R81.20 Jumbo Hotfix Take 122
R81.20 Jumbo Hotfix Take 122
| Download Jumbo Hotfix Accumulator Takes | Download Previous Recommended Takes |
| Note - This Take contains all fixes from all earlier Takes. |
Download CSV
| ID | Product | Description |
|---|---|---|
| Take 122 Released on 07 January 2026 |
||
| Take 122 - New Functionality | ||
| PRJ-64538, PMTR-119998 |
VPN | NEW: It is now possible to add host/range/network objects for split tunnel on exclusion/inclusion options. Refer to R81.20 Remote Access VPN Administration Guide > Dynamic Split Tunneling for SaaS Using Updatable Objects. |
| Take 122 - Improvements and Resolved Issues | ||
| PRJ-62102, PMTR-116716 |
Harmony Endpoint | UPDATE: Check Point response to Apache Tomcat CVEs on Harmony Endpoint Security Management Server - CVE-2025-31651 and CVE-2025-31650. Refer to sk183615. |
| PRJ-62360, PRHF-40849 |
Security Management | UPDATE: Policy verification error messages are now improved for scenarios when verification fails because of updatable objects, dynamic objects, and Domain objects in a Remote Access VPN community. |
| PRJ-63718, PMTR-119125 |
Gaia OS | UPDATE: Added ability to use the '.', '@', '~', ',' characters for non-local users using the Clish command " set aaa allow-unsanitized-username enable <all/dot/at/comma/tilde>". Refer to sk183201. |
| PRJ-64184, PMTR-118961 |
Security Management | UPDATE: JRE is updated from version 8.0_8.35 to version 8.0_8.50 |
| PRJ-63472, PMTR-117101 |
Security Management | UPDATE: SmartTasks are now supported in the System Domain of Multi-Domain Security Management. This feature enables the automation of system-domain operations, reducing manual tasks and enhancing reliability. Refer to R82 Quantum Security Management Administration Guide > Preferences and Management Settings > SmartTasks. |
| PRJ-63365, MGMTTECH-621 |
Security Management | UPDATE: Enhanced packet search in SmartConsole with three IP address modes: - "Exact": Returns rules where the IP address/network in the rule is exactly the same as the IP address/network in the search. - "Containing": Returns rules where the IP address/network you searched for contains the IP address/network of the rule. - "Contained in": Returns rules where the IP address/network you searched for is contained within the IP address/network of the rule. |
| PRJ-63735, PMTR-119349 |
Security Gateway | UPDATE: Added a new kernel parameter " up_rulebase_run_implied_rules" (enabled by default - "1"). Setting to "0" disables execution of implied rules in the Access Control Rule Base. |
| PRJ-59065, PRHF-32989 |
CloudGuard Network | UPDATE: CloudGuard Controller status in SmartConsole is now automatically updated. |
| PRJ-65287, ODU-3387 |
Automatic Updates - Web SmartConsole | UPDATE: New features and improvements are released in Take 157 via self-updatable package. Refer to sk170314. |
| PRJ-62554, PRHF-40800 |
Security Management | In SmartConsole, if the Task pane has no tasks to show, the Task pane incorrectly shows an " Error retrieving results" message. |
| PRJ-62992, PRHF-41249 |
Security Management | Regenerating a token on a Security Gateway Smart-1 Cloud may fail with an unclear validation message " No error in result from fwm command: [gen-pki-cert-req]". |
| PRJ-62777, PRHF-41168 |
Security Management | In rare scenarios, High Availability synchronization might fail with a connectivity error. |
| PRJ-60374, PRHF-38836 |
Security Management | VMcore crashes may occur with core dumps of the LOG_INDEXER, LOG_EXPORTER, and JAVA processes on the Security Management Server, causing high CPU utilization. |
| PRJ-62550, PMTR-117467 |
Security Management | In rare scenarios, the Security Management Server fails to start after performing a "Revert to Revision" operation. |
| PRJ-64884, PRHF-42660 |
Security Management | In rare scenarios, login using Management API fails with a timeout and the " api status" command returns " API readiness test failed" message. Refer to sk184342. |
| PRJ-60526, PRHF-38743 |
Security Management | When running the " mgmt_cli -r true gaia-api/set-ntp target pocsms enabled true --format json" Management API command, the output is not the same as running it directly from Gaia API. Refer to sk184510. |
| PRJ-62531, PRHF-40750 |
Security Management | Importing a large policy package fails with validation and API errors on the Multi-Domain Security Management Server. Refer to sk183697. |
| PRJ-65808, PRHF-43517 |
Security Management | The " show-packages" Management API command executed with " async-response" parameter may fail with " generic_err_invalid_parameter_name". |
| PRJ-60488, PRHF-39032 |
Security Management | In some scenarios, when Configuration Sharing is enabled, audit logs may show failed login attempts to the CPM Server after publishing changes. |
| PRJ-61808, PRHF-40205 |
Security Management | When a user with read-only permissions for Global Domains (for example, a user with the Global Manager profile) connects to the System Domain in SmartConsole, the SmartConsole status bar incorrectly displays the user as having read-write permissions. |
| PRJ-59750, PRHF-38490 |
Security Management | In some scenarios, creating a Standby Domain Security Management Server fails with a " You do not have the permissions to complete this action" message. |
| PRJ-59515, PRHF-37612 |
Security Management | In rare scenarios, after an IPS update, all protections are set to Staging mode in Threat Profiles configured with "Set activation as Staging mode". |
| PRJ-62194, PMTR-116551 |
Security Management | When using the " set-threat-protection" Management API command, overriding either the packet-capture or track values also overrides the action field and sets it to "inactive". |
| PRJ-64739, PMTR-121337 |
Security Management | When the Dynamic URL List feature is enabled, Security Gateway may crash during policy installation. See the Critical Information section. |
| PRJ-61327, PRHF-39881 |
Security Management | In rare scenarios, an IPS update fails because of duplicate objects. |
| PRJ-63543, PMTR-119007 |
Multi-Domain Security Management | On the Multi-Domain Security Management Server, when staging is cleared for an IPS protection in the Global Domain, any staging configuration for that same protection in the local Domain (within a Global profile) remains unchanged during policy assignment. |
| PRJ-64104, PMTR-120043 |
Multi-Domain Security Management | The Configuration Sharing feature does not work as expected with VSX Gateways on a specific Domain. |
| PRJ-65235, PMTR-121265 |
Multi-Domain Security Management | In certain scenarios, an upgrade of the Multi-Domain Security Management Server may fail with a " During synchronization a new object was found through a relationship that was not marked cascade PERSIST" message. - The fix will only be applied if the upgrade to this Jumbo Hotfix Take is done using a Blink image or with the Advanced Upgrade method. |
| PRJ-63792, PRHF-41803 |
Multi-Domain Security Management | On Multi-Domain Security Management Servers, custom Compliance Software Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level. |
| PRJ-55866, PRHF-34777 |
CPView | CPView may display incorrect concurrent connection statistics (negative values) because of improper aggregation of connection data during a Cluster failover. |
| PRJ-64040, PMTR-118032 |
Security Gateway | In a rare scenario, when running " cpstart;cpstop", the Security Gateway may crash. |
| PRJ-62131, PRHF-40631 |
Security Gateway | The FWK memory leak may occur during FTP connections with high file volume. Refer to sk183662. |
| PRJ-56832, PRHF-35857 |
Security Gateway | Potential memory leak in the CPD process. |
| PRJ-60990, PMTR-110282 |
Security Gateway | In some scenarios, when SecureXL is working in User Mode (UPPAK) mode, QoS service is unable to start, displaying the " QoS is not responding. Verify that QoS is installed on the gateway" error. Refer to sk183752. |
| PRJ-64396, PMTR-120304 |
Security Gateway | When changing the CoreXL configuration (for example, adjusting the number of SND and FW instances), a network interface may unexpectedly go down. This can cause traffic disruption. |
| PRJ-64492, PMTR-120932 |
Security Gateway | The Security Gateway may drop packets and potentially crash because of memory allocation issues. |
| PRJ-62919, PMTR-117427 |
Security Gateway | Infinite routing loop may occur because of TTL handling in SecureXL Medium Path. Refer to sk183728. |
| PRJ-63941, PRHF-41674 |
Security Gateway | In a Quantum Maestro VSX environment, Layer 2 MAC address table in Bridge Mode (Bridge Forwarding Database) entries may be incorrectly deleted, causing connectivity issues. |
| PRJ-65818, PMTR-122907 |
Security Gateway | When using a Security Gateway as a Proxy "Non-transparent" and HTTPS Inspection is set to "inspect" with "X-Forward-For header", video playback on YouTube fails. See the Critical Information section. |
| PRJ-63029, PMTR-117588 |
Security Gateway | Web browsing is slow, or pages freeze after an upgrade when using Security Gateway as an HTTP/HTTPS Proxy. Refer to sk184683. |
| PRJ-57793, TEMTA-1237 |
Threat Prevention | In some scenarios, Mail Transfer Agent (MTA) file type classification may be inaccurate when both MTA and Threat Emulation are enabled. |
| PRJ-61473, PMTR-115790 |
IPS | In some conditions, the Packet Capture may be missing from IPS logs in SmartConsole. |
| PRJ-63324, PRHF-41553 |
HTTPS Inspection | In some traffic flows, packets containing certain headers may be dropped regardless of how the non-compliant HTTP Inspection is configured. |
| PRJ-62830, PRHF-41229 |
Mobile Access | In rare scenarios, Mobile Access SmartConsole Logs may not match views/queries, including the "MAC address" or "Methods" field names. |
| PRJ-62836, PRHF-39978 |
Mobile Access | Mobile Access Software Blade may incorrectly terminate Guacamole-based clientless RDP/SSH sessions due to client idleness. |
| PRJ-60481, PMTR-110991 |
Mobile Access | Mobile Access SSL Network Extender (SNX) remote users with Windows 11 24H2 fail to connect. Refer to sk182923. |
| PRJ-58679, PMTR-110608 |
SecureXL | Concurrent NAT64 and NAT46 operations may cause packet processing threads to become unresponsive because of improper issue handling in the SIM v6 kernel module. |
| PRJ-59484, PRHF-37901 |
SecureXL | When using DOS Deny List, CPU usage may increase. |
| PRJ-59481, PRHF-38329 |
SecureXL | When using DOS Deny List, a firewall kernel module memory leak may occur. |
| PRJ-64329, PMTR-120628 |
SecureXL | When using MDPS with IPv6 disabled on the Security Gateway side, the Security Gateway may leak IPv6 packet buffers instead of dropping them. Refer to sk184419. |
| PRJ-43137, STRM-499 |
SecureXL | In rare scenarios, Fast Accel flow may result in SecureXL Kernel Space Mode (KPPAK) crash. |
| PRJ-64142, PMTR-120092 |
SecureXL | In a Maestro setup, the USIM process may exit under high load when handling encrypted VPN traffic with the other Security Gateway. |
| PRJ-60844, PRHF-39251 |
SecureXL | In some scenarios, the Security Gateway may crash when IoC feed contains an IPv6 address. |
| PRJ-62420, PMTR-115630 |
SecureXL | In some scenarios, the Security Gateway may crash. |
| PRJ-64333, PMTR-120460 |
SecureXL | Potential USIM process exit when using virtio devices and changing the MTU value. |
| PRJ-64456, PMTR-120707 |
SecureXL | Traffic may be disrupted when reconfiguring the virtual hardware interfaces. |
| PRJ-64880, PRHF-42050 |
SecureXL | When a VLAN interface is configured as the synchronization interface for the VSX cluster and SecureXL User Mode (UPPAK) is enabled, Virtual Systems on non-active members cannot forward traffic to Virtual Systems on the active member through a warp interface. |
| PRJ-64612, PMTR-121137 |
SecureXL | Multiple threads may be performing a routing next hop lookup for the same next hop at the same time, causing a rare race condition and USIM-related processes to exit. |
| PRJ-57693, PMTR-109360 |
SecureXL | Multiple " radix_get_value" messages may appear in fwk.elg log files. |
| PRJ-61615, PMTR-116026 |
SecureXL | The USIM process may exit when multiple routes are using the same nexthop and the nexthop is not yet resolved |
| PRJ-62959, PMTR-117546 |
SecureXL | The USIM process may exit when viewing the fg_conn table using the " fwaccel tab -t" command. |
| PRJ-62907, PMTR-118106 |
SecureXL | The USIM process may exit during the FWK restart. |
| PRJ-61311, PMTR-115500 |
SecureXL | In some scenarios, the VSX Security Gateway may not route traffic correctly for non-accelerated connections and accelerated connections that require Active or Passive Streaming when SecureXL User Mode (UPPAK) is enabled. |
| PRJ-61826, PRHF-40390 |
SecureXL | Interface cards are not displayed in the output of the " show asset network" command when SecureXL User Mode (UPPAK) and MDPS are enabled. Refer to sk184218. |
| PRJ-61622, PMTR-116027 |
SecureXL | Rate Limiting policy installation (when the Rate Limiting policy is updated or country code data is updated) may take a long time. |
| PRJ-65295, PMTR-122243 |
SecureXL | SecureXL hardware offload fails when a bond (link aggregation) is configured with two UP (active) member interfaces. See the Critical Information section. |
| PRJ-63261, PRHF-29936 |
Gaia OS | The LLDP Clish " lldpneighbors" command may have a corrupted output in case of extensive data. Refer to sk182065. |
| PRJ-62337, PRHF-40826 |
Gaia OS | LLDP data formatting issues when querying using SNMP. Refer to sk183733. |
| PRJ-60765, PRHF-39354 |
Gaia OS | DHCP traffic peaks may cause high utilization, potentially impacting connectivity. |
| PRJ-62465, PRHF-40902 |
Gaia OS | SNMP Power Supply trap reports false "Down" status. Refer to sk183702. |
| PRJ-61976, PRHF-40429 |
Gaia OS | When taking snapshots of the Security Group Members, some of them may crash, the dmesg_dumps shows multiple messages occurred before the crash " the active connections feature is currently enabled in the SmartView Tracker and due to high load it is making sync too slow to function properly. Therefore, 319489 active connection updates were dropped and no sync updates were lost". |
| PRJ-62534, PRHF-40972 |
Gaia OS | Gaia Portal Session Cookie missing the SameSite attribute. Security scanners and penetration tests flag the missing SameSite attribute as a vulnerability. Refer to sk183645. |
| PRJ-62040, PRHF-40558 |
Gaia OS | The MONITORD process unexpectedly exits on Security Gateways. Refer to sk184076. |
| PRJ-43417, PMTR-89314 |
VPN | The VPN granular encryption link is deleted when changing Security Gateway role. |
| PRJ-64410, AAD-4359 |
VPN | VPN traffic outage may occur in ClusterXL environments after a Cluster failover. |
| PRJ-62635, PRHF-40410 |
VSX | Services fail after Virtual System failover in Maestro dual-site environment using the Same Virtual MAC feature. Refer to sk183956 and sk184194. |
| PRJ-64095, PRHF-38127 |
VSX | In large scale environments, the " cpstat vsx" commands sometimes take a long time to execute or fail. |
| PRJ-50961, PMTR-97170 |
VSX | Creating a Virtual System (VS) with an IPv6-only interface (without configuring IPv4) succeeds without any warning or error. However, after the VS is created and modified, pushing the configuration fails with " In a VSX cluster, IPv6-only interfaces are not supported. Virtual System Processing Completed with Errors". |
| PRJ-60523, PRHF-38972 |
VSX | On a VSX Cluster Member, the FWK process may exit with a core dump and cause BGP session drops, resulting in 10-15 second network outages. Error messages in the core dumps and logs include TLS-related backtraces and memory corruption errors. |
| PRJ-63507, PRHF-41452 |
CloudGuard Network | Registration of an updated Data Center asset to the Security Management Server may fail. |
| PRJ-59518, PMTR-111921 |
SD-WAN | A Virtual System may lose connectivity on the Backup and the Standby member when route-based traffic is configured with specific SD-WAN configurations in VSX environments. |
| PRJ-59584, PRHF-38432 |
Scalable Platforms | After enabling Maestro Fastforward on a Security Group, traffic matching relevant rules is routed to the default Security Gateway instead of the correct nexthop because the static route is missing from /etc/mlx_routing.json on the Maestro Orchestrator. The Orchestrator shows 200 routes and fails to pick up the interface's routes, despite the interface topology is configured as "according to routes" in SmartConsole. |
| PRJ-63555, PRHF-41584 |
Scalable Platforms | Running the command " ccutil ssm_exec 1 'show system uptime'"generates no output. |
| PRJ-63617, PRHF-41710 |
Scalable Platforms | The " Invalid property name for chassis" error is displayed when changing the " alert_threshold packet_rate_total_threshold_low_ratio" value. |
| PRJ-63475, PMTR-119026 |
Scalable Platforms | Installing policy to the Maestro Security Group under extreme load with Resource Separation may fail. |
| PRJ-64592, PMTR-121110 |
Scalable Platforms | In rare scenarios, in a Maestro setup, traffic interruption may occur after Security Gateway reboots when the Gaia Database is corrupted. |
| PRJ-62567, PMTR-119109 |
Scalable Platforms | When the Maestro Fastforward feature is enabled, policy installation may fail with a " Maestro acceleration (MXL) failed, reason: General error. Please check /var/log/acl_cli.log on the security group SMO for more details" message instead of indicating that it is a policy parser issue. |
| PRJ-64400, PMTR-120751 |
Scalable Platforms | A configuration issue may cause link flapping on bonded uplink interfaces when using Maestro with SecureXL User Mode (UPPAK) enabled. The bond interface may fail to establish connectivity, with the physical interface reporting link status as up but showing unknown speed values. |
| PRJ-54677, PMTR-91449 |
Scalable Platforms | In a Maestro environment, BFD (Bidirectional Forwarding Detection) sessions may flap, slowing down the connections. |
| PRJ-64803, PMTR-109427 |
Scalable Platforms | In rare scenarios, in a Quantum Maestro environment, during the Nano-Agent installation, a configuration mismatch between Security Group Members may cause an affected SGM to enter a DOWN state and generate a configuration PNOTE (problem notification). |
| PRJ-62817, PRHF-41165 |
Scalable Platforms | In a Maestro VSX VSLS Cluster, after setting the kernel parameters " fwha_monitor_all_vlan=1" and " fwha_enable_if_probing=1", memory consumption may immediately increase to 100% and cause an outage. |
| PRJ-62899, PMTR-118072 |
Scalable Platforms | In rare scenarios, enabling interface monitoring may cause the FWK process to exit. |
| PRJ-65635, PMTR-122661 |
Scalable Platforms | In the Maestro and Chassis environment with multiple Virtual Systems (VSs) and updatable objects, the disk may reach full capacity. Refer to sk184576. See the Critical Information section. |
| PRJ-64503, CST-399 |
Carrier Security | Policy installation fails with an internal error when the Security Gateway policy includes rules that match a specific Access Point Name (APN) for GTPv0 or GTPv1 traffic. |
| PRJ-63852, PRHF-31869 |
Carrier Security | GTP traffic may not be well balanced, some CPU cores may be overloaded while others are underutilized, leading to performance issues. |
| PRJ-56451, PRHF-31961 |
Carrier Security | SAM rules fail to gracefully terminate PDP context when the timer expires. |
| PRJ-56447, PRHF-31901 |
Carrier Security | Running to " snmpwalk" or " stattest" command for any of GX OIDs results in the " No Such Instance currently exists at this OID" error. |