R82 Jumbo Hotfix Take 44

 

Note - This Take contains all fixes from all earlier Takes.

ID

Product

Description

Take 44

Released on 05 November 2025 and declared as Recommended on 23 November 2025

Take 44 - New Functionality

 

PRJ-62668,
PMTR-116161

Gaia OS

NEW: Hardened the authentication in the Gaia Cloning Group.

Important - After the installation of this Jumbo Hotfix Accumulator Take, you must follow these steps in each current Cloning Group:

  1. Make sure this Jumbo Hotfix Accumulator Take is installed on each Cloning Group Member

  2. On each of the Cloning Group Members, enter a Cloning Group password - enter the current password again or a new password.

  3. On each Cloning Group Member, re-synchronize the Cloning Group.

For more information, see the Gaia Administration Guide > Chapter "System Management" > Section "Cloning Group".

PRJ-62143,
PMTR-116780

CPView

NEW: Added the new Skyline metric "system.traffic.templates". Refer to the Skyline Administration Guide > Skyline Metrics Repository > System > Traffic.

Take 44 - Improvements and Resolved Issues

 

PRJ-63003,
PMTR-117744

Gaia OS

UPDATE: Check Point response to CVE-2025-32728 - The SSH directive "DisableForwarding" fails to disable "X11 Forwarding" and "Agent Forwarding". Refer to sk183394.

PRJ-63322,
MGMTTECH-2142

Security Management

UPDATE: A Security Management Server/Domain Management Server can now manage up to 1500 Security Gateways/Cluster members, allowing concurrent policy installation on all Security Gateways/Cluster members at once.

PRJ-59094,
PRHF-37840

Security Management

UPDATE: It is possible now to run the "show-packages" Management API command asynchronously using the "async-response" parameter.

PRJ-62339,
PMTR-115295

CPUSE

UPDATE: Added an HCP test to check whether the CPAC-2-100/25F, CPAC-2-100/25F-B, CPAC-2-40F-B, or CPAC-2-40F-C FW firmware is safe to update from R81.10 to a higher version. Refer to sk182403.

PRJ-62729,
PMTR-117738

Logging

UPDATE: Improved the design of the Security Checkup report in SmartView.

PRJ-62347,

PMTR-117114

Logging

UPDATE: The "tops" calculation method is now consistent between SmartConsole and Management CLI (mgmt_cli), so both tools produce matching results.

PRJ-61802,
PRHF-39531

Logging

UPDATE: The SOLR process (listening on port 8211) no longer accepts connections using the TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA cipher suite.

PRJ-62730,
PMTR-117759

Security Gateway

UPDATE: ISP Redundancy is now supported in VSNext Mode.

PRJ-62857,
PMTR-117982

Security Gateway

UPDATE: ICAP Server is now supported in VSNext Mode.

PRJ-62310

Identity Awareness

UPDATE: Added Identity Awareness metrics to Skyline. Refer to the Skyline Metrics Repository.

PRJ-62473,
PMTR-117312

IPS

UPDATE: HTTP/1.1 requests missing host headers are now processed by the non-compliant HTTP Protection feature (Strict Parsing option). Previously, such requests were dropped immediately. Refer to sk183569.

PRJ-60142,
PMTR-87460,

PRJ-60464,

PMTR-114416

SecureXL

UPDATE: SecureXL Rate Limiting rules for DoS Mitigation now support these parameters with automatic IP range updating enabled by default:

  • "cc:<COUNTRY_CODE>"

  • "asn:<AUTONOMOUS_SYSTEM_NUMBER>"

Refer to sk112454.

PRJ-62684,
PMTR-116747

CloudGuard Network

UPDATE: The Microsoft Azure Network Adapter (MANA) driver is now disabled by default. To enable it, refer to sk183754.

PRJ-61325,
PRHF-39697

CloudGuard Network

UPDATE: Updated supported regions in OCI (Oracle Cloud Infrastructure) data centers and changed the fetching domain logic.

PRJ-62731,
PMTR-117699

Scalable Platforms

UPDATE: CPView now monitors the Quantum Maestro backplane interfaces, Sync, and Chassis Internal Network (CIN) interfaces.

PRJ-61404,
PMTR-112536

Scalable Platforms

UPDATE: Increased the maximum supported number of Uplink interfaces from 64 to 99 on Maestro Orchestrator. Refer to Quantum Maestro Getting Started Guide.

PRJ-63900,
ODU-3127

Automatic Updates - CPView

UPDATE: Added Take 50 of CPquid (QUID) Release Updates. Refer to sk181458.

PRJ-63518,
ODU-3040

Automatic Updates - CPView

UPDATE: Added Take 201 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522.

PRJ-63522,

ODU-3064,

PRJ-63713,

ODU-3111

Automatic Updates - Web SmartConsole

UPDATE: New features and improvements are released in Take 149 and Take 150 via self-updatable package. Refer to sk170314.

PRJ-63782,

ODU-3095

Automatic Updates - Policy Insights

UPDATE: Added Take 76 of Policy Insights Release Updates. Refer to sk183421.

PRJ-62244,
PMTR-116383

Security Management

In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit, creating a core dump file because of the incorrect license update.

PRJ-61899,

PRHF-40211

Security Management

After editing an Interoperable Device object, the number of changes of the current session presented in SmartConsole may be inaccurate.

PRJ-57302,
PRHF-35813

Security Management

In rare scenarios, the User Check policy is not updated during the Accelerated Policy installation.

PRJ-62665,
PRHF-41094

Security Management

When Global Domain Assignment removal fails with the "Global Domain Assignment failed: object XXX could not be deleted because it is referenced by other objects" error, only a partial list of the referencing objects is displayed in the error message.

PRJ-59982,
PRHF-38312

Security Management

When migrating a Security Management Server to a Multi-Domain Security Management Server more than once, the operation fails with the "got at least one duplicate UID in requested list" error.

PRJ-63200,
PMTR-118466

Security Management

In rare scenarios, the FWM process may not start automatically after an unexpected exit.

PRJ-63490,
MGMTTECH-516

Security Management

Security Management Server upgrade may fail when running out of memory.

PRJ-62638,
PRHF-40995

Security Management

After an IPS update, reassigning global policies may take a long time.

PRJ-61806,
PRHF-40186

Security Management

In rare scenarios, discarding an old session fails with an "An internal error has occurred" message.

PRJ-60214,
PRHF-38893

Multi-Domain Security Management

In rare cases, Security Gateway licenses are not displayed in SmartUpdate when connected at the Multi-Domain Security Management level, despite being visible at the Domain level.

PRJ-61169,
PMTR-107107

SmartProvisioning

When updating a VSX cluster configured as a Central Office Gateway through SmartProvisioning, the SmartProvisioning application displays "Server is disconnected. SmartProvisioning will be terminated" and crashes.

PRJ-63721,

SMBGWY-12611

SmartProvisioning

In the SmartProvisioning application, the hardware for 2530, 2550, 2560, 2570, 2580 Quantum Spark appliances is displayed as 1100 appliances instead of their actual hardware. This may lead to policy installation failures.

PRJ-58825,

PRHF-29330

CPView

In CPView, under Network > Traffic in Concurrent Connections table, the amount of non-TCP connections is higher than shown in the output of the "fw ctl pstat" and "fw tab -t connections -s" command. The issue is cosmetic only.

PRJ-60005,
PRHF-38733

Security Gateway

Policy installation may fail when an updatable object is processed incorrectly.

PRJ-57689,
PRHF-29290

Security Gateway

Intermittent drops of transmission packets for "Streaming Engine: TCP Invalid Retransmission" causing HTTP loading issues. Refer to sk181282.

PRJ-61859,
PRHF-40380

Security Gateway

When configuring NAT64 rules for specific targets, the rules may fail to apply. Return traffic may be dropped.

PRJ-62017,
PRHF-40483

Security Gateway

The RAD daemon may unexpectedly exit on VSX Gateways.

PRJ-59451,
PRHF-38172

Security Gateway

An application may fail to match correctly when URL Filtering is configured in Hold Mode.

PRJ-61437,
PRHF-39815

Security Gateway

In Maestro Dual Site in the VSX VSLS mode, although CoreXL Dynamic Balancing is enabled, CoreXL does not change the number of Firewall instances and SND instances during traffic load. Refer to sk183485.

PRJ-62563,
PRHF-41025

Security Gateway

ICAP Server may fail to process multipart HTTP requests (when request body is split into multiple parts, each with its own headers and content).

PRJ-62895,
PRHF-41242

Security Gateway

HTTP/2 connection may fail when Threat Prevention Software Blades are enabled with Deep Inspection because of a protocol error. Refer to sk183990.

PRJ-58194,
PRHF-37156

Threat Prevention

In some scenarios, the Anti-Virus blade fails to parse and load external IoC observables of type IPv6. Refer to sk182947.

PRJ-63023,
PMTR-117719

Threat Prevention

In a rare scenario, the DLPU process may exit during traffic inspection when holding a connection.

PRJ-61619,
PRHF-40065

Threat Prevention

The testing of external IoC feed connectivity from SmartConsole fails because of improper retrieval of configuration values.

PRJ-60587,
PRHF-38756

Identity Awareness

Users on shared Servers (MUH v1 and v2) cannot access resources they should have permission to use. When this happens, the Security Gateway fails to recognize the user's identity and does not apply the correct access permissions. Refer to sk183268.

PRJ-60983,
PRHF-39261

Identity Awareness

Entra ID (Azure ID) authorization may fail when more than one tenant is configured for authorization and the "fetch-user-group"s or "fetch-machine-groups" mode is enabled.

PRJ-58059,
PRHF-36813

IPS

In rare scenarios, the source IP shown in the IPS detection log is invalid. Refer to sk182914.

PRJ-62812,
PRHF-41088

IPS

When using Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails.

PRJ-61303,
PRHF-39517

Anti-Virus

In a rare scenario, the memory consumption of the DLPU process continuously increases.

PRJ-63062,
PMTR-118347

Anti-Virus

In a rare scenario, the Security Gateway may crash during traffic inspection.

PRJ-63026,

PMTR-116661

Anti-Virus

In some scenarios, the Anti-Virus Software Blade reaches a timeout when inspecting Domains because of latency in the RAD daemon.

PRJ-62687,
PRHF-40994

ClusterXL

Modifying the number of CoreXL instances in a VSLS cluster containing three or more members causes traffic interruption on the updated Virtual System.

PRJ-60349,
PMTR-113063

ClusterXL

In cluster environments using Bonds and VLANs, the ClusterXL Monitoring command "cphaprob stat" (Expert Mode) and the Clish command "show cluster state" may display an incorrect failover reason when an interface disconnects or a link goes down.

PRJ-59745,
PRHF-38554

ClusterXL

In a ClusterXL setup, a rare performance issue may be caused by policy installation failure.

PRJ-61110,
PMTR-115083

ClusterXL

A rare race condition occurs during "cpstart" command execution in VSX environments that prevents proper sync interface installation, specifically in the cluster flow process, causing synchronization problems between cluster members.

PRJ-61740,
PMTR-115808

ClusterXL

An FWK core file is generated when configuring a Bridge Group with more than two interfaces.

PRJ-61583,
PMTR-115396

ClusterXL

6in4 tunnels are shown in Down state when monitored using the "cphaprob -a if" command.

PRJ-62302,

PMTR-115027

ClusterXL

In ClusterXL High Availability (HA), in some scenarios, the Active cluster member stops sending Cluster Control Protocol (CCP) heartbeats, and the Standby member may misinterpret this as an Interface Active Check (IAC) failure.

PRJ-62201,
PMTR-116890

SecureXL

SecureXL does not immediately send packets to the appropriate handler when it receives packets from a Virtual Router or Virtual Switch and fails to forward them to the connected Virtual System. This delay causes significant routing delays and potential routing errors on VSX Security Gateways.

PRJ-62395,
PMTR-117108

SecureXL

The Security Gateway can take a significant amount of time to boot up when SecureXL User Mode (UPPAK) is enabled.

PRJ-63054,
PMTR-118395

SecureXL

The link on the 4-Port 10/25GbE CX7 Lightspeed Network Interface Card may fail to establish when multiple 4-port CX7 Lightspeed Network Interface Cards are installed.

PRJ-60628,
PMTR-114633

SecureXL

Memory corruption may occur in rare VPN routing scenarios.

PRJ-60897,
PMTR-111305

SecureXL

When SecureXL User Mode (UPPAK) is enabled, there can be a significant latency on a Security Gateway when opening an FTP data connection.

PRJ-62888,
PRHF-40086

SecureXL

In cluster environments, on the Active member, the USIM_x86 process may experience frequent core dumps, causing Security Gateway instability.

PRJ-62576,
PMTR-109269

SecureXL

The USIM core file may be generated when rebooting the Security Gateway.

PRJ-62588,
PRHF-41038

CoreXL

In rare scenarios, CoreXL Firewall instances may become fully utilized because of resource contention from the Parallel Processing Engine (PPE). Refer to sk184183.

PRJ-62851,
PRHF-31534

Routing

In a specific scenario, where SSM static groups are configured on an interface, after a failover, these IP addresses do not appear as Outgoing Interfaces (OIFs).

PRJ-63118,
PRHF-41346

Routing

ASE LSAs for routes sharing the same prefix but having different mask lengths may not be re-originated correctly when a topology change restores previously unreachable routes to a reachable state.

PRJ-60970,

PMTR-117291

VPN

IKEv2 negotiation and Child SA re-keying processes may experience instability during Remote Access VPN connections.

PRJ-61918,
PRHF-40237,

PMTR-116423

VPN

In VSX environments with VS and VR configurations, when Policy-Based Routing (PBR) is configured on the Virtual Router, Remote Access VPN traffic bypasses the PBR table and uses the default route instead.

PRJ-62228,
PMTR-110683

VSX

The "vsx-provisioning-tool" CLI command returns asynchronous task IDs before it is ready for monitoring, causing Terraform and similar automation tools to immediately fail when attempting to track task status.

PRJ-63818

VSX

In a rare scenario, the FWM process may exit on the Security Management Server managing VSX Gateways/Clusters.

PRJ-63287

VSNext

After installing a Jumbo Hotfix Accumulator R82 Take 14 and higher, assigning an IPv6 address to the SMO interface fails.

PRJ-61593,
PRHF-40115

Gaia OS

  • The sysLocation OID (1.3.6.1.2.1.1.6.0) returns "UNKNOWN", even though the value is configured in the SNMP settings and exists in the Gaia database (/config/active).

  • When editing sysLocation or sysContact using the SNMP configuration interface, the Gaia database is updated, but the SNMP configuration file is not updated.

PRJ-62735,
PMTR-117714

Gaia OS

When using Resource Separation on MDPS on Maestro, and the Security Gateway is under extreme load, policy installation fails, although the Resource Separation should handle the load.

PRJ-62585,
PRHF-41027

Gaia OS

The Security Management Server hangs during a Backup operation because of endless SSH handshake retry, making it impossible to access via SSH or CLI.

PRJ-63279

Gaia OS

The "See more information in Gaia updates" link in CPUSE is broken.

PRJ-59688,
PRHF-38276

Gaia OS

HealthCheck Point (HCP) reports "rx_length_errors" for Security Group Members. Refer to sk183040.

PRJ-63584,

PRHF-41381

Gaia OS

SNMP query for "vsxStatusInterfaceRxBytes" and "vsxStatusInterfaceTxBytes" OIDs returns "0". Refer to sk183871.

PRJ-62997,

PRHF-41344

Gaia OS

The "show syslog logs" Clish command returns the "cat: /var/log/messages*: No such file or directory" error even though these files exist.

PRJ-61994,
PRHF-39856

CloudGuard Network

In rare scenarios, in a VSX Cluster running in VSLS Mode with Identity Sharing configuration, CloudGuard Controller may send identities to the VS IP address and not the Cluster IP address, causing Security Gateway update failures.

PRJ-62798,
PRHF-41139

CloudGuard Network

In the Smart-1 Cloud environment, in the Gateways & Servers view, newly provisioned CloudGuard Autoscaling Security Gateways may be shown as disconnected.

PRJ-63452,

PRHF-41488

SD-WAN

In rare scenarios, after an upgrade, installing an Access Control policy in an SD-WAN cluster environment causes the Standby member to transmit probes and may cause traffic disruption.

PRJ-61793,

SDWANGW-4359

SD-WAN

In rare scenarios, after an upgrade or "cpstop;cpstart", SD-WAN policy installation fails with "Error code: 2-4-2000279".

PRJ-58056,

PRHF-37015

Scalable Platforms

When handling multiple shared uplinks across numerous interfaces, errors related to LACP bond uplink updates may be printed in logs.

PRJ-59278,
PMTR-111692

Scalable Platforms

Gaia database lock on a Maestro Security Group configured with Management Aggregation (MAGG) is lost when using API or Gaia gClish to add a new Management interface to the Security Group. Refer to sk183031.

PRJ-58671,
PMTR-110323

Scalable Platforms

When the Maestro Fastforward feature is enabled, rebooting a member may cause the member to be down because of the policy installation failure and the "Site HA module not started" error may be displayed.

PRJ-59845,
PRHF-38430

Scalable Platforms

In a Security Group in VSX mode, if an interface's link state changes during boot, there may be a delay in updating the link state. This delay can cause traffic interruption on that interface.

PRJ-62409,
PMTR-117173

Scalable Platforms

Security Group members may reboot because of cp-nano database entries. The /var/log/configuration_reboot_reason.log may show "process:cp-nano-watchdog" when database entries exist only on the local member or only on the SMO member.

PRJ-62804,
PMTR-117683

Scalable Platforms

In Maestro Security Group or Scalable Chassis Security Group with VSX with many Virtual Systems (VSs), boot may take a long time when the database file (/config/active) is very large (200,000 lines or more).

PRJ-63208,
PMTR-118598

Scalable Platforms

During an upgrade process, a member gets stuck in the DOWN(TpPolicy) state although Threat Prevention is not configured in the environment.

PRJ-59791,
PMTR-105687

Scalable Platforms

On the Mobile Access Portal, SAML authentication does not display the login fields in a Maestro Security Group in the VSX. Refer to sk182548.

PRJ-59581,
PMTR-112587

Scalable Platforms

The minimum and maximum thresholds are incorrectly reported (the values are flipped) for PMIC-3 1V sensor readings in MHO-175.

PRJ-62759,
PMTR-117801

Scalable Platforms

Unnecessary reboots may be caused by differences in the database's scheduled backup entries (creation and update time) between the Security Group members.

PRJ-63448,
PRHF-23287

Scalable Platforms

After adding a custom command in Gaia gClish with the "add command", the custom command is available only on the Single Management Object (SMO). Refer to sk178671.

PRJ-58146,
PMTR-98993

Scalable Platforms

In ElasticXL, each Security Group Member allocates only 1785 ports for Hide NAT instead of approximately 16600 ports. Refer to sk183481.

PRJ-63944,

PMTR-119974

Scalable Platforms

Quantum Maestro Orchestrator Gaia WebUI may become inaccessible after installing R82 Jumbo Hotfix Accumulator Take 41 or Take 43.

See the Critical Information section.

PRJ-58127,

PMTR-109620

Scalable Platforms

In rare scenarios, authentication between MHOs is not established. Trying to establish authentication manually fails with the "TrustEstablishmentError: Failed to set up communication user on host 1_1: invalid literal for int() with base 10" error.

PRJ-59939,
PRHF-38620

Carrier Security

Security Gateway drops GTP traffic with the log "Message includes unexpected information element type". Refer to sk106469.