R82 Jumbo Hotfix Take 103
|
|
Note - This Take contains all fixes from all earlier Takes. |
|
ID |
Product |
Description |
|---|---|---|
|
Take 103 Released on 26 May 2026 |
||
|
Take 103 - New Functionality
|
||
|
PRJ-67316, PRJ-65896, PMTR-125495 |
Security Management |
NEW: Policy Auditor is a policy analytics and auditing tool that provides visibility into traffic behavior within the user's network. In SmartConsole > Security Policies > Access Control, Policy Auditor presents a matrix view of the network's logical segments and the access rules defined between them. The tool allows administrators to audit these security rules and verify that they align with organizational access policies and segmentation requirements.
|
|
PRJ-67021, |
Security Management |
NEW: Added a new Management API command to retrieve an entire Access Control Layer (including inline layers) - "export-access-rulebase". |
|
PRJ-64780, |
ElasticXL |
NEW: Introduced the new Migration Tool for converting ClusterXL to ElasticXL. Refer to sk183894. |
|
PRJ-64973, |
VPN |
NEW: Added support for nested groups with Host/Range/Network objects for split tunnel on exclusion/inclusion options. Refer to R82 Remote Access VPN Administration Guide. |
|
PRJ-66627, |
Security Management |
NEW: Added integration between the Security Management Server and Illumio to extend Check Point micro-segmentation capabilities. This integration enables importing Illumio Workloads and Labels into SmartConsole and using them directly in the Access Control Policy. It improves policy visibility and operational awareness, with enforcement performed on the Security Gateway without requiring an additional policy installation. |
|
Take 103 - Improvements and Resolved Issues
|
||
|
PRJ-67984, PMTR-126652 |
Security Gateway |
UPDATE: Resolved CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero. Refer to sk184981. |
|
PRJ-67839, PMTR-126457 |
Security Gateway |
UPDATE: Resolved CVE-2026-48132 - VPN process may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP. Refer to sk184982. |
|
PRJ-67874, PMTR-126538 |
Security Gateway |
UPDATE: Resolved CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion. Refer to sk184993. |
|
PRJ-67836, PMTR-126454 |
Security Gateway |
UPDATE: Resolved CVE-2026-48134 - SQL injection issue in UserCheck Web Portal when DLP is active. Refer to sk184983. |
|
PRJ-68009, PMTR-126694 |
Security Gateway |
UPDATE: Resolved CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests. Refer to sk184991. |
|
PRJ-68355, PMTR-126828 |
Security Management |
UPDATE: Resolved CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance. Refer to sk184992. |
|
- |
- |
This Jumbo Hotfix Accumulator Take includes dozens of code and functionality hardening changes. |
|
PRJ-66695, PMTR-124314 |
Mobile Access |
UPDATE: The Magnific Popup JavaScript library is upgraded from version 1.1.0 to 1.2.0. |
|
PRJ-67354, PRHF-43660 |
Security Management |
UPDATE: JRE is updated from version 8.0_8.50 to 8.0_8.60. |
|
PRJ-67396, |
Security Management |
UPDATE: Policy installation is now accelerated after performing Global Domain Reassignment. |
|
PRJ-65271, |
Security Management |
UPDATE: In environments with thousands of Domain objects or External User Groups, the policy installation duration is now significantly improved. |
|
PRJ-65116, MGMTPROD-2359 |
Security Management |
UPDATE: The "Test Feed" functionality in Check Point's Network Feed and IoC Feed allows administrators to validate the connectivity, parsing, and loading of Threat Intelligence feeds directly on cluster members. |
|
PRJ-65041 |
Security Management |
UPDATE: When connecting a Domain to the Check Point Portal, Dedicated Log Servers in the Domain are now connected automatically. |
|
PRJ-67100, PMTR-89328 |
Security Management |
UPDATE: Added a validation that helps to prevent assigning a single Security Gateway as both the Center and Satellite member within the same VPN Star Community. |
|
PRJ-65923, PMTR-114424 |
Security Management |
UPDATE: The Zero Phishing Software Blade improvements:
Requires installing R82 SmartConsole Build 1065. |
|
PRJ-65596, HEC-1347 |
HCP |
UPDATE: Added a new HCP test that analyzes load balancing and NAT utilization, and suggests optimal distribution adjustments accordingly. Refer to sk171436. |
|
PRJ-62378, |
Logging |
UPDATE: Added a capping status indicator to CPView and SmartConsole showing whether log sharing is actively sending logs to the Cloud or it reached its daily limit. Refer to R82 Security Management Administration Guide. |
|
PRJ-65493, |
Logging |
UPDATE: SmartEvent now supports the "system alert" log type for URL Filtering and Application Control Software Blades. |
|
PRJ-65538, PRHF-42643 |
Security Gateway |
UPDATE: When OCSP certificate validation fails, the Security Gateway now automatically falls back to CRL validation. Manual configuration via the Check Point Registry (described in Scenario 2 in sk179434) is no longer required. |
|
PRJ-66949, |
Security Gateway |
UPDATE: Added the "tap_mode" parameter to a dispatcher (fwmultik_dispatcher_in_tap_mode). This parameter puts the multi-core dispatcher into the Tap Mode for inbound traffic. Refer to sk184455. |
|
PRJ-64355, |
Security Gateway |
UPDATE: Added the ability to automatically stop kernel debugging after a specified number of seconds. See the R82 Quantum Security Gateway Administration Guide. Refer to the command "fw ctl debug -T <Number of Seconds>". |
|
PRJ-64005, |
SecureXL |
UPDATE: Improved Debug Filtering for specific flows in SecureXL User Space Mode (UPPAK) debug messages. |
|
PRJ-62990, |
VSNext |
UPDATE: Added an ability to automatically roll back CoreXL instance changes on a VS if the operation fails on one of the cluster members. |
|
PRJ-65094, PRJ-63808 |
Cloud Firewall |
UPDATE: Azure VM sizes v2 and v3 are no longer supported. During installation of Jumbo Hotfix Accumulator or in-place upgrade, this message is now displayed: "The Azure VM size {VMsize} is deprecated for upgrade. Refer to sk183693 for details". |
|
PRJ-65822, CGNSIS-157 |
Cloud Firewall |
UPDATE: Added support for Microsoft Azure Network Adapter (MANA) driver. Refer to sk183754. |
|
PRJ-64540 |
Scalable Platforms |
UPDATE:
|
|
PRJ-66546, ODU-3619, PRJ-67790, ODU-3852, PRJ-67786, ODU-3894, PRJ-68755, ODU-4023 |
Automatic Updates - Web SmartConsole |
UPDATE: New features and improvements are released in Take 163, Take 165, Take 170 via self-updatable package. Refer to sk170314. |
|
PRJ-67867, |
Automatic Updates - HCP |
UPDATE: Added Update 27 of HealthCheck Point (HCP) Release. Refer to sk171436. |
|
PRJ-66728, ODU-3666 |
Automatic Updates - Log Exporter |
UPDATE: Added Take 53 to Log Exporter Auto Update Deployment. Refer to sk182866. |
|
PRJ-66382, ODU-3435, PRJ-68135, ODU-3901 |
Automatic Updates - Policy Insights |
UPDATE: Added Take 82, Take 91 of Policy Insights Release Updates. Refer to sk183421. |
|
PRJ-67870, ODU-3950 |
Automatic Updates - CPSDC |
UPDATE: Added Take 43 of Check Point Support Data Collector (CPSDC) for Scalable Platforms and Maestro Security Appliances. Refer to sk164414. |
|
PRJ-62809, |
Security Management |
Running a Packet Mode search using the Management API for a service object fails to match the correct service rules. |
|
PRJ-61645, |
Security Management |
In rare scenarios, CME (Cloud Management Extension) fails to run because of the "show-simple-gateway" Management API command failure. The CME logs show such entries: "Product - CMESeverity - criticalDescription - Error during synchronization with Security Gateways. Error details: Failed to scan for gateway instances in the cloud account". |
|
PRJ-63826, |
Security Management |
Best Practices may be missing or show incorrect results in the Security Best Practices view of the Compliance Software Blade. Refer to sk184239. |
|
PRJ-63948, |
Security Management |
Policy installation may fail when an inline layer is used more than once in the same policy and this error is displayed "Policy installation had failed due to an internal error. If the problem persists please contact Check Point support". |
|
PRJ-62989, |
Security Management |
In some scenarios, when updatable objects are used in the policy, policy installation fails with error code "0-2-2000245". Refer to sk183844. |
|
PRJ-62087, PRHF-40511 |
Security Management |
In a Full High Availability (HA) ClusterXL deployment, the Check Point Portal does not display the Active Management Server as connected. As a result, Configuration Sharing is not working as expected in the Check Point Portal. |
|
PRJ-65971, PMTR-120900 |
Security Management |
After an upgrading the Security Management Server, policy installation may fail with "error code - 325", "SIC general failure". |
|
PRJ-56529, PRHF-34095 |
Security Management |
The delay may be observed during the "compiling policy" and "generating policy files" stages in SmartConsole. |
|
PRJ-63437, |
Security Management |
In some scenarios, SmartConsole may disconnect during policy installation. |
|
PRJ-64541, |
Security Management |
When using the "add/set data-type-weighted-keywords" and "add/set data-type-file-attributes" Management API commands, the field "description" is missing from the response. |
|
PRJ-64702, PRHF-42579 |
Security Management |
Hitcount of NAT Rule Base fails after Security Management Server upgrade. Refer to sk184336. |
|
PRJ-63084, |
Security Management |
SMB packages may not appear in the Multi-Domain Security Management "package repository list", even though they uploaded successfully. |
|
PRJ-61595, |
Security Management |
After installing a policy on a Security Gateway running R81.20 or lower, the PDPD (Policy Decision Point) process on the Security Gateway fails to retrieve user information from Microsoft Entra ID (formerly Azure Active Directory). |
|
PRJ-65162, |
Security Management |
In SmartTask-generated emails, the Sender field displays the username instead of the user's email address. |
|
PRJ-63494, |
Security Management |
If the "Revert to Revision" operation fails:
|
|
PRJ-61281, |
Security Management |
In rare scenarios, the /var/tmp directory may be filled up with redundant tmpUserDefineCmd_OS0*.sh files, created during Compliance Software Blade scans. |
|
PRJ-66497, |
Security Management |
In some scenarios, uninstalling Threat Prevention policy on a Security Gateway fails with "An internal error has occurred". |
|
PRJ-66046, MLS-1482 |
Security Management |
In some scenarios, an upgrade of the Security Management Server may fail with a "There can only be one Automatic Purge Setting for this domain. Duplicates are invalid" message.
|
|
PRJ-65036, PRHF-42720 |
Security Management |
In some scenarios, the status of a Security Gateway is incorrectly displayed in the Gateways & Servers View. |
|
PRJ-66344, |
Security Management |
The "set-checkpoint-host" Management API command with the "interfaces" field may fail with the "generic_err_invalid_parameter" error. |
|
PRJ-66606, |
Security Management |
If the MGMTCOMP-DIFF-REPORT-CLIENT process becomes suspended on the Security Management Server, the Server-side Change Report Generator fails to generate and send reports when processing a large number of changes. |
|
PRJ-59614, |
Security Management |
Upon creation of a new Domain on a Multi-Domain Security Management Server, the Domain Server's virtual IP address is not added to the Gaia database, making it inaccessible via Clish commands. Refer to sk183941. |
|
PRJ-66376, |
Security Management |
In some scenarios, SmartConsole disconnects during policy installation. |
|
PRJ-66031, |
Security Management |
In some scenarios, the Management Server may generate excessive log messages, causing the cpm.elg log file to reach its size limit quickly. |
|
PRJ-65447, |
Security Management |
In some scenarios, Global Domain assignment may fail with the "Failed to save the access policy assignment properties" error. |
|
PRJ-65670, PRHF-43067 |
Multi-Domain Security Management |
In some scenarios, the Domain Log Management Server fails to connect to the Check Point Portal. |
|
PRJ-63590, |
CPView |
In some scenarios, the CPD process may exit with core dumps. |
|
PRJ-64206, PMTR-120236 |
CPView |
Apostrophes used in CPView strings cause CPDiag to fail. CPView History data is not shown. Refer to sk184873. |
|
PRJ-68509, PRJ-68481, PMTR-127053 |
CPView |
The CPVIEWD daemon may exit during startup. |
|
PRJ-65332, |
Logging |
In SmartView Monitor, opened from Logs & Events > Tunnel & User Monitoring, the "SmartEvent Correlation Unit" status may be displayed as "Not running" although the CPSEMD process is running. |
|
PRJ-63974, |
Logging |
In SmartConsole, when exporting logs from the Logs tab to a CSV file, the "Rule" column may display only the parent rule number instead of the specific inline rule number. |
|
PRJ-65906, PMTR-121592 |
Logging |
In the "HTTPS Inspection Statistics" in SmartView, filtering by the "bypass_reason" field returns no results. |
|
PRJ-63227, PRHF-40388 |
Logging |
In some scenarios, disk space on the Security Management Server may increase significantly if PostgreSQL database log rotation does not function as expected. |
|
PRJ-64074, |
Logging |
In some scenarios, incorrect values are shown in the "Total Bytes" field in the logs. Refer to sk184237. |
|
PRJ-66531, PRHF-44001 |
Logging |
CPView may display "N/A" values for logging-related metrics when there is insufficient free disk space in the log partition. |
|
PRJ-56716, PRHF-35509 |
Logging |
In the Connection logs, the Source Country and Destination Country fields may contain missing or incorrect values. |
|
PRJ-59833, |
Logging |
In HTTPS Inspection logs, some log entries may incorrectly display "Log Update" in the Software Blade field. |
|
PRJ-66842, |
Logging |
In some scenarios, non-ASCII characters may appear garbled in SmartEvent Automatic Reaction emails. |
|
PRJ-64756, |
Security Gateway |
The ICAP client does not work correctly, impacts the allowed number of characters for the ":service" field in the $FWDIR/conf/icap_client_blade_configuration.C ICAP configuration file. |
|
PRJ-63958, |
Security Gateway |
Changing instances on Virtual Systems may not trigger synchronization flows in some relevant directories and in the High Availability module. |
|
PRJ-65442, |
Security Gateway |
The SD-WAN NAT rule may not be applied when no NAT is defined in the Access Control policy. |
|
PRJ-67357, |
Security Gateway |
In rare scenarios, after an upgrade, the Security Gateway may crash because of a missing route. |
|
PRJ-64519, |
Security Gateway |
First packet may be delayed for around 10 seconds because of pending WSDNSD DNS lookup over TCP. Refer to sk184096. |
|
PRJ-66004, |
Security Gateway |
In a rare scenario, an incorrect zone assignment occurs when NAT Rule Base returns HOLD. Refer to sk184530. |
|
PRJ-64834, |
Security Gateway |
Legitimate files may be incorrectly flagged as malicious when scanned with ICAP. Refer to sk184628. |
|
PRJ-66804, |
Security Gateway |
In rare scenarios, the FWK process may unexpectedly exit when the Anti-Bot Software Blade inspects a specific malformed domain. |
|
PRJ-62969, |
Security Gateway |
In rare scenarios, when deleting a subordinate interface from a bonding group, the FWK process may exit. Refer to sk183736. |
|
PRJ-67519, |
Security Gateway |
Running the "g_tcpdump mcap" with "-C" flag fails with the file matching or captured packets merging error. |
|
PRJ-64162, |
Security Gateway |
In rare scenarios, ElasticXL VSX Cluster Members fail over several times per day because of HTTP/2 explicit proxy process termination. Refer to sk184932. |
|
PRJ-66891, PMTR-113018 |
Security Gateway |
During a ClusterXL High Availability failover, the FWK process may unexpectedly exit when processing Web Security traffic. |
|
PRJ-63384, |
Security Gateway |
In rare scenarios, the FWK process may exit when parsing an invalid SIP packet. |
|
PRJ-65053, |
Security Gateway |
In some scenarios, SNMPv3 monitoring fails on Data Plane when MDPS is enabled. Refer to sk184379. |
|
PRJ-59892, PRHF-38489 |
Security Gateway |
In rare scenarios, the FWK process may exit with core files because of a segmentation fault. |
|
PRJ-63235, PRHF-41491 |
Security Gateway |
Enabling ForceAuth for Remote Access VPN fails because of a typo in the saml_force_authn_override.sh script (sk182042). |
|
PRJ-64976, PRA-5005 |
Security Gateway |
In a rare scenario, the FWK process may restart unexpectedly when the Security Gateway processes accelerated connections. |
|
PRJ-64078, |
Security Gateway |
In scenarios where a network connection is closed before the Anti-Virus ThreatCloud emulation or scanning response is received, the affected session may experience connectivity instability. |
|
PRJ-66359, |
Security Gateway |
The BMAC/VMAC verification for a VSX Maestro Security Group member incorrectly reports a failure on warp interfaces. |
|
PRJ-65268, |
Security Gateway |
In some scenarios, non-accelerated traffic from a Standby VSX Cluster member may not be routed to the correct virtual instance on the current Active member when SecureXL User Mode (UPPAK) is enabled. |
|
PRJ-66173, |
Security Gateway |
The Security Gateway may fail to correctly handle return traffic for pass-through GRE connections in scenarios with NAT. |
|
PRJ-66198, PRHF-43742 |
Security Gateway |
In some scenarios, when processing HTTPS traffic in the accelerated pipelined path, the FWK process may unexpectedly exit. |
|
PRJ-67156, PRHF-44365 |
Security Gateway |
In some scenarios related to Check Point Active Streaming (CPAS), the Security Gateway may unexpectedly crash. |
|
PRJ-65585, PRHF-43161 |
Threat Prevention |
In Smart-1 Cloud environments, the "Threat Prevention" view may display 0 in the "Logs" column under the "Top Protections" widget. Refer to sk184505. |
|
PRJ-66235, |
Threat Prevention |
In some scenarios, the IoC parser may fail to process feeds that include IPv6 observables when running on systems that do not support IPv6. |
|
PRJ-66296, PMTR-123479 |
Threat Prevention |
In a rare scenario, the Threat Prevention rule base may fail to match traffic to any rule. |
|
PRJ-65833, PRHF-42534 |
Identity Awareness |
In a rare scenario, a Policy Decision Point (PDP) Security Gateway that acts as both an Identity Broker Subscriber and a sharing identity with a Policy Enforcement Point (PEP) may become unresponsive. |
|
PRJ-64694, PRHF-42522 |
Identity Awareness |
When the Packet Tagging feature is enabled on the Full Identity Agent, new user and machine identity sessions reported to the Identity Awareness Gateway may not be assigned the correct Access Roles. As a result, traffic from these sessions may not match Access Control Policy rules that use access roles with Packet Tagging enabled. |
|
PRJ-64120, PRHF-41176 |
Identity Awareness |
In a rare scenario, there may be no access to resources for identities received from the Remote Access identity source. |
|
PRJ-67094, PRHF-36542 |
Identity Awareness |
In a rare scenario, when the fetch_by_SID feature is enabled, the PDPD process repeatedly exits. Refer to sk182745. |
|
PRJ-65868, |
Identity Awareness |
Skyline may not return data for part of Identity Awareness metrics described in Skyline Administration Guide. |
|
PRJ-60571, |
Content Awareness |
In some scenarios, a memory leak may occur in the DLPU process. The /var/log directory on the Active Cluster member reaches critical disk usage levels. |
|
PRJ-65960, |
Application Control |
Updating two or more Dynamic URL Lists may result in partial updates. |
|
PRJ-65876, |
Application Control |
In a rare scenario, when using Dynamic URL List, updating the version file may result in a FWK process restart. |
|
PRJ-63611, |
IPS |
In rare scenarios, the IPS update package may become corrupted. This could cause the Security Gateway to load the initial policy instead of the active security policy. |
|
PRJ-59838, |
DLP |
In some scenarios, changes to the kernel parameter "dlpk_drv_default_queue_sz" may not take effect. |
|
PRJ-64751, |
Anti-Virus |
In some scenarios, a memory leak may occur in the Anti-Virus Software Blade process when the Security Gateway is configured as a proxy. |
|
PRJ-66185, |
Anti-Virus |
In some scenarios, the Security Gateway may drop DNS traffic with non-malicious Domains. |
|
PRJ-66452, |
SSL Inspection |
Several WSTLSD processes running for each Security Gateway may exhaust memory consumption. |
|
PRJ-58810, |
Mobile Access |
After an upgrade, the Mobile Access Software Blade's CVPND daemon fails to load and the Mobile Access Portal becomes inaccessible when adding new Virtual Systems or converting to a VSX Gateway, due to improper updates to the gateway-side configuration file cvpnd.C. Refer to sk183293. |
|
PRJ-66594, |
Mobile Access |
When Mobile Access is working in Path Translation (PT) Link Translation mode, the Citrix application may not load after an upgrade to Citrix version LTSR 2507. |
|
PRJ-62167, |
ClusterXL |
Connections with fragmented packets drop on Scalable Platform/Maestro when there are multiple active Security Group Members (SGMs) on the site. Refer to sk182559. |
|
PRJ-64090, |
ClusterXL |
When MDPS is enabled, cluster may get stuck in "Init" state with FullSync pnote because of a failure to bind to a socket. |
|
PRJ-64916, |
ClusterXL |
After creating a High Availability ClusterXL and syncing to Smart-1 Cloud, running the "get interfaces with topology" in Smart-1 Cloud may cause the Sync interface to be removed from the Cluster object. |
|
PRJ-59711, |
ClusterXL |
The "cphaconf failover_bond <bond_name>" command fails with Management Data Plane Separation (MDPS). Refer to sk183935. |
|
PRJ-66293, |
ClusterXL |
In rare scenarios, CPHASTART, CPHACONF, and CPHAMCSET processes may intermittently unexpectedly exit. |
|
PRJ-65901, |
ClusterXL |
After rebooting specific Security Group Members (SGMs) in a dual-site Maestro environment, PDP (Policy Decision Point) to PEP (Policy Enforcement Point) connections are not always corrected to the SMO (Single Management Object) as expected. This results in connection restarts and additional CPU load. |
|
PRJ-67239, |
SecureXL |
IPv4 addresses in the SYN Defender Allow List in SmartConsole may be loaded with the address octets reversed. |
|
PRJ-67245, |
SecureXL |
Maestro backplane interfaces may appear in the SYN Defender interface list. This is a cosmetic issue. |
|
PRJ-67685, |
SecureXL |
Changes to the SYN Defender Allow List made in SmartConsole may not override or replace local modifications made directly on the Security Gateway. |
|
PRJ-67242, |
SecureXL |
When loading the SYN Defender Allow List from the Gateway CLI using only the "-L" parameter, the entries are merged with the existing Allow List (including those configured in SmartConsole), rather than overwriting it. |
|
PRJ-67933, |
SecureXL |
When using DoS Deny List and running "cpstop", an error message may be displayed, and a memory leak may occur. |
|
PRJ-67066, |
SecureXL |
The FWK process may exit during an upgrade if DOS/Rate limiting is active. |
|
PRJ-67241, |
SecureXL |
A failed Access Control policy installation may block future installs until the Security Gateway is rebooted, even after the original issue is resolved. |
|
PRJ-64147, |
SecureXL |
The Security Gateway with SecureXL User Mode (UPPAK) enabled may not properly update routes when bond interfaces are configured. |
|
PRJ-66171, |
SecureXL |
In some scenarios, when installing a policy fails, the Sand Blast Security Gateway becomes unresponsive and reboots automatically. The "Installation failed. Reason: Due to a timeout value of 600000 (millisecond) (port) (IP), Security Management Server aborted the connection with the peer" error is displayed in SmartConsole. |
|
PRJ-65914, |
SecureXL |
When SecureXL User Mode (UPPAK) is enabled on a VSX Security Gateway, taking down a warp interface on any Virtual System may cause all Virtual Systems connected to the same Virtual Router or Switch to lose network connectivity. |
|
PRJ-63692, |
SecureXL |
In some scenarios, the USIM_X86 process may become unresponsive. |
|
PRJ-63079, |
SecureXL |
GRE tunnels fail after upgrade to R82 when SecureXL is enabled on the Security Gateway. Refer to sk184007. |
|
PRJ-63124, |
SecureXL |
The USIM process may exit with core dumps when debug information is collected. |
|
PRJ-62251, |
SecureXL |
SYN Defender (Synatk) does not recognize or enforce protections on bridge interfaces. |
|
PRJ-62198, |
SecureXL |
When the Security Gateway is working with SecureXL in User Mode (UPPAK) mode, in some scenarios, the USIM process may exit and not restart, although it should. |
|
PRJ-66163, PRJ-66223 |
SecureXL |
A vmcore dump may occur when enabling kernel debugs in Kernel Mode (KPPAK) while processing multicast traffic. |
|
PRJ-61390, |
SecureXL |
When configuring PIM in Sparse Mode across multiple Virtual Systems on a VSX Security Gateway, the Security Gateway may crash, resulting in loss of connectivity. |
|
PRJ-64318, |
SecureXL |
When SecureXL is working in User Mode (UPPAK) mode, some packets may sometimes appear twice in the output of the "tcpdump" command. |
|
PRJ-65106, |
SecureXL |
When SecureXL User Mode (UPPAK) mode may be disabled if some scripts are incorrectly edited. |
|
PRJ-65451, PMTR-121744 |
SecureXL |
Permanently disabling the "cphwd_enable_ecmp" global parameter on a VSX Gateway using the "-f" option of the "fwl ctl set" command may fail. |
|
PRJ-65601, PMTR-122439 |
SecureXL |
When SecureXL works in User Mode (UPPAK) on Security Gateways with CPAC-4-10F-C interface modules, invalid Ethernet frames permanently shut down the port's transmit queue, causing complete connectivity loss. |
|
PRJ-64616, |
Routing |
When a routemap rule is configured to match a specific BGP community, it incorrectly matches routes that have no community set at all, instead of excluding them. |
|
PRJ-67173, |
Routing |
A ROUTED daemon may exit with a dump file during an OSPF route lookup on a route being redistributed between BGP and OSPF. |
|
PRJ-62566, |
Routing |
When SecureXL runs in User Mode (UPPAK), local IGMP and MLD multicast groups are not added to listener reports. This causes the output of the "show igmp groups" command to miss expected local group memberships. Additionally, the router does not send MLD reports for IPv6 multicast groups, breaking IPv6 Dynamic Routing. |
|
PRJ-65917, |
Routing |
A VSX Security Gateway may drop traffic with IPv4 options or IPv6 extension headers arriving from a Virtual Switch (VSW) interface. |
|
PRJ-66408, |
Gaia OS |
The SNMPD daemon fails to restart when an interface configured with an IPv6 address is set as the SNMP agent interface. |
|
PRJ-65154, |
Gaia OS |
When MDPS routing separation is enabled, Link Layer Discovery Protocol (LLDP) fails to be enabled from Gaia Portal. |
|
PRJ-65220, |
Gaia OS |
SNMP monitoring systems may report format errors related to the structure of the chkpnt.mib file. |
|
PRJ-62338, |
Gaia OS |
LLDP data formatting issues when querying using SNMP. Refer to sk183733. |
|
PRJ-65223, |
Gaia OS |
When integrating SNMP monitoring systems with Gaia OS, compilation of the GaiaTrapsMIB.mib file with the CHECKPOINT-MIB (chkpnt.mib) may fail. SNMP management stations or MIB browsers (such as HP OpenView, CA Spectrum, or HP Network Node Manager) return errors like "File GaiaTrapsMIB.mib failed to parse" or "ERROR : Cannot find symbol file://GaiaTrapsMIB.mib:Line XX:Column XX:multiDiskName". |
|
PRJ-61179, PRHF-33954 |
Gaia OS |
On a Scalable Platform Security Group, although an SHA hash type was configured for Gaia OS passwords with the Gaia Global Clish command "set password-controls password-hash-type", the Gaia Global Clish command "set expert-password" saves the password as an MD5 hash in the Gaia OS database. Refer to sk182339. |
|
PRJ-65857, PMTR-122180 |
Gaia OS |
Users cannot create read-only roles, cannot modify roles by removing permissions, or assign roles with all features to specific virtual servers, and all operations fail silently without warnings. |
|
PRJ-63238, PRHF-41507 |
Gaia OS |
The SSHD process unexpectedly exits on the Multi-Domain Log Server (MLM) after an SSH session ends. Refer to sk183972. |
|
PRJ-65026, PRHF-42775 |
Gaia OS |
"No Such Instance currently exists at this OID" message is displayed when querying the OID tree 1.3.6.1.4.1.2620.1.48 on a Maestro Security Group. Refer to sk184363. |
|
PRJ-65526, |
Gaia OS |
Upon logging in to the Gaia Portal, the login page accepts the credentials, briefly displays the homepage, and then automatically redirects back to the login screen. |
|
PRJ-65857, PMTR-122180 |
Gaia OS |
Users cannot create read-only roles, cannot modify roles by removing permissions, and cannot assign roles with all features to specific virtual servers, with all operations failing silently without warnings. |
|
PRJ-57484, |
Gaia OS |
Custom log rotation configured using Gaia OS does not apply to SAML-related log files, so these logs are not rotated automatically. Refer to sk113241. |
|
PRJ-57485, |
Gaia OS |
Custom log rotation configured using Gaia OS does not apply to UserCheck Portal log files, so these logs are not rotated automatically. Refer to sk113241. |
|
PRJ-66751, |
Gaia OS |
Cloning groups may fail during configuration updates. Refer to sk184701. |
|
PRJ-67944, PMTR-126636 |
Gaia OS |
In a Maestro setup with MDPS enabled, the Security Gateway may crash when processing IPv6 traffic while under load. |
|
PRJ-66465, PMTR-123351, PRHF-44661 |
VPN |
VPN traffic outage may occur in ClusterXL environments with SD-WAN Overlay or Enhanced Link Selection after a Cluster failover. The new Active cluster member fails to properly handle VPN traffic because of synchronization or MAC address handling problems. |
|
PRJ-65321, |
VPN |
The VPND or IKED daemon may unexpectedly exit during IKEv2 negotiation. |
|
PRJ-65011, |
VPN |
SSL Network Extender Portal is accessible even when it is disabled in SmartConsole. Refer to sk184344. |
|
PRJ-63552, |
VPN |
CRL files may not be synchronized as expected in Management High Availability and Multi-Domain Security Management environments. |
|
PRJ-66855, |
VPN |
The VPND daemon intermittently exits after a downgrade. |
|
PRJ-68715, PMTR-127505 |
VPN |
Remote Access Endpoint Security Client may disconnect and reconnect approximately every 15 seconds. |
|
PRJ-68992, PMTR-122433 |
VPN |
Remote Access Endpoint Security Client may fail to connect. |
|
PRJ-63829, |
VPN |
When generating a CPInfo file using the CPInfo utility, major CPU spikes may occur on the Security Gateway or Security Management Server. |
|
PRJ-67110, |
VPN |
The VPND and IKED daemons keep restarting after upgrading to R82 in an environment with multiple VTI interfaces. Refer to sk184895. |
|
PRJ-66467, |
VPN |
In ClusterXL environments, a VPN traffic outage of up to 60 seconds may occur after an ungraceful cluster failover. |
|
PRJ-66365, |
VPN |
In some scenarios, over time, prolonged VPN traffic may lead to gradual memory growth. |
|
PRJ-65826, |
VPN |
A customized Per-gateway Secure Configuration Verification (SCV) policy is not enforced for Remote Access VPN clients. Refer to sk184863. |
|
PRJ-66770, |
VPN |
VPN traffic outage may occur in ClusterXL environments with IKEv2 after a Cluster failover. |
|
PRJ-64249, |
VPN |
After an upgrade of the Security Management Server to R82.10, after starting SmartConsole, a validation error "DYNAMIC MESSAGE" is displayed, and VPN Community shows a warning "R82 gateways use the deprecated Kyber algorithm, for PQC. It is recommended to use R8210 and above gateways that use standard PQC algorithms. See sk184080 for details". |
|
PRJ-65419, |
VPN |
After a Cluster failback, RDP (Routed Data Path) or DPD (Dead Peer Detection) probing may not be triggered, which can result in traffic continuing to use outdated Multiple Entry Point (MEP) Gateway selections. |
|
PRJ-66012, PMTR-117053 |
VPN |
VPN traffic from L2TP clients may fail to pass through the Security Gateway working in SecureXL User Mode (UPPAK). |
|
PRJ-58820, PMTR-110326, AAD-3140 |
VPN |
In environments where all Security Gateways are configured with IPv6 addresses only, Site-to-Site VPN connectivity may be disrupted when Enhanced Link Selection is enabled. |
|
PRJ-63074, PMTR-118391 |
VPN |
IPv6 traffic disruption may occur on Security Gateways when Enhanced Link Selection is enabled and VPN links are directly connected interfaces. |
|
PRJ-65740, PMTR-122271 |
VPN |
The IKED process may exit when the traffic is passing through IKEv2 tunnels. |
|
PRJ-62344, |
VPN |
In some scenarios, only a partial list of traffic selectors may be sent during tunnel negotiation for Remote Access IKEv2 tunnels. |
|
PRJ-62763, |
VPN |
Enhanced Link Selection configured with Auto Next Hop uses invalid IP addresses, preventing tunnel initiation. |
|
PRJ-60957, |
VPN |
High CPU utilization on single core because of excessive VPN probing and SEP correction in ClusterXL HA Mode. Refer to sk183814. |
|
PRJ-62055, |
VPN |
IKE daemons may fail to start on Cluster members without generating dump files. |
|
PRJ-62491, |
VPN |
Policy installation fails in a Remote Access community with only R82 Security Gateways when SHA-384 or SHA-512 are enabled, although failure should occur only if lower Security Gateway versions are part of the community. |
|
PRJ-62774, PRHF-41154 |
VSX |
A malformed or incorrect interface name in the "cphaprob -a if" command on VS0 triggers a fatal error in the cluster process, causing the member to go DOWN and generating a core dump. |
|
PRJ-65191, |
VSX |
During interface reallocation between Virtual Systems on a VSX Gateway, Management access (SSH/Gaia Portal) to VS0 may be disrupted after the interface move. Returning the interface to its original VS does not recover connectivity. |
|
PRJ-65232, |
VSX |
After upgrading the firmware, the interface on one of the VSX cluster members may go down. |
|
PRJ-67230, |
VSX |
Incorrect MAC address configuration on WRP interfaces in a VSNext environment leads to ClusterXL Load Sharing malfunctions and traffic correction issues. |
|
PRJ-65673, |
VSX |
Deleting a Virtual Switch (VSW) may break connectivity for unrelated Virtual Systems (VSs). |
|
PRJ-64608, |
VSX |
The number of IPv6 instances remains "0" on VS1 after enabling IPv6 state on it through Clish and performing a reboot. |
|
PRJ-61255, |
VSX |
The Netscout feature may not monitor network connectivity to remote known hosts on VSs other than VS0. |
|
PRJ-65479, |
VSX |
When attempting to create a new Virtual System (VS) with management connectivity enabled, the operation may fail. This prevents the successful provisioning of the Virtual System in the environment. |
|
PRJ-67114, |
VSX |
When adding or deleting static routes in the huge VSX environment (more than 50 Virtual Systems and hundreds of static routes), VS creation fails with "Unable to watch directory /etc/routed-mc-enable: init: Too many open files". Refer to sk181317. |
|
PRJ-65934, |
VSX |
The "show configuration" gClish command may fail for showing configuration for LLDP, VSNext, VSLS, SSH, and OSPF. |
|
PRJ-65388, |
VSNext |
In VSNext ElasticXL and VSNext Maestro, running the "cpconfig" command from Clish/gClish within a Virtual System context may trigger execution in the Global context. |
|
PRJ-65242, PMTR-121780 |
VSNext |
After adding a virtual link between a Virtual System (VS) and a Virtual Switch (VSW), policy installation may fail with the "Installation failed. Reason: TCP connectivity failure [ error no. 10 ]" error. |
|
PRJ-63697, PMTR-119366 |
VSNext |
When capturing packets on a warp interface in a Virtual System (VS) of a VSX Security Gateway with SecureXL User Mode (UPPAK) enabled, certain reply packets may not be captured, for example, ICMP Echo Replies to traffic directed at the Security Gateway. |
|
PRJ-65483, PRHF-43055 |
VSNext |
Three out of four Virtual Systems (VS) on a single site may show a "Problem" Health status in the output of the "asg stat vs all" test. This is a cosmetic issue. |
|
PRJ-65386, PMTR-122058 |
VSNext |
When the Same VMAC Mode is enabled on ElasticXL, VS0 may lose connectivity (SSH). |
|
PRJ-65592, PMTR-122597 |
Cloud Firewall |
When a new Cloud Firewall Gateway is added to the Security Management Server, and a security policy is installed, the Security Gateway may not appear in the Central License Tool (vsec_lic_cli). As a result, the Security Gateway fails to receive a central license. |
|
PRJ-66385, PRHF-43223 |
Cloud Firewall |
The FWM may unexpectedly exit when attaching a license to a Security Gateway using vSEC license distribution (vsec_lic_cli). |
|
PRJ-65296, PRHF-42496 |
Cloud Firewall |
When using VSLS with Identity Sharing enabled, CloudGuard Controller may fail to send updates to Virtual Systems that have no Data Center Objects in their policy. |
|
PRJ-65013, |
Cloud Firewall |
Registration of Data Center assets with a numeric, non-UID unique identifier may fail, potentially causing performance impact on the Security Management Server. |
|
PRJ-63858, |
SD-WAN |
When VPN Enhanced Link Selection is configured and SD-WAN is enabled, pushing a new SD-WAN policy may result in loss of connectivity. |
|
PRJ-66471, PRJ-66469, |
SD-WAN |
VPN traffic outage may occur in ClusterXL environments after a Cluster failover. |
|
PRJ-64070, PRHF-41754 |
SD-WAN |
In an SD-WAN overlay environment when there is no matching rule, the /var/log/messages directory may contain many "could not find rule uuid for connection", "invalid return value from callback" errors. |
|
PRJ-64871, |
SD-WAN |
In rare scenarios, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) may be incomplete, causing SD-WAN rules to match traffic incorrectly. Refer to sk184814. |
|
PRJ-66033, |
VoIP |
Real-time Transport Protocol (RTP) may not function correctly, this results in the VoIP/RTP traffic being dropped. |
|
PRJ-65800, |
VoIP |
Security Gateway may drop legitimate H323 traffic with "Illegal H.225(Q931) No Q.931 User-user IE found". Refer to sk184591. |
|
PRJ-67482, |
Scalable Platforms |
If a management interface on ElasticXL Security Gateway is a part of a bond, the license distribution mechanism may not work as expected. |
|
PRJ-64407, |
Scalable Platforms |
In a Maestro environment with Multi-Domain Security Management and enabled MDPS, SNMP per member queries do not survive member failover. Additionally, SNMP queries to the SMO may be routed to the dplane instead of the mplane. |
|
PRJ-64704, |
Scalable Platforms |
When working in the VSnext setup, creating Virtual Systems, deleting them, and recreating them may fail with an error. |
|
PRJ-67349, |
Scalable Platforms |
A Security Group Member may enter a continuous boot loop after the other members were upgraded. An incorrect image file (with an invalid or mismatched MD5 checksum) is presented on the Single Management Object (SMO). As a result, the problematic member fails to complete the autoclone and repeatedly reboots. |
|
PRJ-67176, |
Scalable Platforms |
In ElasticXL Clusters, a new member that exits ungracefully (force shutdown, power loss, unexpected exit) may not appear in the Clish "delete cluster member" options and cannot be deleted from the cluster configuration. |
|
PRJ-66015, |
Scalable Platforms |
Using a unique IP address with the Same VMAC feature enabled may cause connections to the Standby unique IP address to fail. |
|
PRJ-65524, |
Scalable Platforms |
Members added to an ElasticXL Security Group with the MDPS feature enabled may remain in the Down state because of a missing license. Licenses are not automatically distributed from the SMO member to newly added Security Group members. |
|
PRJ-65135, |
Scalable Platforms |
In DNS per-Virtual System (per-VS) mode, the DNSMASQ process may allocate ports outside the defined local port pool, potentially resulting in dropped DNS traffic. |
|
PRJ-66511, PMTR-121748 |
Scalable Platforms |
When MDPS Resource Separation is enabled, pushing policy under load may cause Single Management Object (SMO) to become unresponsive. |
|
PRJ-65993 |
Scalable Platforms |
When an upgraded site holds the initial connection, subsequent site failovers may cause out-of-state packet drops. |
|
PRJ-62900, |
Scalable Platforms |
In rare scenarios, enabling interface monitoring may cause the FWK process to exit. |
|
PRJ-64701, |
Scalable Platforms |
When "g_ClusterXL admin up" is triggered from a non-VS0 member (for example, VS1), the command fails and the upgraded site remains down with a pnote. |
|
PRJ-66122, |
Scalable Platforms |
BGP Sessions may fail to re-establish after SMO failover because of physical link failure. Refer to sk184371. |
|
PRJ-65767, |
Scalable Platforms |
After creating a light snapshot locally, the snapshot appears in the output of "show lightshots", but the /mnt/lightshot directory is empty. When attempting to export the snapshot using the "set snapshot-onetime export <Snapshot-Name> target local path <Local-Path>" command, the operation fails with the "General Rsync failure" error. |
|
PRJ-64393, |
Scalable Platforms |
When adding a subordinate to an LACP bond, a member may go down, which triggers a site failover. |
|
PRJ-65969, PMTR-92125 |
Scalable Platforms |
After creating a bridge interface using Gaia Portal and rebooting, the Security Gateway state is down. |
|
PRJ-63868, |
Scalable Platforms |
In a Maestro Security Group with a Threat Prevention policy applied, performing an SIC reset may cause non-Single Management Object (non-SMO) Security Group members to enter a Down state. The affected members display an Anti-Malware pnote as the reason for the state change. |
|
PRJ-65500, PMTR-122485 |
Scalable Platforms |
These actions applied through the Web Portal are not applied to all Security Group members, but only to the SMO:
|
|
PRJ-64390, |
Scalable Platforms |
In a Maestro deployment, the file $PPKDIR/conf/adpkern.conf may not be synchronized between Security Group members. |
|
PRJ-65545, PRHF-43121 |
Scalable Platforms |
In a rare scenario, when a VPN-corrected packet is dropped, the packet truncation warning "14 bytes missing" may be seen in the "tcpdump" output. |
|
PRJ-64316, PRHF-42296 |
Scalable Platforms |
When changing IP addresses according to sk179028, the ORCHD daemon may restart and cause communication issues. |
|
PRJ-65118, |
Scalable Platforms |
OSPF adjacencies repeatedly disconnect in a VSNext Cluster. Refer to sk184396. |
|
PRJ-65693, |
Scalable Platforms |
In VSX setup, a configuration note may be generated after a reboot, although the configuration is synchronized. |
|
PRJ-62049, PMTR-116460 |
Scalable Platforms |
On a Maestro dual-site environment, the sgm_pmd core dump file may be generated after the Jumbo Hotfix Accumulator installation. There is no functional impact. |
|
PRJ-65727, |
Scalable Platforms |
In VSNext setup, when a numbered VTI interface is created for a route-based VPN under VS0 and attached to a Virtual System, the interface appears correctly in the output of the "ifconfig" command under VS0 but becomes invisible in "ifconfig" within the assigned VS context, although it remains visible in the Clish commands output. |
|
PRJ-67210 |
Scalable Platforms |
Bond interface deletion or IP address change may cause a site failover. |
|
PRJ-65903 |
Scalable Platforms |
On Maestro running VSNext, when a Virtual Switch (VSW) shares a physical interface with a Virtual System (using different VLANs), the VSW's VLAN interface may not be propagated to the Maestro Hyperscale Orchestrator (MHO). |
|
PRJ-66558, |
Scalable Platforms |
In ElasticXL setups, it may not be possible to add a second Sync interface to the bonding group. |
|
PRJ-66521, |
Scalable Platforms |
Rebooting an Active member in the Single Management Object (SMO) role may trigger a brief connectivity loss. |
|
PRJ-67595, |
Scalable Platforms |
After joining a VSNext ElasticXL member to a second site via automation, a pnote for the management (magg1) interface appears under vs0 in "cphaprob -a if", instead of under Virtual Switch (vswOID) as expected. |
|
PRJ-65684, |
Carrier Security |
The FWK process may exit when GTP Intra Tunnel Inspection is enabled. |
|
PRJ-65687, |
Carrier Security |
GTP-U intra-tunnel packets may be dropped with "Packet too short" and "Invalid IP packet" errors in Bridge Mode, preventing proper inspection of encapsulated traffic. |
|
PRJ-66714, |
Carrier Security |
A "Tunnel established" message may be printed for rejected sessions. The issue is cosmetic. |
|
PRJ-60645, |
Carrier Security |
GTPv1 traffic may be dropped with code description "Invalid IE length value", "GTP info: Parsing IE type 133 failed". |