF-38461,

PRJ-60394,
PRHF-39028

SecureXL

In an asymmetric UDP traffic scenario (Client-to-Site VPN and Site to Site VPN distributed to different members), the connection may not get accelerated.

PRJ-61025,

PRJ-61004

SecureXL

SecureXL in User Mode (UPPAK) may restart when adding or removing VLAN interfaces and the Security Gateway is under high load.

PRJ-60056,
PRHF-38747

SecureXL

After a VSX reboot, other Virtual Systems (VS's) enter a Down/Lost state while USIM core files are generated.

PRJ-60238,

PRHF-37606

Routing

In rare cases, when an internal BGP (iBGP) peer disconnects during a graceful restart, BGP may fail to advertise all routes. However, the missing routes still appear under "adj-rib-out" with a next hop of "0.0.0.0."

PRJ-58788,
PRHF-37697

Routing

Duplicate entries in the kernel routing table can occur when iBGP peers disconnect and reconnect, causing the same routes to be added multiple times rather than properly replaced.

PRJ-60690,
PMTR-114670

Routing

When obtaining a new IP address using the "dhclient -r" command turning off and on the interface configured as Dynamic Address IP (DAIP), the interface loses its IP address and fails to acquire a new one from the DHCP Server.

PRJ-59245,
ROUT-3336

Routing

The ROUTED daemon asserts when enabling eBGP multihop on a directly connected interface.

PRJ-58782,
ROUT-3107

Routing

The ROUTED daemon may exit with a core dump file during IBGP synchronization.

PRJ-60101,

HAAN-880

Routing

BGP sessions may terminate upon receiving a BGP Update containing an AS_SET Path Attribute when Peer Local AS was configured on the Security Gateway.

PRJ-57627,
PMTR-109855

VPN

When a network connection is established simultaneously in both directions (server-to-client and client-to-server), the Security Gateway experiences connectivity issues because of incorrect packet dispatching, leading to dropped packets. Refer to sk183072.

PRJ-60613,
PMTR-114453

VPN

After establishing a successful VPN connection from IKEv2 Client to VS with traffic flowing, the Client disconnects repeatedly with "VPN tunnel has disconnected: Failed to renew IP address" then reconnects with a new Office Mode IP address.

PRJ-61823,

PRHF-40371

VPN

After an upgrade, Site to Site VPN tunnels (IKEv2) fail to establish. Logs show the "Auth exchange: Sending notification to peer: Invalid syntax" and "INVALID_KE_PAYLOAD" errors for IKE traffic. Refer to sk183550.

PRJ-57842,

PMTR-110144

VSNext

In VSX/VSNext environments with 50 or more VS's, CPView VSX statistics is blocked until re-enabled manually.

PRJ-58292,

PMTR-110132

VSNext

In VSNext environments, CPView VSX Data shows only VS0.

PRJ-58599,

PMTR-110482

VSNext

VSNext configuration is not included in the output of the "show configuration" command in Clish.

PRJ-57418,

PMTR-110875

VSNext

Virtual Switches with names larger than 128 characters cannot be deleted, the "Virtual System with ID2 does not exist" error is displayed.

PRJ-59014,

HEC-926

VSNext

VS creation request may fail because the timeout was too short

PRJ-57478,

PMTR-109849

VSNext

Occasional failures during simultaneous creation of multiple Virtual Systems (VS's), where identical IDs are assigned to more than one VS.

PRJ-59015,

HEC-1032

VSNext

Some Management API requests may not be sent when creating many VS's in parallel.

PRJ-61129,

PMTR-116039

VSNext

VSNext Virtual Gateway drops traffic when it is connected to a Virtual Switch. This issue affects systems running NGTP software blades. Refer to sk183460.

PRJ-57672,

PMTR-109851

VSNext

Creating multiple Virtual Gateways may fail with the "Setting management connection failed!" message.

PRJ-59171,
PRHF-37466

VSX

A memory leak may occur in a VSX environment, related to the transmitting packets module.

PRJ-58249,
PRHF-37106

VSX

SNMP counters may return incorrect data on VSX.

PRJ-59035,
PRHF-27999

VSX

In a VSX environment, the Security Gateway may crash when removing an interface from topology.

PRJ-57746,
PRHF-36734

VSX

In a rare scenario, during the VSX Gateway Wizard, SmartConsole disconnects with the warning "The connection with the server was lost. Any unsaved changes will be preserved". And SmartConsole may crash with the "SmartConsole has experienced a serious problem and must close immediately" error.

PRJ-57294,

PRHF-36254

VSX

Output of the "dynamic_split -p" command shows "Dynamic Split is currently off (Stopped due to State Verification failure)" on a VSX Gateway. Refer to sk181231.

PRJ-61046,

HEC-1463

VSX

After enabling CoreXL instances on a Virtual System, the policy status may be displayed as "N/A".

PRJ-58803,
PRHF-37713

Gaia OS

When attempting to create cloning groups on an R82 Security Gateway, the "Error - Home directory for 'cadmin' cannot be in /home/cadmin directory" error is printed. Refer to sk182989.

PRJ-58700,
PRHF-37362

Gaia OS

In a Maestro environment with RADIUS users, accessing the Gaia Portal for MHO causes an "ERR_EMPTY_RESPONSE" error and may cause the Gaia Portal not to respond.

PRJ-59012,
PRHF-37820

Gaia OS

In a Maestro environment, an error message about short string length may be incorrectly displayed when setting an expert password string that includes the colon ":" character on the Security Gateway.

PRJ-61662,

ODU-2714

Gaia OS

The Redis Server does not start after installing the Gaia API Build 299. Refer to sk143612.

PRJ-59293,
PRHF-27173

VoIP

High volumes of VoIP/ SIP traffic may trigger a Security Gateway crash.

PRJ-60460,

PMTR-114441,

VSECPC-10081

CloudGuard Network

The CloudGuard Network Central License utility incorrectly distributes licenses to Azure Virtual vWAN Gateways that already have licenses included during deployment.

PRJ-59475,

SDWANGW-2360,

PMTR-112190

SD-WAN

Dynamic IP address changes for DAIP Gateway objects are not propagated to all Security Gateways in the SD-WAN VPN community, causing VPN connectivity failures.

PRJ-59849,
HEC-951

Scalable Platforms

The logging_worker daemon may consume a lot of memory per Virtual System.

PRJ-58555,
PMTR-110252

Scalable Platforms

On ElasticXL platform, there may be unnecessary or unsuccessful attempts to update the distribution of traffic among the cluster members.

PRJ-59846,
HEC-952,

PMTR-112869,

PMTR-112683

Scalable Platforms

In VSNext mode, Virtual Systems there may be high CPU consumption.

PRJ-60318,
HEC-1289

Scalable Platforms

In the VSNext mode (on ElasticXL and Maestro Security Groups), the Gaia gClish / Gaia Clish command "show interface" in the context of Virtual Switches fails with "CLINFR0699 Invalid command".

PRJ-58961,
PRJ-57191

Scalable Platforms

Import an R82 upgrade package may fail with "[ERROR] Failed to transfer package to several members, Import was aborted" because of timeout which occurs while copying the package to all Security Group members.

PRJ-59061,
PMTR-106842

Scalable Platforms

Changing the bond mode on Scalable Platform Security Group members may cause a MAC address mismatch on the bond interface because of the bond slaves reordering that does not match the database. Refer to sk182488.

PRJ-58041,
HEC-983

Scalable Platforms

The "fw fetch local" command fails on a Virtual System without SIC established because the SIC name is missing.

PRJ-57813,
PRHF-29470

Scalable Platforms

DNS configuration may not be pulled to other Security Gateway Members (SGMs) from the Single Management Object (SMO).

PRJ-59359,
PRJ-58161

Scalable Platforms

IP broadcast helper cannot forward the packets if the IP address of the "relay to" is not directly connected to the Security Gateway.

PRJ-59395,
PMTR-111927

Scalable Platforms

Maestro may not properly respond to Router Solicitation messages with the expected Router Advertisement messages.

PRJ-58600,
PMTR-110500

Scalable Platforms

In some scenarios, the perfanalyze scripts output shows duplicates in cores data, this can cause the CPD process to crash.

PRJ-59168,

FMW-3410

Scalable Platforms

The "ws_mux_host_only_active_pass: ERROR: There is not enough data in stream to pass" error may be printed in logs. This is a cosmetic issue.

PRJ-59670,
PMTR-110155

Scalable Platforms

When running the license deletion command "g_cplic del <license signature to delete>" in a Maestro setup, the license is removed from the cp.license file but not from cp.license.smo, causing the deleted license to unexpectedly reappear after a policy installation.

PRJ-58088,
PRHF-36586

Scalable Platforms

Configured proxy ARP may not work as expected, when the "Same VMAC" feature is enabled.

PRJ-60476,

PMTR-110389

Scalable Platforms

The "asg_dr_verifier" script fails when OSPF Graceful Restart is configured with a grace period.

PRJ-59877,

PMTR-113194

Scalable Platforms

A reboot loop with a generated configuration pnote may be triggered when Security Group hostname contains strings with "mq" or "otlp".

PRJ-58489,
PMTR-109895

Scalable Platforms

Upon contract renewal, non-SMO members in the Maestro Security Group may not get the updated contract automatically.

  • The fix requires this Jumbo Hotfix Accumulator Take to be installed on all the members of the group.

Take 19

Released on 29 May 2025 and declared as Recommended on 04 June 2025

Take 19 - New Functionality

 

PRJ-61143

Security Management

NEW: Added ability for R82 Security Management Server and Multi-Domain Security Management Server to manage Quantum Force 3900 Appliances.

Take 18

Released on 14 May 2025

Take 18 - Improvements and Resolved Issues

 

PRJ-61176,

PRJ-58517

Logging

In some scenarios, in Log Servers or Multi-Domain Log Servers (MDLS):

  • The SOLR process consumes high CPU.

  • There is a delay in displaying logs in the Logs view.

Take 14

Released on 20 April 2025

Take 14 - New Functionality

 

PRJ-56952,
PRJ-56616

SD-WAN

NEW: In SD-WAN, added support for:

  • Traffic steering based on Differentiated Services Code Point (DSCP).

  • Rule based NAT per ISP.

PRJ-56409,
PRJ-53464

SD-WAN

NEW:

  • Added ARP Next-Hop prober to enhance support for additional network topologies.

  • Introduced HTTP prober to reflect real-time Web Access metrics.

  • Implemented Link Aggregation mode proportional to Download and Upload bandwidth.

  • Administrators are now able to override SD-WAN interface Circuit configuration.

  • Integrated Forward Error Correction to ensure successful traffic delivery by adding error correction code packets to the Overlay packet stream.

  • Introduced Dynamic Objects (SD-WAN Internet, My VPN Domain, and Peer VPN Domain) to better represent Overlay and Internet address spaces.

  • Added administrator control for Symmetric Packet Return, forcing Ingress Traffic to be replied on the same ISP.

  • Enabled SD-WAN Overlay establishment across different Domains using Global VPN Community (MDS).

  • Allowed SD-WAN Overlay to operate on top of Route-based VPN.

  • Increased maximum Overlay size to support up to 500 Security Gateways.

  • Improved accuracy of SD-WAN decision-making during policy installation.

  • Enabled setup of IPv4 SD-WAN overlay when non-SD-WAN IPv6 interfaces are configured.

PRJ-57083,
AAD-1761

VPN

NEW: Local SCV settings can be customized by Security Gateway when creating a $FWDIR/conf/local.scv_<GW NAME> file, otherwise the settings fall back to the standard local.scv configuration.

Take 14 - Improvements and Resolved Issues

PRJ-58376,

PMTR-110261

Mobile Access

UPDATE: Resolved CVE-2024-52887 - Self-XSS vulnerability in Mobile Access Native Applications 'favorites' dialog. Refer to sk183054.

PRJ-58382,

PMTR-110274

Mobile Access

UPDATE: Resolved CVE-2024-52888 - Mobile Access File Share applications are vulnerable to stored XSS attacks. Refer to sk183055.

PRJ-56536,
PRHF-34745

Security Management

UPDATE: The Management API logs outbound payloads to api.elg only for non-"200" response codes. It is now possible to enable the "WRITE_FULL_OUT_PAYLOAD" environment variable to force comprehensive logging of all API call payloads, regardless of the response status. Refer to sk182786.

PRJ-58728,

PMTR-110883

Security Management

UPDATE: The Global Domain automatic purge settings now automatically restore and reschedule after a Security Management Server restart.

PRJ-57848,
PMTR-109621

Logging

UPDATE: Enhanced the CLI "cp_log_export" command with additional examples and expanded help documentation.

PRJ-56569,
PRHF-32539

Security Gateway

UPDATE: Reduced memory usage of LDAP keepalives and improved connection error handling, resulting in improved system reliability and security performance.

PRJ-56706,
PRHF-34380

Security Gateway

UPDATE: Added information about VSX context to the mem.report files in /var/log/CP_mem_dwarf/.

PRJ-58468,
ROUT-3004

Routing

UPDATE: Added a new Gaia Clish parameter to ignore the Autonomous System (AS) Path when aggregating routes: "set aggregate <IP Address>/<IP Mask> aspath-ignore {on | off}". Note, enabling "aspath-ignore" will disable "aspath-truncate" if configured.

PRJ-58466,
PRHF-33825

Routing

UPDATE: IP Reachability Detection now supports simultaneous BFD and ping monitoring to the same remote address, where previously only one method was functional at a time. When both are configured, each monitoring protocol operates independently, allowing features to track their preferred detection method while maintaining existing configuration syntax.

PRJ-58738,
ACCHA-3835

SecureXL

UPDATE: Optimized memory management when processing Jumbo Frames.

PRJ-58795,

PMTR-110837

VSNext

UPDATE: All interfaces are now automatically assigned to VS0 (the default virtual system) with no instance bind, and can be moved between Virtual Systems without requiring unassigning, enabling immediate VSNext functionality.

PRJ-57735,
PMTR-109486

Scalable Platforms

UPDATE: In ElasticXL, restoring Gaia OS backup is now supported.

PRJ-58348,
PMTR-110224

Scalable Platforms

UPDATE: VSLS Mode is now supported in VSNext ElasticXL environments.

PRJ-57616,

PMTR-109197

Scalable Platforms

In VSNext ElasticXL Load Sharing environments, traffic latency and interface flapping may occur between two members in the Virtual Switch (VSW), when the switch is configured on non-management interfaces and both members are on the same site.

PRJ-57907,
PRHF-36295

Security Management

In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit, creating a core dump file.

PRJ-58942

Security Management

In SmartConsole, in the Quantum Spark Cluster object, editing the interfaces (manually or with the "Get Interfaces" action) fails with an unclear error message "Failed to save object".

PRJ-57658,
PRHF-36501

Security Management

In some scenarios, High Availability synchronization fails with "NGM failed to export data" because of invalid Global Domain Assignments.

PRJ-58274,
PRHF-37209

Security Management

In rare scenarios:

  • Login to the Security Management Server may fail with timeout.

  • Publish operations may take a long time.

PRJ-58222,
PMTR-110042

Security Management

In SmartConsole, when exporting Access Policy data to a CSV file, the hit count values may be displayed incorrectly in the exported file.

PRJ-57541,
PRHF-33773

Security Management

Scheduled Snapshot Issues:

  • Gaia may not recognize the Remote Server as a known host during scheduled backup creation, even after following sk164234 instructions.

  • The "Remote server identity is not known by Gaia" error is displayed despite proper HBA configuration.

  • The "set snapshot-scheduled recurrence monthly" command fails when using the "all" option.

Refer to sk182665.

PRJ-57782,
PRHF-36576

Security Management

In rare scenarios, publishing Multi-Domain Security Management level changes such as Administrator configuration changes fails. The "Action Failed due to an Internal Error" error is displayed.

PRJ-60340,

PRHF-38803

Security Management

In some scenarios, SmartTasks triggered by "after submit", "approve" and "reject" events fail to run.

PRJ-57069,
PRHF-36058

Security Management

After an upgrade, when browsing to SmartConsole > Manage & Settings > Permissions & Administrator > Administrators, the page may display "Error retrieving results".

PRJ-57036,
PRHF-35374

Security Management

In some scenarios, deleting a Security Gateway object fails if the Security Gateway is a participant in the Global VPN Community.

PRJ-57539,
PRHF-36475

Security Management

In some scenarios, the "show packages" Management API command with "details-level full", fails with "Null Pointer exception: null".

PRJ-59028,
PMTR-111209

Security Management

In the "Gateways and Servers" tab, when opening a shell on a specific Security Gateway, a "Connection failed" message pops up.

PRJ-59038,
PRHF-37790

Security Management

SmartConsole "Validations" panel shows "'statusDescription' can not include html tags". Refer to sk183075.

PRJ-58696,
PMTR-110640

Security Management

Performing changes to the Global Properties may not be possible if:

  • Encryption algorithms in Remote Access > VPN-Authentication and encryption are SHA384 or SHA512.

  • There is at least one Security Gateway configured with a version lower than R81.

PRJ-58030,
PRHF-36922

Multi-Domain Security Management

In rare scenarios, in Multi-Domain Security Management environments, domain creation fails with "Failed to create Domain server "Domain name" Permission calculation failed."

PRJ-57982,
PRHF-36890

Multi-Domain Security Management

In rare scenarios, an upgrade of Multi-Domain Security Management Server, handling Domain Log Server certificates, may get stuck.

  • The fix will only be applied if the upgrade to R82 Jumbo Hotfix Accumulator Take 14 or higher is done using a Blink image or the Advanced Upgrade method.

PRJ-57785,
PRHF-36479

Multi-Domain Security Management

In environments where not all Domains are Active on the same Server (for example, in a multi-site environment), and there is no Domain Management Server for a specific Domain, logs from that Domain are not forwarded to the Infinity Portal.

PRJ-57829,
PRHF-36779

Security Gateway

In some scenarios, an HTTP format size protection exception is not applied to the HTTP/2 flow.

PRJ-56815,
PRHF-29467

Security Gateway

GTP-U traffic may be dropped because of incorrect message type handling.

PRJ-58091,
PMTR-109845

Security Gateway

When the autodebug feature is enabled, the RAD service may consume high CPU and trigger "RAD service not available" alert logs.

PRJ-58271,
PRHF-36963

Security Gateway

Security Gateway with QoS enabled may crash because of a rare race condition.

PRJ-58206,
PRHF-36513

Security Gateway

Incorrect Rule Base parameters synchronization logic may lead to the FWK process exit.

PRJ-57962,
PRHF-36794

Security Gateway

In the HTTP/2 connection scenario, the tenant restriction header injection mechanism encountered an issue affecting the connectivity.

PRJ-58768,
PMTR-111974

Security Gateway

High CPU usage on SND cores related to processing network traffic and distributing it to the appropriate firewall instances.

PRJ-58152,
PRHF-37032

Security Gateway

In a rare scenario, the FWK process may exit when HTTPS Inspection is enabled and TLS connections are inspected on non-standard ports (ports other than 443 or 8080).

PRJ-56740,
FMW-795

Security Gateway

Large NAT Rule Base may lead to high CPU usage during packet processing.

PRJ-58420,
PRHF-37014

Security Gateway

Android devices' HTTP HEAD requests to Google services are blocked by Security Gateway proxy, generating excessive logs that impact Security Gateway performance through high CPU usage. Refer to sk182990.

PRJ-58902,

PRJ-58903,

PMTR-110909

Security Gateway

The FWK process may exit with a core dump file when the Security Gateway passes SMB traffic and the Hyperflow feature is enabled.

PRJ-59119,

PMTR-110235

Security Gateway

In a rare scenario, the RAD daemon may crash during large memory allocation operations.

PRJ-58407,
PRHF-32698

Security Gateway

PPPoE interface fails to restart when it is disconnected from the Server side. Refer to sk182154.

PRJ-56404,
PRHF-35372

Internal CA

The "cpca_dbutil print" command may delete the provided output file content if the input file does not exist.

PRJ-58131,
PRHF-36964

Identity Awareness

In a rare scenario, the PDPD process may unexpectedly exit during the PDP sharing flow.

PRJ-58441,
PRHF-37240

Identity Awareness

In some scenarios, SAML authentication fails with "Error 500".

PRJ-58191,
PMTR-108416

Application Control

HTTPS Site Categorization fails to properly handle unsupported QUIC protocol versions, causing classification errors instead of following the configured fail-mode (open/close) policy.

PRJ-59452,

PMTR-112600

IPS

In rare scenarios, a memory leak in the FWK process may occur when IPS is active.

PRJ-57969,
PRHF-36711

DLP

The DLP Software Blade may not block the password-protected files of a specific type, although it should.

PRJ-58170,
PRHF-37164

Anti-Virus

In a specific scenario involving a long-lived SMTP connection, the memory usage allocated by the Anti-Virus Software Blade steadily increases over time.

PRJ-57690,
PMTR-109185

SSL Inspection

HTTPS inspection session logs lack detailed explanations in the "explanation" field, displaying generic messages that do not clarify action reasons. This is a cosmetic issue.

PRJ-58073,
PRHF-33345

Mobile Access

The debug output file for Mobile Access, named "exchangeRegistration_portal_error_log" is increasing in size.

PRJ-59491,

PMTR-111453

ClusterXL

During cluster startup with routing separation enabled, a mismatch between routing and firewall process initialization can trigger premature full synchronization pnotes when the routing process is not fully synchronized.

PRJ-59725,

HEC-336

ClusterXL

ElasticXL may fail to pass IPv6 traffic when the internal mechanism assigns the Server-to-Client response traffic to a different Cluster Member than the Cluster Member that processed the Client-to-Server request traffic.

PRJ-58173,
ACCHA-3774,

PRJ-58174,

ACCHA-3821

SecureXL

SD-WAN may not work as expected when SecureXL User Space Mode (UPPAK) is enabled.

PRJ-60467,

PMTR-114455

SecureXL

In some scenarios, a memory leak occurs in the FWK process when SecureXL fails to update an existing route's next hop.

PRJ-60160,

PRHF-38880

SecureXL

Routing related connectivity and stability issues may occur when SecureXL operates in User Mode (UPPAK). Refer to sk183181.

PRJ-58276,
PMTR-110096

SecureXL

SecureXL User Mode crashes if an acceleration card interface has an MTU above 9000 and receives frames larger than 9234 bytes.

PRJ-57991,
PRHF-36805

Routing

The "iphelper" (IP Broadcast Helper) service may trigger high CPU utilization because of a recursive packet broadcasting loop between network interfaces.

PRJ-57987,
ROUT-3189

Routing

Static routes may get permanently deleted from the kernel during rapid interface configuration changes when there is a large number of routes.

PRJ-59288,

PMTR-111756

Routing

Network traffic to the Internet experiences slowdowns and file download interruptions due to packets being dropped with "OS routing failed" errors during route lookup failures.

PRJ-58001,
PRHF-36849

VPN

Capsule VPN connectivity failures may occur after a configuration change of the VPND daemon table parameters.

PRJ-58061,
PRHF-33418

VPN

Two or more Endpoint Security VPN (Remote Access VPN) Users may get the same Office Mode IP address. Refer to sk182537.

PRJ-57797,
PMTR-108966

VPN

Authentication failure may occur when an IKEv2 VPN Endpoint client connects using a machine certificate configured for a specific realm.

PRJ-59251,

PMTR-109563

VPN

When using machine-restricted Access Roles, IKEv2 VPN connections fail at the cleanup rule due to missing machine information and user source IP, while IKEv1 connections are unaffected.

PRJ-57943,
PMTR-108894,

PRJ-58107,
PMTR-109743

VPN

When configuring machine authentication without an LDAP server, the computer is authenticated during the connection with the RA VPN. However, the logs in SmartConsole do not display the "Authenticated machine ..." message as expected.

PRJ-58155,
PMTR-103301

VPN

VPN connection may not be stable when transitioning from Legacy Link Selection to R82 Link Selection.

PRJ-58067,
PMTR-109183

VPN

Different members in a Quantum Maestro environment may show different statuses for VPN probes.

PRJ-58268,
PMTR-108409

VPN

After traffic is stopped and tunnels are deleted, the tunnels may appear as "Disconnected" for about 30 seconds, and then again as "Connected" because of DPD probing.

PRJ-58750,

PMTR-109317

VPN

Remote Access VPN client repeatedly reconnects to a VPN Virtual System when it connects through another Virtual System on a Scalable Platform in the VSX/ VSNext mode. Refer to sk183052.

PRJ-57423,

PMTR-108927

VSNext

In VSNext, multiple CPRID processes running on different ports per virtual system may cause instability in large scale environments.

PRJ-58165,
PRHF-37102

Gaia OS

The ROUTED daemon fails to start when a VTI is configured with a local IP address that matches the next-hop address used in the static route configuration. Refer to sk182848.

PRJ-58036,
MBS-14520

Scalable Platforms

Using the "#" character in the Message of the Day (MOTD) banner message causes SGMs to fail during boot.

PRJ-57640,
PMTR-100964

Scalable Platforms

Security Group Member may be in Down state during the license distribution to Maestro Security Group members. Refer to sk181245.

PRJ-57606,
PRJ-57507

Scalable Platforms

When running the "enabled_blades" command multiple times simultaneously, the command output may be incorrect.

PRJ-58736,
PRJ-58323

Scalable Platforms

In a Maestro environment, a Security Gateway may enter a reboot loop because of sync issues of the settings.fwset file.

PRJ-58375,
PMTR-110163

Scalable Platforms

In rare scenarios, Security Group members may fail to receive their Gaia database from the Single Management Object (SMO). When this occurs, gClish commands related to these missing Security Group configurations may fail.

PRJ-58561,

PMTR-105372

Scalable Platforms

During the upgrade of Scalable Platform Security Group Gateways, SSH keys are deleted.

PRJ-56444,
PRHF-31476

Carrier Security

When Carrier Security is enabled, GTP-U packets are incorrectly matched against GTP rules instead of a non-GTP UDP rule, causing drops with the "Unestablished tunnel" error.

Take 12

Released on 26 February 2025 and declared as Recommended on 18 March 2025

Take 12 - Improvements and Resolved Issues

PRJ-59635,

PMTR-113416

Gaia OS

In a rare scenario, when installing a blink package, the Security Gateway may get stuck in a boot loop.

Take 10

Released on 27 January 2025

Take 10 - New Functionality

 

PRJ-57908,
PRHF-32290

Identity Awareness

NEW: Added new OID (1.3.6.1.4.1.2620.1.38.55) to monitor the Identity Collector connection status in the $CPDIR/lib/snmp/chkpnt.mib file.

  • This capability is supported for Identity Collector agents running with version R82.120.0000 or higher.

Take 10 - Improvements and Resolved Issues

PRJ-56747,
PMTR-106894

SmartConsole

UPDATE: Resolved CVE-2024-3596 - Blast-RADIUS attacks. Fix for Remote Access VPN and login to SmartConsole, Mobile Access and Identity Awareness Captive Portal. Refer to sk182516.

PRJ-58281,

PMTR-97400

Security Gateway

UPDATE: Deprecated RC2-CBC cipher for SIC in OpenSSL.

PRJ-57491,
PMTR-108994

Security Management

UPDATE: The Management API command "set-https-rule" now automatically sets the negative value to "false" when modifying the destination, source, service, or site-category fields, regardless of its previous setting.

PRJ-57066,
PRHF-34509

SecureXL

UPDATE:

  • Improved debugging in the Security Gateway to identify problematic hosts when resolving their next-hop IP addresses.

  • The custom ADP queue size configuration now persists after rebooting the Security Gateway. The relevant global parameters are located in the $PPKDIR/conf/adpkern.conf file:

    • "adp_nh_total_max_arp_qents"

    • "adp_nh_local_max_arp_qents"

PRJ-58125,

PMTR-106186

Scalable Platforms

UPDATE: Added support for Multicast Listener Discovery (MLD) on Maestro Hyperscale Orchestrator (MHO).

PRJ-57074,
PRHF-35818

Security Management

In rare scenarios, when exporting policy hitcounts to CSV format, the "Hitcount" column may appear blank in the exported file.

PRJ-58104,
PRHF-32246

Security Management

Audit logs may not be generated when changes are made to an inline (shared) layer that appears multiple times within the same policy.

PRJ-57319,
PRHF-25950

Security Management

The Database Installation progress bar may not update during task execution.

PRJ-59004,

PMTR-111056

Security Management

When editing the administrator expiration date, after publishing, the expiration date resets to "Never". Refer to sk182997.

PRJ-56542,
PRHF-34752

Multi-Domain Security Management

In some scenarios, in a Multi-Domain Security Management environment, the Hit Count retention mechanism may not remove the Hit Count data from all the Domains.

PRJ-56532,
PRHF-35418

Multi-Domain Security Management

The Multi-Domain Security Management Server experiences high CPU usage when communicating with the Multi-Domain Log Server. And the cpm.elg log prints the "You have reached the maximum number of active session" error. Refer to sk182738.

PRJ-57531,
PRHF-36514

Multi-Domain Security Management

In rare scenarios, in Multi-Domain Security Management environments, login to SmartConsole fails.

PRJ-57310,
MCFG-666

SmartConsole

SmartConsole fails to connect with "Unable to connect to server. Server is initializing". Refer to sk182507.

PRJ-57273,

PMTR-108672

SmartConsole

When the Security Management has an additional NAT configuration in the SD-WAN policy (Infinity Portal), an indicating banner may not appear in SmartConsole NAT Rule Base. This is a cosmetic issue.

  • Requires R82 SmartConsole Build 1051 or higher.

PRJ-58050,
PMTR-109735

Security Gateway

In a rare scenario, the FWK process may exit when processing traffic over QUIC protocol.

PRJ-58659,

PMTR-110556

Security Gateway

In a rare scenario, the FWK process may exit due to a race condition.

PRJ-56911,

PRJ-56840,
PRHF-33037,

PRHF-35918

Security Gateway

The Security Gateway may crash after a failure in policy installation.

PRJ-56702,
PRHF-35624

Security Gateway

Anti-Spoofing may drop IPv6 traffic that arrives at an interface with an IPv6 address configured. Refer to sk182725.

PRJ-57844,
PMTR-109616

Security Gateway

In a rare scenario, when multiple Elephant Flows are running in parallel in the accelerated pipelining path, there may be high CPU utilization. Refer to sk183007.

PRJ-58100,
PMTR-109857

Security Gateway

Traffic through specific interfaces is dropped when the QoS Software Blade is active and "ISP redundancy-LS" is configured. Refer to sk182807.

PRJ-57109,
PRHF-36116

Security Gateway

Memory leak may occur in SecureXL templates. Refer to sk182648.

PRJ-57895,

PMTR-108660

Security Gateway

DoS protection and connection rate limiting configurations may fail to effectively enforce rules.

PRJ-57098,

PMTR-108273

SD-WAN

In a rare scenario, when SD-WAN transport is incorrectly marked as "UP" despite its underlying ISP interface is "DOWN", traffic fails to reach the remote peer because of incorrect routing decisions.

PRJ-58021,
PMTR-109729

Threat Prevention

In a VSX environment, enabling Threat Prevention Software Blades may cause continuous file accumulation on the Security Gateway's hard drive.

PRJ-57007,

PRHF-35823

Threat Prevention

In some scenarios, when Zero Phishing is enabled, kernel crash may occur.

PRJ-57926,
PMTR-109709

Identity Awareness

Identity Broker Subscriber configured with recalculation of Access Roles does not match all Access Roles after the User and Machine are identified.

PRJ-56869,
PRHF-35625,

PRJ-56873,

PRHF-35636

Identity Awareness

In rare scenarios:

  • The PDPD process may become unresponsive during termination.

  • PDP to PEP Identity synchronization fails on the PEP side when Identity Sharing is configured with PUSH Identity Sharing.

Refer to sk182613.

PRJ-57046,
PRHF-36045

Identity Awareness

In a rare scenario, the PDPD process may unexpectedly exit during policy installation.

PRJ-57411,
PMTR-108321

SSL Inspection

The Trusted CA package update fails when the Security Management Server connects to the Internet only through a Proxy Server.

PRJ-57682,
PRHF-36561

SecureXL

A memory leak may occur in the SIM process when using DOS/Rate Limiting rules.

PRJ-58592,

PMTR-110486

SecureXL

When working with SecureXL in User mode (UPPAK), some CPUs may reach 100% utilization when enabling or disabling debug filters.

PRJ-57801,
PMTR-109570

SecureXL

Policy installation failures can disrupt the expected behavior of "fwaccel dos" commands.

PRJ-57558,
PRHF-34632

VPN

SSL Network Extender (SNX) traffic on Maestro may be dropped with "vpnk_tcpt invalid negative tunnel id". Refer to sk182806.

PRJ-56335,
PRHF-35251

VPN

An ECDH object may be deleted before its associated event is completed processing.

PRJ-57901,
PMTR-109649

VPN

After a cluster failover, VPN tunnels may be not stable.

PRJ-56499,
PRHF-35416

VPN

There is no audio during the first 5 seconds of each VoIP call. Refer to sk182730.

PRJ-57825,
PRHF-17665

VSX

Multi-Queue configuration does not survive reboot on VSX. Refer to sk173950.

PRJ-56915,
PRHF-35806

VSX

In SmartConsole, in the Device and License Information view, the Compliance Software Blade license status may incorrectly display "Quota Exceeded" when Virtual Routers or Virtual Switches are present.

PRJ-57059,

PRHF-34508

VSX

After a Jumbo Hotfix upgrade, the Mail Transfer Agent may fail on all Virtual Systems except one.