# Jumbo Hotfix Accumulator for R82

# R82 Jumbo Hotfix Take 10

|     |     |     |
| --- | --- | --- |
| [Download Jumbo Hotfix Accumulator Takes](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82_Downloads.htm) |  | [Download Previous Recommended Takes](https://support.checkpoint.com/results/sk/sk174185) |

Download CSV

| ID | Product | Description |
| --- | --- | --- |
| **Take 10**<br>Released on 27 January 2025 |
| **Take 10** \- **New Functionality** |
| PRJ-57908,<br>PRHF-32290 | Identity Awareness | **NEW**: Added new OID (1.3.6.1.4.1.2620.1.38.55) to monitor the Identity Collector connection status in the _$CPDIR/lib/snmp/chkpnt.mib_ file. <br>- This capability is supported for Identity Collector agents running with version R82.120.0000 or higher. |
| **Take 10** \- **Improvements and Resolved Issues** |
| PRJ-56747,<br>PMTR-106894 | SmartConsole | **UPDATE**: Resolved [CVE-2024-3596](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3596) \- Blast-RADIUS attacks. Fix for Remote Access VPN and login to SmartConsole, Mobile Access and Identity Awareness Captive Portal. Refer to [sk182516](https://support.checkpoint.com/results/sk/sk182516). |
| PRJ-58281,<br>PMTR-97400 | Security Gateway | **UPDATE**: Deprecated RC2-CBC cipher for SIC in OpenSSL. |
| PRJ-57491,<br>PMTR-108994 | Security Management | **UPDATE**: The Management API command " _set-https-rule_" now automatically sets the negative value to " _false_" when modifying the destination, source, service, or site-category fields, regardless of its previous setting. |
| PRJ-57066,<br>PRHF-34509 | SecureXL | **UPDATE**:<br>- Improved debugging in the Security Gateway to identify problematic hosts when resolving their next-hop IP addresses. <br>  <br>- The custom ADP queue size configuration now persists after rebooting the Security Gateway. The relevant global parameters are located in the _$PPKDIR/conf/adpkern.conf_ file:<br>  <br>  - " _adp\_nh\_total\_max\_arp\_qents_"<br>    <br>  - " _adp\_nh\_local\_max\_arp\_qents_" |
| PRJ-58125,<br>PMTR-106186 | Scalable Platforms | **UPDATE**: Added support for Multicast Listener Discovery (MLD) on Maestro Hyperscale Orchestrator (MHO). |
| PRJ-57074,<br>PRHF-35818 | Security Management | In rare scenarios, when exporting policy hitcounts to CSV format, the "Hitcount" column may appear blank in the exported file. |
| PRJ-58104,<br>PRHF-32246 | Security Management | Audit logs may not be generated when changes are made to an inline (shared) layer that appears multiple times within the same policy. |
| PRJ-57319,<br>PRHF-25950 | Security Management | The Database Installation progress bar may not update during task execution. |
| PRJ-59004,<br>PMTR-111056 | Security Management | When editing the administrator expiration date, after publishing, the expiration date resets to "Never". Refer to [sk182997](https://support.checkpoint.com/results/sk/sk182997). |
| PRJ-56542,<br>PRHF-34752 | Multi-Domain Security Management | In some scenarios, in a Multi-Domain Security Management environment, the Hit Count retention mechanism may not remove the Hit Count data from all the Domains. |
| PRJ-56532,<br>PRHF-35418 | Multi-Domain Security Management | The Multi-Domain Security Management Server experiences high CPU usage when communicating with the Multi-Domain Log Server. And the _cpm.elg_ log prints the " _You have reached the maximum number of active session_" error. Refer to [sk182738](https://support.checkpoint.com/results/sk/sk182738). |
| PRJ-57531,<br>PRHF-36514 | Multi-Domain Security Management | In rare scenarios, in Multi-Domain Security Management environments, login to SmartConsole fails. |
| PRJ-57310,<br>MCFG-666 | SmartConsole | SmartConsole fails to connect with " _Unable to connect to server. Server is initializing_". Refer to [sk182507](https://support.checkpoint.com/results/sk/sk182507). |
| PRJ-57273,<br>PMTR-108672 | SmartConsole | When the Security Management has an additional NAT configuration in the SD-WAN policy (Infinity Portal), an indicating banner may not appear in SmartConsole NAT Rule Base. This is a cosmetic issue.<br>- Requires R82 SmartConsole Build 1051 or higher. |
| PRJ-58050,<br>PMTR-109735 | Security Gateway | In a rare scenario, the FWK process may exit when processing traffic over QUIC protocol. |
| PRJ-58659,<br>PMTR-110556 | Security Gateway | In a rare scenario, the FWK process may exit due to a race condition. |
| PRJ-56911,<br>PRJ-56840,<br>PRHF-33037,<br>PRHF-35918 | Security Gateway | The Security Gateway may crash after a failure in policy installation. |
| PRJ-56702,<br>PRHF-35624 | Security Gateway | Anti-Spoofing may drop IPv6 traffic that arrives at an interface with an IPv6 address configured. Refer to [sk182725](https://support.checkpoint.com/results/sk/sk182725). |
| PRJ-57844,<br>PMTR-109616 | Security Gateway | In a rare scenario, when multiple Elephant Flows are running in parallel in the accelerated pipelining path, there may be high CPU utilization. Refer to [sk183007](https://support.checkpoint.com/results/sk/sk183007). |
| PRJ-58100,<br>PMTR-109857 | Security Gateway | Traffic through specific interfaces is dropped when the QoS Software Blade is active and " _ISP redundancy-LS_" is configured. Refer to [sk182807](https://support.checkpoint.com/results/sk/sk182807). |
| PRJ-57109,<br>PRHF-36116 | Security Gateway | Memory leak may occur in SecureXL templates. Refer to [sk182648](https://support.checkpoint.com/results/sk/sk182648). |
| PRJ-57895,<br>PMTR-108660 | Security Gateway | DoS protection and connection rate limiting configurations may fail to effectively enforce rules. |
| PRJ-57098,<br>PMTR-108273 | SD-WAN | In a rare scenario, when SD-WAN transport is incorrectly marked as "UP" despite its underlying ISP interface is "DOWN", traffic fails to reach the remote peer because of incorrect routing decisions. |
| PRJ-58021,<br>PMTR-109729 | Threat Prevention | In a VSX environment, enabling Threat Prevention Software Blades may cause continuous file accumulation on the Security Gateway's hard drive. |
| PRJ-57007,<br>PRHF-35823 | Threat Prevention | In some scenarios, when Zero Phishing is enabled, kernel crash may occur. |
| PRJ-57926,<br>PMTR-109709 | Identity Awareness | Identity Broker Subscriber configured with recalculation of Access Roles does not match all Access Roles after the User and Machine are identified. |
| PRJ-56869,<br>PRHF-35625,<br>PRJ-56873,<br>PRHF-35636 | Identity Awareness | In rare scenarios:<br>- The PDPD process may become unresponsive during termination.<br>  <br>- PDP to PEP Identity synchronization fails on the PEP side when Identity Sharing is configured with PUSH Identity Sharing. <br>  <br>Refer to [sk182613](https://support.checkpoint.com/results/sk/sk182613). |
| PRJ-57046,<br>PRHF-36045 | Identity Awareness | In a rare scenario, the PDPD process may unexpectedly exit during policy installation. |
| PRJ-57411,<br>PMTR-108321 | SSL Inspection | The Trusted CA package update fails when the Security Management Server connects to the Internet only through a Proxy Server. |
| PRJ-57682,<br>PRHF-36561 | SecureXL | A memory leak may occur in the SIM process when using DOS/Rate Limiting rules. |
| PRJ-58592,<br>PMTR-110486 | SecureXL | When working with SecureXL in User mode (UPPAK), some CPUs may reach 100% utilization when enabling or disabling debug filters. |
| PRJ-57801,<br>PMTR-109570 | SecureXL | Policy installation failures can disrupt the expected behavior of " _fwaccel dos_" commands. |
| PRJ-57558,<br>PRHF-34632 | VPN | SSL Network Extender (SNX) traffic on Maestro may be dropped with " _vpnk\_tcpt invalid negative tunnel id_". Refer to [sk182806](https://support.checkpoint.com/results/sk/sk182806). |
| PRJ-56335,<br>PRHF-35251 | VPN | An ECDH object may be deleted before its associated event is completed processing. |
| PRJ-57901,<br>PMTR-109649 | VPN | After a cluster failover, VPN tunnels may be not stable. |
| PRJ-56499,<br>PRHF-35416 | VPN | There is no audio during the first 5 seconds of each VoIP call. Refer to [sk182730](https://support.checkpoint.com/results/sk/sk182730). |
| PRJ-57825,<br>PRHF-17665 | VSX | Multi-Queue configuration does not survive reboot on VSX. Refer to [sk173950](https://support.checkpoint.com/results/sk/sk173950). |
| PRJ-56915,<br>PRHF-35806 | VSX | In SmartConsole, in the Device and License Information view, the Compliance Software Blade license status may incorrectly display " _Quota Exceeded_" when Virtual Routers or Virtual Switches are present. |
| PRJ-57059,<br>PRHF-34508 | VSX | After a Jumbo Hotfix upgrade, the Mail Transfer Agent may fail on all Virtual Systems except one. |

22 July 2026
