R82 Jumbo Hotfix Take 25

R82 Jumbo Hotfix Take 25

Download Jumbo Hotfix Accumulator Takes Download Previous Recommended Takes
Note - This Take contains all fixes from all earlier Takes.

Download CSV

ID Product Description
Take 25
Released on 15 June 2025
Take 25 - New Functionality
PRJ-59495 Hardware NEW: Added support for Quantum Smart-1 700-S, 700-M, 7000-L, 7000-XL, 7000-UL. Refer to sk182601.
PRJ-57860,
PMTR-112034
SD-WAN NEW: SD-WAN functionality now supports AWS Cross Availability Zone and traffic steering with configurable multi-target probing.
PRJ-58894,
PRHF-31058
SSL Inspection NEW: This Take introduces a fail-open mechanism for HTTPS Inspection with Hardware Security Module (HSM) integration. If the HSM becomes unavailable, TLS connections now automatically bypass HTTPS Inspection, ensuring continuous network connectivity.
Take 25 - Improvements and Resolved Issues
PRJ-59936,
PMTR-113250
Gaia OS UPDATE: A patch on top of OpenSSL 1.1.1w to fix CVE-2024-13176. Refer to sk183168.
PRJ-60772,
HEC-868,
PMTR-114867
Diagnostics UPDATE: Added the ability to monitor the CPU cores that run CoreXL SND (Secure Network Dispatcher) instances separately from the CPU cores that run CoreXL Firewall instances. The monitoring of CPU cores handling CoreXL SND instances was improved. It is possible now to:
- view the exact number of CPU cores running SND instances that are under load, instead of seeing it as a percentage of total CPU cores.

- configure the load threshold for CPU cores running CoreXL SND instances.

- configure the load duration for SND CPU cores.

When these parameters are configured, the load on SND CPUs triggers a failover at a different time and under different load conditions compared to Firewall CPUs. Refer to the R82 ClusterXL Administration Guide > Advanced Features and Procedures > ClusterXL Failover based on the Load on ClusterXL SND Instances.
PRJ-59727,
PMTR-112995
Security Management UPDATE: Added the "Type" and "Resource" columns to the HTTPS Inspection Logs table under Logs & Events.
PRJ-58951,
PMTR-110805
Security Management UPDATE: Management upgrade performance is improved by up to 15%.

- The fix will only be applied if the Management Server upgrade is performed using either the Blink image of the current Jumbo Hotfix Accumulator Take or the Advanced Upgrade method (where the current Jumbo Hotfix Accumulator Take is installed on the target Management Server).
PRJ-57995,
PMTR-112672
Security Management UPDATE: Added support for using Network Groups in the "Install On" column of the NAT Policy. Refer to sk176846.
PRJ-60049,
FMW-4284
CPView UPDATE: CPView and SNMP can now show Hide NAT statistics for up to 200 top NAT IP Pools (the default is 3 top NAT IP Pools). Configure the required value for the kernel parameter " fwx_alloc_top_pools_num" with the CLI command " fw ctl set -f int fwx_alloc_top_pools_num <integer from 1 to 200>".
PRJ-60364,
PMTR-108410
Logging UPDATE: Added a count of Session and Connection logs to the " cpstat" command output.
PRJ-58669,
PMTR-110592
Security Gateway UPDATE: Added multi-interface packet fragment reassembly support to prevent drops in Equal Cost Multipath (ECMP) environments.
PRJ-58552,
FMW-2292,
PMTR-110440
Security Gateway UPDATE: Support TLS 1.3 for the RAD process requests. To activate it, change the TLS version to "TLSv1_3". Refer to sk178505.
PRJ-57079,
PRHF-35181
Security Gateway UPDATE: RAD extended flow information is now logged into a cyclic CSV file - $FWDIR/log/rad_events/rad_flows.csv. This enhancement provides visibility into RAD connections, helping to monitoring and troubleshooting. Refer to sk183108.
PRJ-58815,
PRHF-37100
Security Gateway UPDATE: Added a kernel parameter " domo_reverse_lookup_disabled" to disable reverse DNS lookups to avoid rare incorrect matches in scenarios involving non-Fully Qualified Domain Name (non-FQDN) Domains.
- " domo_reverse_lookup_disabled 1" to disable reverse DNS lookups.

- " domo_reverse_lookup_disabled 0" to enable reverse DNS lookups (the default value).

Refer to sk120633.
PRJ-57317,
PMTR-108735
Threat Prevention UPDATE: Improved Threat Prevention Software Blades performance by 15%-25% on Quantum Force 9000, 19000 and 29000 appliances.
PRJ-54144,
PRHF-31274
SSL Inspection UPDATE: HTTPS Inspection statistics are now available through SNMP requests.
PRJ-59774,
PMTR-113092
SSL Inspection UPDATE: In SmartConsole, added a new section "Application/Site" to the HTTPS Inspect log details. It provides details on resource and categorization matching.
PRJ-58754,
PRHF-36873
Mobile Access UPDATE: Added support for the Mobile Access Portal "WebSocket" applications to work in environments with asymmetric network bandwidth (the download speed is faster than the upload speed) between external and internal networks. Refer to sk95311.
PRJ-60000,
PMTR-111169
ClusterXL UPDATE: SecureXL User Mode (UPPAK) is now blocked in Active-Active cluster configurations, as this combination is not supported.
PRJ-58673,
SDWANM-2809
SD-WAN UPDATE: Added selection of specific Security Gateways to onboard to the Infinity Portal, and the ability to disable the feature completely. Refer to sk180557.
PRJ-57542,
PMTR-110262
VSX UPDATE: Implemented a validation in Clish to restrict virtual switch (VSW) configuration to a single interface, preventing setup disruption.
PRJ-59233,
PMTR-111643
VSNext UPDATE: In the Clish API, added the comprehensive VSNext task monitoring capabilities, previously available only in the Gaia Portal.
PRJ-59274,
HEC-915
VSNext UPDATE: The " add-virtual-gateway" Management API is updated: added the option to not connect the new VS to the virtual switch.
PRJ-60148,
PMTR-113933
VSNext UPDATE: Rather than using the management switch, it is now possible to choose a different management interface for each virtual system (VS).
PRJ-59121,
PMTR-110666
VSNext UPDATE: Improved debuggability for the " cpstart" command in a large scale VSNext environments.
PRJ-57224,
PMTR-110740
CloudGuard Network UPDATE: Traffic between an external network host and an internal network host is now accelerated when a static NAT is configured to translate a cluster member's IP address or specific high port to an internal host IP address or specific service port. This scenario is relevant in Check Point CloudGuard Network Security Azure High Availability deployments, where traffic passes through a Load Balancer.
- To enable acceleration, add this kernel parameter to the $FWDIR/boot/modules/fwkern.conf file - " accel_dnat_to_cluster=1".

- The change can also be applied immediately to the running FW1 process without requiring a reboot: " fw ctl set int accel_dnat_to_cluster 1".
PRJ-57795,
PMTR-109576
CloudGuard Network UPDATE: CloudGuard Network for AWS Gateway Load Balancer Auto Scaling Group now supports inspection of IPv6 traffic encapsulated with GENEVE IPv4 headers.
PRJ-56783,
PRHF-35847
Diagnostics In SmartConsole, in the Gateways & Servers view, under Device & License Information of a Security Gateway or Cluster object, or in CPView and SNMP traps, the value of "new connection rate" for OID .1.3.6.1.4.1.2620.1.1.26.11.6.0 is incorrect.
PRJ-58243,
PMTR-110065
Diagnostics After rebooting a Multi-Domain Security Management Server, the CPView ( sk101878) and Skyline ( sk178566) tools do not return data (for example, when running the " cpview -m", " cpview -t", " cpview -s" commands).
PRJ-58851,
PRHF-37388
Security Management In rare scenarios, a core file of the CPRLIC process is generated.
PRJ-56974,
PRHF-36032
Security Management Using the " set simple-cluster" command without the " members.add" option to add cluster members may result in recreating existing cluster members and potential loss of SIC.
PRJ-60696,
PRHF-39191,
PMTR-114757
Security Management Login using a TACACS Server created with the " add tacacs-server" Management API command, fails with " authentication to server failed".
PRJ-59097,
PRHF-37788
Security Management Management Server operations may be slow because of some API commands, and multiple core dumps may be generated.
PRJ-58472,
PRHF-37430
Security Management Creating a Threat Prevention Exception from a log fails with the " Failed to add exception" error when the "File Name" field in the log contains a Windows directory separator ("\").
PRJ-58718,
PRHF-37561
Security Management Changes to a SmartConsole administrator's Authentication Server (RADIUS or TACACS) may occasionally fail to take effect.
PRJ-57818,
PMTR-107227
Security Management In some scenarios, Web SmartConsole session gets disconnected after several minutes.
PRJ-58448,
PRHF-37393
Security Management In rare scenarios, Revert to Database Revision is stuck at 10%.
PRJ-57397,
PRHF-36340
Security Management In rare scenarios, when more than one Security Blade is enabled on the Security Gateway, Presets for policy installation may fail after purging all revisions.
PRJ-59308,
PRHF-38068
Security Management In some scenarios, the "Log Servers" tab in the Logs and Events view of SmartConsole is not visible. Refer to sk183154.
PRJ-59059,
PRHF-37185
Security Management When using SmartWorkflow on a Security Management Server with more than 200 administrators, requests may stall or cause SmartConsole crashes during submission.
PRJ-57721,
PRHF-36549
Security Management Inserting the " \n" character in the name of a rule fails with an unclear error message not indicating the cause of the failure.
PRJ-59023,
PRHF-37832
Security Management Access Control Policy installation may take a long time when updatable objects are used in the policy.
PRJ-58524,
PRHF-37446
Security Management In rare scenarios, login to SmartConsole may fail with the timeout.
PRJ-58341,
PRHF-37251
Security Management In rare scenarios, login to SmartConsole using LDAP, TACACS or RADIUS authentication fails with a timeout.
PRJ-58901,
PRHF-37631
Security Management After an IPS update, reassigning global policies may take a long time.
PRJ-58574,
PRHF-37436
Security Management Global Policy Reassignment fails with the " org.postgresql.util.PSQLException: ERROR: more than one row returned by a subquery used as an expression" error printed in the cpm.elg file.
PRJ-57917 Security Management In rare scenarios, the CPD process may unexpectedly exit and create a core dump file. Refer to sk182787.
PRJ-58920,
PRHF-37819
Security Management In rare scenarios, policy installation fails with " Policy installation had failed due to an internal error".
PRJ-57630,
PRHF-36614
Security Management In rare scenarios, Infinity Portal shows the
" Failed to update Infinity Portal with objects from your on-premises Management Server. Contact Check Point Support" error.
PRJ-57323,
PRHF-36147
Security Management When modifying the URL definition type in an Application Site object using the " set application-site" Management API command with the " urls-defined-as-regular-expression" parameter, the type of pre-existing URLs remains unchanged.
PRJ-58503,
PRHF-37445
Security Management Renaming a Secondary Security Management Server that was promoted to Primary fails.
PRJ-58527,
PRHF-37141
Security Management In some scenarios, policy state directories are synchronized between Active and Standby Security Management Servers, leading to high disk space usage.
PRJ-58917,
PRHF-37822
Security Management Policy Installation may not be accelerated after modifying a host in a rule with the inline layer action.
PRJ-58686,
PMTR-110626
Security Management Duplicated licenses on the Security Management Server may impact the vsec_lic_cli utility.
PRJ-59700,
PRHF-38273
Security Management The Compliance Software Blade incorrectly reports Gaia Best Practices as insecure for cluster members.
PRJ-59433,
PRHF-38264
Security Management In some scenarios, opening a specific VPN community in SmartConsole fails and the " Unable to load page" message is printed, while other communities can be opened.
PRJ-59600,
PRHF-38330
Security Management In rare scenarios, Global Policy Assignment fails with an " IPS update is currently running in local domain" message, although IPS update is not running in that Domain.
PRJ-57307,
PRHF-36241
Security Management If a custom login message exceeds 1000 characters, the login output file, which contains the sid and other session data, cannot be parsed as expected. Using the " mgmt_cli" with the " -s" parameter results in the " Failed to parse login output file" error.
PRJ-57139,
PRHF-36149
Security Management In some scenarios, the Security Management Server with a proxy configured is unable to connect to Infinity Portal after changing the proxy settings.
PRJ-59341,
PMTR-111778
Security Management When a Security Gateway object is deleted, its license may still appear as attached even though the Security Gateway Object no longer exists.
PRJ-58606,
PRHF-34898
Security Management Packet mode search or search within Object Explorer for IP address ranges may not work correctly on the Standby Security Management Server.
PRJ-59631,
PRHF-38384
Security Management In a rare scenario, December date comments in the IPS User Settings view may display incorrect year.
PRJ-60151,
PRHF-38525
Security Management In some scenarios, Virtual Security Gateways lose their licenses. This causes Site to Site VPN and Remote Access VPN services to go down, while general internet access remains functional. SmartUpdate may not load.
PRJ-57440,
PRHF-23903
Multi-Domain Security Management In a Multi-Domain Security Management environment, RADIUS authentication may be sent with an incorrect IP address. Refer to sk180723.
PRJ-58777,
PRHF-37360
Multi-Domain Security Management In a Multi-Domain Security Management environment, an audit log is not created after changing the "Parent rule for Domain's policy" Domain layer.
PRJ-58847,
PRHF-34721
Multi-Domain Security Management In a Multi-Domain Security Management environment with a VSX Gateway, such operations as login to SmartConsole, Global Domain Assignment, Domain creation or deletion may take longer than expected or fail with a timeout message " Task failed".
PRJ-58969,
PRHF-37258
Multi-Domain Security Management In rare scenarios, the " mdsstat" command shows that the CPD process is down even though it is up and running.
PRJ-58874,
PRHF-37752
Multi-Domain Security Management In certain scenarios, when Cluster objects are used in a Multi-Domain Security Management Server with Domains that have Global Domain Assignments, an upgrade may fail with " Tried to persist object OBJ_ID with domain 1e294ce0-367a-11e3-aa6e-0800200c9a66 while active domain is DOMAIN_ID".
- The fix will only be applied if the upgrade to this Jumbo Hotfix Take is done using a Blink image or with the Advanced Upgrade method.
PRJ-56977,
PRHF-35998
Multi-Domain Security Management In some scenarios, in the Multi-Domain Security Management Server, certain previously utilized global objects may remain hidden from both the SmartConsole's Object Explorer View and the " show unused-objects" Management API command.
PRJ-59215,
PRHF-38104
Multi-Domain Security Management Policy installation fails on all Domains on the Multi-Domain Security Management Server with " Layer '': Verification failed due to an internal error" if an Externally Managed Security Gateway object with IPsec enabled does not have an encryption Domain. Refer to sk183003.
PRJ-58981,
PRHF-37890
Multi-Domain Security Management In some scenarios, the " SIC Error for EntitlementManager: Peer sent wrong DN" error is printed
in cpd.elg on a VSX Gateway.
PRJ-60322,
PMTR-114256
Multi-Domain Security Management Multiple errors " T_get_event: cannot register socket %d (%d sockets already registered for %s)" are printed in $MDSDIR/log/ in.msd.
PRJ-59767,
PMTR-112934
Compliance In rare scenarios, the "Blades" widget in the Compliance Software Blade Overview page is blank.
PRJ-58260,
PMTR-110658
CPView Interfaces with VLAN are not visible in CPView stats.
PRJ-59348,
PMTR-111094
Logging In the cloud environments (Smart-1 Cloud and EPMaaS), logs query may fail because of the AWS certificate change.
PRJ-59591,
PRJ-59592
Logging When opening a log card in the Logs View, duplicate values may appear in the "Resource" and "Reason" fields.
PRJ-60574,
PMTR-106428
Logging When disconnecting the Security Management Server from the Infinity Portal and connecting to a different region, log sharing from Log Servers does not work until the Log Server restarts.
PRJ-57787,
PMTR-100187
Security Gateway The " fileapp_parser_get_attribs: call orig_get_attrib failed" error is printed in the $FWDIR/log/fwk.elg file.
PRJ-57256,
PRHF-25598
Security Gateway When a NAT-T tunnel is set up between VPN peers, packets having UDP encapsulation added to the headers are not transmitted out of the PPPoE interface as they should be. VPN connection appears to be established but does not actually pass traffic.
PRJ-57513,
PRHF-32506
Security Gateway VoIP H.323 calls are dropped with reason " Handler 'h323_h245_code' reject". Refer to sk182835.
PRJ-59131,
PRHF-38022
Security Gateway The DHCPv6 relay drops reply messages from the DHCPv6 server rather than forwarding them to the clients.
PRJ-58744,
PRHF-37487
Security Gateway In a rare scenario, when the Anti-Virus Software Blade and the ICAP Server are enabled, there may be high CPU usage.
PRJ-60804,
PRHF-38473
Security Gateway The FWK process exits with core dumps and error messages in $FWDIR/log/fwk.elg:" malware_res_rep_match_dns_response: check_dns_response_activate() failed".
PRJ-57740,
PRHF-36496
Security Gateway Local connections originating from the Security Gateway may fail to refresh their timeout values.
PRJ-60290,
PRHF-38919
Security Gateway Memory handling issue, causing the FWK process to unexpectedly restart.
PRJ-60286,
PRHF-38898
Security Gateway In rare scenarios, HTTPS inspection may block the downloading and uploading of PDF files to and from the Web Server.
PRJ-59786,
PRHF-38340
Security Gateway The FWK process may unexpectedly restart when running the memory detection leak procedure.
PRJ-59607,
PRHF-38380
Security Gateway In a specific scenario, file downloads intermittently stop until resumed manually because of HTTP parsing issues and Content Awareness parsing failures.
PRJ-58628,
PRHF-36742
Security Gateway In a Maestro environment with configured Virtual System Load Sharing (VSLS) Mode, one of the Security Gateways on an SGM may be unresponsive until it is restarted several times.
PRJ-58390,
PRHF-36744
Security Gateway The DSD process (Dynamic Split Daemon) may exit when the " affinity" command input is large.
PRJ-61165,
PRHF-39691
Security Gateway A rare issue in HTTP/2 multiplexing may lead to traffic disruption. Refer to sk183441.
PRJ-56438,
PRHF-35363,
PRJ-58861,
PMTR-110741,
PRJ-59203,
PRHF-37975
Security Gateway In a rare scenario, the FWK process may unexpectedly exit and bring down the Security Gateway.
PRJ-58393,
PRHF-36652
Security Gateway In some scenarios, a memory leak may occur in the FWK process.
PRJ-60946,
PRHF-39464,
PRJ-61452,
PRHF-39847
Security Gateway - The CPD or FWK process may unexpectedly restart when handling the interface statistics.

- The CPVIEW_SERVICES, RAD, SNMPD and VPN processes may exit with a core dump file because of memory corruption.

Refer to sk183544.
PRJ-59353,
PRHF-37361
Security Gateway In a rare scenario, an outage may occur in an Azure environment after one cluster member crashes and recovers.
PRJ-58217,
PRHF-37208
Security Gateway A rare race condition may cause a Security Gateway to restart when updating the statistics.
PRJ-59114,
PRJ-57842
Security Gateway Some Access Control Rule Base flows may increase CPU utilization .
PRJ-57932,
PRHF-36685
Security Gateway In rare scenarios, Security Gateway may crash when running the " ethtool -x" or the " ethtool -X" command for an interface that uses the AWS ENA network driver.
PRJ-59816,
PRHF-38598
Security Gateway In rare scenarios, the CPD process may unexpectedly exit, generating a core dump.
PRJ-59151,
PRHF-37843
Security Gateway After enabling Security Zones in NAT Rule Base, wrong IP address is shown in logs and NAT is performed incorrectly. Refer to sk183088.
PRJ-59619,
PMTR-111544
Security Gateway In a rare scenario, if the USIM process exits during firewall memory mapping, it can result in a Security Gateway crash.
PRJ-58631,
PRHF-36749
Security Gateway In a rare scenario, the FWK process may exit because of memory corruption.
PRJ-60412,
PRHF-39061
Security Gateway Policy installation fails with the error message: " All the rules in layer "" contain only expired time objects. See sk155253 for more details".
PRJ-58445,
PMTR-109929
Security Gateway In a rare scenario, Security Gateway may crash with vmcore when working in Kernel Mode Firewall (KMFW).
PRJ-59119,
PMTR-110235
Security Gateway In a rare scenario, the RAD daemon may exit during large memory allocation operations.
PRJ-57676,
PRHF-36647
Security Gateway A stability issue where the ICAP Server may unexpectedly restart when processing traffic from a Security Gateway with Threat Emulation enabled.
PRJ-60536,
PRHF-38638
Security Gateway In some scenarios, in a cluster environment, when URL Filtering is enabled, there may be traffic disruption.
PRJ-60203,
PRHF-38844
Security Gateway In a rare scenario, VoIP Traffic fails after the initial call when SecureXL operates in User Mode (UPPAK). Refer to sk183218.
PRJ-60530,
PRHF-38547
Security Gateway In a rare scenario, the Security Gateway may crash during email inspection.
PRJ-60548,
PRHF-38708
Security Gateway Incorrect memory handling may cause the FWK process to unexpectedly exit.
PRJ-56340,
PRHF-35382
Internal CA In some scenarios, a VPN outage may occur after an ICA renewal.
PRJ-57869,
AAD-2659
Threat Prevention In rare scenarios, SSH connections may be dropped when SSH Deep Packet Inspection (SSH DPI) is activated on the Security Gateway.
PRJ-59994,
PRHF-33276
Threat Emulation In rare scenarios, the Threat Emulation Software Blade may fail to correctly classify the file type.
PRJ-61767,
PMTR-116315
Threat Extraction The Threat Extraction Software Blade may inadvertently delete some system files on the Security Gateway. Refer to sk183512.
PRJ-61981 Threat Extraction A memory leak can occur in the Threat Extraction file inspection process for HTTP/S protocols. When memory consumption reaches the maximum allowed allocation, it causes the process to crash and automatically restart.
PRJ-60243,
PRHF-38820
Identity Awareness PDP to PEP Identity synchronization may fail on the PDP side if an alternative IP address for PEP communication is configured, as described in sk60701.
PRJ-59252,
PMTR-111703
Identity Awareness In a rare scenario, the PDPD process may unexpectedly exit during a cluster failover.
PRJ-57645,
PRHF-36542
Identity Awareness In a rare scenario, when fetch_by_SID is enabled, the PDPD process repeatedly exits. Refer to sk182745.
PRJ-58460,
PRHF-37149
Application Control HTTP traffic dropped by PSL because of missing Host header. Refer to sk183569.
PRJ-59611,
PRHF-38383
Application Control If the Access Rule Base does not contain Extended/Detailed Log Tracking options, category override functionality fails when the "partial load" feature is enabled.
PRJ-59617,
PRHF-38387
Application Control Some custom applications in the HTTPS Inspection policy are not matched if they are part of a Group object. Refer to sk183176.
PRJ-57182,
PRHF-36126
URL Filtering URL Filtering may not classify a site in a specific rare scenario when the Security Gateway is configured as a proxy.
PRJ-58757,
PRHF-37462
URL Filtering In some scenarios, when URL Filtering Software Blade analyzes web requests, the RAD error may appear in /var/log/messages: " rad_kernel_urlf_request_serialize: string len =XXXX bigger than max 4096".
PRJ-56476,
PRHF-35174
IPS In some scenarios, a Security Gateway is not listed as an option for the Threat Prevention uninstall, even though the Threat Prevention Software Blade is disabled on the Security Gateway object.
PRJ-60940,
PRHF-38863
IPS The FWK process may unexpectedly exit during HTTPS inspection flow which requires the RAD service categorization.
PRJ-56517,
PRHF-35504
DLP DLP policies may not correctly block password-protected and unprotected files during Google Drive uploads, despite the Content Awareness Software Blade configuration.
PRJ-59500,
PRHF-30036
Anti-Virus When Anti-Virus is enabled, files are not downloaded with the " Failed writing the file" error printed in logs, and the block page is not displayed.
PRJ-58656,
PRHF-37376
Anti-Virus RAD queries fail, generating " wrong status code in reply" errors logged in $FWDIR/log/rad_events/Error/* files. Refer to sk183009.
PRJ-60011,
PMTR-113461
Anti-Bot In some scenarios, the Anti-Bot Software Blade fails to parse external IoC feeds with IP address observables.
PRJ-58841,
PMTR-105936
Anti-Bot When the Security Gateway with FIPS mode is enabled, running the Anti-Virus and Anti-Bot Software Blades updates with the " fw update -b AB -b AV -f" command fails.
PRJ-59224,
PRHF-38081
Anti-Bot In some scenarios, a SmartConsole log with the Anti-Bot Software Blade entries may appear when the Anti-Bot Software Blade is disabled in the profile.
PRJ-58804,
AAD-3331,
PMTR-110853
SSL Inspection The "Detect" logs for Client's TLS alerts are not aligned with the Server's TLS alerts logs. This is a cosmetic issue.
PRJ-57461,
PMTR-109067,
PRJ-58871,
PMTR-110943
SSL Inspection When a TLS connection is rejected because of no shared key exchange between the client and the Security Gateway, no log is generated to inform the administrator.
PRJ-59777,
PMTR-113097
SSL Inspection The "HTTPS Inspection Rule ID" and "HTTPS Inspection Rule Name" fields are seen in the "Bypass Under Load" and "Learning Mode" bypasses logs although they should not be printed.
PRJ-60106,
PRHF-38755
Mobile Access The HTTPD process periodically exits when accessing the Mobile Access Software Blade Citrix application because of the memory leak in the Citrix proxy implementation.
PRJ-60391,
PMTR-114281
ClusterXL The CPHAPROB process may exit with a core dump file.
PRJ-60533,
PRHF-38566,
PRJ-60545,
PRHF-38704
ClusterXL In ClusterXL High Availability setup, a crash may occur on both the primary and secondary members, causing network outages.
PRJ-59391,
PMTR-110959
ClusterXL Running the " cphaprob -a if " command in the VSX Cluster may cause the FWK process to exit.
PRJ-59874,
PRJ-59583
ClusterXL The FWK process may exit after enabling or disabling the "Same VMAC" feature. Refer to sk165674.
PRJ-60293,
PRHF-38847
ClusterXL A race condition may occur during startup when the ROUTED daemon does not receive all cluster Virtual IP addresses, causing static routes to disappear.
PRJ-59565,
PMTR-112079
ClusterXL ClusterXL drops traffic that is sent to its IPv6 Virtual IP Address that is configured with the Unicast Link-Local scope (/64). Refer to sk183104.
PRJ-58081,
PMTR-68784
SecureXL Packet drops may occur if the same multicast packet is received on multiple interfaces.
PRJ-57037,
PRHF-32840
SecureXL High volumes of RST packets may cause CPU spikes, resulting in incoming network packet drops on SND instances.
PRJ-60686,
PRHF-39209
SecureXL The packets may not be accelerated because of a routing issue.
PRJ-60568,
PMTR-113304
SecureXL In a rare scenario, the Security Gateway may become unresponsive during extended high memory utilization.
PRJ-60256,
PMTR-113688
SecureXL SecureXL in User Mode (UPPAK) may restart when the Security Gateway is under high load and cpWatchDog triggers a reboot.
PRJ-60606,
PMTR-114373
SecureXL The Hardware Acceleration offloaded connection may break when the route is updated, affecting the offload flow and slowing down operations.
PRJ-60070,
PMTR-111505
SecureXL Running the " tcpdump" command on all interfaces (for example, " tcpdump -peni any") on machines with SecureXL in User Mode (UPPAK) while under heavy traffic load may cause the system to hang. Refer to sk183222.
PRJ-59363,
PMTR-111468
SecureXL When SecureXL works in User Mode (UPPAK), in a VSX environment with many virtual systems, the Gaia Portal may not be accessible when it reaches its internal connection limit.
PRJ-60310,
PMTR-114110
SecureXL The USIM_x86 process may potentially exit because of a race condition when a route is simultaneously used by multiple SND cores.
PRJ-59969,
PMTR-113266
SecureXL A warning message " adp_rt4_delete: rt entry .... does not exist for slot 1" may be printed in the /var/log/dmesg file while VPN connection remains active.
PRJ-60257,
PMTR-113479
SecureXL In some scenarios, the Security Gateway may crash while running " cpstop" or disabling MDPS when SecureXL works in User Mode (UPPAK).
PRJ-61217,
PRHF-39512
SecureXL The Security Gateway with SecureXL in User Mode (UPPAK) may crash under load during bond interface state flapping.
PRJ-61107,
PMTR-108077
SecureXL SecureXL in User Mode (UPPAK) may be incorrectly enabled or disabled during runtime or Jumbo Hotfix Accumulator installation.
PRJ-59017,
PMTR-111199
SecureXL Memory allocation issue when handling Jumbo Frames.
PRJ-60384,
PRHF-38461,
PRJ-60394,
PRHF-39028
SecureXL In an asymmetric UDP traffic scenario (Client-to-Site VPN and Site to Site VPN distributed to different members), the connection may not get accelerated.
PRJ-61025,
PRJ-61004
SecureXL SecureXL in User Mode (UPPAK) may restart when adding or removing VLAN interfaces and the Security Gateway is under high load.
PRJ-60056,
PRHF-38747
SecureXL After a VSX reboot, other Virtual Systems (VS's) enter a Down/Lost state while USIM core files are generated.
PRJ-60238,
PRHF-37606
Routing In rare cases, when an internal BGP (iBGP) peer disconnects during a graceful restart, BGP may fail to advertise all routes. However, the missing routes still appear under "adj-rib-out" with a next hop of "0.0.0.0."
PRJ-58788,
PRHF-37697
Routing Duplicate entries in the kernel routing table can occur when iBGP peers disconnect and reconnect, causing the same routes to be added multiple times rather than properly replaced.
PRJ-60690,
PMTR-114670
Routing When obtaining a new IP address using the " dhclient -r" command turning off and on the interface configured as Dynamic Address IP (DAIP), the interface loses its IP address and fails to acquire a new one from the DHCP Server.
PRJ-59245,
ROUT-3336
Routing The ROUTED daemon asserts when enabling eBGP multihop on a directly connected interface.
PRJ-58782,
ROUT-3107
Routing The ROUTED daemon may exit with a core dump file during IBGP synchronization.
PRJ-60101,
HAAN-880
Routing BGP sessions may terminate upon receiving a BGP Update containing an AS_SET Path Attribute when Peer Local AS was configured on the Security Gateway.
PRJ-57627,
PMTR-109855
VPN When a network connection is established simultaneously in both directions (server-to-client and client-to-server), the Security Gateway experiences connectivity issues because of incorrect packet dispatching, leading to dropped packets. Refer to sk183072.
PRJ-60613,
PMTR-114453
VPN After establishing a successful VPN connection from IKEv2 Client to VS with traffic flowing, the Client disconnects repeatedly with " VPN tunnel has disconnected: Failed to renew IP address" then reconnects with a new Office Mode IP address.
PRJ-61823,
PRHF-40371
VPN After an upgrade, Site to Site VPN tunnels (IKEv2) fail to establish. Logs show the " Auth exchange: Sending notification to peer: Invalid syntax" and " INVALID_KE_PAYLOAD" errors for IKE traffic. Refer to sk183550.
PRJ-57842,
PMTR-110144
VSNext In VSX/VSNext environments with 50 or more VS's, CPView VSX statistics is blocked until re-enabled manually.
PRJ-58292,
PMTR-110132
VSNext In VSNext environments, CPView VSX Data shows only VS0.
PRJ-58599,
PMTR-110482
VSNext VSNext configuration is not included in the output of the " show configuration" command in Clish.
PRJ-57418,
PMTR-110875
VSNext Virtual Switches with names larger than 128 characters cannot be deleted, the " Virtual System with ID2 does not exist" error is displayed.
PRJ-59014,
HEC-926
VSNext VS creation request may fail because the timeout was too short
PRJ-57478,
PMTR-109849
VSNext Occasional failures during simultaneous creation of multiple Virtual Systems (VS's), where identical IDs are assigned to more than one VS.
PRJ-59015,
HEC-1032
VSNext Some Management API requests may not be sent when creating many VS's in parallel.
PRJ-61129,
PMTR-116039
VSNext VSNext Virtual Gateway drops traffic when it is connected to a Virtual Switch. This issue affects systems running NGTP software blades. Refer to sk183460.
PRJ-57672,
PMTR-109851
VSNext Creating multiple Virtual Gateways may fail with the " Setting management connection failed!" message.
PRJ-59171,
PRHF-37466
VSX A memory leak may occur in a VSX environment, related to the transmitting packets module.
PRJ-58249,
PRHF-37106
VSX SNMP counters may return incorrect data on VSX.
PRJ-59035,
PRHF-27999
VSX In a VSX environment, the Security Gateway may crash when removing an interface from topology.
PRJ-57746,
PRHF-36734
VSX In a rare scenario, during the VSX Gateway Wizard, SmartConsole disconnects with the warning " The connection with the server was lost. Any unsaved changes will be preserved". And SmartConsole may crash with the " SmartConsole has experienced a serious problem and must close immediately" error.
PRJ-57294,
PRHF-36254
VSX Output of the " dynamic_split -p" command shows " Dynamic Split is currently off (Stopped due to State Verification failure)", on a VSX Gateway. Refer to sk181231.
PRJ-61046,
HEC-1463
VSX After enabling CoreXL instances on a Virtual System, the policy status may be displayed as "N/A".
PRJ-58803,
PRHF-37713
Gaia OS When attempting to create cloning groups on an R82 Security Gateway, the " Error - Home directory for 'cadmin' cannot be in /home/cadmin directory" error is printed. Refer to sk182989.
PRJ-58700,
PRHF-37362
Gaia OS In a Maestro environment with RADIUS users, accessing the Gaia Portal for MHO causes an " ERR_EMPTY_RESPONSE" error and may cause the Gaia Portal not to respond.
PRJ-59012,
PRHF-37820
Gaia OS In a Maestro environment, an error message about short string length may be incorrectly displayed when setting an expert password string that includes the colon ":" character on the Security Gateway.
PRJ-61662,
ODU-2714
Gaia OS The Redis Server does not start after installing the Gaia API Build 299. Refer to sk143612.
PRJ-59293,
PRHF-27173
VoIP High volumes of VoIP/ SIP traffic may trigger a Security Gateway crash.
PRJ-60460,
PMTR-114441,
VSECPC-10081
CloudGuard Network The CloudGuard Network Central License utility incorrectly distributes licenses to Azure Virtual vWAN Gateways that already have licenses included during deployment.
PRJ-59475,
SDWANGW-2360,
PMTR-112190
SD-WAN Dynamic IP address changes for DAIP Gateway objects are not propagated to all Security Gateways in the SD-WAN VPN community, causing VPN connectivity failures.
PRJ-59849,
HEC-951
Scalable Platforms The logging_worker daemon may consume a lot of memory per Virtual System.
PRJ-58555,
PMTR-110252
Scalable Platforms On ElasticXL platform, there may be unnecessary or unsuccessful attempts to update the distribution of traffic among the cluster members.
PRJ-59846,
HEC-952,
PMTR-112869,
PMTR-112683
Scalable Platforms In VSNext mode, Virtual Systems there may be high CPU consumption.
PRJ-60318,
HEC-1289
Scalable Platforms In the VSNext mode (on ElasticXL and Maestro Security Groups), the Gaia gClish / Gaia Clish command " show interface" in the context of Virtual Switches fails with " CLINFR0699 Invalid command".
PRJ-58961,
PRJ-57191
Scalable Platforms Import an R82 upgrade package may fail with " [ERROR] Failed to transfer package to several members, Import was aborted" because of timeout which occurs while copying the package to all Security Group members.
PRJ-59061,
PMTR-106842
Scalable Platforms Changing the bond mode on Scalable Platform Security Group members may cause a MAC address mismatch on the bond interface because of the bond slaves reordering that does not match the database. Refer to sk182488.
PRJ-58041,
HEC-983
Scalable Platforms The " fw fetch local" command fails on a Virtual System without SIC established because the SIC name is missing.
PRJ-57813,
PRHF-29470
Scalable Platforms DNS configuration may not be pulled to other Security Gateway Members (SGMs) from the Single Management Object (SMO).
PRJ-59359,
PRJ-58161
Scalable Platforms IP broadcast helper cannot forward the packets if the IP address of the "relay to" is not directly connected to the Security Gateway.
PRJ-59395,
PMTR-111927
Scalable Platforms Maestro may not properly respond to Router Solicitation messages with the expected Router Advertisement messages.
PRJ-58600,
PMTR-110500
Scalable Platforms In some scenarios, the perfanalyze scripts output shows duplicates in cores data, this can cause the CPD process to crash.
PRJ-59168,
FMW-3410
Scalable Platforms The " ws_mux_host_only_active_pass: ERROR: There is not enough data in stream to pass" error may be printed in logs. This is a cosmetic issue.
PRJ-59670,
PMTR-110155
Scalable Platforms When running the license deletion command " g_cplic del " in a Maestro setup, the license is removed from the cp.license file but not from cp.license.smo, causing the deleted license to unexpectedly reappear after a policy installation.
PRJ-58088,
PRHF-36586
Scalable Platforms Configured proxy ARP may not work as expected, when the "Same VMAC" feature is enabled.
PRJ-60476,
PMTR-110389
Scalable Platforms The " asg_dr_verifier" script fails when OSPF Graceful Restart is configured with a grace period.
PRJ-59877,
PMTR-113194
Scalable Platforms A reboot loop with a generated configuration pnote may be triggered when Security Group hostname contains strings with " mq" or " otlp".
PRJ-58489,
PMTR-109895
Scalable Platforms Upon contract renewal, non-SMO members in the Maestro Security Group may not get the updated contract automatically.
- The fix requires this Jumbo Hotfix Accumulator Take to be installed on all the members of the group.