R82 Jumbo Hotfix Take 44
|
|
Note - This Take contains all fixes from all earlier Takes. |
|
ID |
Product |
Description |
|---|---|---|
|
Take 44 Released on 05 November 2025 and declared as Recommended on 23 November 2025 |
||
|
Take 44 - New Functionality
|
||
|
PRJ-62668, |
Gaia OS |
NEW: Hardened the authentication in the Gaia Cloning Group. Important - After the installation of this Jumbo Hotfix Accumulator Take, you must follow these steps in each current Cloning Group:
For more information, see the Gaia Administration Guide > Chapter "System Management" > Section "Cloning Group". |
|
PRJ-62143, |
CPView |
NEW: Added the new Skyline metric "system.traffic.templates". Refer to the Skyline Administration Guide > Skyline Metrics Repository > System > Traffic. |
|
Take 44 - Improvements and Resolved Issues
|
||
|
PRJ-63003, |
Gaia OS |
UPDATE: Check Point response to CVE-2025-32728 - The SSH directive "DisableForwarding" fails to disable "X11 Forwarding" and "Agent Forwarding". Refer to sk183394. |
|
PRJ-63322, |
Security Management |
UPDATE: A Security Management Server/Domain Management Server can now manage up to 1500 Security Gateways/Cluster members, allowing concurrent policy installation on all Security Gateways/Cluster members at once. |
|
PRJ-59094, |
Security Management |
UPDATE: It is possible now to run the "show-packages" Management API command asynchronously using the "async-response" parameter. |
|
PRJ-62339, |
CPUSE |
UPDATE: Added an HCP test to check whether the CPAC-2-100/25F, CPAC-2-100/25F-B, CPAC-2-40F-B, or CPAC-2-40F-C FW firmware is safe to update from R81.10 to a higher version. Refer to sk182403. |
|
PRJ-62729, |
Logging |
UPDATE: Improved the design of the Security Checkup report in SmartView. |
|
PRJ-62347, PMTR-117114 |
Logging |
UPDATE: The "tops" calculation method is now consistent between SmartConsole and Management CLI (mgmt_cli), so both tools produce matching results. |
|
PRJ-61802, |
Logging |
UPDATE: The SOLR process (listening on port 8211) no longer accepts connections using the TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA cipher suite. |
|
PRJ-62730, |
Security Gateway |
UPDATE: ISP Redundancy is now supported in VSNext Mode. |
|
PRJ-62857, |
Security Gateway |
UPDATE: ICAP Server is now supported in VSNext Mode. |
|
PRJ-62310 |
Identity Awareness |
UPDATE: Added Identity Awareness metrics to Skyline. Refer to the Skyline Metrics Repository. |
|
PRJ-62473, |
IPS |
UPDATE: HTTP/1.1 requests missing host headers are now processed by the non-compliant HTTP Protection feature (Strict Parsing option). Previously, such requests were dropped immediately. Refer to sk183569. |
|
PRJ-60142, PRJ-60464, PMTR-114416 |
SecureXL |
UPDATE: SecureXL Rate Limiting rules for DoS Mitigation now support these parameters with automatic IP range updating enabled by default:
Refer to sk112454. |
|
PRJ-62684, |
CloudGuard Network |
UPDATE: The Microsoft Azure Network Adapter (MANA) driver is now disabled by default. To enable it, refer to sk183754. |
|
PRJ-61325, |
CloudGuard Network |
UPDATE: Updated supported regions in OCI (Oracle Cloud Infrastructure) data centers and changed the fetching domain logic. |
|
PRJ-62731, |
Scalable Platforms |
UPDATE: CPView now monitors the Quantum Maestro backplane interfaces, Sync, and Chassis Internal Network (CIN) interfaces. |
|
PRJ-61404, |
Scalable Platforms |
UPDATE: Increased the maximum supported number of Uplink interfaces from 64 to 99 on Maestro Orchestrator. Refer to Quantum Maestro Getting Started Guide. |
|
PRJ-63900, |
Automatic Updates - CPView |
UPDATE: Added Take 50 of CPquid (QUID) Release Updates. Refer to sk181458. |
|
PRJ-63518, |
Automatic Updates - CPView |
UPDATE: Added Take 201 of CPotelcol (OpenTelemetry Collector) Release Updates. Refer to sk180522. |
|
PRJ-63522, ODU-3064, PRJ-63713, ODU-3111 |
Automatic Updates - Web SmartConsole |
UPDATE: New features and improvements are released in Take 149 and Take 150 via self-updatable package. Refer to sk170314. |
|
PRJ-63782, ODU-3095 |
Automatic Updates - Policy Insights |
UPDATE: Added Take 76 of Policy Insights Release Updates. Refer to sk183421. |
|
PRJ-62244, |
Security Management |
In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit, creating a core dump file because of the incorrect license update. |
|
PRJ-61899, PRHF-40211 |
Security Management |
After editing an Interoperable Device object, the number of changes of the current session presented in SmartConsole may be inaccurate. |
|
PRJ-57302, |
Security Management |
In rare scenarios, the User Check policy is not updated during the Accelerated Policy installation. |
|
PRJ-62665, |
Security Management |
When Global Domain Assignment removal fails with the "Global Domain Assignment failed: object XXX could not be deleted because it is referenced by other objects" error, only a partial list of the referencing objects is displayed in the error message. |
|
PRJ-59982, |
Security Management |
When migrating a Security Management Server to a Multi-Domain Security Management Server more than once, the operation fails with the "got at least one duplicate UID in requested list" error. |
|
PRJ-63200, |
Security Management |
In rare scenarios, the FWM process may not start automatically after an unexpected exit. |
|
PRJ-63490, |
Security Management |
Security Management Server upgrade may fail when running out of memory. |
|
PRJ-62638, |
Security Management |
After an IPS update, reassigning global policies may take a long time. |
|
PRJ-61806, |
Security Management |
In rare scenarios, discarding an old session fails with an "An internal error has occurred" message. |
|
PRJ-60214, |
Multi-Domain Security Management |
In rare cases, Security Gateway licenses are not displayed in SmartUpdate when connected at the Multi-Domain Security Management level, despite being visible at the Domain level. |
|
PRJ-61169, |
SmartProvisioning |
When updating a VSX cluster configured as a Central Office Gateway through SmartProvisioning, the SmartProvisioning application displays "Server is disconnected. SmartProvisioning will be terminated" and crashes. |
|
PRJ-63721, SMBGWY-12611 |
SmartProvisioning |
In the SmartProvisioning application, the hardware for 2530, 2550, 2560, 2570, 2580 Quantum Spark appliances is displayed as 1100 appliances instead of their actual hardware. This may lead to policy installation failures. |
|
PRJ-58825, PRHF-29330 |
CPView |
In CPView, under Network > Traffic in Concurrent Connections table, the amount of non-TCP connections is higher than shown in the output of the "fw ctl pstat" and "fw tab -t connections -s" command. The issue is cosmetic only. |
|
PRJ-60005, |
Security Gateway |
Policy installation may fail when an updatable object is processed incorrectly. |
|
PRJ-57689, |
Security Gateway |
Intermittent drops of transmission packets for "Streaming Engine: TCP Invalid Retransmission" causing HTTP loading issues. Refer to sk181282. |
|
PRJ-61859, |
Security Gateway |
When configuring NAT64 rules for specific targets, the rules may fail to apply. Return traffic may be dropped. |
|
PRJ-62017, |
Security Gateway |
The RAD daemon may unexpectedly exit on VSX Gateways. |
|
PRJ-59451, |
Security Gateway |
An application may fail to match correctly when URL Filtering is configured in Hold Mode. |
|
PRJ-61437, |
Security Gateway |
In Maestro Dual Site in the VSX VSLS mode, although CoreXL Dynamic Balancing is enabled, CoreXL does not change the number of Firewall instances and SND instances during traffic load. Refer to sk183485. |
|
PRJ-62563, |
Security Gateway |
ICAP Server may fail to process multipart HTTP requests (when request body is split into multiple parts, each with its own headers and content). |
|
PRJ-62895, |
Security Gateway |
HTTP/2 connection may fail when Threat Prevention Software Blades are enabled with Deep Inspection because of a protocol error. Refer to sk183990. |
|
PRJ-58194, |
Threat Prevention |
In some scenarios, the Anti-Virus blade fails to parse and load external IoC observables of type IPv6. Refer to sk182947. |
|
PRJ-63023, |
Threat Prevention |
In a rare scenario, the DLPU process may exit during traffic inspection when holding a connection. |
|
PRJ-61619, |
Threat Prevention |
The testing of external IoC feed connectivity from SmartConsole fails because of improper retrieval of configuration values. |
|
PRJ-60587, |
Identity Awareness |
Users on shared Servers (MUH v1 and v2) cannot access resources they should have permission to use. When this happens, the Security Gateway fails to recognize the user's identity and does not apply the correct access permissions. Refer to sk183268. |
|
PRJ-60983, |
Identity Awareness |
Entra ID (Azure ID) authorization may fail when more than one tenant is configured for authorization and the "fetch-user-group"s or "fetch-machine-groups" mode is enabled. |
|
PRJ-58059, |
IPS |
In rare scenarios, the source IP shown in the IPS detection log is invalid. Refer to sk182914. |
|
PRJ-62812, |
IPS |
When using Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails. |
|
PRJ-61303, |
Anti-Virus |
In a rare scenario, the memory consumption of the DLPU process continuously increases. |
|
PRJ-63062, |
Anti-Virus |
In a rare scenario, the Security Gateway may crash during traffic inspection. |
|
PRJ-63026, PMTR-116661 |
Anti-Virus |
In some scenarios, the Anti-Virus Software Blade reaches a timeout when inspecting Domains because of latency in the RAD daemon. |
|
PRJ-62687, |
ClusterXL |
Modifying the number of CoreXL instances in a VSLS cluster containing three or more members causes traffic interruption on the updated Virtual System. |
|
PRJ-60349, |
ClusterXL |
In cluster environments using Bonds and VLANs, the ClusterXL Monitoring command "cphaprob stat" (Expert Mode) and the Clish command "show cluster state" may display an incorrect failover reason when an interface disconnects or a link goes down. |
|
PRJ-59745, |
ClusterXL |
In a ClusterXL setup, a rare performance issue may be caused by policy installation failure. |
|
PRJ-61110, |
ClusterXL |
A rare race condition occurs during "cpstart" command execution in VSX environments that prevents proper sync interface installation, specifically in the cluster flow process, causing synchronization problems between cluster members. |
|
PRJ-61740, |
ClusterXL |
An FWK core file is generated when configuring a Bridge Group with more than two interfaces. |
|
PRJ-61583, |
ClusterXL |
6in4 tunnels are shown in Down state when monitored using the "cphaprob -a if" command. |
|
PRJ-62302, PMTR-115027 |
ClusterXL |
In ClusterXL High Availability (HA), in some scenarios, the Active cluster member stops sending Cluster Control Protocol (CCP) heartbeats, and the Standby member may misinterpret this as an Interface Active Check (IAC) failure. |
|
PRJ-62201, |
SecureXL |
SecureXL does not immediately send packets to the appropriate handler when it receives packets from a Virtual Router or Virtual Switch and fails to forward them to the connected Virtual System. This delay causes significant routing delays and potential routing errors on VSX Security Gateways. |
|
PRJ-62395, |
SecureXL |
The Security Gateway can take a significant amount of time to boot up when SecureXL User Mode (UPPAK) is enabled. |
|
PRJ-63054, |
SecureXL |
The link on the 4-Port 10/25GbE CX7 Lightspeed Network Interface Card may fail to establish when multiple 4-port CX7 Lightspeed Network Interface Cards are installed. |
|
PRJ-60628, |
SecureXL |
Memory corruption may occur in rare VPN routing scenarios. |
|
PRJ-60897, |
SecureXL |
When SecureXL User Mode (UPPAK) is enabled, there can be a significant latency on a Security Gateway when opening an FTP data connection. |
|
PRJ-62888, |
SecureXL |
In cluster environments, on the Active member, the USIM_x86 process may experience frequent core dumps, causing Security Gateway instability. |
|
PRJ-62576, |
SecureXL |
The USIM core file may be generated when rebooting the Security Gateway. |
|
PRJ-62588, |
CoreXL |
In rare scenarios, CoreXL Firewall instances may become fully utilized because of resource contention from the Parallel Processing Engine (PPE). Refer to sk184183. |
|
PRJ-62851, |
Routing |
In a specific scenario, where SSM static groups are configured on an interface, after a failover, these IP addresses do not appear as Outgoing Interfaces (OIFs). |
|
PRJ-63118, |
Routing |
ASE LSAs for routes sharing the same prefix but having different mask lengths may not be re-originated correctly when a topology change restores previously unreachable routes to a reachable state. |
|
PRJ-60970, PMTR-117291 |
VPN |
IKEv2 negotiation and Child SA re-keying processes may experience instability during Remote Access VPN connections. |
|
PRJ-61918, PMTR-116423 |
VPN |
In VSX environments with VS and VR configurations, when Policy-Based Routing (PBR) is configured on the Virtual Router, Remote Access VPN traffic bypasses the PBR table and uses the default route instead. |
|
PRJ-62228, |
VSX |
The "vsx-provisioning-tool" CLI command returns asynchronous task IDs before it is ready for monitoring, causing Terraform and similar automation tools to immediately fail when attempting to track task status. |
|
PRJ-63818 |
VSX |
In a rare scenario, the FWM process may exit on the Security Management Server managing VSX Gateways/Clusters. |
|
PRJ-63287 |
VSNext |
After installing a Jumbo Hotfix Accumulator R82 Take 14 and higher, assigning an IPv6 address to the SMO interface fails. |
|
PRJ-61593, |
Gaia OS |
|
|
PRJ-62735, |
Gaia OS |
When using Resource Separation on MDPS on Maestro, and the Security Gateway is under extreme load, policy installation fails, although the Resource Separation should handle the load. |
|
PRJ-62585, |
Gaia OS |
The Security Management Server hangs during a Backup operation because of endless SSH handshake retry, making it impossible to access via SSH or CLI. |
|
PRJ-63279 |
Gaia OS |
The "See more information in Gaia updates" link in CPUSE is broken. |
|
PRJ-59688, |
Gaia OS |
HealthCheck Point (HCP) reports "rx_length_errors" for Security Group Members. Refer to sk183040. |
|
PRJ-63584, PRHF-41381 |
Gaia OS |
SNMP query for "vsxStatusInterfaceRxBytes" and "vsxStatusInterfaceTxBytes" OIDs returns "0". Refer to sk183871. |
|
PRJ-62997, PRHF-41344 |
Gaia OS |
The "show syslog logs" Clish command returns the "cat: /var/log/messages*: No such file or directory" error even though these files exist. |
|
PRJ-61994, |
CloudGuard Network |
In rare scenarios, in a VSX Cluster running in VSLS Mode with Identity Sharing configuration, CloudGuard Controller may send identities to the VS IP address and not the Cluster IP address, causing Security Gateway update failures. |
|
PRJ-62798, |
CloudGuard Network |
In the Smart-1 Cloud environment, in the Gateways & Servers view, newly provisioned CloudGuard Autoscaling Security Gateways may be shown as disconnected. |
|
PRJ-63452, PRHF-41488 |
SD-WAN |
In rare scenarios, after an upgrade, installing an Access Control policy in an SD-WAN cluster environment causes the Standby member to transmit probes and may cause traffic disruption. |
|
PRJ-61793, SDWANGW-4359 |
SD-WAN |
In rare scenarios, after an upgrade or "cpstop;cpstart", SD-WAN policy installation fails with "Error code: 2-4-2000279". |
|
PRJ-58056, PRHF-37015 |
Scalable Platforms |
When handling multiple shared uplinks across numerous interfaces, errors related to LACP bond uplink updates may be printed in logs. |
|
PRJ-59278, |
Scalable Platforms |
Gaia database lock on a Maestro Security Group configured with Management Aggregation (MAGG) is lost when using API or Gaia gClish to add a new Management interface to the Security Group. Refer to sk183031. |
|
PRJ-58671, |
Scalable Platforms |
When the Maestro Fastforward feature is enabled, rebooting a member may cause the member to be down because of the policy installation failure and the "Site HA module not started" error may be displayed. |
|
PRJ-59845, |
Scalable Platforms |
In a Security Group in VSX mode, if an interface's link state changes during boot, there may be a delay in updating the link state. This delay can cause traffic interruption on that interface. |
|
PRJ-62409, |
Scalable Platforms |
Security Group members may reboot because of cp-nano database entries. The /var/log/configuration_reboot_reason.log may show "process:cp-nano-watchdog" when database entries exist only on the local member or only on the SMO member. |
|
PRJ-62804, |
Scalable Platforms |
In Maestro Security Group or Scalable Chassis Security Group with VSX with many Virtual Systems (VSs), boot may take a long time when the database file (/config/active) is very large (200,000 lines or more). |
|
PRJ-63208, |
Scalable Platforms |
During an upgrade process, a member gets stuck in the DOWN(TpPolicy) state although Threat Prevention is not configured in the environment. |
|
PRJ-59791, |
Scalable Platforms |
On the Mobile Access Portal, SAML authentication does not display the login fields in a Maestro Security Group in the VSX. Refer to sk182548. |
|
PRJ-59581, |
Scalable Platforms |
The minimum and maximum thresholds are incorrectly reported (the values are flipped) for PMIC-3 1V sensor readings in MHO-175. |
|
PRJ-62759, |
Scalable Platforms |
Unnecessary reboots may be caused by differences in the database's scheduled backup entries (creation and update time) between the Security Group members. |
|
PRJ-63448, |
Scalable Platforms |
After adding a custom command in Gaia gClish with the "add command", the custom command is available only on the Single Management Object (SMO). Refer to sk178671. |
|
PRJ-58146, |
Scalable Platforms |
In ElasticXL, each Security Group Member allocates only 1785 ports for Hide NAT instead of approximately 16600 ports. Refer to sk183481. |
|
PRJ-63944, PMTR-119974 |
Scalable Platforms |
Quantum Maestro Orchestrator Gaia WebUI may become inaccessible after installing R82 Jumbo Hotfix Accumulator Take 41 or Take 43. See the Critical Information section. |
|
PRJ-58127, PMTR-109620 |
Scalable Platforms |
In rare scenarios, authentication between MHOs is not established. Trying to establish authentication manually fails with the "TrustEstablishmentError: Failed to set up communication user on host 1_1: invalid literal for int() with base 10" error. |
|
PRJ-59939, |
Carrier Security |
Security Gateway drops GTP traffic with the log "Message includes unexpected information element type". Refer to sk106469. |