Header/footer test page

[My Favorites](https://support.checkpoint.com/favorites)

Solution ID: sk106162

* * *

Technical Level:

Basic

[Email](mailto:?subject=sk106162%20-%20Jumbo%20Hotfix%20Accumulator%20for%20R77.30%20(R77_30_jumbo_hf)&body=Solution%20Title:%20Jumbo%20Hotfix%20Accumulator%20for%20R77.30%20(R77_30_jumbo_hf)%0D%0ASolution%20ID:%20sk106162%0D%0ASolution%20Link:%20https://support.checkpoint.com/results/sk/sk106162%0D%0A-------------------------------------------------------------%0D%0AFor%20Disclaimer%20of%20Warranty%20and%20Copyright%20info:%20http://www.checkpoint.com/copyright.html)

[Print](https://support.checkpoint.com/results/sk/sk106162#)

# Jumbo Hotfix Accumulator for R77.30 (R77\_30\_jumbo\_hf)

ProductMulti-Domain Security Management, Security Gateways, Security Management

VersionR77.30 (EOS)

OSGaia

PlatformAll

Last Modified2023-09-11

## Solution

**Table of Contents:**

- Introduction

- Availability
  - General Availability Take
- Important Notes

- List of resolved issues in the General Availability Takes

- Installation instructions

- Uninstall instructions

- List of replaced files

- Revision History

## Introduction

**R77.30 Jumbo Hotfix Accumulator** is an accumulation of stability and quality fixes resolving multiple issues in different products.

This Incremental Hotfix and this article are periodically updated with new fixes.

The list of resolves issues below describes each resolved issue and provides a Take number, in which the fix was included. A resolved issue is included in the Incremental Hotfix starting from the Take number listed in this table (inclusive). The date, when this take was made available is also listed in the table.

## Availability

- ### General Availability Take

- _**Take\_351**_ is the _latest_ General Availability release that can be directly downloaded from Check Point Cloud using CPUSE and from this article:

|     |     |     |     |
    | --- | --- | --- | --- |
    | Take | Date | CPUSE Identifier | CPUSE offline package |
    | Take\_351 | 06 Oct 2019 | `Check_Point_R77_30_JUMBO_HF_1_Bundle_T351_FULL.tgz` |  (TGZ) |

**Note:** Effective Oct 6th 2019, General Availability Take\_351 is available for CPUSE online installation in Gaia Portal and Gaia Clish (it replaces Take\_345).

Notes:
    1. For _Smart-1 405 / 410 appliances_, it is necessary to install _Take\_266_ and higher (refer to [sk117578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117578)).
    2. Effective February 17th 2017, the GA Take\_216 is available for CPUSE online installation in Gaia Portal and Gaia Clish (it replaces Take\_205).
    3. Effective December 15th 2016, the GA Take\_205 is available for CPUSE online installation in Gaia Portal and Gaia Clish (it replaces Take\_185).
    4. Effective November 10th 2016, the GA Take\_185 is available for CPUSE online installation in Gaia Portal and Gaia Clish (it replaces Take\_159).
    5. Effective June 20th 2016, the GA Take\_159 is available for CPUSE online installation in Gaia Portal and Gaia Clish (first General Availability Take).
    6. For _15000 / 23000 appliances with 40 GbE_ cards, it is necessary to install _Take\_162_ and higher (refer to [sk112517](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112517)).
    7. For 23900 appliances, it is necessary to install Take\_327 or Take\_331 and higher (refer to [sk107516](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107516)).
  - **Online installation** \- use CPUSE _identifier_ either in Gaia Portal, or in Gaia Clish.

- **Offline installation** \- use CPUSE _offline / exported package_ either in Gaia Portal, or in Gaia Clish.

## Important Notes

- Users with extended support for R77.30, who are using Client Authentication, and who need to handle the POODLE Bites vulnerability (CVE-2014-3566) ( [sk102989](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102989)), [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

- Refer to [sk98028 - Jumbo Hotfix Accumulator FAQ](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98028).

- This Jumbo Hotfix Accumulator is suitable only for **Gaia OS** (SecurePlatform / Linux / IPSO / XOS / Windows OS are _not_ supported).

- This Jumbo Hotfix Accumulator (starting in _Take 189_) can be applied to R77.30 instances running in [Amazon Web Services (AWS)](https://www.checkpoint.com/products/virtual-appliance-for-amazon-web-services/), or in [Microsoft Azure](https://www.checkpoint.com/products/vsec-microsoft-azure/).

Refer to [sk109141 - Installing the Jumbo Hotfix Accumulator on Security Gateways in Amazon Web Services (AWS) and Microsoft Azure](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109141) for additional information.

On Security Gateway running in Amazon Web Services (AWS), it is _**not**_ supported to install **Takes 189 and higher** of this Jumbo Hotfix Accumulator when the user's shell is configured to **`/etc/cli.sh`** (the default shell).
1. _**Before**_ installing Takes 189 and higher, the user's shell must be changed to any shell other than `/etc/cli.sh` \- e.g., `/bin/bash`, `/bin/csh`, `/bin/tcsh` (refer to [R77 versions Gaia Administration Guide](http://supportcontent.checkpoint.com/documentation_download?id=24828) \- chapter "User Management" - section "Users").
2. _**After**_ installing Takes 189 and higher, it is _**not**_ supported to change the user's shell back to `/etc/cli.sh`.
- This Jumbo Hotfix Accumulator (all its Takes) is _**not**_ supported on [vSEC for Google Cloud Platform](https://www.checkpoint.com/products/vsec-google-cloud-platform/).

- Each "Take" of this Jumbo Hotfix Accumulator is always based on latest GA Take of [Check Point R77.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104859).

- It is _**not**_ supported to install this Jumbo Hotfix Accumulator using the [ISOmorphic Tool](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk65205)

(do _not_ add this Jumbo Hotfix Accumulator in the "`Select hotfixes:`" section of the ISOmorphic Tool).

- It is recommended to install Jumbo Hotfix Accumulator on all the R77.30 machines in the environment - Security Gateways / Management Servers / etc. running on Gaia OS.

- This Jumbo Hotfix Accumulator is suitable for these products and configurations:
  - Security Gateway
  - Cluster
  - VSX
  - Security Management Server
  - Multi-Domain Security Management Server
  - Standalone machine (Gateway + Management)
  - Endpoint Security Server
  - Log Server
  - SmartEvent Server
  - SmartReporter Server
- There is _no_ conflict between this Jumbo Hotfix Accumulator and the [R77.30 Add-On](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105412). These two packages can be installed in parallel without any issues on R77.30 Security Management Server / Multi-Domain Security Management Server / Log Server / Endpoint Security Management Server / Endpoint Security Policy Server.

- Starting in _Take\_266_, this Jumbo Hotfix Accumulator supports **[TLS 1.2](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107166)** in the following products / features:

- ICA Management Portal / Management Portal
  - Secure Internal Communication (SIC), except the SIC initialization that communicates over SSLv3
  - Gaia Portal
  - Platform Portal
  - Software Updates
  - Mobile Access blade
  - Endpoint Security Management Server
  - SSL Network Extender (SNX)

Notes:
  - For _Threat Emulation_ customers that do not allow automatic updates from the Check Point Cloud, it is important to update the Threat Emulation Engine according to [sk92509 - Offline updates for Threat Emulation images and engine](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92509).

- To get an improved SmartConsole that supports TLS 1.2, refer to [sk107166](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107166).
- For _Smart-1 405 / 410 appliances_, it is necessary to install _Take\_266_ and higher (refer to [sk117578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117578)).

- For _15000 / 23000 appliances with 40 GbE_ cards, it is necessary to install _Take\_162_ and higher (refer to [sk112517](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112517)).

- On _21000 appliances with SAM card_, due to specific stability issues, Take 210, Take 213 and Take 216 should _**not**_ be installed. Refer to [sk116070](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116070).

- **This Jumbo Hotfix Accumulator has to be installed only after successful completion of Gaia First Time Configuration Wizard and _reboot_.**

## List of resolved issues in the General Availability Takes

Enter the string to filter this table:

|     |     |     |
| --- | --- | --- |
| ID | Product | Description |
| Take 351 (06 Oct 2019) - _General Availability Take_ |
| PRJ-2376,<br>PRJ-2358 | Gaia OS | CVE-2019-11477, CVE-2019-11478 & CVE-2019-11479: TCP SACK PANIC - Linux Kernel vulnerabilities. Refer to [sk156192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk156192). |
| PRJ-1330,<br>02541089 | SecureXL | Resolved issue in multicast routing lookup. |
| PMTR-27365,<br>IDA-1609 | Identity Awareness | In some scenarios, the Identity Agent fails to authenticate using Kerberos SSO due to very large Kerberos ticket, and the agent fallsback to User/Password authentication. Refer to [sk145832](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk145832). |
| PRJ-366,<br>PMTR-33177 | Identity Awareness | In some scenarios, when using Load Sharing, upon the same IP address used by two different users, users may be able to access or to be restricted from accessing resources without proper roles. |
| Take 348 (24 Apr 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T348\_FULL.tgz |
| IDA-1689,<br>PMTR-31034 | Identity Awareness | Removed unnecessary identity update, during Identity Agent or Terminal Server Agent IP address change, that results in corruption of PEP database. |
| GAIA-3010,<br>PMTR-23157 | Gaia OS | CVE-2018-15473: Username enumeration is possible due to a premature bail-out while dealing with a malformed packet. The issue exists in several authentication protocols. |
| IDA-1225,<br>PMTR-33364 | Identity Awareness | Fixed possible session corruption on PDP side that could lead to unexpected behavior. |
| Take 347 (27 Mar 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T347\_FULL.tgz |
| PMTR-26171,<br>PMTR-26174 | SSL Inspection | Changed SSL Network Extender on MacOS to 64-bit architecture to support 32 bit apps depreciation in OSX. |
| PMTR-35032,<br>PRJ-99 | VPN | Important security update for IPSec Site-to-Site (S2S) VPN. |
| Take 346 (13 Feb 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T346\_FULL.tgz |
| 02468036 | UserCheck | Improved stability when Push Notifications are enabled on Mobile Access blade. |
| 02657434 | VPN | Improved connectivity with 3rd party VPN peers using IKEv2. Refer to [sk120835](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120835) |
| 02100804 | VPN | After Cluster failover, VPN tunnel is down and "Unknown SPI for IPsec packet" log is shown. Refer to [sk112339](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112339). |
| PRHF-608 | SecureXL | Improved stability of VSX gateway when under heavy load when SecureXL is enabled. |
| JPMC-284 | SecureXL | Improved stability of SAM card when running multicast jumbo traffic packets. |
| JPMC-316 | SecureXL | Improved stability of SAM card when PIM is configured in Sparse Mode on its interfaces. |
| Take 345 (25 Feb 2019) - _General Availability Take_ |
| PMTR-19734 | IPS Blade | Legitimate EDNS queries are dropped with "Non Compliant DNS - Bad Resource Record format, Illegal EDNS0 RR" log. Refer to  [sk112578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112578). |
| PMTR-26587 | Identity Awareness | On some occasions, Terminal Server users are not enforced by the correct access role. |
| Take 344 (10 Jan 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T344\_FULL.tgz |
| PMTR-24897 | VoIP | H323 - Connection might fail when Gatekeeper initiate the call to endpoint. |
| PMTR-18093,<br>PMTR-11941, PMTR-13827, 02482488 | CoreXL | CoreXL FW instance offloads a partial/anticipated connection that already exists. Refer to Scenario 5 in [sk100467](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100467). |
| PMTR-27889 | Threat Extraction | When /tmp/scrub folder has large amount of files (over 5000) it won't be cleaned. |
| PMTR-23309 | Security Gateway | In some MGCP clients - Source port changes even when MGCP protocol is disabled which cause MGCP traffic to not reach its destination properly. |
| PMTR-20131 | SecureXL | Connectivity issues with following drops: 'handle\_outbound\_pac, Reason: connection not found' - Refer to [sk101134](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101134), Scenario 2 |
| PMTR-24938 | VoIP | SIP packets that contain \* in the 'contact' field are being dropped. |
| PMTR-26139 | SSL Inspection | HTTPS inspection added support to custom extension used by Apple. |
| PMTR-22966 | SSL Inspection | HTTPS categorization: add support for certificates up to 16KB in size. |
| PMTR-26020 | Web Intelligence | In rare cases, XFF header obfuscation may not work when HTTPs Inspection is enabled. |
| Take 343 (17 Dec 2018)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T343\_FULL.tgz |
| PMTR-22951,<br>02490101 | VPN | ikeV2 stability improvement with 3rd party peers. |
| PMTR-18922,<br>PMTR-24797 | VPN | Certificate validation: In compliance with RFC 2560 - added support for empty 'nextUpdate' fields in OCSP response. |
| PMTR-23443,<br>02757621 | Endpoint Security | "Cannot create certificate" error message, when cannot enroll user certificate on Endpoint Security VPN client after January 24th 2018.<br>Refer to [sk122874](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122874). |
| PMTR-23326,<br>PRHF-1352 | Gaia OS | "set fcd revert" command fails, between Take 309 and 343 of Jumbo Hotfix Accumulator for R77.30 |
| PMTR-19536<br>CLUS-1073 | ClusterXL | Improved Cluster stability during policy installation, reduced interface flapping events and high CPU load on the Cluster Gateways.<br>Refer to [sk133372](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk133372) |
| Take 342 (26 Dec 2018) - _General Availability Take_ |
| PMTR-19062,<br>02305365 | SecureXL | In rare cases, in SIP implementations, call might disconnect after a few minutes. Refer to [sk112913](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112913) |
| PMTR-17227,<br>UP-225 | Security Gateway | Fixed SAM rules corruption after reboot. |
| PMTR-19771,<br>02645755 | Security Gateway,<br>CoreXL | SecureXL forwards non-accelerated packets to the gateway causing it to crash. |
| PMTR-15680,<br>02508263 | SecureXL | Connectivity issue during policy installation, when NAT templates are enabled between CPUs. |
| PMTR-15586,<br>PMTR-10842 | SecureXL | Reduce/eliminate drops on interface during install policy with high load traffic. |
| PMTR-22572,<br>PMTR-3899 | HW Accelerator | Additional fixes to resolve crashes for certain conditions with logs indicating "ADP Slot hung." |
| PMTR-19551,<br>02694599 | Gaia OS | Output of "show message motd" clish command is corrupted if the "motd" message is too long. Refer to [sk122199](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122199). |
| PMTR-22724,<br>02059238 | VPN | Improved VPN connectivity when using Diffie Hellman groups 19 or 20 with 3rd parties. Refer to [sk112156](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112156) |
| PMTR-17522,<br>SWG-1078 | DLP | Memory leaks when HTTPS Inspection and Probe Bypass are enabled. |
| PMTR-19863,<br>01619775 | Security Gateway | Policy installation failure when number of SAM rules is higher than 25000. Refer to [sk110560](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110560) |
| 02763128 | Web Intelligence | Enhanced HTTP parser to distinguish between malformed HTTP traffic and valid HTTP traffic that is not RFC compliant, but exists in the real world. |
| Take 339 (31 Oct 2018) |
| 02669997 | Hardware | Improved forensic data collection for SAM stability. |
| 02366690 | Gaia OS | Improved stability of CPD process on Multi Domain Server, during hardware sensor reading. Refer to [sk114936](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114936). |
| 02413299 | VoIP | CPU peaks may be experienced when using H323 (VoIP protocol). |
| IDA-648 | Identity Awareness | Improved pdpd stability with AD Query in specific manual configuration overriding per gateway for Account Unit. |
| 02708339 | VPN | Improved IKEv2 compatibility in clustered CloudGuard Azure environments. Refer to [sk123374](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk123374). |
| 02436860 | Content Awareness | Improved DLP NCR encoding support. |
| Take 338 (20 Sep 2018) - _General Availability Take_ |
| 02481671 | Threat Extraction | When Threat Extraction is configured to block access to original files and to block corrupted/encrypted files (both not default) - The email that indicates that the encrypted/corrupted file has been removed is not received by email recipient. |
| 01850251 | Anti-Malware | UDP performance with Threat Prevention was improved. |
| SA-31 | Gaia OS | Fixing an issue which can lead to the loss of connectivity. |
| 02421166,<br>02482081,<br>02468381 | VPN | Added Azure VPN IKEv2 enhancement. Refer to [sk116157](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116157). |
| 02431088 | VPN | Stability improvements for IKEv2 and Azure gateways. |
| 02058553 | VPN | IKEv2 support for more than 8 proposals. |
| 02471564 | SSL Inspection | Improved stability of WSTLSD daemon. |
| IDA-949 | Identity Awareness | RADIUS accounting server does not understand accounting-response from Check Point gateway. Refer to [sk130532](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk130532). |
| 01786753 | Identity Awareness | AD users with special characters in their names cannot authenticate.<br>Refer to [sk131872](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk131872). |
| 01500409 | Identity Awareness | " _Group membership of the required account (user or machine) could not be retrieved from the AD. Make sure the account exists in the AD_." log is received from Identity Awareness blade when format of RADIUS user is " _user@domain_".<br>Refer to scenario 6 in [sk106133](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106133). |
| IDA-1150 | Identity Awareness | Fixed a MUH Agent issue of sending unnecessary MUH updates causing high CPU on PEP. This lead to delays with getting identities and can cause connectivity issues. |
| IDA-735 | Identity Awareness | Identities are not synced to PEP if two PDPs will report the same network<br>Refer to [sk130373](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk130373). |
| Take 336 (21 Aug 2018) |
| PMTR-20184 | Security Gateway | Check Point response to SegmentSmack (CVE-2018-5390) & FragmentSmack (CVE-2018-5391). <br>Refer to [sk134253](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk134253). |
| PMTR-20189 &<br>PMTR-20188 | UserCheck, <br>VSX | In VSX environment portals are down after uninstalling R77.30 Jumbo Hotfix take 266 or later and there are multiple defunc instances of mpdaemon. |
| 02729238 | SSL Inspection | Improved accuracy of HTTPS Inspection rule-base matching. |
| 01699431 | Mobile Access | Improving stability of SNX roaming feature. |
| 02408359 | QoS | VPN Stability improvements in setups with NAT. |
| PMTR-19603 | Gaia | Jumbo Hotfix uninstall causes issues in boot and communication in TEX product line. |
| 01855951 | VPN | Improved stability for VPN Remote Access when using tcpt. |
| Take 331 (26 Jul 2018) |
| GAIA-2269 | Data Center Security Appliances | Added support for 23900 appliances. Refer to [sk107516](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107516). |
| 02396869 | VPN | Improved tunnel stability in site to site setups. |
| 02447010 | VPN | "You cannot receive an office Mode IP address because the security gateway does not have a license for Office mode" error on SSL Remote Access VPN client (SNX client / Capsule VPN client / Capsule Connect client / Endpoint Connect client) that tries to connect to a Cluster in High Availability mode.<br>Refer to [sk120652](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120652) |
| Take 329 (10 Jul 2018) – Not supported on 23900 appliances |
| 02006858 | VPN | Improving consistency and stability of supernet encryption domains of gateways with Mobile Access blade. |
| PMTR-14587 | Gaia OS | Security hardening for Gaia WebUI |
| PMTR-14615 | Gaia OS | Security hardening for Gaia WebUI |
| PMTR-14614 | Gaia OS | Security hardening for Gaia WebUI |
| 01944349 | Gaia OS | When browsing to the Time page in the GAIA WebUI, two messages are spammed in _/var/log/_ messages (flag is ... and data is...). |
| 02049361 | Gaia OS | Intel X520 DP 10Gb DA/SFP+ Server Adapter is not detected by GAIA OS. |
| 01876093 | Mobile Access | Adding configurable option to allow compressed https connections to internal servers. Refer to [sk128513](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk128513) |
| PMTR-15763 | Gaia OS | Gaia Portal shows blank page after login with Firefox 5x or Chrome 66. Refer to [sk121373](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk121373). |
| THREATEMUL-4272 | Threat Emulation | If Threat Emulation disk space threshold is higher than Log disk space threshold, then Threat Emulation will stop emulation while the logs will continue to accumulate, resulting in the emulation entering fail open. |
| Take 327 (26 Jul 2018) – to be installed only on 23900 appliances |
| GAIA-2269 | Data Center Security Appliances | Added support for 23900 appliances. Refer to [sk107516](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107516). |
| Take 322 (18 Jun 2018) |
| 02725585 | Mobile Access | _CVPN_ daemon stability. |
| Take 320 (11 Jun 2018) |
| 02764970 | Gaia OS | _lspci_ utility showing unknown devices on HP G9 server with 4TH gen Xeon CPU's. |
| 02764972 | Gaia OS | Fixed the output of _raid\_diagnostics_ command. |
| PMTR-9275 | Security Gateway | In rare scenarios, _CPD_ process stops working when running for a long time. |
| 02757263 | SSL Inspection | Improved resumption handshake behavior in SSL inspection. |
| 02757276 | SSL Inspection | Improved handshake handling in case of re-negotiation. |
| CPDIAG-936 | Check Point Diagnostic tool | - New _cpview_ capability to collect and present IO data. <br>- Enabled _cpview_ history collection on Management machines |
| Take 317 (27 Jun 2018) - _General Availability Take_ |
| 02734847 | Web Intelligence | Improved non-compliant HTTP handling. |
| 02365162 | Multi-Domain Security Management Server | When using the Compliance blade with Management HA, _FWM_ might consume high CPU. |
| Take 315 (26 Apr 2018) |
| 02329735 | Check Point Appliances | Customers using 40Gbe Cards with firmware version 12.12.3072 might experience unexpected behavior while using port beacon ( _ethtool –p_) and RMA diagnostics tool. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) for a new firmware version. |
| 02718182 | SSL Inspection | Improved handling of trusted CAs certificates when HTTPS inspection is enabled. Refer to [sk122973](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122973). |
| 02420344 | vSEC VE Security Gateway | vSEC Virtual Edition (running on Azure, AWS, GCP, KVM, Hyper-V) 'too many internal hosts' error in _/var/log/messages_ on Security Gateway. Fix for identifying only VMware platform as vSEC Virtual Edition. |
| Take 311 (4 Apr 2018) |
| IDA-650 | UserCheck | When users try to access an non-existing page in the portal it will redirected to the base home page instead of getting an HTTP 404 response. |
| 01678514 | DLP | Improved connectivity of DLP and FTPS. |
| Take 310 (14 Mar 2018) |
| 02694299 | Cluster | Deleting last backup IP address from VRRP Interface triggers a transition from master state to backup. |
| 02722259,<br>MCFG-101 | Identity Awareness | Captive Portal Kerberos SSO redirection does not work in VSX in new installed VS.<br>**Note:** This fix is relevant for any Take of R77.30 Jumbo Hotfix Accumulator between Take 266 and Take 309 (inclusive). |
| 02693681 | Gaia OS | _fwm logexport -f_ command does not properly export some fields from the log file to an ASCII file. |
| Take 309 (26 Feb 2018) |
| GAIA-1737 | Gaia OS | Security hardening for Gaia Clish |
| Take 308 (19 Feb 2018) |
| THREATEMUL-1861 | Threat Emulation | Integrated Threat Emulation forensics report update capability. For more details, refer to [sk120357](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120357) |
| 02685256 | Threat Emulation | Fixed an issue causing Gaia backup size to increase significantly when using Threat Emulation. |
| IDA-621 (Giraffe) | Identity Awareness | Identity Awareness Feature Pack (including Identity Collector support) scale and quality enhancements. For more details, refer to [sk120979](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120979). |
| 02449938 | SecureXL | SAM enabled interfaces have a maximum MTU of 3950 bytes. |
| Take 302 (27 Mar 2018) _\- General Availability Take_ |
| 02660171 | SecureXL | In a very rare scenario, interface state could change midway through handling of fragmented packet causing SAM to crash. |
| 02701723 | IPS Blade | In rare conditions, following policy installation with an IPS update, some IPS inspected traffic is being dropped, and message logs include messages like:<br>"FW-1 - ips\_cmi\_handler\_match\_cb\_ex: signature (XXX) does not have a policy" |
| 02703382 | Gaia OS | In some cases, "missing state" is erroneously displayed when checking the disk's status via _raid\_diagnostic_, _cpstat_ and _snmpwalk_ commands. |
| PMTR-4786 | DLP | Stability improvement of _dlpu_ process when DLP blade is enabled. |
| IDA-636 | DLP, User Check | Stability improvement of _fwucd_ process during process exit. |
| 02669195 | Multi-Domain Security Management Server | Upon MDS startup in large MDM environments, the _fwm_ process may consume high CPU resources for some time. |
| Take 301 (16 Jan 2018) |
| 02704101 | Security Management Server | After installing R77.30 Jumbo HF take 297, CPD\\SNMPD cores are found on the machine. |
| 02685526 | Security Gateway | In SmartDashBoard, the "Hits" counter in a specific rule does not increase even though traffic was matched to this rule. Refer to [sk115098](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115098). |
| 02694079 | VPN | Simplifying MSS clamping configuration. |
| 02694314 | VPN | Improved stability of _vpnd_ daemon. |
| 02528926 | SecureXL | Improved stability while pushing policy after extended longevity of 8 months on SAM enabled gateways. |
| 02693271 | Gaia OS | PIM hello packets dropped in SmartView Tracker. |
| 02445000 | SecureXL | On rare occasions, multiple iterations of multicast join and leave may result in memory leak. |
| Take 297 (18 Dec 2017)<br>This Take is not supported with SNMP Monitoring. |
| 01986657 | VPN | _cpd_ stability improvements. |
| 02676734 | VPN | Remote Access users cannot connect when using a certificate issued by subordinate CA. |
| 02689074 | VPN | Prevent defaulting Remote Access TTM Configuration files (such as trac\_client\_1.ttm) during jumbo installation after installing any Take higher than Take 266 up to Take 294 (inclusive) of R77.30 Jumbo Hotfix Accumulator. |
| 02676736 | VPN | IKE negotiation fails when using certificates from subordinate CAs. |
| 02439945 | VPN | RIM routes not removed when MEP node fails. |
| 02439913 | VPN | RIM routes are not added to the routing table after failover and immediate failback. |
| 02440245 | VPN | VPN stability improvements. |
| 02678619 | VPN, HTTPS Inspection | Improved stability of WSTLSD daemon during CRL validation. |
| 02655364 | Security Gateway | Improved stability when processing VoIP traffic |
| 02661935 | Security Management Server | If there are more than ten thousand Binary Large Objects (BLOBs) on the Log Server, there may be a delay before new logs show in SmartConsole after a policy installation. |
| 02677133 | Security Management Server, Multi-Domain Security Management Server, VSX | Improved stability of CPD process in Multi-Domain server, Security Gateway and VSX Gateway. |
| Take 294 (23 Nov 2017) |
| 02110663 | VPN | Tunnel to Azure fails periodically. |
| 02489908 | SSL Inspection | Improved SSL handshake for HTTPS inspection. |
| 02674931 | Identity Awareness | httpd process repeatedly failing during startup.<br>**Note:** This fix is relevant for any Take of R77.30 Jumbo Hotfix Accumulator between Take 266 and Take 292 (inclusive).<br>For VSX configurations, refer to 02722259 (Take\_310 ) |
| 02575864 | VPN | IKEv2 - response not send if failed to decode request message. |
| 02455007 | Data Center Security Appliances | On rare occasions (with a very large uptime of more than 250 days), traffic can be dropped after policy installation because a SecureXL template is deleted prematurely from FireWall kernel. Refer to [sk119999](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119999) |
| 02449938 | Check Point Appliances | For SAM enabled interfaces, jumbo frames beyond 4k size may cause instability. Hence, for SAM enabled interfaces, the max MTU is limited to 3950. |
| 02478098 | UserCheck | UserCheck is not presented because the error page was already triggered by another blade in the same session. |
| 02668257 | VSX | When attempting to debug _fwk_ process using the _fw debug_ command, some debugs do not appear correctly. |
| 02658404 | ClusterXL | Traffic interruption on VLAN interfaces during policy installation on ClusterXL Load Sharing Multicast mode. |
| 02489933 | Gaia OS | Output of dmesg command shows "bonding: bond<N>: Error: bond\_3ad\_get\_active\_agg\_info failed" when working with 802.3ad link aggregation |
| 02564276 | Identity Awareness | After IDA agent sends NACHello request, it receives response with empty portal names. |
| 02582480 | Security Management | Policy installation fails on DAIP gateways after changing Domain Server from Standby to Active. |
| Take 292 (19 Dec 2017) - _General Availability Take_ |
| 02563960 | IPS | _fwd process_ or _fw\_full_ process on Security Gateway consumes memory at high level after installing Take 206 of R77.30 Jumbo Hotfix Accumulator ( [sk117655](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117655)) |
| 02569432 | Threat Emulation | When Threat Emulation was configured to send some of the files to the cloud and some locally, the files were sent only locally and not to the cloud. In this release, the configuration in the GUI will take effect and files will be sent to emulation according to the policy. |
| 02659361 | ClusterXL | SNMP query returns wrong outputs for haClusterIpTable |
| 02665619 | SNX | In rare cases, client running Windows 10 Anniversary update experiences disconnections within SNX tunnel. |
| 02656968 | Security Gateway | In rare scenarios, when working with Dynamic Objects, NAT rules are not applied anymore after policy installation or update of software blades signatures. This causes traffic outage for all connections that should undergo NAT. |
| 02536207 | VSX | Added:<br>- Ability to query specific Virtual Device directly using the IP address of the Virtual System.<br>- Ability to query SNMP daemons in the contexts of Virtual Devices sent to the IP Address of VSX Gateway itself using SNMPv1, SNMPv2 and SNMPv3.<br>- New OIDs in the SNMP VSX tree: <br>  - Memory usage for each Virtual System.<br>CPU usage for each Virtual System for each core. |
| 02659849 | VoIP | Data connections of H323 protocol were not opened correctly in VSX cluster environments. |
| 02660349 | DLP, Threat Extraction | Security enhancements for Data Loss Prevention and Threat Extraction blades |
| 02659678 | Threat Emulation | Links inside email with Domain suffix (e.g. www.example.com) were emulated as com files. |
| 02661043 | SmartLog | Improved stability of "`smartlog_server`" process when running queries in SmartLog GUI to several Log Servers.<br>Refer to [sk112826](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112826).<br>Note: This fix is relevant for any Take of R77.30 Jumbo Hotfix Accumulator between Take 198 and Take 286 including. |
| 02655985 | SmartLog | Improved stability of "`smartlog_server`" process when activating the "Auto Refresh" button in SmartLog GUI (upper right corner) for several hours. |
| 02555984 | Security Gateway, Security Management Server, Multi-Domain Security Management Server | Improved memory consumption by FW process and FWD process.<br>Refer to [sk117655](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117655).<br>Note: This fix is relevant for any Take of R77.30 Jumbo Hotfix Accumulator between Take 206 and Take 286 including. |
| 02590882 | SmartEvent | New events are not created in SmartEvent GUI, and "`ERROR: duplicate key value violates unique constraint "seam_event_XXX_pkey"`" in _$RTDIR/log/cpsemd.elg_ file.<br>Refer to [sk105185](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105185). |
| 02532160 | SecureXL | For 21000 appliances with SAM card, improved stability of SAM card when running the "`cpstop -fwflag -driver`" command as a part of kernel memory leak detection procedure.<br>Refer to [sk35496](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk35496). |
| 02401494 | VoIP | Improved check for memory allocation failures under heavy load of VoIP traffic. |
| 02573235 | VSX | Improved support for Connectivity Upgrade (CU) in VSX VSLS.<br>Note: This fix is relevant for any Take of R77.30 Jumbo Hotfix Accumulator between Take 198 and Take 286 including. |
| Take 286 (13 Sep 2017) |
| 02646492 | Gaia OS | In very rare cases, Gaia Portal is not accessible after installing any Take higher than _Take 226_ up to _Take 282_ (including) of R77.30 Jumbo Hotfix Accumulator. |
| Take 282 (24 Aug 2017) |
| 02562476 | Threat Emulation | Mail Transfer Agent does not process e-mails queued prior to installation/upgrade/uninstall of Jumbo Hotfix Accumulator.<br>Relevant only to Takes 221, 225, 226, 266, 272, and 280.<br>Refer to [sk119515](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119515). |
| 02567302 | HTTPS Inspection | HTTPS Inspection fails occasionally during CRL validation failure. |
| Take 280 (16 Aug 2017) |
| 02498183 | HTTPS Inspection, Security Management Server, Multi-Domain Security Management Server | Applications, Dynamic objects and Domain objects are available for use in the HTTPS Inspection policy, but these objects are not enforced on the Security Gateway.<br>Refer to [sk119276](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119276). |
| 02498239 | Threat Prevention, Security Management Server, Multi-Domain Security Management Server | Domain objects are available in the Threat Prevention policy in the following columns: Source, Destination and Scope, although they are not supported in the Threat Prevention policy. |
| 02557325 | Threat Extraction, DLP | Security enhancements for Threat Extraction and Data Loss Prevention blades. |
| 02570146 | HTTPS Inspection, Security Gateway | Improved stability of Security Gateway when HTTPS Inspection is enabled and/or Security Gateway is configured as Proxy (this issue is relevant only to _Take 272_ of R77.30 Jumbo Hotfix Accumulator). |
| 02561565 | Anti-Virus, Anti-Bot, URL Filtering | Improved URL recognition mechanism for Anti-Virus, Anti-Bot, and URL Filtering blades. |
| 02548031 | Client Authentication Portal | Security hardening for Client Authentication Portal. |
| 02040869 | VSX | " _kernel: VRF ERROR: Illegal parameters during call to sock\_setsockopt() @ net/core/sock.c:<N> : sk\_family=<X> sk\_type=<Y> sk\_state=<Z>_" error appears randomly in _/var/log/messages_ file on Active member of VSX cluster.<br>Refer to [sk111101](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111101). |
| 02552177 | Gaia OS | SNMP Query for the following OID trees does not return the expected information ( _snmpwalk_ command returns "`No Such Instance currently exists at this OID`"):<br>- 1.3.6.1.4.1.2620.1.24 (.iso.org.dod.internet.private.enterprises.checkpoint.products.avi)<br>- 1.3.6.1.4.1.2620.1.29 (.iso.org.dod.internet.private.enterprises.checkpoint.products.uf)<br>- 1.3.6.1.4.1.2620.1.30 (.iso.org.dod.internet.private.enterprises.checkpoint.products.ms)<br>Note: Issue occurs only in Take 221, 225, 226, 266, and 272. |
| - | Endpoint Security Server | Added support for Endpoint Security Server R77.30.03.<br>Refer to [sk119893](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119893). |
| Take 272 (26 July 2017) |
| 02552331 | IPS, Application Control, URL Filtering, Anti-Virus, Anti-Bot, Threat Emulation, DLP | A "`malformed protocol name in request`" log is seen in SmartView Tracker / SmartLog for HTTP traffic. HTTP traffic that contains "HEAD" request is mistakenly identified as non-compliant HTTP traffic by the HTTP parser. As a result, the connection is rejected/bypassed either according to the non-compliant HTTP settings, or according to the "Fail Open"/"Fail Close" settings. |
| 01778991, 02443602;<br>02453169 | HTTPS Inspection | Improved stability of HTTPS Inspection with enabled Probe Bypass.<br>Refer to [sk111600](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111600). |
| 02538223 | URL Filtering | Improved URL recognition mechanism for Anti-Virus, Anti-Bot, and URL Filtering blades. |
| 02459918 | Anti-Virus | Improved inspection of "Unknown" file types according to the Threat Prevention policy (when the option "`Process specific file types families`" is selected in the Threat Prevention profile - "Anti-Virus Settings"). |
| 02524486 | Security Gateway | CIFS traffic is dropped on certain CIFS requests. |
| 02519295, 02519439 | VPN | Improved stability of VPND process in IKEv2 flows. |
| 02537316 | VSX, SmartView Monitor | Virtual Switches in VSX cluster are shown in "PROBLEM" status in SmartView Monitor without any error message.<br>Refer to [sk112067](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112067). |
| Take 266 (03 July 2017)<br>This Take is _**not**_ supported on Cluster High Availability configured in Bridge mode. |
| - | Gaia, Security Gateway, Management Server, etc. | Support for TLS 1.2<br>Refer to [sk107166](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107166).<br>Note: For _Threat Emulation_ customers that do not allow automatic updates from the Check Point Cloud, it is important to update the Threat Emulation Engine according to [sk92509 - Offline updates for Threat Emulation images and engine](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92509). |
| - | VPN | Support for Online Certificate Status Protocol (OCSP):<br>The Security Gateway now validates the certificate from the server (on the Internet) using the <br>OCSP standard, which is faster and uses much less memory than CRL Validation.. |
| - | Mobile Access | Support for Mobile Access Reverse Proxy.<br>Refer to [sk110348](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110348). |
| - | Mobile Access | Support for Capsule Workspace App Wrapping.<br>Refer to [sk111558](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111558). |
| 02517569 | Mobile Access | Improved stability of Mobile Access WebMail application. |
| 02531747 | Check Point Appliances | Added support for Smart-1 405 and 410 appliances.<br>Refer to [sk117578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117578). |
| 02514370;<br>02429601 | Threat Emulation | Large files downloaded over HTTP are not inspected by Threat Emulation blade if they are encoded with "gzip". |
| 02517497 | DLP | DLP supports Microsoft Office only from versions lower than 2016<br>(this issue is relevant only to R77.30 Jumbo Hotfix Accumulator). |
| 02508656 | SSL Network Extender, Endpoint Security On Demand, SecureWorkspace | Unable to connect with SNX, ESOD and SWS after updating the Java to version 8 update 131.<br>The SNX connection remains at '`initializing`' state. |
| 02497785, 02510894 | HTTPS Inspection | Improved stability of WSTLSD daemon by removing Issue ID 02439917 ( [sk109096](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109096)) that was added in Take 210<br>(this issue is relevant only to R77.30 Jumbo Hotfix Accumulator - Takes 210, 213, 216, and 225). |
| 02498309 | HTTPS Inspection | Connection to an HTTPS web site can get stuck in the following scenario:<br>1. HTTPS Inspection is enabled on Security Gateway<br>2. "Website categorization mode" is set to "Hold"<br>   <br>   (in R77X SmartDashboard, go to the "Application & URL Filtering" tab - expand the "Advanced" - click on the "Engine Settings")<br>3. The HTTPS web site's category is not in RAD daemon's cache yet<br>   <br>   (i.e., categorization of this HTTPS web site will require a "Hold")<br>Refer to [sk119273](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk119273). |
| Take 226 (14 June 2017) |
| 02516659, 02521220 | Threat Emulation, Threat Extraction | Fixed Mail Transfer Agent (MTA) enforcement issue. |
| 02513169 | Threat Emulation, Threat Extraction | Security Gateway configured as MTA does not forward e-mails / forward e-mails very slowly that contain attachments in the TNEF format.<br>Refer to [sk117312](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117312). |
| Take 225 (22 Mar 2017) |
| 02486948 | Security Gateway, SmartView Monitor | SmartView Monitor incorrectly shows R77.30 Security Gateway as "Disconnected" and its software blades as "not responding".<br>This cosmetic issue appears only after installing _Take\_221_ of R77.30 Jumbo Hotfix Accumulator.<br>Refer to [sk116366](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116366). |
| 02485155 | MTA, DLP, UserCheck | E-mails are not passing through the DLP Gateway configured as Mail Transfer Agent (MTA).<br>Refer to [sk116469](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116469). |
| 02487339 | MTA, Threat Emulation, Threat Extraction, DLP, Anti-Spam | Improved processing of e-mails and attachments when Security Gateway is configured as Mail Transfer Agent (MTA) -<br>improved an internal mechanism that generates random internal IDs for processed e-mails / attachments.<br>This prevents failures to clean attachments by Threat Extraction blade / strip attachments by Threat Emulation blade. |
| Take 221 (06 Mar 2017) |
| 02468493 | URL Filtering, HTTPS Inspection | Improved Security Gateway stability when URL Filtering and HTTPS Inspection are enabled after installing Takes 209, 210, 213, or 216 of R77.30 Jumbo Hotfix Accumulator. |
| 02057763, 02059521 | HTTPS Inspection | Added support of SHA384 and SHA512 hash algorithms that are used by some HTTPS sites to sign their certificates.<br>This specific fix (ID 02325804) was reverted in Take 184 (ID 02366619) to resolve the issue of not being able to open some HTTPS web sites in Chrome browser when HTTPS Inspection is enabled after installing Take 172, Take 174, or Take 178 of R77.30 Jumbo Hotfix Accumulator.<br>Refer to [sk112672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112672). |
| 02267698, 02465120 | HTTPS Inspection | Some HTTPS sites do not load when HTTPS Inspection is enabled, if TLS 1.2 with ECDHE cipher is used.<br>Refer to [sk112954](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112954). |
| 02468724 | SecureXL | 21000 appliance with SAM card is not able to boot after installing Take 210, Take 213 or Take 216 of R77.30 Jumbo Hotfix Accumulator.<br>Refer to [sk116070](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116070). |
| 02071893 | Threat Emulation | New feature in Threat Emulation and Mail Transfer Agent (MTA):<br>Detecting links to malicious files inside e-mails.<br>Refer to [sk115313](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115313). |
| 02279050 | Threat Emulation | New feature in Threat Emulation:<br>Support for encrypted (password protected) archives - Threat Emulation blade tries to decrypt the protected archive and extract it based on a preconfigured passwords dictionary.<br>Refer to [sk112821](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112821). |
| 02367623, 02369699 | Threat Emulation | New feature in Mail Transfer Agent (MTA):<br>File Classifier for MTA - MTA will use the same File Classifier that is used by the Threat Emulation blade, and will be able to detect the real type of a file. |
| 02074197 | Threat Emulation | New feature in Mail Transfer Agent (MTA):<br>Ability to configure load balancing / high availability based on the DNS configuration for Mail Transfer Agent (MTA).<br>Refer to [sk110369](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110369). |
| 02333089 | Threat Emulation | New features in Mail Transfer Agent (MTA):<br>- Improved debug messages for MTA flow.<br>  <br>  During the debug of _in.emaild.mta_ daemon (per [sk60387](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk60387)), postfix "`Message-ID`" will appear in the _$FWDIR/log/emaild.mta.elg_ file on the Security Gateway to assist in the analysis of the e-mail flow.<br>  <br>- Logs will be generated (will appear in SmartLog / SmartView Tracker) by the Security Gateway if e-mails are piling up in the queue, or if there has been a delay in e-mail processing.<br>  <br>  Refer to [sk109699](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109699) \- Section "Control intervals and thresholds for MTA logs". |
| 02002951 | Threat Emulation | New features in Mail Transfer Agent (MTA):<br>- Postfix was upgraded to version 3.1<br>  <br>  New Postfix version includes full protection against "Drown" attack, and serves as a vehicle for other future features, such as LDAP support.<br>  <br>- New monitoring utility for Postfix queue - _cpqshape_.<br>  <br>  Refer to [sk109699](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109699) \- Section "Troubleshooting" - subsection "Analyze Postfix bottlenecks using the _cpqshape_ utility". |
| 02472626 | Threat Emulation | Security Gateway configured as Mail Transfer Agent (MTA), does not forward e-mails that contain more levels of nested MIME content (attachment inside attachment inside attachment etc.) than configured in the Threat Prevention Profile (Threat Emulation Settings - "Mail (SMTP)" - "Configure...") - such e-mails are discarded due to timeout). |
| 02462393 | Threat Emulation | Improved handling of e-mail attachments with long names. |
| 02466877 | Gaia OS | " _Wrong Type (should be Gauge32 or Unsigned32): INTEGER_" message in SNMP Response.<br>Refer to [sk115119](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115119). |
| 01951357, 02388316 | Gaia OS | _/var/log/messages_ file shows the line " _sshd\[<PID>\]: pam\_radius\_auth: Got response from RADIUS server_" even when the RADIUS server is not accessible. |
| 01961177, 02388317 | Gaia OS | The "Network Interfaces" page in the Gaia Portal does not load if the text string "NAN" or "inf" is saved in the interface's "Comment" field. |
| 02466343 | Gaia OS, VSX | " _Wrong Type (should be INTEGER)_" errors when querying SNMP OID '`vsxCountersTable`' (.1.3.6.1.4.1.2620.1.16.23.1) on VSX Gateway.<br>Refer to [sk109469](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109469). |
| 02466231 | VSX | Commands executed in Gaia OS on VSX Gateway are logged in _/var/log/messages_ file without VSID of Virtual Systems.<br>Refer to [sk113128](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113128). |
| 02465996 | VPN | In certain cases, depending on encryption domain configuration, the "ike\_enable\_supernet" parameter (refer to [sk101219](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101219)) does not create the correct supernetting pattern - the subnet mask does not correlate to the original subnet mask that was defined by the user. |
| 02450974, 02454119 | SSL Network Extender | " _Cannot establish connection to SSL Network Extender gateway. Try to reconnect._" error from SNX client on Mac OS X / macOS after disabling both RC4 and 3DES cipher suites on the Mobile Access Gateway.<br>Refer to [sk116156](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116156). |
| 02331736 | Mobile Access | Occasionally, the Mobile Access Deployment Agent fails to invoke SNX, ESOD Compliance or SecureWorkspace in FireFox browser.<br>"`Java unavailable`" error message is displayed to the user. |
| 02440490 | Security Management Server, Multi-Domain Security Management Server | " _Bad Response format_" error in SmartDashboard when enrolling a VPN certificate using SCEP from the external CA based on Windows Server 2008 and higher.<br>Refer to [sk106405](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106405). |
| Take 216 (17 Feb 2017) - _General Availability Take_<br>On _21000 appliances with SAM card_, this Take should _**not**_ be installed (refer to [sk116070](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116070)). |
| 02447851 | Check Point Appliances | Added support for [3100](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110052) and [5100](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110053) models. |
| 02449825 | Check Point Appliances | Added support for [5900](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110053) model. |
| - | Check Point Appliances | - "VBAT3 Voltage" is shown as "Low" in Gaia Portal on the Hardware Health page on 3200 appliance.<br>- Alert LED is red on 3200 appliance.<br>Refer to [sk115575](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115575). |
| 02463143 | SecureXL | If Bond or Bridge interfaces are configured on the Security Gateway, then the following cosmetic message is displayed on the screen during boot, or when executing the "`cpstart`" / "`sim affinity`" commands:<br>_basename: missing operand_<br>_Try basename -help for more information._ |
| Take 213 (05 Feb 2017)<br>On _21000 appliances with SAM card_, this Take should _**not**_ be installed (refer to [sk116070](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116070)). |
| 02442459;<br>02443332;<br>02442078;<br>02443892 | DLP, Threat Extraction | R77.30 Security hotfix for DLP and Threat Extraction blades.<br>Refer to [sk115596](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115596). |
| 02448398 | Threat Extraction | - Added ability to block corrupted files that could not be emulated<br>- Added ability to block access to original corrupted files that could not be emulated<br>Refer to [sk115792](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115792). |
| Take 210 (25 Jan 2017)<br>Note: This take replaces Take 209 released on 25 Jan 2017<br>On _21000 appliances with SAM card_, this Take should _**not**_ be installed (refer to [sk116070](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116070)). |
| 02419870 | URL Filtering, HTTPS Inspection | Access to HTTPS sites is intermittent - web site opens only after the user refreshes the page several times when URL Filtering blade and HTTPS Inspection are enabled.<br>Refer to [sk115638](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115638). |
| 02344419 | Security Gateway | Intermittent access to some web sites because _in.ahttpd_ process constantly consumes CPU at 100% in certain scenarios.<br>Refer to [sk106916](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106916). |
| 02045637, 02389862 | Security Gateway | Proxy ARP table is not loaded when Bond interface changes MAC address during reboot.<br>Refer to [sk111675](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111675). |
| 01963489\. 02388707 | Security Gateway | The Client Authentication _in.ahclientd_ process crashes with core dump files. |
| 02356285, 02419742 | Security Gateway | H.323 VoIP call drops after exactly one hour because Keep Alive "ACK" packets are not forwarded to the VoIP client.<br>Refer to [sk113749](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113749). |
| 01873031, 02387645 | Security Gateway | "Via" field in HTTP Request sent to a web server by Security Gateway in Non Transparent proxy mode contains incomplete HTTP version.<br>Refer to [sk108900](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108900). |
| 01709059 | Security Gateway, Cluster, SecureXL | " _Error: bond\_3ad\_get\_active\_agg\_info failed_" in the output of "`dmesg`" command when using 802.3ad mode.<br>Refer to [sk110344](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110344). |
| 02368502, 02419738 | SecureXL | In rare cases, Security Gateway with enabled SecureXL crashes during policy installation when SAM card is not installed on 21000 appliance.<br>Refer to [sk114153](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114153). |
| 02399631, 02441021 | Cluster | " _Try to update state to ACTIVE because member is down and state might should be changed_" message in _/var/log/messages_ file.<br>Refer to [sk115228](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115228). |
| 02079428, 02394915 | Cluster, SecureXL | ClusterXL in _Load Sharing_ mode with SAM card installed may restart when an interface is administratively shut down (e.g., with '`ifconfig ethX down`' command). |
| 02434403 | CoreXL | - "`BUG: soft lockup - CPU#X stuck for 10s! [fw_worker_Z:...]`" appears repeatedly in _/var/log/messages_ file<br>  <br>- When VLAN interfaces are configured, the _/var/log/messages_ file repeatedly shows:<br>  `;FW-1: _fwhamultik_set_mem: changing IF_UNIQUE(i) from X to Y(changed by [fwhaif.c:N]);<br>   ;FW-1: _fwhamultik_set_mem: changing IF_UNIQUE(ifn) from Y to X(changed by [fwhaif.c:M]);`<br>Refer to [sk116870](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116870). |
| 02337475 | Anti-Spam | Fixed memory leak in the _in.msd_ process. |
| 02084934, 02344067 | VSX | " _SmartView Monitor error has occurred (error code: 2147483647)_" pop-up in SmartView Monitor GUI when viewing data from a VSX Gateway / VSX Cluster Member.<br>Refer to [sk112154](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112154). |
| 01931909, 02420752 | VSX | If there are interfaces on VSX Gateway / VSX Cluster Members, whose name is longer than 11 characters, then the following occurs:<br>- " _Illegal routing gateway or interface retrieved from the VSX GW_" error when creating a new VSX Gateway / VSX Cluster object.<br>- Result of SNMP Query for OID .1.3.6.1.4.1.2620.1.6.6 (`iso.org.dod.internet.private.enterprises.checkpoint.products.svn.routingTable`) does not show those interfaces.<br>Refer to [sk109815](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109815). |
| 02341399, 02339540 | Mobile Access | Sign out from Mobile Access Portal does not run application that were configured to run at SNX disconnection. |
| 02421847;<br>02424129 | Mobile Access | Login page of Apache Guacamole web application is blank when published via Mobile Access using Path Translation.<br>Refer to [sk134075](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk134075). |
| 02395361, 02414919 | Mobile Access | " _Error:Request Time-out_" message when trying to upload files larger than 5 MB via Outlook Web App (OWA).<br>Refer to [sk114695](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114695). |
| 02422452 | Identity Awareness | Configuring ADQuery with a non-administrator user without membership in "Server Operators" group.<br>Refer to [sk104900](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104900).<br>This option will be fully available in _**future**_ Takes.<br>Relevant note about it will be published. |
| 02422440 | Identity Awareness | Decreased the timeout for WMI query (ADQuery) from 30 min to 5 min. |
| 01817285, 02422448 | Identity Awareness | " _Status: At least one DC is currently disconnected_" when running "`cpstat identityServer -f default`" command on Identity Awareness Gateway.<br>Refer to [sk107838](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107838). |
| 02367904 | Gaia OS | Improved behavior of the _routed_ daemon on cluster members:<br>OSPF Hello packets are now forced to be sent out even when the _routed_ daemon is busy processing the LS Updates, SPF calculation or synchronizing OSPF routes to other cluster member.<br>Refer to [sk95968](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk95968) and [sk115117](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115117). |
| 02441209 | Gaia OS | In rare cases, the _confd_ process might trigger high CPU load on Check Point appliance (that has LOM card installed), if more than 512 "`show asset lom-info`" / "`show asset all`" commands were invoked.<br>Refer to [sk115634](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115634). |
| 02413967 | Gaia OS | In some configurations (where one of the Power Supply Units is not plugged to a power outlet), the following message might appear in _/var/log/messages_ file:<br>`xpand[PID]: [ERR] i2c_smbus_read_byte_data STATUS_WORD 0x2848`.<br>Refer to [sk112829](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112829). |
| 02110490, 02110665 | Gaia OS | The _routed_ daemon crashes in rare scenario, if PIM is configured and machine is rebooted when all network cables are disconnected.<br>Refer to [sk112251](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112251). |
| 02434509 | VPN | When IKEv2 is used in Site-to-Site VPN tunnel, the "`IKE current SAs`" value in the output of the "`cpstat -f IKE vpn`" command is larger than then actual number of IKE SAs in the kernel as seen in the output of the "`fw tab -t ikev2_sas -s`" command. |
| 02436837 | VPN | VPN Central Gateway drops SIP RTP traffic between the SIP Call Manager and the phone behind VPN Satellite Gateway, where the SIP call was initiated.<br>Refer to [sk111839](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111839). |
| 02439917 | VPN | In certain scenarios, if the corresponding Certificate Revocation List (CRL) is very long, the _vpnd_ daemon consumes the CPU at 90-100% for several minutes after policy installation.<br>Refer to [sk109096](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109096). |
| 01877490, 02429368 | SmartEvent, SmartReporter | - " _Dev Mode: ON - Syntax error_" in SmartEvent / SmartReporter reports when creating reports from SmartEvent Intro GUI client.<br>- SmartEvent / SmartReporter reports are missing full pages.<br>Refer to [sk108979](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108979). |
| Take 207 (08 Jan 2017) |
| 02020740, 02023251 | SecureXL | In rare scenario, Security Gateway with enabled SecureXL crashes during policy installation.<br>Refer to [sk111411](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111411). |
| 01952431, 02420157 | VPN | IKEv2 fails repeatedly with " _Message::addPayload: Too many payloads_" error in the debug of the _vpnd_ daemon.<br>Refer to [sk110156](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110156). |
| 01933566, 02420155 | VPN | Improved stability of the _vpnd_ daemon when handling Visitor Mode traffic. |
| 01877586, 02420570 | SmartReporter | SmartReporter PDF reports are displayed in landscape view, and the tables are not displayed in proportion to the page layout.<br>Refer to [sk104840](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104840). |
| 02387947;<br>01835442 | Security Gateway | Issues related to Suspicious Activity Module (SAM) rules:<br>- SAM rules do not survive reboot, and therefore SAM policy is not enforced.<br>- Policy installation after rebooting the Security Gateway fails in SmartDashboard with:<br>  <br>  `Error Reason: Load on Module Failed - Failed to Load Security Policy`<br>- Fetching the policy on Security Gateway under debug shows:<br>  <br>  `fw_sam_recover_state: failed to read XXX entries`<br>- Attempt to reviewing the SAM kernel table with fails:<br>  <br>  `# fw tab -t sam_requests -s<br>   Cannot read the formats structure from localhost: No such file or directory`<br>Refer to [sk101368](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101368). |
| 02364390 | Mobile Access | Check Point response to CVE-2016-2183 (Sweet32).<br>Added the fix for Mobile Access curl - for SSL connections from Mobile Access Gateway to internal servers.<br>Refer to [sk113114](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113114). |
| 02421829 | Mobile Access | Issue publishing in Mobile Access a web application that uses WebSocket. |
| 01949612 | Mobile Access | When using Mobile Access blade, error occurs in web application as a result of an incorrect HTTP code from destination web server.<br>Refer to [sk109040](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109040). |
| 02418422 | Check Point appliances | Updated the "`sysObjectID`" for 3200 / 5000 / 15000 / 23000 / Sandblast Threat Emulation TE100X, TE250X, TE1000X, TE2000X appliances in the [chkpnt.mib](https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=53467) file.<br>Refer to [sk90470](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk90470). |
| Take 206 (26 Dec 2016) |
| 02359254, 02412348 | Security Gateway, Security Management Server, Multi-Domain Security Management Server | In rare scenarios, the _fwd_ process or _fw\_full_ process on Security Gateway consumes memory at high level and crashes with core dump file.<br>Refer to [sk113736](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113736). |
| 02329308, 02386581 | Security Gateway | In rare scenarios, Security Gateway crashes with kernel panic when connecting to web sites that prefer AES GCM (Galois Counter Mode) cipher.<br>Refer to [sk113873](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113873). |
| 02407215 | URL Filtering, Application Control, HTTPS Inspection | Some web sites do not load completely when connecting through Check Point Security Gateway configured as Proxy in Non-Transparent Mode.<br>Refer to [sk114736](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114736). |
| 02295419, 02397150 | Mobile Access | SSO Kerberos Authentication is not triggered in Mobile Access Web Application when 'SPNegoTokenRequested' header is being sent by the internal Web Server.<br>Refer to [sk114555](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114555). |
| 02334659 | SecureXL | Improved stability of SAM card. |
| 02420705 | Security Gateway | " _sip reason: Too many streams in SDP_" drop log in SmartView Tracker when passing VoIP SIP SDP messages that exceed 4 streams.<br>Refer to [sk93752](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk93752). |
| 02400714 | vSEC Virtual Edition | vSEC Virtual Edition (running on [Linux KVM](http://www.linux-kvm.org/page/Main_Page)) might hang during its boot under heavy traffic load. |
| 02390872 | vSEC Virtual Edition | vSEC Virtual Edition (running on [Linux KVM](http://www.linux-kvm.org/page/Main_Page)) exhibits low network performance when working with Virtio network configuration (issues with _virtio\_net_ driver). |
| 02397378 | vSEC Virtual Edition | vSEC Virtual Edition (running on [Linux KVM](http://www.linux-kvm.org/page/Main_Page)) is not able to configure SecureXL SIM Affinity for Virtio interfaces. |
| 02404454 | vSEC Virtual Edition | vSEC Virtual Edition does not support SR-IOV for following Intel network adapters: 82599, x540, x550 (issues with _ixgbevf_ driver). |
| 02402663 | SmartReporter, SmartEvent | The '`evs_backup`' command sometimes fails with " _Failed to start postgres service_" due to long database startup duration.<br>Refer to [sk104839](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104839). |
| Take 205 (15 Dec 2016) - _General Availability Take_ |
| 02390116 | Check Point Appliances | _/var/log/messages_ file might show the following on 23500 appliance:<br>`xpand[PID]: [ERR] i2c_smbus_read_block_data failed <X>`<br>SNMP Trap for Power Failure / PSU Failure might be sent at the same time. |
| 02413912 | HTTPS Inspection | The _wstlsd_ daemon might crash. |
| 02405257 | Threat Extraction | " _An error has occurred while extracting file_" message in Threat Extraction log when processing an attached image file.<br>Refer to [sk115107](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115107). |
| 02357493 | Security Gateway, Threat Emulation | Firewall-1 information is not restored from a Gaia OS backup file when Threat Emulation is enabled.<br>Refer to [sk113594](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113594). |
| Take 198 (23 Nov 2016) |
| - | Check Point Appliances | Support for the [new improved R77.30 Gaia image](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104859#Gaia%20Downloads) (released 16 Dec 2016) for 3200 / 5000 / 15000 / 23000 / TE100X / TE250X / TE1000X / TE2000X appliances. |
| - | Threat Extraction | Threat Extraction image cleaning and other enhancements hotfix.<br>Stability and quality fixes resolving issues, as well as new features on Threat Extraction products.<br>Refer to [sk114613](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114613). |
| 02005542 | Threat Extraction | Ability to add support for new file types in Threat Extraction.<br>Refer to [sk112240](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112240). |
| 02387864 | All | Check Point response to CVE-2016-5195 (Dirty Cow).<br>Refer to [sk114161](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114161). |
| 02297576 | SmartLog | Issues with SmartLog GUI in Multi-Domain environment with multiple Domain Log Servers:<br>- "`Server is disconnected!`" message for connected clients<br>- SmartLog GUI fails to open; Sometimes, it loads to 35%, an then displays a message that SmartLog is unreachable<br>Running the `smartlogstop;smartlogstart` commands resolves the issue only temporarily. |
| 01984127, 01984392 | SmartLog | SmartLog GUI of Global SmartLog does not sort the logs by time when running a query.<br>Refer to [sk112826](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112826). |
| 01935060, 01936585 | SmartLog | In some records, the Origin field in SmartLog is displayed with 0.0.0.x format.<br>Refer to [sk109820](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109820). |
| 01910154, 02386501 | SmartLog | The smartlog process crashes occasionally on R77.30 Log Server that runs SmartLog.<br>Refer to [sk114417](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114417). |
| 01725423, 01725724 | SmartLog | SmartLog GUI freezes occasionally, and it is not possible to log in to SmartLog GUI again.<br>Refer to [sk107153](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107153). |
| 01710875, 01711097 | SmartLog | After upgrade to R77.30, SmartLog becomes non-responsive.<br>The "`smartlog_server`" process consumes CPU at 100%.<br>Refer to [sk106782](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106782). |
| 01702895, 01703025 | SmartLog, Multi-Domain Security Management Server | Global SmartLog R77.30 does not show logs from remote Multi-Domain Server.<br>Refer to [sk106600](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106600). |
| 01864909, 01865057 | SmartLog, Multi-Domain Security Management Server | "User" column in Global SmartLog GUI shows asterisks "\*\*\*\*\*\*" instead of "User@Domain".<br>Refer to [sk108771](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108771). |
| 02387363 | Mobile Access | Mobile Access Web Form SSO login fails if the password contains special characters (e.g., exclamation sign "!", asterisk "\*", plus "+", minus "-", etc.).<br>Refer to [sk114458](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114458). |
| 01982715, 02385180 | Mobile Access, VSX | SNX packages are not updated on VSX Gateway in the contexts of Virtual Systems during the installation of R77.30 Jumbo Hotfix Accumulator.<br>Refer to [sk114624](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114624). |
| 01939363 | SecureXL | " _sim dropcfg -l_" command incorrectly shows " _Enforced on external interfaces only_".<br>Refer to [sk109960](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109960). |
| 02358210, 02364750 | Cluster | VRRP Backup member on Gaia OS sends BGP traffic to BGP peers.<br>Refer to [sk114265](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114265). |
| 02079535 | Cluster | Dynamic Routing routes are not synchronized during Connectivity Upgrade (CU), which causes outage during the CU fail-over.<br>Refer to [sk107042](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107042#Upgrade%20paths%20with%20Dynamic%20Routing%20synchronization) \- section "(3) Upgrade paths with Dynamic Routing synchronization". |
| 01961260, 02381185 | Cluster, CoreXL | Traffic between ClusterXL members is dropped randomly.<br>Refer to [sk110312](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110312). |
| 02367867, 02369381 | Cluster, Gaia OS | Improved stability of the _routed_ daemon on Standby cluster member. |
| 02367871, 02369379 | Cluster, Gaia OS | Improved behavior of the _routed_ daemon on cluster members:<br>Wait at least 15 seconds after the routes are synchronized between cluster members to bring the Critical Device "routed" back to the "up" state.<br>This gives the _routed_ daemon enough time to run the SPF calculation and push OSPF routes down to the kernel. |
| 01995709, 01996404 | CoreXL | The " _fw -i <id> ctl pstat_" command shows " _memory used: 0%_".<br>Refer to [sk110881](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110881). |
| 01852502, 02388218 | CoreXL | Session Authentication fails for all connections when CoreXL is enabled on Security Gateway.<br>Refer to [sk109838](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109838). |
| 02361143 | Appliances | Multi-Queue does not work on 3200 / 5000 / 15000 / 23000 appliances when it is enabled for on-board interfaces.<br>Refer to [sk114625](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114625). |
| 02333130;<br>02382905 | VPN | Traffic over VPN tunnel does not pass for several seconds during policy installation on Security Gateway (which causes traffic loss).<br>Refer to [sk55244](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk55244). |
| Take 189 (07 Nov 2016) |
| 01961629, 01965728 | Gaia OS | All OSPF routes are lost after configuring "Add redistribution from Aggregate" in Gaia Portal.<br>Refer to [sk110337](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110337). |
| 02355536 | Gaia OS | - _mail_ daemon writes its logs to the _/var/log/messages_ file although the "`mail.none`" directive was added to the _/etc/syslog.conf_ file.<br>- _cron_ daemon writes its logs to the _/var/log/messages_ file although the "`cron.none`" directive was added to the _/etc/syslog.conf_ file. |
| 02325549 | VPN | When using AES-128 with SHA256, negotiation succeeds, but VPN tunnel fails.<br>Refer to [sk111132](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111132). |
| 02364953 | VPN | Site-to-Site VPN with 3rd party DAIP Gateway fails with "no proposal chosen" error.<br>Refer to [sk114834](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114834#Scenario%201) (Scenario 1). |
| 02008783, 02351118 | Cluster | Cluster member with highest priority is not able to become new Active after changing the Members' Priorities.<br>Refer to [sk110999](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110999). |
| 02351092 | Cluster | Only lowest VLAN is monitored on Bond interface, instead of lowest and highest.<br>Refer to [sk106776](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106776). |
| 02273695, 02366138 | SecureXL | Improved stability of SAM card when processing the handled notification for a connection that was created from a template in SAM card. |
| 02366189 | SecureXL | DHCP Relay / DHCP Server stops working on ClusterXL with enabled VMAC mode installing Takes 128, 138, 143, 145 of R77.30 Jumbo Hotfix Accumulator.<br>Refer to [sk111588](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111588). |
| 02057286, 02366103 | SecureXL, Cluster | Cluster member might crash when processing a NAT connection, if SecureXL is not enabled on all cluster members.<br>Refer to [sk111888](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111888). |
| 01916191, 01932799 | Identity Awareness | If an access role is set to have identified machines, it will sometimes disappear from sessions (refer to the output of "`pdp m a`" command) that have user and machine sessions. As a result, users can lose access to resources.<br>Issue is most likely to occur when using access role with identified machines in policy and working with sessions with both user and machine. |
| 02350625, 01941785 | Threat Emulation | SmartView Tracker / SmartLog does not show all e-mail recipients when an e-mail is received through the Mail Transfer Agent (MTA).<br>Refer to [sk114416](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114416). |
| 02380610 | Threat Emulation | Fixed Mail Transfer Agent (MTA) protection bypass.<br>Refer to [sk114664](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114664). |
| 02366239 | Application Control | Memory leak on loaded Security Gateway with UserCheck rules in the policy.<br>Refer to [sk110362](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110362). |
| 02370708 | SmartEvent | "`ERROR: duplicate key value violates unique constraint "seam_event_XXX_pkey"`" in _$RTDIR/log/cpsemd.elg_ file.<br>Refer to [sk105185](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105185). |
| 02135303, 02364625 | Multi-Domain Security Management Server | Global Policy assign fails with "`There is already local object with the name: <Name> among the Domain Management Server's objects`" error.<br>Refer to [sk112342](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112342). |
| Take 185 (20 Oct 2016) - _General Availability Take_ |
| 02332164, 02350096 | Data Center Security Appliances | Hardware Sensors on 15000 and 23000 appliances show zero (0) values after completing the Gaia OS First Time Configuration Wizard.<br>Refer to [sk112829](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112829). |
| 01960960, 02342230 | Security Management Server, Multi-Domain Security Management Server | The _fwm_ process crashes after the size of _$FWDIR/tmp/fwmtrace.log_ file reaches 2GB limit.<br>Refer to [sk105579](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105579). |
| 01820334, 02364974 | Security Gateway | Security Gateway might crash after running 'cpstop' command if MSS Adjustment (Clamping) for IPsec VPN traffic is enabled ( _fw\_clamp\_vpn\_mss=1_).<br>Refer to [sk101219](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101219). |
| 01912515, 02364959 | SecureXL | Connections are broken for short time after disabling SecureXL, or after installing a policy.<br>Refer to [sk109468](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109468). |
| Take 184 (13 Oct 2016) |
| 02366619 | HTTPS Inspection | Removed support of SHA384 and SHA512 hash algorithms (that was integrated in Take 172 as ID 02325804) that are used by some HTTPS sites to sign their certificates.<br>Refer to [sk112672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112672). |
| 02352496 | Check Point Appliances | Check Point Appliance might freeze and not reboot in the following scenario:<br>1. Threat Emulation blade is enabled<br>2. KVM is enabled<br>3. Kernel crash / panic occurs (`kdump` or `kdb`) |
| 02359428 | VoIP | VoIP data on non-encrypted connection is dropped with " _Failed to initialize data connection paramters_" log. |
| 02339267 | Gaia OS | Some eBGP routes are advertised with the source IP address of BGP peer as the next-hop, instead of the next-hop configured in routemap.<br>Refer to [sk112834](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112834). |
| 02361295 | Gaia OS | Routes get stuck in the OSPF database even though they were deleted from Linux kernel<br>(issue might mostly occur for RIM routes not being removed when a VPN tunnel is dropped). |
| 01996800, 02356078 | Gaia OS | The _routed_ daemon might crash when working with PIM Sparse Mode. |
| 02070300 | Gaia OS | " _getaddrinfo: "::1" invalid host address_" message appears repeatedly in the _/var/log/messages_ file after enabling NTP while IPv6 is disabled. |
| 01818839, 02336244 | VPN | Randomly, new VPN tunnels are not being established with the peers.<br>Randomly, traffic is not passing over multiple VPN tunnels.<br>Refer to [sk113837](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113837). |
| 02325549 | VPN | Security Gateway / Cluster member might crash / go into kernel panic during policy installation if using AES encryption and [AES-NI](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105119#Choosing%20an%20encryption%20algorithm%20and%20AES-NI) is enabled. |
| 02351733 | VPN | IPsec SAs are deleted when value of configuration parameter _**ike\_keep\_child\_sa\_interop\_devices**_ is set to " **`true`**".<br>Refer to [sk105860](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108600#Scenario%204) (Scenario 4). |
| 02336379 | Security Management Server, Multi-Domain Security Management Server | User is not able to re-connect with any SmartConsole application to Security Management Server.<br>Refer to [sk105860](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105860). |
| 02340121 | Security Management Server, Multi-Domain Security Management Server | " _Bridge uses two different VLAN tags for interfaces. This configuration cannot be used with Active-Active bridge mode_" error when creating a Virtual System in Bridge mode.<br>Refer to [sk107972](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107972). |
| 01993128, 01994944 | Security Management Server, Multi-Domain Security Management Server | Users are deleted after installation of R77.30 Management Add-on.<br>Refer to [sk110887](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110887). |
| 02013718, 02015361 | Security Management Server, Multi-Domain Security Management Server | "Where used" does not show results while logged into Log Server with SmartDashboard.<br>Refer to [sk111077](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111077). |
| 02340062 | Multi-Domain Security Management Server | Global Policy assignment problem after failing IPS update.<br>Refer to [sk110498](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110498). |
| 02337143 | Threat Emulation | Improved Mail Transfer Agent (MTA) ability to insert a text-only disclaimer into e-mails that have no body. |
| 01825619, 01962131 | Security Gateway, Cluster, VSX | Security Gateway / Virtual System might crash due to double record of a connection in Connections Table.<br>Refer to [sk110476](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110476). |
| Take 178 (29 Sep 2016) |
| This specific Take package was recalled for additional testing.<br>Users who have already installed this specific Take, should install either Take 184, or a hotfix from [sk112672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112672). |
| 02349820 | Threat Emulation | Added support for SHA-256 based certificates for Threat Emulation Engine self-update.<br>Refer to [sk113333](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113333) and [sk103839](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103839). |
| Take 174 (22 Sep 2016) |
| This specific Take package was recalled for additional testing.<br>Users who have already installed this specific Take, should install either Take 184, or a hotfix from [sk112672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112672). |
| 02346611 | HTTPS Inspection, Mobile Access, Mobile Access Portal, Identity Awareness Portal, ICA Portal, SmartManagement Portal, SecurePlatform WebUI | Check Point response to CVE-2016-2183 (Sweet32).<br>Refer to [sk113114](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113114). |
| 02348603 | Security Gateway | Security Gateway might crash if a connection that was closed, but was not yet deleted from the Connections table is reused. |
| 02331952, 02331960 | Cluster | " _Warning! No active machines were found_" message in _/var/log/messages_ file on ClusterXL Load Sharing Unicast members.<br>Refer to [sk105063](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105063). |
| 01989782 | Gaia OS | Routes redistributed by Gaia OS to BGP peer are sent without BGP community value.<br>Refer to [sk110563](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110563). |
| Take 172 (01 Sep 2016) |
| This specific Take package was recalled for additional testing.<br>Users who have already installed this specific Take, should install either Take 184, or a hotfix from [sk112672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112672). |
| 02325804 | HTTPS Inspection | Added support of SHA384 and SHA512 hash algorithms to resolve a failure accessing some HTTPS sites if the site's certificate is signed with SHA384 / SHA512 hash algorithm.<br>**Important Note:** This specific fix was reverted in Take 184. Refer to [sk112672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112672). |
| 01817004, 02158447;<br>01891486, 02158426;<br>01817044, 02279342 | IPS, URL Filtering, Application Control | Security Gateway becomes unresponsive and memory consumption increases when HTTP traffic passes through.<br>Refer to [sk109801](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109801). |
| 02103280 | Security Gateway | Check Point Response to Logjam Vulnerability CVE-2015-4000.<br>Refer to [sk106147](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106147). |
| 02336294 | Security Gateway | The _cpd_ process crashes on Security Gateway during Anti-Virus update, when both Primary and Secondary Management Servers are not accessible from the Security Gateway.<br>Refer to [sk110684](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110684). |
| 02049960 | DLP, Threat Emulation | Added ability to monitor the Postfix process by WatchDog.<br>Refer to [sk111783](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111783). |
| 02194784 | Gaia OS | Improved handling of a scenario where VRRP cluster members are communicating with two OSPF neighbors advertising the same routes, where one OSPF neighbor has a lower metric than the other:<br>When the OSPF neighbor with lower metric goes down, OSPF routes are re-installed on the VRRP Master member with the new nexthop.<br>However, when the OSPF routes with the new nexthop are synchronized to the VRRP Backup member, instead of deleting the old nexthop and installing the new one, the VRRP Backup member just adds the new nexthop.<br>Output of Expert command "`route -n`" shows an OSPF route to a destination with two separate nexthops, which is incorrect.<br>Output of Clish command "`show route`" shows the correct single nexthop. |
| 02054453 | Gaia OS | "Performance Optimization" page in Gaia Portal is either stuck at "`Please wait a few moments while the data is loaded...`" pop up, or freezes when applying changes to CoreXL or Multi-Queue configuration on 15000 / 23000 appliances.<br>Refer to [sk112897](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112897). |
| 02209721 | CoreXL | Although CoreXL Affinity was configured to assign only a specific process to certain CPU cores, some interfaces are still being assigned to those CPU cores.<br>Refer to [sk110940](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110940). |
| 02296180 | CoreXL | Session Authentication fails for all connections when CoreXL is enabled on Security Gateway.<br>Refer to [sk109838](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109838). |
| 01863108;<br>02220278 | CoreXL, SecureXL | After upgrading a Security Gateway with enabled CoreXL on machine with 2 CPU cores (i.e., each CPU runs a CoreXL FW instance and as SND) to R77.30, only CPU0 is handling IRQs, and CPU1 is not handling any IRQs - all interfaces are affined only to CPU0 (i.e., each CPU runs a CoreXL FW instance, but only one CPU runs as SND).<br>Refer to [sk110422](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110422). |
| 02290247 | IPS | When transferring a large file via FTP, _fw\_worker_ process consumes 100% CPU.<br>Refer to [sk105411](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105411). |
| 02334185 | Application Control | When Security Gateway configured as proxy, Skype is blocked by Application Control.<br>Refer to [sk113124](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113124). |
| 01669385 | Threat Emulation, Anti-Spam | Improved stability of _in.emaild.mta_ process and _mdq_ process. |
| 02182146, 02327167 | SecureXL | Improved stability of SAM card. |
| 02113430, 02327965 | SecureXL | Improved stability of SAM card when processing a mix of multicast and unicast traffic. |
| 02162414, 02328150 | SecureXL | Improved stability of SAM card when processing multicast traffic. |
| 02164796, 02328938 | SecureXL | Improved stability of SAM card when processing multicast traffic. |
| 02171440, 02329106 | SecureXL | Improved stability of SAM card when processing multicast traffic. |
| 02114009, 02328096 | SecureXL | Improved stability of SAM card when connections are deleted from the Connections Table. |
| 02135463, 02329152 | SecureXL | Improved stability of SAM card when running the _tcpdump_ utility. |
| 02164746, 02329227 | SecureXL | Improved stability of SAM card under large amount of traffic. |
| 02326054, 02326630 | VPN | The _vpnd_ daemon might crash when running under debug (per [sk89940](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk89940)) and SNX user connects and authenticates on Security Gateway. |
| 02337360 | VPN | Improved Security Gateway stability. |
| 01888621, 02221764 | Cluster | NAT rule installed on cluster does not hide the Source IP address behind the _Cluster VIP address_ if the packet is sent to Cluster VIP address.<br>Refer to [sk113163](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113163). |
| 01971837, 02290543 | Security Management Server, Multi-Domain Security Management Server | "Gaia OS Best Practices" on the Compliance tab of SmartDashboard shows status "N/A" for clusters.<br>Refer to [sk110474](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110474). |
| 01940333, 02332728 | VPN, Security Management Server, Multi-Domain Security Management Server | " _Warning: on gw 'Name\_of\_Security\_Gateway', for the range (127.0.0.1, 127.0.0.1), peers were found in communities 'Name\_of\_Community\_1' and 'Name\_of\_Community\_2', peers from the second community will be ignored_" during policy installation.<br>Refer to [sk110562](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110562). |
| 02257309 | Multi-Domain Security Management Server | SmartUpdate in MDS level shows different licensing information than SmartUpdate in Domain level.<br>Refer to [sk98898](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98898). |
| Take 171 (25 Aug 2016) |
| - | Mobile Access | Stability enhancement for Windows 10 support. |
| Take 165 (08 Aug 2016) |
| - | Enterprise Appliances | Added support for 5000 appliances.<br>Refer to [sk110053](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110053). |
| - | Small and Medium Business Appliances | Added support for 3200 appliances.<br>Refer to [sk110052](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110052). |
| 01951006, 02152601 | Small and Medium Business Appliances, Enterprise Appliances | "Factory" button on the front panel is now functioning on [3200](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110052#Downloads) and [5200/5400/5600](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110053#Downloads) appliances. |
| 02158983;<br>02159087;<br>02159457 | HTTPS Inspection | Added support for ECDH p-384 elliptic curve (to resolve an issue with specific HTTPS sites that use ECDHE ciphers not being accessible when HTTPS Inspection is enabled).<br>Refer to [sk110883](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110883). |
| 02009223 | SecureXL | Improved performance on Security Gateway configured in Monitor Mode (Mirror Port mode) per [sk101670](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101670).<br>Refer to [sk112798](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112798). |
| 01957968 | Cluster | Previously reachable BGP routes are still advertised to BGP peers on ClusterXL after switch that connects these members goes down. |
| Take 164 (01 Aug 2016) |
| 02173793 | Mobile Access, VSX | Mobile Access Portal on VSX Gateway is unresponsive with "HTTP 500" error after installing takes between _Take\_143_ and _Take\_162_ of R77.30 Jumbo Hotfix Accumulator because _$CVPNDIR/template/phpincs/php-ews/ExchangeWebServices.php_ file is not copied to the contexts of Virtual Systems.<br>Refer to [sk111677](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111677) (Scenario 2). |
| 01712179 | Security Gateway | ISP Redundancy in Load Sharing mode is disabled when Non-Transparent Proxy is defined.<br>Refer to [sk111678](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111678). |
| 02167277 | Application Control | Improved stability. |
| Take 162 (20 July 2016) |
| 02159332 | Data Center Security Appliances | Added support for 40 GbE fiber cards on 15000 / 23000 appliances.<br>Refer to [sk112517](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112517). |
| 02150866 | Security Management Server, Multi-Domain Security Management Server | The _cpd_ daemon might crash when working in SmartProvisioning GUI with ROBO Gateways (e.g., when clicking on "Get Actual Settings"). |
| 02151317 | Security Management Server, Multi-Domain Security Management Server | " _Communication has been aborted by the peer_" error in SmartDashboard connected to Active Security Management Server / Domain Management Server in High Availability mode, after the state was changed from Active to Standby for the third time.<br>Issue occurs when the state is changed while the the _fwm_ processes run under debug (per [sk86186](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk86186)/ [sk33207](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk33207)) on both Primary and Secondary Security Management Server / Domain Management Server. |
| 02082365 | Security Management Server, Multi-Domain Security Management Server | Pushing VSX configuration fails with " _Internal Error - Failed to commit changes in the OS_".<br>Refer to [sk103844](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103844). |
| 02103175 | Security Management Server, Multi-Domain Security Management Server | Memory leak in the _cpd_ daemon when thresholds are enabled with " _threshold\_config_" command.<br>Refer to [sk111880](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111880). |
| 02103182 | Security Management Server, Multi-Domain Security Management Server | Memory leak in the _cpd_ daemon (in licutil) causes the daemon to crash (due to exhaustion of available memory). |
| 01911675, 02103172 | Security Management Server, Multi-Domain Security Management Server | Memory leak in the _cpd_ daemon (in cpmon) causes the daemon to crash (due to exhaustion of available memory). |
| 02098132 | Security Management Server, Multi-Domain Security Management Server | In Management HA environment, the _fwm_ daemon might crash during an attempt to delete Security Gateway / Cluster object in SmartDashboard.<br>Refer to [sk110748](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110748). |
| 02151722 | Multi-Domain Security Management Server | The _fwm_ daemon on MDS server might randomly crash during assignment of Global Policy. |
| 02150810 | Multi-Domain Security Management Server | Assignment of Global Policy might fail randomly with " _Failed to open connection with Domain Management Server or connection with Domain Management Server ended unexpectedly_" error message. |
| 02150773 | Multi-Domain Security Management Server | Removal of Global Policy with IPS might fail with:<br>_error: Failed to (delete) object (<UID>) from table (asm) in Domain Management Server database._<br>_Error received: (Object References Deletion Failed - Failed to remove references of object <UID>)_<br>_error: Disconnected from Domain Management Server. Check Domain Management Server status. Operation failed._<br>in the following scenario:<br>1. Domain Management Server is subscribed to Global Policy with IPS<br>2. Compliance blade is enabled on Domain Management Server<br>Alternatively, removal of Global Policy with IPS might end successfully, but the global IPS profile is not removed. |
| 02150871 | Multi-Domain Security Management Server | Assignment of Global Policy might freeze randomly because the _fwm mds fwmconnect_ proccess hangs. |
| 02150774 | Multi-Domain Security Management Server | Assignment of Global Policy might fail randomly, and core dump files for the _fwm_ process are generated (with size of 2 GB) after running _mdsstop ; mdsstart_ commands. |
| 02071813 | VPN | IPSec instability with IKEv2.<br>Refer to [sk112160](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112160). |
| 01961523 | VPN | Traffic over VPN tunnel does not pass for several seconds during policy installation on Security Gateway (which causes traffic loss).<br>Refer to [sk55244](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk55244). |
| 02151898; 01959895, 01987676 | VSX | Virtual Systems are "Down" after reboot of VSX Cluster Member.<br>Refer to [sk110073](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110073). |
| 02024874 | Gaia OS | Apache HTTP server daemon (httpd) crashes with core dump file during shutdown of Gaia OS. |
| Take 161 (14 July 2016) |
| 02043721 | Anti-Virus | " _cmi\_execute\_ex: cmik\_loader\_fw\_context\_match\_cb(context\_apps=1000 buf\_len=14) failed;_" message appears repeatedly in _/var/log/messages_ file on Security Gateway. |
| 02066100 | Identity Awareness | Machine sessions that are used by various users receive an incorrect large session timeout (TTL is set to one week from the discovery time). |
| 02071227 | Identity Awareness | Identity Awareness Gateway might crash when running ' _cpstop_' command.<br>Refer to [sk111315](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111315). |
| 02077462 | Mobile Access | Kerberos Single Sign On (SSO using Kerberos) for Web Applications might fail from time to time. |
| 02058573 | Mobile Access | Web Applications do not work as expected when accessing Mobile Access Portal with Web Form SSO enabled and the web page contains a form with encoded "+" sign (%2B). |
| 02059445 | Mobile Access | Manual SSO does not work when the password contains special characters such as "%". |
| 02029758 | Threat Emulation | " _Maximum delay time_" setting for Mail Transfer Agent is not applied if the defined value is greater than 15 minutes.<br>Refer to [sk109893](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109893). |
| 02039586 | Multi-Domain Security Management Server | Users and GUI clients are overwritten on Security Management Server during MDS synchronization when Domain Management Server and Security Management Server are configured in HA mode.<br>Refer to [sk111175](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111175). |
| 01904538, 02052848 | HTTPS Inspection | HTTPS Inspection Bypass rules that use Destination IP or Source IP stop working after enabling Probe Bypass.<br>Refer to [sk111617](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111617). |
| 01819431 | SecureXL | Improved handling of Bond Group IDs greater than 35 when creating bond interface of SAM card ports. |
| 01959704;<br>02158515 | Gaia OS | Not able to configure routemap for each BGP peer on Gaia OS.<br>Refer to [sk110477](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110477). |
| Take 159 (20 June 2016) - _General Availability Take_ |
| - | General | Minor improvement in Jumbo Hotfix Accumulator _**package**_ to support software updates to this Jumbo Hotfix Accumulator. |
| Take 158 (16 June 2016) |
| 01621251;<br>02077494;<br>01621253 | Cluster | Gratuitous ARP Request packets (GARP) are not sent during cluster fail-over for IP addresses configured in the _$FWDIR/conf/local.arp_ file (per [sk30197](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30197)), if those IP addresses and Cluster VIP address are on different subnets.<br>Refer to [sk105645](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105645). |
| 02042497;<br>01834487,<br>02006059 | HTTPS Inspection | Probe Bypass is initiated on non-SSL connection.

Refer to [sk108294](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108294).

|     |     |
| --- | --- |
| **Important Note:** | For this fix to work correctly, at least this _Take\_158_ _**must be installed on both sides**_ -<br>on Security Management Server _**and**_ Security Gateway.<br>Otherwise, HTTPS Inspection Probe Bypass feature will _not_ work at all. | |
| Take 156 (30 May 2016) |
| 02051292 | Gaia OS | Gaia OS might crash when removing a Bond interface in Gaia Portal.<br>Refer to [sk111673](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111673). |
| 02021344 | Gaia OS | " _CLINFR0412 Inconsistent ValFlag & MultiValue_" message appears repeatedly in _/var/log/messages_ file on Gaia OS.<br>Refer to [sk111632](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111632). |
| 02027698;<br>02027733;<br>02027775 | Security Gateway | HTTP/HTTPS connections that should be accepted on a rule with 'Domain Object', do not pass through the Security Gateway.<br>Refer to [sk110687](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110687). |
| 02029554 | Mobile Access | Version of ESOD Compliance Updates on Mobile Access Gateway does not change after successful update.<br>Refer to [sk111627](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111627). |
| 02051629 | Mobile Access, VSX | Mobile Access Portal on VSX Gateway is unresponsive with "HTTP 500" error after installing Takes 143, 145 of R77.30 Jumbo Hotfix Accumulator because _$CVPNDIR/phpincs/php-ews/EWSType/\*.php_ files are not copied to the contexts of Virtual Systems.<br>Refer to [sk111677](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111677) (Scenario 1). |
| 02042653 | VPN | The _vpnd_ daemon crashes after installing R77.30 Jumbo Hotfix Accumulator over [sk108192: R77.30 Recommended Hotfix #5](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192).<br>Refer to [sk111555](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111555). |
| 02020823;<br>02020869 | Threat Extraction | " _This notification page has expired_" error in UserCheck page when a user tries to download the original file that was blocked by Threat Extraction.<br>Refer to [sk106249](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106249). |
| 02015157 | Cluster | Configuring PIM Sparse Mode with dynamic Rendezvous Point (RP) fails in cluster environment.<br>Refer to [sk110939](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110939). |
| 02045987 | Cluster | DHCP Relay stops working on ClusterXL with enabled VMAC mode installing Takes 128, 138, 143, 145 of R77.30 Jumbo Hotfix Accumulator.<br>Refer to [sk111588](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111588). |
| 01680839, 02006901 | Security Management Server, Multi-Domain Security Management Server | Fixed Cross-Site Scripting (XSS) vulnerability in Management Portal. |
| Take 155 (26 May 2016) |
| This specific Take package was recalled for additional testing and was replaced by Take 156. |
| Take 145 (10 May 2016) |
| 02010218 | VPN, SecureXL | Site-to-Site VPN using IKEv2 fails when SecureXL is enabled.<br>Refer to [sk114834](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk114834#Scenario%205) (Scenario 5). |
| 02022420 | VPN | The _vpnd_ daemon might crash when processing CRL cache. |
| 02017992 | VPN | VPN Central Gateway drops SIP RTP traffic between the SIP Call Manager and the VPN Satellite Gateway, where the SIP call was initiated.<br>Refer to [sk111839](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111839). |
| 01998381, 02022414 | HTTPS Inspection | The _wstlsd_ daemon might crash. |
| 02027270 | Security Management Server, Multi-Domain Security Management Server | Policy installation fails, and the _fwm_ process crashes with core dump file when Security Gateway and Security Management Server run R77.30.<br>Refer to [sk109616](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109616). |
| Take 143 (21 Apr 2016) |
| 01979082 | Security Management, SmartDomain Manager, Multi-Domain Management / Provider-1 | Connectivity between SmartDashboard / SmartDomain Manager and Security Management / Multi-Domain Management Server R77.30 and below fails on fresh installation after January 24th 2018.<br>Refer to [sk122612](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122612) |
| - | 2012 Models Security Appliances, Data Center Security Appliances | R77.30 NGTP, NGTX and HTTPS Inspection performance and memory consumption optimization.<br>Refer to [sk109772](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109772). |
| 02012973 | Mobile Access, Endpoint Security On Demand Secure Workspace (SWS) | The " _User must use Check Point Secure Workspace_" setting on Mobile Access Gateway is not enforced when a user running on Windows 10 signs on to the Mobile Access Portal.<br>Refer to [sk111115](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111115). |
| 01898695 | Mobile Access, Cluster | Push Notifications are not shown on handheld devices after failover in Mobile Access cluster.<br>Refer to [sk109318](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109318). |
| 01807600, 01807879 | Mobile Access | Accessing SSLVPN portal without providing certificate, results in unclear log in SmartView Tracker.<br>Refer to [sk107812](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107812). |
| 01989333 | Mobile Access | Capsule Workspace Push Notifications do not work on iOS 9.3 (or higher).<br>Refer to [sk110623](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110623). |
| 01982148, 01984883 | Mobile Access | No Push Notifications in Capsule Messages.<br>Refer to [sk110215](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110215). |
| 01832865, 01834664 | Mobile Access | Mobile Access fails to perform SSL handshake with web servers that use SHA-512 certificates.<br>Refer to [sk108283](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108283). |
| 02019281 | Threat Emulation | File download from some web sites over HTTP through Threat Emulation gateway times out.<br>Refer to [sk111136](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111136). |
| 02019094 | Threat Emulation | Improved Threat Emulation performance in CoreXL by reducing the ratio of the _dlpu_ processes per CoreXL FW instances:<br>- from 1:2 = 1 _dlpu_ process for each 2 CoreXL FW instances<br>- to 1:4 = 1 _dlpu_ process for each 4 CoreXL FW instances |
| 02008306 | Threat Emulation | " _File is pending emulation. Threat scan failed_" log in SmartView Tracker / SmartLog.<br>Refer to [sk106739](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106739) (Scenario 1 - "E-mail attachment is encoded in Base64 charset"). |
| 02013906 | Application Control, URL Filtering | When the "Categorize HTTPS Sites" option is enabled, accessing HTTP URLs can cause an "`Internal System Error`" logs in SmartView Tracker and failure to open the web page. |
| 01953147 | Gaia OS | In cluster with PIM Sparse Mode, multicast outgoing interfaces (refer to the output of " _ip mroute_" command") for some or all multicast groups are deleted and never restored by themselves after rebooting both cluster members at the same time. |
| 01946518, 01953158 | Gaia OS | Security Gateway randomly stops forwarding the IGMP / PIM Sparse Mode multicast traffic - in PIM Sparse Mode, low amount of arriving multicast traffic causes the local multicast members to be pruned early.<br>Refer to [sk106858](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106858). |
| 01953146 | Gaia OS | Improved stability of the _routed_ daemon when working with PIM Sparse Mode. |
| 01956738, 01957576 | Gaia OS | Output of Clish command " _show sysEnv all_" / Expert mode command " _dbget sysEnv:all_" on Gaia OS is corrupted (text is not ordered).<br>Refer to [sk110220](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110220). |
| 01990563 | Gaia OS | RIM (Route Injection Module) routes are removed from Gaia OS routing table when running " _ifdown <Name\_of\_Interface>_" command in Expert mode. However, these RIM routes still appear when running " _show route_" command in Clish.<br>Refer to [sk105527](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105527). |
| 02004564 | Gaia OS, Cluster | The _routed_ daemon on the active cluster with configured PIM might crash after a peer cluster member is rebooted. |
| 02003221 | Security Gateway | The "X-Forward-For" (XFF) header is not stripped from web traffic when Security Gateway is configured as HTTP/HTTPS Proxy in Non Transparent mode.<br>Refer to [sk111016](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111016). |
| 02011289 | Security Gateway, Security Management Server, Multi-Domain Security Management Server | SNMP counters for "packets rate" / "throughput" show incorrect values - .1.3.6.1.4.1.2620.1.1.25.9 and .1.3.6.1.4.1.2620.1.1.25.16 - " _fwDroppedBytesTotalRate_" counter and " _fwDroppedTotalRate_" counter always show "0" value.<br>Refer to [sk104882](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104882). |
| 02002926 | Security Management Server, Multi-Domain Security Management Server | " _Unexpected error_" message pops up in the SmartDashboard when trying to connect to Primary Security Management Server after two failovers - from Primary Security Management Server to Secondary Security Management Server and back.<br>Refer to [sk107176](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107176). |
| 01972280 | Security Management Server, Multi-Domain Security Management Server | Topology in SmartDashboard for interfaces named "Internal" and "External" (e.g., on UTM-1, Power-1, DLP-1 appliances) is always set based on their names.<br>Refer to [sk111017](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111017). |
| 01834487, 02006059 | HTTPS Inspection | Probe Bypass is initiated on non-SSL connection.<br>Refer to [sk108294](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108294). |
| 02003519, 02019844 | HTTPS Inspection, CoreXL | Improved SSL handshake performance in CoreXL by reducing the ratio of the _wstlsd_ processes per CoreXL FW instances to be either:<br>- 1:4 = 1 _wstlsd_ process for each 4 CoreXL FW instances<br>- 1:2 = 1 _wstlsd_ process for each 2 CoreXL FW instances<br>- any other ratio<br>Default is:<br>- 1:1 - if SMT (HyperThreading) is disabled ( [sk93000](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk93000))<br>- 1:2 - if SMT (HyperThreading) is enabled [sk93000](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk93000) |
| 01926907, 02005808 | CoreXL | "Dynamic Hide NAT" feature reuses NAT ports too quickly.<br>Refer to [sk103656](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103656#Troubleshooting). |
| 02012536, 02013035 | CoreXL | Traffic outage on ClusterXL after enabling both CoreXL Dynamic Dispatcher ( [sk105261](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105261)) and SecureXL NAT Templates ( [sk71200](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk71200)).<br>Refer to [sk111015](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111015). |
| 01925621, 01946714 | SecureXL | Non-tagged packets are sent out VLAN over SAM card bond in PXL path. |
| 01980215, 01961276 | DLP | " _Your emails are about to expire_" notifications from DLP. However, there are no e-mails in the DLP portal.<br>Refer to [sk110314](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110314). |
| Take 138 (14 Apr 2016) |
| This specific Take package was recalled for additional testing. |
| Take 135 (07 Apr 2016) |
| This specific Take was recalled for additional testing. |
| Take 128 (31 Mar 2016) |
| 01685521;<br>01713626;<br>01724275;<br>01782998;<br>01814720;<br>01820258;<br>01821776;<br>01834453;<br>01852560 | Threat Extraction, Threat Emulation | Integrated SandBlast Parallel Extraction Hotfix.<br>Refer to [sk108074](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108074). |
| 01978917 | Threat Extraction | Increased the size of files that can be scanned by Threat Extraction Extension to 15MB. |
| 01915777, 01936336 | Mobile Access | Kerberos is not supported as SSO method for registration to Exchange Server for Mobile Access Push Notifications.<br>Refer to [sk110629](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110629). |
| 01892929 | Mobile Access | Mobile Access Portal does not work after uninstalling Jumbo Hotfix Accumulator from Mobile Access gateway.<br>_Workaround_: After uninstall, run: _\# $CVPNDIR/scripts/cvpn\_post\_utility.csh_ |
| 01811956 | Mobile Access, Endpoint Security On Demand (ESOD) Compliance Scanner | Added support for Windows 10 in:<br>- Endpoint Security On Demand (ESOD) Compliance Scanner<br>Refer to [sk107132](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107132). |
| 01958625, 01959114 | Mobile Access, SSL Network Extender | After one SNX user disconnects, all other connected users are disconnected. Mobile Access gateway becomes non responsive.<br>Refer to [sk110316](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110316). |
| 01978856 | Mobile Access, SSL Network Extender | SNX user is unable to connect to resources via Proxy server with authentication:<br>- Example topology:<br>  <br>  (SNX usert)--(Proxy)--(Mobile Access Gateway)--(SNX resource).<br>- The expected flow:<br>  <br>  Log in to the SNX portal -> connect to SNX -> provide credentials for Proxy authentication -> open connection.<br>- The observed flow:<br>  <br>  Log in to the SNX portal -> connect to SNX -> web browser shows "HTTP error 407". |
| 01726719, 01971151 | Cluster | Gaia VRRP member freezes when deleting a VLAN interface previously associated with VRRP.<br>Refer to [sk106226](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106226). |
| 01975771 | SmartEvent | SmartEvent R77.20 / R77.30 stops showing new events occasionally due to failure to get the valid license.<br>Refer to [sk110016](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110016). |
| 01974185;<br>01974187 | Security Gateway | Due to wrong handling of some kernel tables:<br>- Connectivity issue without any relevant logs in SmartView Tracker.<br>- Policy installation fails with " _Load on Module failed_".<br>Refer to [sk109797](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109797). |
| 01980269 | HTTPS Inspection | HTTPS traffic is not routed according to Policy Base Routing (PBR) when HTTPS Inspection is enabled.<br>Refer to [sk110690](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110690). |
| 01947356, 01976641 | IPS | Global IPS Exception for protection "Any" does not work for e-mail traffic when using IPS with Anti-Virus or another blade.<br>Refer to [sk110023](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110023). |
| 01964380 | VSX | The _fwk_ process might crash "with signal 7, Bus error" when H323 traffic passes through CPAS on Virtual System. |
| 01974230 | DLP | " _Quarantined email is about to expire_" notifications from Data Loss Prevention blade are not sent to some e-mail accounts.<br>Refer to [sk109015](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109015). |
| 01979887 | Gaia OS | The _routed_ daemon crashes after receiving an OSPF LSA packet that contains invalid netmask.<br>Refer to [sk104519](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104519). |
| 01915798 | SecureXL | Output of " _fwaccel stat_" command shows:<br>`Accelerator Status : off by Firewall (too many general errors (NUMBER) (caller: Name_of_Function))`.<br>Refer to [sk100467](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100467) (Scenario 3 - "UDP traffic causes too many general errors"). |
| 01916631 | SecureXL, Cluster | Traffic sent to IP addresses X.X.X.255 (last octet is "255", but is not a broadcast address on this network) is dropped by ClusterXL in Load Sharing Unicast mode with "`cluster error`".<br>Refer to [sk107853](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107853). |
| Take 117 (10 Mar 2016) |
| 01960407, 01961587 | Mobile Access | Added " _cvpnd\_admin debug trunc_" command that moves all existing content of the current _$CVPNDIR/log/cvpnd.elg_ file into a new file and empties the current _$CVPNDIR/log/cvpnd.elg_ file (to be used when the current _$CVPNDIR/log/cvpnd.elg_ file becomes corrupted - filled with NULL characters). |
| 01960012 | Mobile Access, SSL Network Extender | When user connects to Mobile Access Portal with RADIUS challenge and starts SNX, re-authentication before end of session does not restart counter.<br>Refer to [sk110175](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110175). |
| 01898695 | Mobile Access, Cluster | Push Notifications are not shown on handheld devices after failover in Mobile Access cluster.<br>Refer to [sk109318](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109318). |
| 01927612 | Security Gateway | Security Gateway now drops and logs TCP SYN packets that contain data (even if CPAS / PSL in not used). |
| 01955875 | Security Gateway, Security Management Server, Multi-Domain Security Management Server | SNMP counters for "packets rate" / "throughput" show incorrect values - .1.3.6.1.4.1.2620.1.1.25.9 and .1.3.6.1.4.1.2620.1.1.25.16 - " _fwDroppedBytesTotalRate_" counter and " _fwDroppedTotalRate_" counter always show "0" value.<br>Refer to [sk104882](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104882). |
| 01846456, 01960991 | Security Management Server, Multi-Domain Security Management Server | Manual NAT policy verification passes while it should fail.<br>Refer to [sk108389](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108389). |
| 01281728, 01866926 | HTTPS Inspection | Unable to access some HTTPS sites after enabling HTTPS Inspection "Probe Bypass" mechanism.<br>Refer to [sk107744](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107744). |
| 01959400 | VPN | IPv6 routing issue in Star community when VPN Routing is set to " _To center, or through the center to other satellites, to internet and other VPN targets_" (VPN Community properties - "Advanced Settings" - "VPN Routing"):<br>- If IPv6 is enabled on the Center Gateway, then all IPv6 traffic will be sent through the Center Gateway<br>- If IPv6 is disabled on the Center Gateway, then IPv6 traffic between internal networks will be dropped by the Center Gateway with " _Clear text packet should be encrypted_" |
| 01947521 | IPS | " _Countries DB download has failed_" logs in SmartView Tracker even when Geo Protection is set to " _Inactive_".<br>Refer to [sk106294](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106294). |
| 01973174 | URL Filtering | Some HTTPS web sites are not categorized correctly when "Categorize HTTPS sites" is enabled.<br>Refer to [sk110475](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110475). |
| 01959509 | URL Filtering, Application Control | Random issues with HTTP web browsing - traffic latency increases, and at some point web browsing stops working.<br>Refer to [sk64162](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk64162). |
| 01948312 | Anti-Virus | HTTP 206 "Partial Content" error in SmartView Tracker.<br>Refer to [sk106446](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106446). |
| 01938571, 01967411;<br>01938659, 01967415;<br>01938796, 01967423 | QoS | QoS (Floodgate) policy install randomly causes Security Gateway to crash and reboot.<br>Refer to [sk109840](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109840). |
| 01915918, 01961123 | Threat Emulation | The download of files that are being emulated on "Hold" times out even though the Threat Emulation ends successfully.<br>Refer to [sk110479](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110479). |
| 01963649 | Cluster, CoreXL | Hide NAT port exhaustion on Standby cluster member in ClusterXL HA mode.<br>Refer to [sk98828](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98828). |
| 01972270 | Gaia OS | "admin" user's password expiry is affected when password-policy is enabled on Gaia OS.<br>Refer to [sk106160](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106160). |
| 01972282 | Gaia OS | The _snmpd_ daemon crashes. |
| 01962335 | Gaia OS | Removed " _\[getTACProles(...)\]: RBA role not found for admin!generated_" message from _/var/log/messages_ file that appeared (since Take\_95) after each authentication to Clish with Local / RADIUS user. |
| 01948282;<br>01948283 | Gaia OS | ' _clish_' and ' _confd_' processes consume CPU at high level after SSH session for non-local TACACS user has been expired/killed.<br>Refer to [sk104579](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104579). |
| 01965115 | Gaia OS | _snmpd_ process might crash with core dump file (due to Segmentation fault) when it exits. |
| 01936069 | Gaia OS | " _Wrong IP Please try again_" error in LCD (go to "Network" - go to "Set MGMT interface") when changing the IP address of management interface on Check Point appliances that run takes from _Take\_95_ to _Take\_111_.<br>Refer to [sk106447](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106447). |
| 01937716, 01937817 | Gaia OS | Backup restore includes the original MAC addresses of the machine.<br>Refer to [sk109934](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109934). |
| 01963688 | Gaia OS | SNMP query for OID .1.3.6.1.4.1.2620.1.6.16.3 (`.iso.org.dod.internet.private.enterprises.checkpoint.products.svn.svnApplianceInfo.svnApplianceSerialNumber.0`) returns " _umber: <Serial\_Number>_". |
| 01719131, 01957088 | SecureXL | Security Gateway might crash when disabling and re-enabling SecureXL.<br>Refer to [sk106934](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106934). |
| Take 111 (23 Feb 2016) |
| - | Gaia OS | Resolved error when installing _Take\_105_ using CPUSE:<br>`Detected inconsistent files for installing this package.<br> In order to successfully install the package, refer to sk97699`. |
| - | Data Center Security Appliances | Added support for 15000 and 23000 appliances.<br>Refer to [sk107516](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107516). |
| Take 105 (11 Feb 2016)<br>**Important Note:** Installation of this specific Take is supported only using Legacy CLI |
| 01944440 | Cluster | Occasionally, SCCP (Skinny) VoIP phones unregister from Call Manager during cluster failover.<br>Refer to [sk110025](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110025). |
| 01932329, 01940409 | Mobile Access | " _Error: Page cannot be displayed. An error occurred while processing the request_" in web browser after entering the credentials in Mobile Access Portal.<br>Refer to [sk110072](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110072). |
| 01890990, 01946973 | VSX | Virtual Systems are in "Unknown" state after reboot of VSX Cluster Member.<br>Refer to [sk110074](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110074). |
| 01896617 | Threat Emulation | E-mail client receives timeout error, e-mails do not reach their destinations, and SmartView Tracker shows duplicated Threat Emulation logs from a cluster.<br>Refer to [sk109198](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109198). |
| 01879709, 01937995 | SmartView Monitor | The _rtmd_ process crashes due to memory corruption. |
| Take 102 (08 Feb 2016)<br>**Important Note:** Installation of this specific Take is supported only using Legacy CLI |
| 01872488, 01916408 | Gaia OS | The _routed_ daemon might crash on VSX Gateway when Traces (debug) are enabled. |
| 01940689, 01944426 | Gaia OS | Cannot change OSPF settings in Gaia Portal using Internet Explorer (IE) browser.<br>Refer to [sk109946](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109946). |
| 01916400 | Gaia OS | The _routed_ daemon might crash when BGP is configured on Gaia OS.<br>Refer to [sk105698](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105698). |
| 01702790, 01935921 | Gaia OS | " _libdb set: missing or invalid argument_" error in Gaia Portal when creating snapshot.<br>Refer to [sk106646](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106646). |
| 01928277 | SecureXL | Check Point 21000 series appliance with SAM card incorrectly forwards connections to 21000 appliance.<br>Note: This fix is an additional improvement of 01850540 integrated into Take\_75.<br>Refer to [sk108589](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108589). |
| 01900767 | SecureXL | Improved detecting and reporting of hardware errors in SAM card. |
| 01906737 | SecureXL | SAM card statistics was unavailable for 3600 sec after reboot. |
| 01818639 | SecureXL | TCP packets are not dropped as Out-of-State when SecureXL is enabled.<br>Refer to [sk104557](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104557). |
| 01886179, 01873994 | HTTPS Inspection, CoreXL | Difficulties in connecting to untrusted sites when both HTTPS Inspection and CoreXL Dynamic Dispatcher are enabled.<br>Refer to [sk108894](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108894). |
| 01939568 | SmartView Monitor | " _Use only external interfaces_" option shows wrong traffic rate in SmartView Monitor.<br>Refer to [sk107353](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107353). |
| 01938186 | VPN | The _vpnd_ daemon might crash if IKE packets arrive fragmented. |
| 01821434 | Mobile Access | User is able to access Mobile Access Portal even if Secure Workspace is forced, but fails to load.<br>Refer to [sk107603](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107603). |
| 01939446 | Anti-Virus, Anti-Bot | Security Gateway with enabled Anti-Virus blade / Anti-Bot blade and Log Suppression might crash during _cpstop_. |
| Take 101 (28 Jan 2016) |
| 01921776 | Security Gateway, VSX | Security Gateway / VSX FWK daemon might crash if Hide NAT is configured on Network object(s). |
| 01697910 | Gaia OS | The _snmpd_ daemon consumes CPU at 90-100% when polling OID _raIkeOverTCP_ (1.3.6.1.4.1.2620.500.9000.1.22) while Endpoint Security Client is connected.<br>**Workaround:** Restart SNMP Agent either in Gaia Portal (' _System Management_' section - ' _SNMP_' page), or in Gaia Clish (' _set snmp agent off_' and ' _set snmp agent on_' commands). |
| 01917104; 01917106; 01917110 | Gaia OS | Improved support of allowed ASCII characters for passwords on Gaia OS.<br>Refer to [sk109148](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109148). |
| 01931796 | Gaia OS | Added support for charset ISO-8859-8-I (Hebrew, logical order). |
| 01878129 | Gaia OS | " _Out of normal bound_" error for PWRS\_FAN and VTT seen in SmartView Monitor.<br>Refer to [sk107855](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107855). |
| 01584565 | Gaia OS | The _snmpd_ daemon crashes due to SIGXFSZ signal. |
| 01584749 | Gaia OS, Cluster | Clish crashes with Segmentation fault after running any ' _show cloning-group ..._' Clish command on cluster members.<br>Refer to [sk104885](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104885). |
| 01929775 | Security Gateway, Security Management Server | Removing ECDHE from CURL cipher proposal list. |
| 01932161 | Application Control, URL Filtering | RAD daemon might incorrectly parse its configuration, which causes it to assume that proxy is configured. This leads to categorization failures. |
| 01931123 | Threat Emulation | SmartView Tracker displays e-mail subject as ISO string if it is written not in English.<br>Refer to [sk105164](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105164) (Scenario 4). |
| 01917419 | Application Control, URL Filtering, Anti-Bot, Anti-Virus | RAD daemon might shutdown due to SIGPIPE signal, which causes functionality issues with various Software Blades that rely on this daemon. |
| 01921779 | SecureXL | Connections are dropped as Out-of-State after some idle time when SecureXL is enabled.<br>Refer to [sk101232](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101232). |
| 01901962 | SecureXL | Now it is possible to configure IP address of loopback interface as source address in NetFlow. |
| 01929294 | Security Gateway, Security Management Server | Standby Cluster member fails to fetch policy from Active member during _cpstart_.<br>Refer to [sk109393](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109393). |
| 01925676 | Security Management Server, Multi-Domain Security Management Server | SmartView Monitor "Interface table" shows only one configured cluster interface on IPSO-based cluster members.<br>Refer to [sk109143](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109143). |
| 01622993 | Security Management Server, Multi-Domain Security Management Server | Objects and policies are not restored from Gaia Backup (SmartDashboard shows only default objects), although the restore operation succeeded.<br>Code was improved:<br>- Matching of Backed-up products and Local installed products made stricter.<br>- Improved validation for Threat Emulation blade being enabled.<br>- Improved validation for VSX mode being enabled (resolves false positives).<br>Refer to [sk105641](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105641). |
| Take 99 (20 Jan 2016) |
| 01642962, 01885055 | SecureXL | Packets are not routed correctly when PBR is configured and SecureXL is enabled.<br>Refer to [sk109741](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109741). |
| 01892651 | SecureXL | Traffic is dropped by IPS protection " _TCP Segment Limit Enforcement_" due to attack " _TCP segment out of maximum allowed sequence_" when SecureXL is enabled and traffic passes through Medium Path.<br>Refer to [sk66576](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk66576). |
| Take 98 (17 Jan 2016) |
| 01910745 | Security Gateway | When running _fw monitor_ command, it returns " _cp: cannot stat '/opt/CPsuite-R77/fw1/conf/updates.def': No such file or directory_" error. |
| 01914959 | Gaia OS | Monitoring of the _routed_ daemon is now disabled completely:<br>- In Gaia Portal - the following checkbox was removed:<br>  <br>  In the tree view, go to _Advanced Routing_ section - click on _Routing Options_ page - in the _Advanced Routing Options_ area - the box _PNOTE Reporting_<br>- In Gaia Clish - the following commands were removed:<br>  <br>  _set router-options pnote-reporting ..._<br>Refer to [sk108069](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108069). |
| 01844422 | Gaia OS, SecureXL | Gaia OS on Check Point 21000 series appliance with SAM card becomes unresponsive when trying to delete a VLAN interface after passing multicast traffic through that VLAN interface.<br>Refer to [sk115420](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115420). |
| 01844424, 01880511 | SecureXL | NAT is not applied by Security Gateway to multicast packets in the following scenario:<br>- SecureXL is enabled on Security Gateway<br>- NAT is configured for multicast sender as "Hide behind Gateway"<br>As a result, the multicast receiver host "sees" the original IP address of the multicast sender. |
| 01844428, 01882993 | SecureXL | SecureXL incorrectly drops multicast control packets (such as 224.0.0.252 - RFC 4795 LLMNR) when Security Gateway / VSX Virtual System runs in Bridge mode. |
| 01907475, 01912368 | Application Control, URL Filtering | Users occasionally are not able to access HTTPS sites when "Categorize HTTPS sites" option is enabled.<br>Refer to [sk109581](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109581). |
| 01917498 | URL Filtering | Connection fails with the following URL Filtering log in SmartView Tracker: " _Internal System Error occurred, allowing / blocking request (as configured in engine settings). See sk64162 for more information_".<br>Refer to [sk103859](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103859). |
| 01896185, 01899771 | Mobile Access | Disabling the Floating Navigation Bar (FNB) via GuiDBedit Tool does not disable the FNB in the Web Application.<br>Refer to [sk109254](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109254). |
| 01907197 | LTE | GTP-C traffic that is matched on IP/UDP part of a rule and mismatched on the GTP part of the rule (for example IMSI prefix filter on GTP service) is dropped. As a result, multiple GTP-C services that include GTP service filters can not be used for the same IP/UDP networks (e.g., mobile carrier core network provides roaming services for multiple MNO subscribers, each of which has different PLMN ID prefix in IMSI, and carrier wants to filter outbound roaming to its network to those multiple IMSI prefixes) - the relevant rule either accepts the packet, or drops the packet when first service is matched. |
| 01907262 | LTE | "Handover Group" field is not shown in SmartView Tracker logs for GTP-C traffic. |
| Take 95 (04 Jan 2016) |
| 01883475 | General | MiniWrapper installation is aborted with " _This installation is not suitable for gateways only_" error when there are more than 50 installed packages (of any type) on the machine. |
| 01879869, 01822961, 01882245 | Gaia OS | Security Gateway / Cluster randomly stops forwarding the IGMP traffic - multicast traffic times out and not resuming.<br>Refer to [sk106858](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106858). |
| 01879870 | Gaia OS | PIM neighbor refresh is slow on Check Point Security Gateway / Cluster after neighbor PIM router failover:<br>- After failover of neighboring PIM router (after disconnecting a router link), multicast traffic is recovered after 6 seconds.<br>- After failback of neighboring PIM router (after reconnecting a router link), multicast traffic is recovered after 10-15 seconds.<br>Refer to [sk107595](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107595). |
| 01887289 | Gaia OS | Deleting an IP address from the Management interface without adding a new IP address is now blocked.<br>Refer to [sk106447](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106447). |
| 01576432 | Gaia OS | Gaia Clish crashes when running _show configuration ..._ commands if the _/web/cgi-bin/validate.tcl_ file does not exist.<br>Refer to [sk104647](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104647). |
| 01697615;<br>01614716 | Gaia OS | - When TACACS+ non-local user runs _clish -c "some\_clish\_syntax"_ command from Expert mode (e.g., _clish -c "show interface eth0"_), the following errors appear:<br>  <br>  <br>  ```<br>  [Expert@HostName:0]# clish -c "some_clish_syntax"<br>  CLINFR0829  Unable to get user permissions.<br>  CLINFR0599  Failed to build ACLs.<br>  ```<br>  <br>- When TACACS+ non-local user runs _clish -c "some\_clish\_syntax"_ command from Expert mode (e.g., _clish -c "show interface eth0"_) on VSX Gateway, the following error appears:<br>  <br>  <br>  ```<br>  [Expert@HostName:0]# clish -c "some_clish_syntax"<br>  CLINFR0220  User is not allowed to access any virtual-system.<br>  ```<br>  <br>Refer to [sk105322](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105322). |
| 01822237 | Gaia OS | DHCP Relay and DHCP Server do not function when configured together on the same Gaia OS.<br>- Between DHCP Relay ( _routed_) process and DHCP Server ( _dhcpd_) process, the last process to start up will receive all the UDP unicast traffic. The first process sees no unicast traffic.<br>- Both DHCP Relay ( _routed_) process and DHCP Server ( _dhcpd_) process will see UDP broadcasts.<br>- If DHCP Server ( _dhcpd_) process starts first, then this joint configuration will work, because _dhcpd_ process only cares about UDP broadcasts.<br>  <br>  If DHCP Relay ( _routed_) process starts first, then this joint configuration would fail to work, because the replies from DHCP Server that should be relayed are UDP unicasts.<br>Refer to [sk98839](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98839). |
| 01799658 | Gaia OS | Backup Schedule Name and Backup Type changed after joining Gaia Cloning Group.<br>Refer to [sk107495](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107495). |
| 01884462, 01783081 | Gaia OS, Security Gateway, Cluster | Security Gateway / Cluster member on Gaia OS with configured Dynamic Routing and ECMP might freeze in the following scenarios:<br>- After adding a new VPN Tunnel Interface "vpnt"<br>- After disconnecting all cables from Bond interface on the VSX Virtual Router (reconnecting the cables does not help)<br>- After administratively bringing the VSX cluster member "down" with "clusterXL\_admin down" command<br>Refer to [sk107418](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107418). |
| 01884966 | Cluster, CoreXL | R77.30 cluster member might go Down after disabling CoreXL Dynamic Dispatcher only on one member.<br>Refer to [sk108856](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108856). |
| 01869737 | Cluster, SecureXL | " _First packet isn't SYN_" drop logs in SmartView Tracker for TCP traffic from ClusterXL in Load Sharing Unicast mode with enabled SecureXL.<br>Refer to [sk107618](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107618). |
| 01878266, 01848272, 01880216, 01855069 | Cluster | Cluster " _Interface table_" is empty in SmartView Monitor and in output of " _cpstat -f all ha_" command.<br>Refer to [sk108546](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108546). |
| 01883357 | Security Gateway | _in.ahttpd_ process crashes repeatedly with core dump files on Security Gateway with HTTP/HTTPS User Authentication rules.<br>Refer to [sk103974](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103974). |
| 01852286, 01852966 | Mobile Access | Occasionally Mobile Access gateway becomes non-responsive after enabling Push Notifications.<br>Refer to [sk108532](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108532). |
| 01898695 | Mobile Access | Push Notifications are not shown on handheld devices after failover in Mobile Access cluster.<br>Refer to [sk109318](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109318). |
| 01907717, 01909788 | Mobile Access | Custom logo can no longer be applied / seen in SSL VPN portal after installing hotfix for issue ID 01732329 (since Take 49).<br>Refer to [sk107454](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107454). |
| 01811956 | Mobile Access, Endpoint Security On Demand Secure Workspace (SWS) | Added support for Windows 10 in:<br>- Endpoint Security On Demand Secure Workspace (SWS)<br>Refer to [sk107132](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107132). |
| 01846041, 01897357;<br>01861402, 01897362 | SecureXL, Cluster | SecureXL on Standby cluster member drops traffic with " _Address spoofing_" log.<br>Refer to [sk108502](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108502). |
| 01893950, 01893952, 01908788 | SecureXL | When NAT is configured on the network/host where SecureXL is enabled, not all entries in SecureXL Connections Table (run ' _fwaccel conns_' command) are deleted after the " _UDP virtual session timeout_" when traffic is stopped. |
| 01906167 | SecureXL | Check Point 21000 series appliance with SAM card might crash during frequent policy installations, or during failover and failback in cluster environment (due to disabling and enabling of watchdog monitoring in SAM card).<br>Refer to [sk108643](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108643). |
| 01870140 | VPN | " _Accept all encrypted traffic_" option does not work on VSX clusters.<br>Refer to [sk105344](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105344). |
| 01879422 | VPN | The _vpnd_ daemon might crash when connecting more than ~1024 SNX Application Mode clients to Mobile Access gateway. |
| 01691222, 01904577 | VPN | Not possible to establish Site-to-Site VPN tunnel with Large Scale VPN (LSV) peer, which is a DAIP device.<br>Refer to [sk109473](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109473). |
| 01894511 | Threat Emulation | Ability to change the default size of the _/var/log/maillog_ file when using Mail Transfer Agent (MTA).<br>Refer to [sk93505](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk93505). |
| 01664717, 01891039 | Threat Emulation | Files are emulated even though their MD5 is added as 'Exception' to Threat Prevention policy.<br>Refer to [sk109438](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109438). |
| 01909632, 01879389 | Identity Awareness | Identity Awareness Agent disconnects with no apparent reason after some time of operation when Kerberos SSO is defined.<br>Refer to [sk107155](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107155). |
| 01707734, 01909020 | IPS | Geo Protection mechanism logs connections from internal IP addresses.<br>Refer to [sk106838](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106838). |
| 01874752, 01913185 | Application Control | Resource Advisor (RAD) performance improvement (increased internal URL parsing speed). |
| 01896491 | URL Filtering, Application Control | Resource Advisor (RAD) does not reuse connections (opens new connection for each request).<br>Refer to [sk103422](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103422). |
| 01861543, 01884021 | URL Filtering, Application Control | Ability to increase the speed of RAD daemon's connection creation/deletion by configuring the number of categorization queries sent by RAD daemon to Check Point cloud in one connection (via parameter _RAD\_QUERIES\_NUMBER\_PER\_CONNECTION_ in Check Point Registry).<br>Refer to [sk103422](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103422). |
| 01856214, 01904755 | Anti-Virus | High CPU utilization on Security Gateway during Anti-Virus scan of large files transferred over CIFS/SMB2 (Windows Sharing on port 445).<br>Refer to [sk109582](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109582). |
| 01910660 | Security Management Server, Multi-Domain Security Management Server | The _fwm_ daemon might crash when running " _fwm getcap_" command (to fetch the packet capture from a log). |
| 01896487 | Multi-Domain Security Management Server | Authentication with MDS user or RADIUS user fails in SmartLog GUI, when SmartLog server is cofigured locally on one of the Domain Management Servers (it is possible to log in only with administrator that was localy defined on that Domain Management Server). |
| 01894840, 01909714 | Multi-Domain Security Management Server | Assigning of Global Policy fails on some Domain Management Servers after modifying a global object.<br>Refer to [sk109436](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109436). |
| Take 84 (06 Dec 2015) |
| - | Check Point Appliances | Support for the [new improved R77.30 Gaia image](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104859#Gaia%20Downloads) (released 16 Dec 2016) for 2200 / 4000 / 12000 / 13000 / 21000 / TE250 / TE1000 / TE2000 appliances. |
| 01867054 | Gaia OS | User is not able to log in to Gaia OS after configuring a password that contains backslash "\\".<br>Refer to [sk106368](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106368). |
| 01786538, 01866514 | Gaia OS | " _Gaia Web-UI recognized a non-valid input data_" error in Gaia Portal when adding a Scheduled Job.<br>Refer to [sk107513](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107513). |
| 01842491, 01855837 | Gaia OS | BGP routemaps stop working correctly after upgrade from R75.4X / R76 versions to R77.10 and later versions.<br>Refer to [sk108497](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108497). |
| 01711169 | Gaia OS | Specific VPN tunnel is not retrieved on first SNMP querying.<br>Refer to [sk106788](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106788). |
| 01711135 | Gaia OS | The routes are not sorted based on the IP address in Gaia Portal - " _Network Management_" section - " _IPv4 Static Routes_" page - " _Gateways_" column.<br>Refer to [sk106747](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106747). |
| 01868833 | Cluster, CoreXL | Hide NAT port exhaustion on Standby cluster member in ClusterXL HA mode.<br>Refer to [sk98828](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98828). |
| 01877245, 01820037 | Cluster | Improved handling of invalid ClusterXL Control Protocol (CCP) packets received on non-trusted (non-sync) interfaces.<br>Refer to [sk108360](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108360) and to [sk108192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192). |
| 01803716, 01816518 | SecureXL | Check Point appliance with SAM card crashes during policy installation.<br>Refer to [sk107857](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107857). |
| 01801507, 01754473 | SecureXL | Memory leak in SecureXL acceleration.<br>Refer to [sk108192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192). |
| 01870777, 01861396 | SecureXL | Traffic does not pass through ClusterXL with enabled VMAC mode and SecureXL.<br>Refer to [sk105577](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105577). |
| 01848712 | Security Gateway | Policy installation fails with error " _Reason: Load on Module failed - failed to load Security Policy_" because internal mapping of IPS protections fails due to kernel table " _spii\_multi\_pset2kbuf\_map_" getting full.<br>Refer to [sk33893](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk33893) (Scenario 22). |
| 01875713, 01821877 | Security Gateway | Proprietary SSL tunnel protocols (e.g., Skype) are not enforced correctly when Security Gateway acts as Proxy (Non-transparent proxy, without the next proxy).<br>Refer to [sk108192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192). |
| 01871427 | Security Gateway | When Dynamic Object is not resolved on the Security Gateway, all traffic that should have been accepted by the rule with this Dynamic Object, is dropped. |
| 01872347 | Security Gateway VE | Security Gateway Virtual Edition (VE) Network Mode is now licensed using a new and improved licensing model. With the new licensing model, managed Security Gateway VE Network Mode is licensed by the total amount of its assigned virtual cores.<br>Affected SKUs: CPSG-VEN-NGTP-GW, CPSG-VEN-NGTX-GW, CPSG-VEN-NGFW-GW.<br>For further licensing details, go to [User Center](https://usercenter.checkpoint.com/) \- at the top, go to _QUOTING TOOLS_ menu - click on _Product Catalog & Quoting_ \- go to section _More Appliances & Solutions_ \- click on _Virtual Security_ \- in _Virtual Edition_ row, select a model - click on _Select_ button - click on _Licensing instructions_ link at the top.<br>Refer to [sk109713](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109713). |
| 01853689 | HTTPS Inspection | Users do not receive UserCheck page for blocked HTTPS content.<br>Refer to [sk93184](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk93184). |
| 01875832 | IPS | Improved handling of HTTP compressions.<br>Refer to [sk108192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192). |
| 01880104, 01830381 | VSX, IPS | Rare crash of the _fwk_ process on VSX Gateway with enabled IPS blade and activated protection "Non-Compliant HTTP".<br>Refer to [sk108192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192). |
| 01859145 | VSX | SNMP OID _vsxCountersConnTableLimit_ (.1.3.6.1.4.1.2620.1.16.23.1.1.4) returns wrong value on VSX if IPv6 is enabled.<br>Refer to [sk106736](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106736). |
| 01854127 | Mobile Access | Mobile Access log in SmartView Tracker shows Browser version instead of OS version.<br>Refer to [sk108711](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108711). |
| 01734925, 01854129 | Mobile Access | " _\[CVPN\_ERROR\] statusToString: Unrecognized status: 5_" error in the debug of the _cvpnd_ daemon on Mobile Access Gateway.<br>Refer to [sk108876](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108876). |
| 01802714 | Multi-Domain Security Management Server | " _Error: Cannot assign the Global IPS policy - The version of IPS on the Domain Management Server and in the Global policy must be the same_".<br>Refer to [sk108877](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108877). |
| 01867540 | Multi-Domain Security Management | Global Policy cannot be assigned after IPS reset due to duplicated objects or profiles.<br>Refer to [sk107817](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107817). |
| 01867540 | Multi-Domain Security Management | Licenses attached to Domain are shown as unattached in SmartUpdate.<br>Refer to [sk104884](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104884). |
| 01626339, 01871531 | Security Management Server, Multi-Domain Security Management Server | The _fwm_ daemon cannot start due to the size of _$FWDIR/tmp/fwmtrace.log_ file reaching 2GB limit.<br>Refer to [sk105579](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105579). |
| 01732223, 01863656 | Security Management Server | Policy verification fails abnormally on R77.30 Security Management Server.<br>Refer to [sk107182](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107182). |
| 01858483 | Security Management Server | " _Multiple account units are using the same domain name_" warning during security policy installation.<br>Refer to [sk104248](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104248). |
| 01864379, 01850825 | Security Management Server | IPS scheduled update fails with " _Failed to create db revision_".<br>Refer to [sk108382](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108382). |
| 01875570, 01827950 | VPN | Not possible to force a minimal allowed _Endpoint Security Client_ version for Remote Access connection<br>(Note: Does not apply to Endpoint Connect Clients).<br>Refer to instructions in [sk108192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192). |
| 01749088, 01782611, 01875953 | Anti-Virus | High memory utilization on Security Gateway during Anti-Virus scan of large files transferred over HTTP.<br>Refer to [sk107384](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107384) and [sk108192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108192). |
| Take 75 (12 Nov 2015) |
| 01848714 | SecureXL | Output of " _fwaccel stat_" command shows:<br>`Accelerator Status : off by Firewall (too many general errors (NUMBER) (caller: Name_of_Function))`.<br>Refer to [sk100467](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100467) (Scenario 3 - "UDP traffic causes too many general errors"). |
| 01848202, 01850540 | SecureXL | Check Point 21000 series appliance with SAM card might crash while handling fragmented TCP packets.<br>Refer to [sk108589](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108589). |
| 01845461, 01853546 | SecureXL | Check Point 21000 series appliance with SAM card might crash during policy installation.<br>Refer to [sk108643](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108643). |
| 01847635 | SecureXL | Check Point 21000 series appliance with SAM card might crash due to removal of Layer 2 header by SAM card.<br>Refer to [sk108652](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108652). |
| 01820185, 01847696 | Multi-Domain Security Management Server | _mds\_backup_ procedure is stuck at " _Releasing all databases_" stage.<br>Refer to [sk107862](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107862). |
| 01857577 | VPN | Some VPN clients are not able to connect to Security Gateway because kernel table " _ccc\_sessions_" fills up very rapidly.<br>Refer to [sk105721](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105721). |
| 01831743, 01842525 | Identity Awareness | Policy installation on Identity Awareness Gateway fails randomly.<br>Refer to [sk108290](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108290). |
| 01811956 | Mobile Access, SSL Network Extender | Added support for Windows 10 in:<br>- SSL Network Extender (SNX) - both Network Mode and Application Mode<br>Refer to [sk107132](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107132). |
| 01850215 | SSL Network Extender | Added support for Mac OS X 10.11 in:<br>- SSL Network Extender (SNX) - both Network Mode and Application Mode<br>Refer to [sk107973](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107973). |
| 01736812 | Gaia OS | Following cluster failover, the _routed_ daemon sends OSPF "Hello" packets with no DR/BDR.<br>Refer to [sk105169](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105169). |
| 01844830 | Gaia OS | - " _Gaia Web-UI recognized a non-valid input data_" error in Gaia Portal when adding SNMP Trap receiver<br>- " _NMSSNM0025 Community names cannot contain spaces or special characters_" error in Gaia Clish when adding SNMP Trap receiver<br>Now, the dollar sign "$" is accepted as well in SNMP Community.<br>Refer to [sk107513](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107513) (Scenario 2 "Adding SNMP Trap receiver in Gaia Portal"). |
| 01787201; 01831464; 01827496; 01818312 | Gaia OS | Enhancement in authentication for SNMPv3 USM user on Gaia OS:<br>- "Authentication Protocol" for SNMPv3 USM user can be set to either **MD5**, or **SHA1**<br>- Interactive configuration of "Privacy Protocol" and "Authentication Protocol" in Clish<br>- When adding new SNMPv3 USM user:<br>  <br>  <br>  - If no "Privacy Protocol" is specified, then "DES" will be set by default<br>  - If no "Authentication Protocol" is specified, then "MD5" will be set by default<br>- "Privacy Protocol" for Read-Write users will be displayed only if those users were defined with Security Level "AuthPriv" (just like for Read-Only users)<br>- Configuration of "Privacy Protocol" and "Authentication Protocol" in Clish was improved to be case-insensitive<br>Refer to [sk90860](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk90860#Advanced%20SNMP%20configuration%20-%20Configure%20SNMPv3%20users%20to%20use%20SHA%20/%20AES%20authentication) \- section " _(IV-5) Advanced SNMP configuration - Configure SNMPv3 users to use SHA / AES authentication_". |
| 01843846 | Gaia OS | " _Could not resolve 'Sensor' within the trap 'Trap'_" errors in Spectrum CA when importing Check Point ' _GaiaTrapsMIB.mib_' file.<br>Refer to [sk97410](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk97410). |
| 01702566 | Gaia OS | OSPF might break upon fail-over in cluster on Gaia OS.<br>Refer to [sk108655](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108655). |
| 01835145 | Cluster | ClusterXL in High Availability mode fails over during policy installations due to missing CUL remote freeze notification.<br>Refer to [sk106576](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106576). |
| 01834555 | Appliances | Outputs of " _show sysenv all_" and " _cpstat os -f power\_supply_" commands show different status for Power Supply units.<br>Refer to [sk107672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107672). |
| 01750204, 01842632 | VSX | Clients behind a Virtual System configured as Non Transparent HTTP/HTTPS Proxy are not able to connect to any site.<br>Refer to [sk107313](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107313). |
| 01730708, 01847073 | HTTPS Inspection | Added ability to control support for SSLv2 handshake in HTTPS Inspection.<br>Refer to [sk108654](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108654). |
| Take 67 (29 Oct 2015) |
| 01829460 | SecureXL | ADP monitor hangs and crashes with " _ADP slot N possibly hung_" on Check Point appliance with SAM card. |
| 01801032, 01829886 | CoreXL | Issues with traffic passing through Security Gateway with enabled CoreXL Dynamic Dispatcher.<br>Refer to [sk108432](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108432). |
| 01751483 | Mobile Access | User is sometimes asked to re-authenticate when accessing web application in Mobile Access Portal.<br>Refer to [sk107314](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107314). |
| 01815100 | VSX, Mobile Access | Backup (scheduled or manual) on VSX Gateway fails while File Shares are open for Mobile Access users: " _not enough space in /var/log/CPbackup/backups_".<br>Refer to [sk106046](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106046). |
| Take 63 (20 Oct 2015) |
| 01825587 | VSX | The _fwk_ daemon crashes during boot of VSX Cluster member with configured Bond interface(s), on which VLAN interfaces are defined. |
| 01817941, 01812866 | Security Management Server, Multi-Domain Security Management Server | False alerts in SmartEvent GUI / SmartView Monitor about low disk space on Security Gateway.<br>Refer to [sk106040](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106040). |
| 01823793 | Cluster | IPv6 static route in Gaia OS with "ping" option fails to send ping in a ClusterXL with IPv6 Virtual IP.<br>Refer to [sk106572](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106572). |
| 01685521 | Anti-Spam | _in.emaild.mta_ process crashes when overloaded with Anti-Spam block. <br>Refer to [sk106240](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106240). |
| 01826612 | Gaia OS | Output of _top_ command on an Open Server shows that _kipmi0_ daemon consumes CPU at 100%.<br>Refer to [sk104316](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104316). |
| 01825932 | Gaia OS | Custom changes made to the _/etc/cpshell/log\_rotation.conf_ file following [sk36798](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk36798), do not survive Jumbo hotfix installation - after installation it goes back to the default. |
| Take 61 (30 Sep 2015) |
| 01752513, 01752529, 01752531 | Security Gateway | Misconfiguration of "Management" interface on Check Point Security Gateway causes outage.<br>Refer to [sk106447](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106447). |
| 01801629, 01811077 | Security Management Server, Multi-Domain Security Management Server | " _Warning: Rule <N> contains a domain object. It will not be enforced by IPv6 policy._" during policy verification refers to wrong rule number.<br>Refer to [sk107601](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107601). |
| 01813036 | SmartEvent | When using send report by mail ('Reports' tab - Report name - Manage - Email Setting - Send By Mail), the SmartEvent sends 'HELO localhost' and gets blocked by the SMTP server.<br>Refer to [sk105279](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105279). |
| 01769402, 01803573 | SecureXL | " _cphwd\_pslglue\_can\_offload\_template: error, psl\_opaque is NULL_" error appears repeatedly in _/var/log/messages_ file after upgrade to R77.30.<br>Refer to [sk107258](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107258). |
| 01814997 | Gaia OS | " _Loading..._" message is stuck in Gaia Portal when trying to open the '`Snapshot Management`', '`System Backup`' or '`Status and Actions`' page after installing a Hotfix / Jumbo Hotfix.<br>Refer to [sk111167](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111167) (Scenario 5 - "Maintenance - Snapshot Management" page and "Maintenance - System Backup" page is stuck at "Loading..." after installing a Hotfix). |
| 01817116 | Gaia OS | _/etc/snmp/userDefinedSettings.conf_ file on Gaia OS (see [sk90860](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk90860)) is overwritten during a hotfix installation.<br>Refer to [sk107861](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107861). |
| 01820060 | Gaia OS | A snapshot image cannot be deleted in Gaia Portal - after clicking on the 'Delete' button (on 'Maintenance' pane - 'Snapshot Management' page), the "Loading..." message is stuck.<br>Refer to [sk111167](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111167) (Scenario 8 - "Maintenance - Snapshot Management" page is stuck at "Loading..." when trying to delete a snapshot). |
| 01693582 | VPN, Mobile Access | Memory leak in the _vpnd_ daemon when Mobile Access blade is enabled. |
| 01736208, 01817908 | Mobile Access | Web Form SSO with configured login page does not work.<br>Refer to [sk107254](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107254). |
| 01808903 | IPS | IPS related kernel tables are kept in memory even when disabled in a later policy, causing table duplication and a memory leak. Leak may lead to an error message " _reached the maximum number of ghtabs_" and install policy failure. |
| 01802551, 01809183 | CoreXL, VSX | Creating a Virtual System with one CoreXL FW instance might end with an error and cause the VSX Gateway / VSX Cluster member to crash with kernel core dump. |
| 01704012, 01720219 | CoreXL | VoIP traffic (or traffic that uses reserved VoIP ports) is interrupted / stops passing after enabling CoreXL Dynamic Dispatcher per [sk105261](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105261).<br>Refer to [sk106665](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106665). |
| Take 54 (07 Sep 2015) |
| 01787367 | Security Gateway | Failure in QoS policy installation can cause Security Gateway to crash during the next network policy installation. |
| 01747684 | Gaia OS | PIM SM: multicast traffic received on an interface, which is in non-DR, but assert winner state is not processed by Security Gateway.<br>Refer to [sk107186](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107186). |
| 01800253 | Gaia OS | Output of Clish command " _show asset memory_" shows less RAM than is actually installed on Check Point appliance.<br>Refer to [sk107032](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107032). |
| 01803002 | Gaia OS | The following commands were added to Gaia Clish:<br>- _show lom_ \- displays LOM card IP address and firmware version<br>- _show lom ip-address_ \- displays LOM card IP address<br>- _show lom version_ \- displays LOM card firmware version |
| 01803039 | Gaia OS | Not able to log in to Gaia OS with username authenticated by TACACS. |
| 01803024 | Gaia OS | Improved support for multiple roles defined on RADIUS server that are separated by space character (e.g., _CP-Gaia-User-Role="rwRole, roRole"_) |
| 01803483 | Gaia OS | Added the ability to get the comment defined on an interface in Gaia OS via SNMP Request by querying the OID _IF-MIB::ifAlias_ (in case _ifXtable.ifAlias_ field is empty).<br>Refer to [sk107615](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107615). |
| 01803493; 01803506 | Gaia OS | After enabling the SNMP Trap "coldStart" in Gaia OS, it is sent every time the SNMP Agent (the _snmpd_ daemon) is started, regardless of the current system up-time.<br>Refer to [sk107616](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107616). |
| 01717878 | Cluster | Output of " _cpstat ha -f all_" command shows status of some VLAN interfaces as " _Partially up_".<br>Refer to [sk106488](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106488). |
| 01801408, 01699396 | Cluster | Both the VRRP Master and VRRP Backup members in Gaia VRRP cluster respond to ARP Requests for Proxy ARP entries (configured per [sk30197](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30197)).<br>Refer to [sk107614](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107614). |
| Take 49 (24 Aug 2015) |
| 01783813 | VPN | Improved specific debug message. |
| 01745911 | Mobile Access | Kerberos does not work for Secure Mail (e.g., Exchange Web Services (EWS) mail app). |
| 01710533, 01732329 | Mobile Access | " _Error while processing the request_" occasional error in SSL Portal Web Application after clicking on the Back button / Home button / repeatedly pressing F5 key. During the issue, SSL Portal stops responding and mobile users are disconnected.<br>Refer to [sk107454](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107454). |
| 01749317 | Gaia OS | Gaia configuration commands are not saved sorted in way that guarantees continuation when loading them.<br>Refer to [sk107286](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107286). |
| 01779716 | Gaia OS | Not able to log in to Gaia Portal anymore after running Clish command " _show user <username> homedir_".<br>Refer to [sk106427](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106427). |
| 01778888 | Gaia OS | _/var/log/messages_ file on Gaia OS repeatedly shows:<br>`xpand[PID]: image_mgmt_get_version: version was get from registry major=[X] minor=[.Y]<br>xpand[PID]: version is X.Y`<br>Refer to [sk109038](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk109038). |
| 01692050, 01709890, 01693135 | Gaia OS | " _This page is currently in read only mode, the requested action cannot be performed_" message appears in Gaia Portal when logging in with the TACACS+ user and clicking on the " _Enable TACACS+ authentication_" button at the top.<br>Refer to [sk106324](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106324). |
| 01707909 | HTTPS Inspection | HTTPS Inspection drops traffic to a web site that uses untrusted server certificate even when the "Untrusted server certificate" is disabled.<br>Refer to [sk107288](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107288). |
| 01749545 | VPN | IKE negotiation fails at Main Mode packet 5 between Security Gateway and DAIP non-Centrally Managed Gateway.<br>Refer to [sk104880](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104880). |
| 01745741, 01746482, 01780378 | Security Gateway | Security Gateway might crash in some scenarios when inspecting H.323 traffic.<br>Refer to [sk107184](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107184) and to [sk106994](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106994). |
| 01718196, 01721499, 01721502, 01782570 | Security Management Server, Multi-Domain Security Management Server | Policy Verification fails to find overlapping rules.<br>Refer to [sk106854](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106854) and to [sk106994](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106994). |
| 01784203, 01784730, 01784728, 01787564 | Security Management Server, Multi-Domain Security Management Server | Policy Verification fails with " _Diameter rule service's check: Failed to flatten services list_".<br>Refer to [sk107322](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107322) and to [sk106994](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106994). |
| 01749879 | Security Management Server, Multi-Domain Security Management Server | After policy installation, traffic that was supposed to be matched on specific "accept" rule is dropped on the Clean Up rule (issue is caused by a corruption in one of the policy files). |
| Take 45 (06 Aug 2015) |
| 01713997 | Gaia OS | Gaia OS _syslogd_ daemon and Check Point _syslog_ daemon can not run simultaneously on Security Management Server / Domain Management Server / Log Server on Gaia OS in the following scenario:<br>- " _Accept Syslog messages_" is enabled in the properties of Management Server / Log Server object (SmartDashboard - object properties - " _Logs_" menu - " _Additional Logging Configuration_").<br>- Gaia OS on Management Server / Log Server is configured to forward the received syslog messages to another Syslog server (Gaia Portal - " _System Management_" pane - " _System Logging_" \- click on " _Add_" \- enter the IP address of another Syslog server).<br>Refer to [sk105580](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105580). |
| 01708195, 01708998 | Gaia OS | " _show asset network_" command does not display all installed cards on Check Point appliance.<br>Refer to [sk106785](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106785). |
| 01727625, 01730966 | VPN | " _vpn debug on TDERROR\_ALL\_ALL=5_" command does not update the previously set debug flags.<br>Refer to [sk107172](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107172). |
| 01731020 | VPN | Improved a print out of " _GwSupportCrashRec_" debug messages in debug of the _vpnd_ daemon. |
| 01619868, 01725472 | Security Management Server, Multi-Domain Security Management Server | Installing policy on R77.X Security Gateway(s) _**and**_ UTM-1 Edge device(s) at the same time might fail during Policy Compilation with the following error:<br>`cpp: line N, Error: Inside #ifdef block at end of input, depth = X<br>1 error in preprocessor`<br>Refer to [sk105488](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105488). |
| 01732552 | Security Management Server, Multi-Domain Security Management Server | " _install/uninstall has been improperly terminated_" error when trying to Install Database.<br>Refer to [sk104998](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104998). |
| 01595501 | Mobile Access | A Mobile device, which is known to be non-compliant, is still able to connect with Mobile VPN / Capsule Connect app to Mobile Access Gateway, and SmartView Tracker log shows this device as compliant.<br>This mobile device had to be checked for compliance by an MDM vendor based on the _$FWDIR/conf/mdm.conf_ file on Mobile Access Gateway.<br>**Important Note:** You must manually edit the _$FWDIR/conf/mdm.conf_ file on Mobile Access Gate - add the following section at the bottom of the file to block the Dummy MAC address "02:00:00:00:00:00":<br>```<br>:custom_macs ( <br>    :020000000000 ("block") <br>)<br>```<br>Refer to [sk107207](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107207). |
| Take 43 (27 July 2015) |
| 01605509 | VPN | Windows 8.1 VPN plugin can connect, but user is unable to reach resources behind the VPN Gateway.<br>Refer to [sk104619](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104619). |
| 01702733 | Mobile Access | The " _cvpnd\_settings_" command crashes when used without full path.<br>Refer to [sk106673](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106673). |
| 01715981 | Gaia OS | Clish on Gaia OS crashes with " _Segmentation fault_" when running " _show configuration user_" command.<br>Refer to [sk101974](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101974). |
| 01722085 | Anti-Bot, Anti-Virus | CPU load and traffic latency after activating Anti-Bot and/or Anti-Virus blade on Security Gateway (especially for complex traffic like CIFS, NFS).<br>Refer to [sk106062](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106062). |
| 01717808, 01647153 | Security Gateway, Cluster | " _fw\_getifs: filter interface <interface\_name> - no IP_" message appears for every interface when running " _fw getifs_" command under " _TDERROR_" debug, although those interfaces have an IP address assigned.<br>Refer to [sk106856](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106856). |
| 01692246 | Cluster | Cluster members crash simultaneously when running kernel debug of Delta Sync ('`fw ctl debug -m fw + sync`') and IPv6 traffic is passing through the cluster, which is inspected by IPS (PSL).<br>Refer to [sk106571](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106571). |
| 01705870 | Security Management Server, Multi-Domain Security Management Server, SmartProvioning | SmartView Tracker displays ROBO gateways / Edge devices managed by SmartProvisioning in the "Origin" column as Device ID "0.0.0.X" instead of the Device real IP address.<br>Refer to [sk106966](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106966). |
| Take 33 (16 July 2015) |
| 01703881; 01704019; 01704130; 01704076 | All | Check Point response to CVE-2015-2808 (Bar Mitzvah) and OpenSSL CVE-2015-1789.<br>Refer to [sk106499](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106499). |
| 01678465, 01709620 | VPN, DLP, Security Management Server, Multi-Domain Security Management Server | Policy installation might fail with " _ERROR: stab identifier <lsv\_profiles> for host redefined_" in the following scenario:<br>1. R77.30 Security Management Server running on Gaia OS or IPSO OS.<br>2. There are two R77.x Security Gateways / Clusters (e.g., "GW\_1" and "GW\_2") managed by this server:<br>   <br>   <br>   - "GW\_1" has IPSec VPN blade enabled<br>   - "GW\_2" has DLP blade enabled, IPSec VPN blade disabled, and belongs to VPN Encryption Domain of "GW\_1"<br>Refer to [sk106196](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106196). |
| 01705404 | SecureXL | 21000 appliance with SAM card might reboot in a loop after configuring a Bond interface on 10Gb card ports. |
| 01710137 | Security Gateway | Issues with traffic and with web pages when Security Gateway is configured in Proxy Non-Transparent mode.<br>Refer to [sk106663](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106663). |
| 01709135 | Security Gateway | If Security Gateway is configured as HTTP/HTTPS Proxy, then unloading of the Check Point kernel modules might fail with the following errors when running kernel memory leak detection per [sk35496](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk35496):<br>` [Expert@HostName:0]# cpstop<br> ... ... ...<br> [Expert@HostName:0]# service cpboot stop<br> ... ... ...<br> [Expert@HostName:0]# cpstop -fwflag -driver<br> ... ... ...<br> ERROR: Module fw_0 is in use<br> FireWall-1: failed to remove IPv4 module<br> cpstop error: Failed to execute fwstop -f . Please check fwflag syntax -driver` |
| 01711501 | Mobile Access | Connection to Citrix through Mobile Access fails if Citrix is configured to use HTML 5.<br>Refer to [sk106574](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106574). |
| 01695987, 01704522 | Gaia OS | Scheduled Gaia backup in R77.30 fails to transfer backup file to remote server.<br>Refer to [sk106647](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106647). |
| 01522914, 01683799 | Security Management Server, Multi-Domain Security Management Server | The _fwm_ daemon frequently crashes due to memory leak on the Security Management Server (triggered when a Security Gateway with Dynamic IP address is monitored in SmartView Monitor and an IP address is changed on that DAIP Security Gateway). |
| 01710257 | IPS | IPS Exception with Protection "ANY" does not work.<br>Refer to [sk105074](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105074). |
| 01697239 | Cluster | SmartView Monitor shows the status of cluster interfaces as " _Partially up_" (in the upper pane, click on the cluster member object - in the lower pane, go to section "ClusterXL" - click on "More..." - refer to the "Interface table").<br>Refer to [sk106488](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106488). |
| Take 18 (01 July 2015) |
| 01594658 | Gaia OS | Different number of IPv6 neighbors is shown in Expert mode and in Gaia Clish:<br>- In Expert mode, output of command " _ip -6 neighbour show_" shows all expected IPv6 neighbors.<br>- In Gaia Clish, output of command " _show neighbor dynamic-table_" shows up to 50 IPv6 neighbors.<br>Refer to [sk106622](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106622). |
| 01681589, 01688680 | SecureXL | Improved memory training logic for "SAM-108-V2" card (memory training is a task performed by the hypervisor to get a sense of the timing necessary for the pins out of the memory controller on the card's processor to achieve maximum throughput to the onboard DIMMs while maintaining reliability). |
| 01690456 | Mobile Access | Added ability to force Kerberos authentication (instead of NTLM) against Capsule Workspace Mail application and Web applications. |
| 01690471 | Mobile Access | The _cvpnd_ daemon crashes when the user/application calls for two factor authentication in Mobile Access Portal using SMS, but the user has no phone number defined. |
| 01690589 | Mobile Access | Added support for Citrix Connection floating bar in Internet Explorer browser when connecting to Citrix Server through external interface on Mobile Access gateway. |
| Take 17 (18 June 2015) |
| 01685651, 01693669; 01688883, 01694383 | SecureXL, Security Management Server / Multi-Domain Security Management Server | Output of " _fwaccel stat_" command on R77.30 Security Gateway / Cluster members shows that Accept Templates are _not_ disabled starting from the expected rule (per [sk32578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk32578)).<br>Problematic scenario (issue occurs _only if all_ these conditions are met):<br>1. **R77.30** Security Management Server / Multi-Domain Security Management Server with installed **R77.30 Add-On**<br>   <br>   (either cleanly installed R77.30 with R77.30 Add-on, or upgraded to R77.30 from R77.20 with R77.20 Add-on).<br>2. Involved rulebase is installed on **R77.30** Security Gateway / Cluster members.<br>3. SecureXL is enabled on R77.30 Security Gateway / Cluster members.<br>4. Involved rulebase contains rules, starting from which SecureXL Accept Templates should not be created anymore (per [sk32578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk32578)) \- e.g., rules for FTP/ICMP traffic, rules with Dynamic objects.<br>5. Involved rulebase contains a rule with service " _**dhcp-request**_" and/or service " _**dhcp-reply**_" (refer to [sk98839](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98839)) and this rule is located _above_ all other rules, which disable SecureXL Accept Templates. |
| 01692710 | Security Gateway | Connectivity issues through Security Gateway in Proxy mode due to an extra space in DNS Query sent by the Security Gateway.<br>Refer to [sk106428](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106428). |
| 01685214, 01693432 | Anti-Virus | Memory consumption on Security Gateway with enabled Anti-Virus blade increases during inspection of CIFS traffic.<br>Refer to [sk106334](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106334). |
| 01668422 | Mobile Access, Security Management Server / Multi-Domain Security Management Server | Policy installation succeeds even if Mobile Access rules contain only services that are not supported by Native Applications - such as Compound TCP and Citrix TCP types.<br>Refer to [sk106502](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106502). |
| 01647109 | Security Management Server, Multi-Domain Security Management Server | SmartView Tracker does not show successful "Log In" or "Log Out" Audit logs for SmartLog GUI.<br>Refer to [sk105881](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105881). |
| 01688838 | Security Management Server, Multi-Domain Security Management Server | Obfuscated information in Application Control/URL Filtering mail alerts - printing \*\*\*\*\*\* instead of real information.<br>Refer to [sk106430](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106430). |
| 01568620 | SmartView Monitor, VPN | SmartView Monitor shows "no data" in tunnel information under "Tunnels on gateway" for R77.20 / R77.30 gateways using Traditional Mode VPN.<br>Refer to [sk104103](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104103). |
| Take 15 (16 June 2015) |
| 01688001 | Mobile Access | Ability to override the [sk102989 - Check Point response to the POODLE Bites vulnerability (CVE-2014-3566)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102989) using the " _CvpnEnableSSLv3_" directive to allow Mobile Access gateway to connect to internal application servers over SSLv3 (connection from outside to Mobile Access gateway is still over TLS).<br>To allow internal connection over SSLv3:<br>1. In the _$CVPNDIR/conf/httpd.conf_ file, add the following lines:<br>   <br>   _\# This directive overrides the hotfix sk102989 - POODLE Bites (CVE-2014-3566)_<br>   <br>   _\# and allows access from Mobile Access gateway to internal application servers over SSLv3_<br>   <br>   _CvpnEnableSSLv3 On_<br>2. Reload the Mobile Access policy:<br>   <br>   _\[Expert@HostName:0\]# cvpnd\_admin policy_ |
| 01681471 | Mobile Access | " _Authentication Failure_" error when launching SNX via Mobile Access Portal using an LDAP user account with OU path that includes asterisk "\*" (wildcard) character.<br>Refer to [sk106299](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106299). |
| 01581791 | SmartReporter | A new consolidation database table does not appear in SmartReporter GUI - 'Database Maintenance' tab - 'Tables' tab.<br>Refer to [sk104842](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104842). |
| 01599078 | SmartReporter | " _No data available for \[SmartReporter\]_" error in reports.<br>Refer to [sk102007](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102007). |
| 01626310 | SmartView Monitor | E-mail alerts from SmartView Monitor arrive with MIME boundary headers " _\_NextPart\_.._".<br>Refer to [sk105578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105578). |
| 01666230 | SmartDashboard | Security Management Server that was configured to forward local log files to a Log Server without deleting them per sk106039, forwards all existing local log files instead of forwarding only the new log files that were created since the last scheduled forwarding event (i.e., also all those local log file that were already forwarded during the past scheduled forwarding events).<br>Refer to [sk106039](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106039). |
| 01607383 | Security Gateway | Kernel panic on Security gateway due to memory access violation. |
| 01594559 | Security Gateway | HTTP traffic with non-common HTTP methods does not pass through Security Gateway configured as Proxy.<br>Refer to [sk104887](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104887). |
| 01621272 | Gaia OS | " _syntax error_" when adding an interface to the redistribution of routes in Gaia OS.<br>Refer to [sk105643](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105643). |
| 01621251; 01621253 | Cluster | Gratuitous ARP Request packets (GARP) are not sent during cluster fail-over for IP addresses configured in the _$FWDIR/conf/local.arp_ file (per [sk30197](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30197)), if those IP addresses and Cluster VIP address are on different subnets.<br>Refer to [sk105645](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105645). |
| 01614571 | Cluster | TCP state logs are sent from all cluster member instead of only the active member.<br>Refer to [sk101221](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101221). |
| 01596291 | SecureXL | SecureXL Accept Templates not created when ISP Redundancy is enabled in Primary/Backup mode.<br>Refer to [sk104679](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104679). |
| 01619159 | VoIP | SIP Call Transfer stopped working after upgrade to R77.20 / R77.30.<br>Refer to [sk105564](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105564). |
| 01607850 | Identity Awareness, Application Control | Security Gateway might crash when Identity sharing and Application Control rules (with access roles) are configured.<br>Refer to [sk106420](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106420) and to [sk106994](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106994). |
| 01605254 | DLP | DLP fingerprint scan failure on Full HA cluster.<br>Refer to [sk105157](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105157). |
| 01692002 | DLP, Threat Emulation | Downloaded file might be bypassed instead of being blocked by DLP in the following scenario:<br>- DLP blade is enabled.<br>- Threat Emulation blade is enabled.<br>- Threat Emulation Connection Handling Mode is set to " _Background_"<br>- Threat Prevention Engine Fail Mode is set to " _Allow all connections (Fail-open)_"<br>Refer to [sk106421](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106421). |

## List of resolved issues in the Ongoing Take

These fixes were added on top of the latest General Availability Take.

Enter the string to filter this table:

|     |     |     |
| --- | --- | --- |
| ID | Product | Description |
| Take 351 (02 Jul 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T351\_FULL.tgz |
| PRJ-2376,<br>PRJ-2358 | Gaia OS | CVE-2019-11477, CVE-2019-11478 & CVE-2019-11479: TCP SACK PANIC - Linux Kernel vulnerabilities. Refer to [sk156192](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk156192). |
| PRJ-1330,<br>02541089 | SecureXL | Resolved issue in multicast routing lookup. |
| PMTR-27365,<br>IDA-1609 | Identity Awareness | In some scenarios, the Identity Agent fails to authenticate using Kerberos SSO due to very large Kerberos ticket, and the agent fallsback to User/Password authentication. Refer to [sk145832](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk145832). |
| PRJ-366,<br>PMTR-33177 | Identity Awareness | In some scenarios, when using Load Sharing, upon the same IP address used by two different users, users may be able to access or to be restricted from accessing resources without proper roles. |
| Take 348 (24 Apr 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T348\_FULL.tgz |
| IDA-1689,<br>PMTR-31034 | Identity Awareness | Removed unnecessary identity update, during Identity Agent or Terminal Server Agent IP address change, that results in corruption of PEP database. |
| GAIA-3010,<br>PMTR-23157 | Gaia OS | CVE-2018-15473: Username enumeration is possible due to a premature bail-out while dealing with a malformed packet. The issue exists in several authentication protocols. |
| IDA-1225,<br>PMTR-33364 | Identity Awareness | Fixed possible session corruption on PDP side that could lead to unexpected behavior. |
| Take 347 (27 Mar 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T347\_FULL.tgz |
| PMTR-26171,<br>PMTR-26174 | SSL Inspection | Changed SSL Network Extender on MacOS to 64-bit architecture to support 32 bit apps depreciation in OSX. |
| PMTR-35032,<br>PRJ-99 | VPN | Important security update for IPSec Site-to-Site (S2S) VPN. |
| Take 346 (13 Feb 2019)<br>CPUSE Identifier: Check\_Point\_R77\_30\_JUMBO\_HF\_1\_Bundle\_T346\_FULL.tgz |
| 02468036 | UserCheck | Improved stability when Push Notifications are enabled on Mobile Access blade. |
| 02657434 | VPN | Improved connectivity with 3rd party VPN peers using IKEv2. Refer to [sk120835](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120835) |
| 02100804 | VPN | After Cluster failover, VPN tunnel is down and "Unknown SPI for IPsec packet" log is shown. Refer to [sk112339](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112339). |
| PRHF-608 | SecureXL | Improved stability of VSX gateway when under heavy load when SecureXL is enabled. |
| JPMC-284 | SecureXL | Improved stability of SAM card when running multicast jumbo traffic packets. |
| JPMC-316 | SecureXL | Improved stability of SAM card when PIM is configured in Sparse Mode on its interfaces. |

## Installation instructions

**Important Notes:**

- **This Jumbo Hotfix Accumulator has to be installed only after successful completion of Gaia First Time Configuration Wizard and _reboot_.**
- **Before installing this Jumbo Hotfix Accumulator, back up any configuration file that was edited manually**.

List of the most important files (many others exist):

- `$FWDIR/boot/modules/fwkern.conf`
  - `$FWDIR/boot/modules/vpnkern.conf`
  - `$PPKDIR/boot/modules/simkern.conf`
  - `$PPKDIR/boot/modules/sim_aff.conf`
  - `$FWDIR/conf/fwaffinity.conf`
  - `$FWDIR/conf/local.arp`
  - `$FWDIR/conf/discntd.if`
  - `$FWDIR/conf/cphaprob.conf`
  - `$FWDIR/conf/cpha_bond_ls_config.conf`
  - `$FWDIR/conf/fwauthd.conf`
  - `$FWDIR/conf/resctrl`
  - `$FWDIR/conf/vsaffinity_exception.conf`
  - `$FWDIR/database/qos_policy.C`
  - `/var/ace/sdconf.rec`
  - `/var/ace/sdopts.rec`
  - `/etc/snmp/snmpd.conf`
  - `/etc/snmp/userDefinedSettings.conf`
  - `/etc/snmp/vsx-proxy/snmpd.vsx.proxy.conf`
  - `/etc/snmp/snmpmonitor.conf`
- It is _**not**_ supported to install this Jumbo Hotfix Accumulator using the [ISOmorphic Tool](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk65205).
- In cluster environment:

Jumbo Hotfix Accumulator must be installed on all members of the cluster. To assure synchronization without losing connectivity, cluster administrator should use either [Optimal Service Upgrade](https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/129990) (OSU) method, or [Connectivity Upgrade](https://sc1.checkpoint.com/documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/html_frameset.htm?topic=documents/R77/CP_R77_Gaia_Installation_and_Upgrade_Guide/129990) (CU) method. For additional information and limitations, refer to [sk107042 - ClusterXL upgrade methods and paths](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107042).
- In Management HA environment:

Jumbo Hotfix Accumulator must be installed on both Management Servers.
- On Multi-Domain Security Management Server:

Note: To check the current Take number, run the "`installed_jumbo_take`" command.

- When running Take 205 and higher of this Jumbo Hotfix Accumulator:

Higher Take can be installed over the current Take.
  - When running Take 198 and lower of this Jumbo Hotfix Accumulator:

_**Before**_ installing a higher Take, the current Take _**must**_ be uninstalled (refer to section "Uninstall instructions" \- "Show / Hide instructions for uninstall of Jumbo Hotfix Accumulator Take 198 and lower on Multi-Domain Security Management Server").
- On VSX Gateways:

Jumbo Hotfix Accumulator should be installed only using [CPUSE in Clish](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE) (requires the latest build of [CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New)).
- For _Smart-1 405 / 410 appliances_:

It is necessary to install _Take\_266_ and higher (refer to [sk117578](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117578)).
- For _15000 / 23000 appliances with 40 GbE_ cards:

It is necessary to install _Take\_162_ and higher (refer to [sk112517](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk112517)).
- On _21000 appliances with SAM card_:

Due to specific stability issues, Take 210, Take 213 and Take 216 should _**not**_ be installed (refer to [sk116070](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116070)).
- It is recommended to install Jumbo Hotfix Accumulator on **all the R77.30 machines in the environment - Security Gateways / Management Servers / etc. running on Gaia OS**.
- Installation of a newer Take of Jumbo Hotfix Accumulator on top of the current Take (refer to [sk107320](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107320)):

- When running [CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New) build 1127 and higher:

- If the previous Take of Jumbo Hotfix Accumulator was installed using Legacy CLI, then the next Take _can be_ installed using the CPUSE.
    - If the previous Take of Jumbo Hotfix Accumulator was installed using CPUSE, then all subsequent Takes _must_ also be installed using CPUSE.
  - When running [CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New) build 1005 and lower ( _users should upgrade to the latest build_):

All Takes of Jumbo Hotfix Accumulator must be installed in the same way:

- If the Jumbo Hotfix Accumulator was installed for the first time using CPUSE, then all subsequent Takes _must_ also be installed using CPUSE.
    - If the Jumbo Hotfix Accumulator was installed for the first time using Legacy CLI, then all subsequent Takes _must_ also be installed using Legacy CLI.

**Procedure:**

- **Show / Hide instructions for installation in Gaia Portal - using CPUSE (Check Point Update Service Engine)**

**Note:** You can also use the [sk111158 - Central Deployment Tool (CDT)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111158) to install this Jumbo Hotfix Accumulator on Security Gateways.

For detailed installation instructions, refer to [sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE) \- section " _(4) How to work with CPUSE_".

- **Online installation for _Latest Ongoing Take_**
    1. [CPUSE Software Updates Policy](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE%20-%20Additional%20How%20To) should be configured to allow self-update of CPUSE Agent.

Otherwise, users should manually install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New).
    2. Connect to the Gaia Portal on your Check Point machine and navigate to _**Upgrades (CPUSE)**_ section - click on _**Status and Actions**_.
    3. In the upper right corner, click on the _**Add hotfixes from the cloud**_ button in the upper right corner.
    4. Paste the CPUSE Identifier and start the search

Note: [Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get the CPUSE Identifier.
    5. When the package is found, click on the link to add the package to the list of available packages.
    6. Select the hotfix package - click on _**More**_ button on the toolbar - click on _**Verifier**_ (or right-click on the package and click on _**Verifier**_).
    7. Select the package - click on _**Install Update**_ button on the toolbar.
    8. **Machine will be rebooted automatically**.
  - **Online installation for _General Availability Take_**
    1. [CPUSE Software Updates Policy](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE%20-%20Additional%20How%20To) should be configured to allow self-update of CPUSE Agent.

Otherwise, users should manually install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New).
    2. Connect to the Gaia Portal on your Check Point machine and navigate to _**Upgrades (CPUSE)**_ section - click on _**Status and Actions**_.
    3. Click on the filter button near the help icon and select _**All**_.
    4. Select the hotfix package - click on _**More**_ button on the toolbar - click on _**Verifier**_ (or right-click on the package and click on _**Verifier**_).
    5. Select the package - click on _**Install Update**_ button on the toolbar.
    6. **Machine will be rebooted automatically**.
  - **Offline installation**

**Note:** Either get the offline package from [Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html), or export the package from a source Gaia machine, on which this package was already downloaded / installed (for package export instructions, refer to [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE%20-%20Additional%20How%20To) \- section " _(4-D) "How to ..."_").
    1. Install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New).
    2. Connect to the Gaia Portal on your Check Point machine and navigate to _**Upgrades (CPUSE)**_ section - click on _**Status and Actions**_.
    3. In the upper right corner, click on the _**Import Package**_ button.
    4. In the _**Import Package**_ window, click on _**Browse...**_ \- select the CPUSE package (either offline TGZ file, or exported TAR file) - click on _**Import**_.
    5. Select the imported package - click on _**More**_ button on the toolbar - click on _**Verifier**_ (or right-click on the package and click on _**Verifier**_).
    6. Select the imported package - click on _**Install Update**_ button on the toolbar.
    7. **Machine will be rebooted automatically**.

- **Show / Hide instructions for installation in Gaia Clish - using CPUSE (Check Point Update Service Engine)**

For detailed installation instructions, refer to [sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE) \- section " _(4) How to work with CPUSE_"

- **Online installation for _Latest Ongoing Take_**
    01. [CPUSE Software Updates Policy](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE%20-%20Additional%20How%20To) should be configured to allow self-update of CPUSE Agent.

Otherwise, users should manually install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New).
    02. Connect to command line on Gaia OS.
    03. Log in to Clish.
    04. Acquire the lock over Gaia configuration database:

_**HostName:0> lock database override**_
    05. Import the package from Check Point cloud:

_**HostName:0> installer import cloud <CPUSE Identifier>**_

Note: [Contact Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) to get the CPUSE Identifier.
    06. Show the packages that are available for download:

Note: Refer to the top section " _Hotfixes_" \- refer to " _Jumbo Hotfix Accumulator for ..._"

_**HostName:0> show installer packages available-for-download**_
    07. Verify that this package can be installed without conflicts:

_**HostName:0> installer verify <Package\_Number>**_
    08. Download the package from Check Point cloud:

_**HostName:0> installer download <Package\_Number>**_
    09. Install the downloaded package:

_**HostName:0> installer install <Package\_Number>**_

Note: The progress (in per cent) will be displayed in Clish.
    10. **Machine will be rebooted automatically**.
  - **Online installation for _General Availability Take_**
    01. [CPUSE Software Updates Policy](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE%20-%20Additional%20How%20To) should be configured to allow self-update of CPUSE Agent.

_**HostName:0> lock database override**_
    05. Check the available packages:

Note: Refer to the top section " _Hotfixes_" \- refer to " _Jumbo Hotfix Accumulator for ..._"

_**HostName:0> show installer packages available-for-download**_
    06. Verify that this package can be installed without conflicts:

_**HostName:0> installer verify <Package\_Number>**_
    07. Download the hotfix package from the Check Point Cloud:

_**HostName:0> installer download <Package\_Number>**_
    08. Show the downloaded packages:

_**HostName:0> show installer packages downloaded**_
    09. Install the downloaded package:

_**HostName:0> installer install <Package\_Number>**_

Note: The progress (in per cent) will be displayed in Clish.
    10. **Machine will be rebooted automatically**.
  - **Offline installation**

_**HostName:0> lock database override**_
    06. Import the package from the hard disk:

**Note:** When import completes, this package might be deleted from the original location.

_**HostName:0> installer import local <Full\_Path>/<Package\_File\_Name>.TGZ\_or\_TAR**_
    07. Show the imported packages:

Note: Refer to the top section " _Hotfixes_" \- refer to " _<Package\_File\_Name>_"

_**HostName:0> show installer packages imported**_
    08. Verify that this package can be installed without conflicts:

_**HostName:0> installer verify <Package\_Number>**_
    09. Install the imported package:

_**HostName:0> installer install <Package\_Number>**_
    10. **Machine will be rebooted automatically**.

## Uninstall instructions

**Important Notes:**

- This Jumbo Hotfix Accumulator removes all its packages during uninstall.
- Uninstall of Jumbo Hotfix Accumulator Take (refer to [sk107320](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107320)):

- If a Take of Jumbo Hotfix Accumulator was installed using Legacy CLI, then it _can be_ uninstalled using the CPUSE.
    - If a Take of Jumbo Hotfix Accumulator was installed using CPUSE, then it _must be_ uninstalled using CPUSE.
  - When running [CPUSE Agent](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New) build 1005 and lower ( _users should upgrade to the latest build_):

All Takes of Jumbo Hotfix Accumulator must be uninstalled in the same way as they were installed:

- If a Take of Jumbo Hotfix Accumulator was installed using CPUSE, then it _must be_ uninstalled using CPUSE.
    - If a Take of Jumbo Hotfix Accumulator was installed using Legacy CLI, then it _must be_ uninstalled using Legacy CLI.

**Procedure:**

- **Show / Hide instructions for uninstall in Gaia Portal - using CPUSE (Check Point Update Service Engine)**

1. [CPUSE Software Updates Policy](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How%20to%20work%20with%20CPUSE%20-%20Additional%20How%20To) should be configured to allow self-update of CPUSE Agent.

Otherwise (and if this machine is offline), users should manually install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New).
2. Connect to the Gaia Portal on your Gaia machine and navigate to the _**Upgrades (CPUSE)**_ section - click on _**Status and Actions**_.
3. Above the list of all software packages, click on the _**Showing Recommended packages**_ button - select _**All**_.
4. Right-click on the Jumbo Hotfix Accumulator package - click on _**Uninstall**_.
5. A warning will be displayed that after this uninstall, the machine will be automatically rebooted.

Click on _**OK**_ to start the uninstall.

- **Show / Hide instructions for uninstall in Gaia Clish - using CPUSE (Check Point Update Service Engine)**

Otherwise (and if this machine is offline), users should manually install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New).
2. Connect to command line on Gaia OS.
3. Log in to Clish.
4. Acquire the lock over Gaia configuration database:

_**HostName:0> lock database override**_
5. Uninstall the package:

_**HostName:0> installer uninstall <Package\_Number>**_

Note: The progress (in per cent) will be displayed in Clish.
6. **Machine will be rebooted automatically**.

- **Show / Hide instructions for uninstall of Jumbo Hotfix Accumulator Take 198 and lower on Multi-Domain Security Management Server:**

**Important Note:** When running Take 198 and lower of this Jumbo Hotfix Accumulator, _**before**_ installing a higher Take, the current Take _**must**_ be uninstalled.

Otherwise (and if this machine is offline), users should manually install the latest build of CPUSE Agent from [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#Latest%20build%20of%20CPUSE%20and%20What's%20New).
2. Uninstall the current Take using CPUSE:

1. Connect to the Gaia Portal on your Gaia machine and navigate to the _**Upgrades (CPUSE)**_ section - click on _**Status and Actions**_.
     2. Above the list of all software packages, click on the _**Showing Recommended packages**_ button - select _**All**_.
     3. Right-click on the Jumbo Hotfix Accumulator package - click on _**Uninstall**_.
     4. A warning will be displayed that after this uninstall, the machine will be automatically rebooted.

Click on _**OK**_ to start the uninstall.
3. Remove the references to the "SecurePlatform" package:

1. Connect to the command line.
     2. Log in to Expert mode.
     3. Remove the references from Check Point Registry:

_**\[Expert@HostName:0\]# mdsenv**_

_**\[Expert@HostName:0\]# cp -v $CPDIR/registry/HKLM\_registry.data $CPDIR/registry/HKLM\_registry.data\_BKP**_

_**\[Expert@HostName:0\]# $CPDIR/bin/ckp\_regedit -d //SOFTWARE//CheckPoint//SecurePlatform//6.0//HOTFIX\_R77\_30\_JUMBO\_HF**_

_**\[Expert@HostName:0\]# $CPDIR/bin/ckp\_regedit -d //SOFTWARE//CheckPoint//SecurePlatform//6.0//HotFixes HOTFIX\_R77\_30\_JUMBO\_HF**_
     4. Remove the references from _crs.xml_ file:

_**\[Expert@HostName:0\]# $CPDIR/bin/CRSValidator -l /opt/SecurePlatform/conf/crs.xml -remove R77\_30\_JUMBO\_HF**_

## List of replaced files

List of files replaced by this Jumbo Hotfix Accumulator can be provided upon request by Check Point Support.

## Revision History

Show / Hide revision history

Enter the string to filter this table:

|     |     |
| --- | --- |
| Date | Description |
| 06 Oct 2019 | - General Availability Take 351 |
| 02 Jul 2019 | - Release of Ongoing take 351 |
| 24 Apr 2019 | - Release of Ongoing take 348 |
| 27 Mar 2019 | - Release of Ongoing take 347 |
| 25 Feb 2019 | - General Availability Take 345 |
| 13 Feb 2019 | - Release of Ongoing take 346 |
| 23 Jan 2019 | - Release of Ongoing take 345 |
| 10 Jan 2019 | -  Release of Ongoing Take 344 |
| 26 Dec 2018 | - General Availability Take 342 |
| 17 Dec 2018 | - Release of Ongoing Take 343 |
| 20 Nov 2018 | - Release of Ongoing Take 342 |
| 31 Oct 2018 | - Release of Ongoing Take 339 |
| 16 Oct 2018 | - General Availability Take 338 |
| 20 Sep 2018 | - Release of Ongoing Take 338 |
| 21 Aug 2018 | - Release of Ongoing Take 336 |
| 26 Jul 2018 | - Release of Ongoing Take 331 |
| 10 Jul 2018 | - Release of Ongoing Take 329 |
| 26 Jul 2018 | - Release of Ongoing Take 327 |
| 27 Jun 2018 | - General Availability Take 317 |
| 18 Jun 2018 | - Release of Ongoing Take 322 |
| 11 Jun 2018 | - Release of Ongoing Take 320 |
| 15 May 2018 | - Release of Ongoing Take 317 |
| 26 Apr 2018 | - Release of Ongoing Take 315 |
| 4 Apr 2018 | - Release of Ongoing Take 311 |
| 27 Mar 2018 | - General Availability Take 302 |
| 14 Mar 2018 | - Release of Ongoing Take 310 |
| 26 Feb 2018 | - Release of Ongoing Take 309 |
| 19 Feb 2018 | - Release of Ongoing Take 308 |
| 06 Feb 2018 | - Release of Ongoing Take 302 |
| 16 Jan 2018 | - Release of Ongoing Take 301 |
| 19 Dec 2017 | - General Availability Take 292 |
| 18 Dec 2017 | - Release of Ongoing Take 297 |
| 23 Nov 2017 | - Release of Ongoing Take 294 |
| 08 Nov 2017 | - Release of OngoingTake 292 |
| 24 Oct 2017 | - Release of Ongoing Take 288. |
| 17 Oct 2017 | - Corrected the description of the Issue ID 02351092 in Take 189. |
| 25 Sep 2017 | - General Availability Take 286 is now available in Gaia Portal and Gaia Clish for CPUSE online installation (it replaces General Availability Take\_216). |
| 18 Sep 2017 | - Added the CPUSE Identifier for Ongoing Take 286. |
| 13 Sep 2017 | - Release of Ongoing Take 286. |
| 24 Aug 2017 | - Release of Ongoing Take 282. |
| 16 Aug 2017 | - Release of Ongoing Take 280.<br>- Moved Issue ID 02040869 from Take 156 to Take 280. |
| 27 July 2017 | - Improved installation instructions for CPUSE Offline package in Gaia Portal. |
| 26 July 2017 | - Release of Ongoing Take 272.<br>- Added a note that it is not supported to install this Jumbo Hotfix Accumulator using the [ISOmorphic Tool](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk65205).<br>- Added "`and reboot`" at the end of the note that this Jumbo Hotfix Accumulator has to be installed only after successful completion of Gaia First Time Configuration Wizard. |
| 16 July 2017 | - Added a note that _Take 266_ is not supported on Cluster High Availability configured in Bridge mode. |
| 04 July 2017 | - Added a note that following the integration of support for TLS 1.2, for _Threat Emulation_ customers that do not allow automatic updates from the Check Point Cloud, it is important to update the Threat Emulation Engine according to [sk92509 - Offline updates for Threat Emulation images and engine](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92509). |
| 03 July 2017 | - Release of Ongoing Take 266.<br>- Added a note that support for TLS 1.2 was integrated starting in _Take\_266_. |
| 15 May 2017 | - Added the note to back up any configuration file that was edited manually (and added the list of the most important files). |
| 11 May 2017 | - Added a note that this Jumbo Hotfix Accumulator (all its Takes) is _**not**_ supported on [vSEC for Google Cloud Platform](https://www.checkpoint.com/products/vsec-google-cloud-platform/). |
| 20 Apr 2017 | - Removed Issue ID 01562489 (that fix was not integrated yet) from _Take 33_. |
| 09 Apr 2017 | - Added Issue ID 01916631 in _Take 128_. |
| 30 Mar 2017 | - Updated the description of Issue ID 02002951. |
| 29 Mar 2017 | - Updated the description of Issue ID 02333089. |
| 22 Mar 2017 | - Release of Ongoing Take 225. |
| 06 Mar 2017 | - Release of Ongoing Take 221. |
| 23 Feb 2017 | - Added a note that on _21000 appliances with SAM card_, due to specific stability issues,<br>  <br>  Take 210, Take 213 and Take 216 should _not_ be installed (refer to [sk116070](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116070)).<br>- Improved the description of Issue ID 02441209.<br>- Improved the description of Issue ID 02413967.<br>- Improved the description of Issue ID 02079428.<br>- Improved the description of Issue ID 01931909.<br>- Changed the description of Issue ID 02422452 to say:<br>  <br>  "This option will be fully available in future Takes". |
| 22 Feb 2017 | - Added sk115575 in Take 216. |
| 17 Feb 2017 | - General Availability Take 216 is now available in Gaia Portal and Gaia Clish for CPUSE online installation (it replaces General Availability Take\_205).<br>- Some changes in the design of this article, e.g., separated the "List of resolved issues per Take" section into these sections:<br>  <br>  <br>  - "List of resolved issues in the General Availability Takes".<br>  - "List of resolved issues in the Ongoing Take".<br>. |
| 05 Feb 2017 | - Release of Ongoing Take 213.<br>- Added sk114613 in Take 198.<br>- Added sk112240 in Take 198. |
| 29 Jan 2017 | - Added Issue ID 02364390 in _Take 207_. |
| 25 Jan 2017 | - Release of Ongoing Take 210 (that replaced Take 209). |
| 23 Jan 2017 | - Release of Ongoing Take 209. |
| 08 Jan 2017 | - Release of Ongoing Take 207. |
| 26 Dec 2016 | - Release of Ongoing Take 206. |
| 22 Dec 2016 | - Added relevant notes about the CPUSE Agent. |
| 16 Dec 2016 | - Added notes that R77.30 Jumbo Hotfix Accumulator supports the new improved R77.30 Gaia image (released 16 Dec 2016):<br>  - Since Take 198 - new R77.30 Gaia image for 3200 / 5000 / 15000 / 23000 / TE100X / TE250X / TE1000X / TE2000X appliances.<br>  - Since Take 84 - new R77.30 Gaia image for 2200 / 4000 / 12000 / 13000 / 21000 / TE250 / TE1000 / TE2000 appliances.<br>. |
| 15 Dec 2016 | - General Availability Take 205 is now available in Gaia Portal and Gaia Clish for CPUSE online installation (it replaces General Availability Take\_185). |
| 23 Nov 2016 | - Release of Ongoing Take 198. |
| 17 Nov 2016 | - Updated a note that R77.30 instances running in Microsoft Azure are supported starting in Take 189. |
| 15 Nov 2016 | - Updated a note that R77.30 instances running in Amazon Web Services (AWS) are supported starting in Take 189 (instead on Take 184). |
| 13 Nov 2016 | - General Availability Take 185 is now available in Gaia Portal and Gaia Clish for CPUSE online installation (it replaces General Availability Take\_159). |
| 07 Nov 2016 | - Release of Ongoing Take 189. |
| 06 Nov 2016 | - Added a note that this Jumbo Hotfix Accumulator has to be installed only after successful completion of Gaia First Time Configuration Wizard. |
| 20 Oct 2016 | - Release of Ongoing Take 185. |
| 19 Oct 2016 | - Removed instructions for Legacy CLI package (deprecated) - CPUSE should be used instead. |
| 18 Oct 2016 | - Removed a note that until further notice, R77.30 Jumbo Hotfix Accumulator should NOT be installed on Check Point Threat Emulation appliances (TE / TEX series) - no degradation / issue was found. |
| 16 Oct 2016 | - Added a note that until further notice, R77.30 Jumbo Hotfix Accumulator should NOT be installed on Check Point Threat Emulation appliances (TE / TEX series). |
| 13 Oct 2016 | - Release of Ongoing Take 184. |
| 10 Oct 2016 | - Reverted to Ongoing Take 171<br>  <br>  The following Take packages were temporarily recalled for additional testing:<br>  - Ongoing Take 178.<br>  - Ongoing Take 174.<br>  - Ongoing Take 172.<br>. |
| 29 Sep 2016 | - Release of Ongoing Take 178. |
| 22 Sep 2016 | - Release of Ongoing Take 174. |
| 01 Sep 2016 | - Release of Ongoing Take 172. |
| 25 Aug 2016 | - Release of Ongoing Take 171. |
| 08 Aug 2016 | - Release of Ongoing Take 165. |
| 01 Aug 2016 | - Release of Ongoing Take 164. |
| 27 July 2016 | - General Availability Take 159 is now available in Gaia Portal and Gaia Clish for CPUSE online installation. |
| 20 July 2016 | - Release of Ongoing Take 162. |
| 14 July 2016 | - Release of Ongoing Take 161. |
| 30 June 2016 | - First release of General Availability Take (Take 159).<br>- Moved all Legacy CLI instructions into a separate section. |

## Article Properties

Access LevelGeneral

StatusApproved

Date Created2015-05-21

Last Modified2023-09-11

Was this page helpful?YesNo

#### Haven't found what you're looking for?

##### Our customer support team is only a click away and ready to help you 24 hours a day.

[Open a Service Request](https://help.checkpoint.com/s/case-creation?visitorId=null)

reCAPTCHA

Recaptcha requires verification.

protected by **reCAPTCHA**
