# Jumbo Hotfix Accumulator for R82

# R82 Jumbo Hotfix Take 14

|     |     |     |
| --- | --- | --- |
| [Download Jumbo Hotfix Accumulator Takes](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82_Downloads.htm) |  | [Download Previous Recommended Takes](https://support.checkpoint.com/results/sk/sk174185) |

|     |     |
| --- | --- |
|  | Note \- This Take contains all fixes from all earlier Takes. |

### Download CSV

| ID | Product | Description |
| --- | --- | --- |
| **Take 14**<br>Released on 20 April 2025 |
| **Take 14** \- **New Functionality** |
| PRJ-56952,<br>PRJ-56616 | SD-WAN | **NEW**: In SD-WAN, added support for:<br>- Traffic steering based on Differentiated Services Code Point (DSCP). <br>  <br>- Rule based NAT per ISP. |
| PRJ-56409,<br>PRJ-53464 | SD-WAN | NEW:<br>- Added ARP Next-Hop prober to enhance support for additional network topologies.<br>  <br>- Introduced HTTP prober to reflect real-time Web Access metrics.<br>  <br>- Implemented Link Aggregation mode proportional to Download and Upload bandwidth.<br>  <br>- Administrators are now able to override SD-WAN interface Circuit configuration.<br>  <br>- Integrated Forward Error Correction to ensure successful traffic delivery by adding error correction code packets to the Overlay packet stream.<br>  <br>- Introduced Dynamic Objects (SD-WAN Internet, My VPN Domain, and Peer VPN Domain) to better represent Overlay and Internet address spaces.<br>  <br>- Added administrator control for Symmetric Packet Return, forcing Ingress Traffic to be replied on the same ISP.<br>  <br>- Enabled SD-WAN Overlay establishment across different Domains using Global VPN Community (MDS).<br>  <br>- Allowed SD-WAN Overlay to operate on top of Route-based VPN.<br>  <br>- Increased maximum Overlay size to support up to 500 Security Gateways.<br>  <br>- Improved accuracy of SD-WAN decision-making during policy installation.<br>  <br>- Enabled setup of IPv4 SD-WAN overlay when non-SD-WAN IPv6 interfaces are configured. |
| PRJ-57083,<br>AAD-1761 | VPN | **NEW**: Local SCV settings can be customized by Security Gateway when creating a _$FWDIR/conf/local.scv\_<GW NAME>_ file, otherwise the settings fall back to the standard _local.scv_ configuration. |
| **Take 14** \- **Improvements and Resolved Issues** |
| PRJ-58376,<br>PMTR-110261 | Mobile Access | **UPDATE**: Resolved [CVE-2024-52887](https://www.cve.org/CVERecord?id=CVE-2024-52887) \- Self-XSS vulnerability in Mobile Access Native Applications 'favorites' dialog. Refer to [sk183054](https://support.checkpoint.com/results/sk/sk183054). |
| PRJ-58382,<br>PMTR-110274 | Mobile Access | **UPDATE**: Resolved [CVE-2024-52888](https://www.cve.org/CVERecord?id=CVE-2024-52888) \- Mobile Access File Share applications are vulnerable to stored XSS attacks. Refer to [sk183055](https://support.checkpoint.com/results/sk/sk183055). |
| PRJ-56536,<br>PRHF-34745 | Security Management | **UPDATE**: The Management API logs outbound payloads to _api.elg_ only for non-"200" response codes. It is now possible to enable the "WRITE\_FULL\_OUT\_PAYLOAD" environment variable to force comprehensive logging of all API call payloads, regardless of the response status. Refer to [sk182786](https://support.checkpoint.com/results/sk/sk182786). |
| PRJ-58728,<br>PMTR-110883 | Security Management | **UPDATE**: The Global Domain automatic purge settings now automatically restore and reschedule after a Security Management Server restart. |
| PRJ-57848,<br>PMTR-109621 | Logging | **UPDATE**: Enhanced the CLI " _cp\_log\_export_" command with additional examples and expanded help documentation. |
| PRJ-56569,<br>PRHF-32539 | Security Gateway | **UPDATE**: Reduced memory usage of LDAP keepalives and improved connection error handling, resulting in improved system reliability and security performance. |
| PRJ-56706,<br>PRHF-34380 | Security Gateway | **UPDATE**: Added information about VSX context to the _mem.report_ files in _/var/log/CP\_mem\_dwarf/_. |
| PRJ-58468,<br>ROUT-3004 | Routing | **UPDATE**: Added a new Gaia Clish parameter to ignore the Autonomous System (AS) Path when aggregating routes: " _set aggregate <IP Address>/<IP Mask> aspath-ignore {on \| off}_". Note, enabling " _aspath-ignore_" will disable " _aspath-truncate_" if configured. |
| PRJ-58466,<br>PRHF-33825 | Routing | **UPDATE**: IP Reachability Detection now supports simultaneous BFD and ping monitoring to the same remote address, where previously only one method was functional at a time. When both are configured, each monitoring protocol operates independently, allowing features to track their preferred detection method while maintaining existing configuration syntax. |
| PRJ-58738,<br>ACCHA-3835 | SecureXL | **UPDATE**: Optimized memory management when processing Jumbo Frames. |
| PRJ-58795,<br>PMTR-110837 | VSNext | **UPDATE**: All interfaces are now automatically assigned to VS0 (the default virtual system) with no instance bind, and can be moved between Virtual Systems without requiring unassigning, enabling immediate VSNext functionality. |
| PRJ-57735,<br>PMTR-109486 | Scalable Platforms | **UPDATE**: In ElasticXL, restoring Gaia OS backup is now supported. |
| PRJ-58348,<br>PMTR-110224 | Scalable Platforms | **UPDATE**: VSLS Mode is now supported in VSNext ElasticXL environments. |
| PRJ-57616,<br>PMTR-109197 | Scalable Platforms | In VSNext ElasticXL Load Sharing environments, traffic latency and interface flapping may occur between two members in the Virtual Switch (VSW), when the switch is configured on non-management interfaces and both members are on the same site. |
| PRJ-57907,<br>PRHF-36295 | Security Management | In rare scenarios, the FWM process on the Security Management Server may unexpectedly exit, creating a core dump file. |
| PRJ-58942 | Security Management | In SmartConsole, in the Quantum Spark Cluster object, editing the interfaces (manually or with the "Get Interfaces" action) fails with an unclear error message " _Failed to save object_". |
| PRJ-57658,<br>PRHF-36501 | Security Management | In some scenarios, High Availability synchronization fails with " _NGM failed to export data_" because of invalid Global Domain Assignments. |
| PRJ-58274,<br>PRHF-37209 | Security Management | In rare scenarios:<br> <br>- Login to the Security Management Server may fail with timeout.<br>   <br>  <br>- Publish operations may take a long time. |
| PRJ-58222,<br>PMTR-110042 | Security Management | In SmartConsole, when exporting Access Policy data to a CSV file, the hit count values may be displayed incorrectly in the exported file. |
| PRJ-57541,<br>PRHF-33773 | Security Management | Scheduled Snapshot Issues:<br>- Gaia may not recognize the Remote Server as a known host during scheduled backup creation, even after following [sk164234](https://support.checkpoint.com/results/sk/sk164234) instructions.<br>  <br>- The " _Remote server identity is not known by Gaia_" error is displayed despite proper HBA configuration.<br>  <br>- The " _set snapshot-scheduled recurrence monthly_" command fails when using the "all" option. <br>  <br>Refer to [sk182665](https://support.checkpoint.com/results/sk/sk182665). |
| PRJ-57782,<br>PRHF-36576 | Security Management | In rare scenarios, publishing Multi-Domain Security Management level changes such as Administrator configuration changes fails. The " _Action Failed due to an Internal Error_" error is displayed. |
| PRJ-60340,<br>PRHF-38803 | Security Management | In some scenarios, SmartTasks triggered by "after submit", "approve" and "reject" events fail to run. |
| PRJ-57069,<br>PRHF-36058 | Security Management | After an upgrade, when browsing to SmartConsole > Manage & Settings > Permissions & Administrator > Administrators, the page may display " _Error retrieving results_". |
| PRJ-57036,<br>PRHF-35374 | Security Management | In some scenarios, deleting a Security Gateway object fails if the Security Gateway is a participant in the Global VPN Community. |
| PRJ-57539,<br>PRHF-36475 | Security Management | In some scenarios, the " _show packages_" Management API command with " _details-level full_", fails with " _Null Pointer exception: null_". |
| PRJ-59028,<br>PMTR-111209 | Security Management | In the "Gateways and Servers" tab, when opening a shell on a specific Security Gateway, a " _Connection failed_" message pops up. |
| PRJ-59038,<br>PRHF-37790 | Security Management | SmartConsole "Validations" panel shows " _'statusDescription' can not include html tags_". Refer to [sk183075](https://support.checkpoint.com/results/sk/sk183075). |
| PRJ-58696,<br>PMTR-110640 | Security Management | Performing changes to the Global Properties may not be possible if:<br>- Encryption algorithms in Remote Access > VPN-Authentication and encryption are SHA384 or SHA512.<br>  <br>- There is at least one Security Gateway configured with a version lower than R81. |
| PRJ-58030,<br>PRHF-36922 | Multi-Domain Security Management | In rare scenarios, in Multi-Domain Security Management environments, domain creation fails with " _Failed to create Domain server "Domain name" Permission calculation failed_." |
| PRJ-57982,<br>PRHF-36890 | Multi-Domain Security Management | In rare scenarios, an upgrade of Multi-Domain Security Management Server, handling Domain Log Server certificates, may get stuck.<br>- The fix will only be applied if the upgrade to R82 Jumbo Hotfix Accumulator Take 14 or higher is done using a Blink image or the Advanced Upgrade method. |
| PRJ-57785,<br>PRHF-36479 | Multi-Domain Security Management | In environments where not all Domains are Active on the same Server (for example, in a multi-site environment), and there is no Domain Management Server for a specific Domain, logs from that Domain are not forwarded to the Infinity Portal. |
| PRJ-57829,<br>PRHF-36779 | Security Gateway | In some scenarios, an HTTP format size protection exception is not applied to the HTTP/2 flow. |
| PRJ-56815,<br>PRHF-29467 | Security Gateway | GTP-U traffic may be dropped because of incorrect message type handling. |
| PRJ-58091,<br>PMTR-109845 | Security Gateway | When the autodebug feature is enabled, the RAD service may consume high CPU and trigger " _RAD service not available_" alert logs. |
| PRJ-58271,<br>PRHF-36963 | Security Gateway | Security Gateway with QoS enabled may crash because of a rare race condition. |
| PRJ-58206,<br>PRHF-36513 | Security Gateway | Incorrect Rule Base parameters synchronization logic may lead to the FWK process exit. |
| PRJ-57962,<br>PRHF-36794 | Security Gateway | In the HTTP/2 connection scenario, the tenant restriction header injection mechanism encountered an issue affecting the connectivity. |
| PRJ-58768,<br>PMTR-111974 | Security Gateway | High CPU usage on SND cores related to processing network traffic and distributing it to the appropriate firewall instances. |
| PRJ-58152,<br>PRHF-37032 | Security Gateway | In a rare scenario, the FWK process may exit when HTTPS Inspection is enabled and TLS connections are inspected on non-standard ports (ports other than 443 or 8080). |
| PRJ-56740,<br>FMW-795 | Security Gateway | Large NAT Rule Base may lead to high CPU usage during packet processing. |
| PRJ-58420,<br>PRHF-37014 | Security Gateway | Android devices' HTTP HEAD requests to Google services are blocked by Security Gateway proxy, generating excessive logs that impact Security Gateway performance through high CPU usage. Refer to [sk182990](https://support.checkpoint.com/results/sk/sk182990). |
| PRJ-58902,<br>PRJ-58903,<br>PMTR-110909 | Security Gateway | The FWK process may exit with a core dump file when the Security Gateway passes SMB traffic and the Hyperflow feature is enabled. |
| PRJ-59119,<br>PMTR-110235 | Security Gateway | In a rare scenario, the RAD daemon may crash during large memory allocation operations. |
| PRJ-58407,<br>PRHF-32698 | Security Gateway | PPPoE interface fails to restart when it is disconnected from the Server side. Refer to [sk182154](https://support.checkpoint.com/results/sk/sk182154). |
| PRJ-56404,<br>PRHF-35372 | Internal CA | The " _cpca\_dbutil print_" command may delete the provided output file content if the input file does not exist. |
| PRJ-58131,<br>PRHF-36964 | Identity Awareness | In a rare scenario, the PDPD process may unexpectedly exit during the PDP sharing flow. |
| PRJ-58441,<br>PRHF-37240 | Identity Awareness | In some scenarios, SAML authentication fails with " _Error 500_". |
| PRJ-58191,<br>PMTR-108416 | Application Control | HTTPS Site Categorization fails to properly handle unsupported QUIC protocol versions, causing classification errors instead of following the configured fail-mode (open/close) policy. |
| PRJ-59452,<br>PMTR-112600 | IPS | In rare scenarios, a memory leak in the FWK process may occur when IPS is active. |
| PRJ-57969,<br>PRHF-36711 | DLP | The DLP Software Blade may not block the password-protected files of a specific type, although it should. |
| PRJ-58170,<br>PRHF-37164 | Anti-Virus | In a specific scenario involving a long-lived SMTP connection, the memory usage allocated by the Anti-Virus Software Blade steadily increases over time. |
| PRJ-57690,<br>PMTR-109185 | SSL Inspection | HTTPS inspection session logs lack detailed explanations in the "explanation" field, displaying generic messages that do not clarify action reasons. This is a cosmetic issue. |
| PRJ-58073,<br>PRHF-33345 | Mobile Access | The debug output file for Mobile Access, named " _exchangeRegistration\_portal\_error\_log_" is increasing in size. |
| PRJ-59491,<br>PMTR-111453 | ClusterXL | During cluster startup with routing separation enabled, a mismatch between routing and firewall process initialization can trigger premature full synchronization pnotes when the routing process is not fully synchronized. |
| PRJ-59725,<br>HEC-336 | ClusterXL | ElasticXL may fail to pass IPv6 traffic when the internal mechanism assigns the Server-to-Client response traffic to a different Cluster Member than the Cluster Member that processed the Client-to-Server request traffic. |
| PRJ-58173,<br>ACCHA-3774,<br>PRJ-58174,<br>ACCHA-3821 | SecureXL | SD-WAN may not work as expected when SecureXL User Space Mode (UPPAK) is enabled. |
| PRJ-60467,<br>PMTR-114455 | SecureXL | In some scenarios, a memory leak occurs in the FWK process when SecureXL fails to update an existing route's next hop. |
| PRJ-60160,<br>PRHF-38880 | SecureXL | Routing related connectivity and stability issues may occur when SecureXL operates in User Mode (UPPAK). Refer to [sk183181](https://support.checkpoint.com/results/sk/sk183181). |
| PRJ-58276,<br>PMTR-110096 | SecureXL | SecureXL User Mode crashes if an acceleration card interface has an MTU above 9000 and receives frames larger than 9234 bytes. |
| PRJ-57991,<br>PRHF-36805 | Routing | The "iphelper" (IP Broadcast Helper) service may trigger high CPU utilization because of a recursive packet broadcasting loop between network interfaces. |
| PRJ-57987,<br>ROUT-3189 | Routing | Static routes may get permanently deleted from the kernel during rapid interface configuration changes when there is a large number of routes. |
| PRJ-59288,<br>PMTR-111756 | Routing | Network traffic to the Internet experiences slowdowns and file download interruptions due to packets being dropped with " _OS routing failed_" errors during route lookup failures. |
| PRJ-58001,<br>PRHF-36849 | VPN | Capsule VPN connectivity failures may occur after a configuration change of the VPND daemon table parameters. |
| PRJ-58061,<br>PRHF-33418 | VPN | Two or more Endpoint Security VPN (Remote Access VPN) Users may get the same Office Mode IP address. Refer to [sk182537](https://support.checkpoint.com/results/sk/sk182537). |
| PRJ-57797,<br>PMTR-108966 | VPN | Authentication failure may occur when an IKEv2 VPN Endpoint client connects using a machine certificate configured for a specific realm. |
| PRJ-59251,<br>PMTR-109563 | VPN | When using machine-restricted Access Roles, IKEv2 VPN connections fail at the cleanup rule due to missing machine information and user source IP, while IKEv1 connections are unaffected. |
| PRJ-57943,<br>PMTR-108894,<br>PRJ-58107,<br>PMTR-109743 | VPN | When configuring machine authentication without an LDAP server, the computer is authenticated during the connection with the RA VPN. However, the logs in SmartConsole do not display the " _Authenticated machine ..._" message as expected. |
| PRJ-58155,<br>PMTR-103301 | VPN | VPN connection may not be stable when transitioning from Legacy Link Selection to R82 Link Selection. |
| PRJ-58067,<br>PMTR-109183 | VPN | Different members in a Quantum Maestro environment may show different statuses for VPN probes. |
| PRJ-58268,<br>PMTR-108409 | VPN | After traffic is stopped and tunnels are deleted, the tunnels may appear as "Disconnected" for about 30 seconds, and then again as "Connected" because of DPD probing. |
| PRJ-58750,<br>PMTR-109317 | VPN | Remote Access VPN client repeatedly reconnects to a VPN Virtual System when it connects through another Virtual System on a Scalable Platform in the VSX/ VSNext mode. Refer to [sk183052](https://support.checkpoint.com/results/sk/sk183052). |
| PRJ-57423,<br>PMTR-108927 | VSNext | In VSNext, multiple CPRID processes running on different ports per virtual system may cause instability in large scale environments. |
| PRJ-58165,<br>PRHF-37102 | Gaia OS | The ROUTED daemon fails to start when a VTI is configured with a local IP address that matches the next-hop address used in the static route configuration. Refer to [sk182848](https://support.checkpoint.com/results/sk/sk182848). |
| PRJ-58036,<br>MBS-14520 | Scalable Platforms | Using the " _#_" character in the Message of the Day (MOTD) banner message causes SGMs to fail during boot. |
| PRJ-57640,<br>PMTR-100964 | Scalable Platforms | Security Group Member may be in Down state during the license distribution to Maestro Security Group members. Refer to [sk181245](https://support.checkpoint.com/results/sk/sk181245). |
| PRJ-57606,<br>PRJ-57507 | Scalable Platforms | When running the " _enabled\_blades_" command multiple times simultaneously, the command output may be incorrect. |
| PRJ-58736,<br>PRJ-58323 | Scalable Platforms | In a Maestro environment, a Security Gateway may enter a reboot loop because of sync issues of the _settings.fwset_ file. |
| PRJ-58375,<br>PMTR-110163 | Scalable Platforms | In rare scenarios, Security Group members may fail to receive their Gaia database from the Single Management Object (SMO). When this occurs, gClish commands related to these missing Security Group configurations may fail. |
| PRJ-58561,<br>PMTR-105372 | Scalable Platforms | During the upgrade of Scalable Platform Security Group Gateways, SSH keys are deleted. |
| PRJ-56444,<br>PRHF-31476 | Carrier Security | When Carrier Security is enabled, GTP-U packets are incorrectly matched against GTP rules instead of a non-GTP UDP rule, causing drops with the " _Unestablished tunnel_" error.
