sk178604
Check Point R81.10.X for 1500, 1600, 1800, 1900, and 2000 appliance Known Limitations
Product: Spark Firewall
Version: R81.10.X
OS: Gaia Embedded
Platform: 1500, 1570R, 1575R, 1595R, 1600, 1800, 1900, 2000
Last Modified: 2026-07-08
Solution
This article provides a list of Supported Features, Unsupported Features, and Known Limitations, for Check Point R81.10.x versions on Spark Firewall Appliances. For R81.10.X Resolved Issues, see sk181134.
For the complete list of R82.00.X Known Limitations, refer to sk183400.
This is a live document that may be updated without special notice.
This article contains two sections:
- Supported and Unsupported Features
- Known Limitations
Important Notes:
- Embedded Gaia software inherits its code base from the R81.10 GA version of enterprise appliances. Therefore, although not specifically mentioned, the R81.10 Spark Firewall inherits all main train limitations (see sk170418).
- All Known Limitations with ID 010XXXX (not SMB-XXX) originate in R77.20 versions.
- For the complete list of R80.20.X Known Limitations, refer to sk159772.
Supported and Unsupported Features
Note: All features available on a Locally Managed appliance are also available in the Spark Management App on the Infinity Portal.
Enter the string to filter this table:
| Blade / Feature | Locally Managed | Centrally Managed | Comments |
|---|---|---|---|
| Access Rules | Yes | Yes | |
| Application Control Blade | Yes | Yes | |
| URL Filtering Blade | Yes | Yes | |
| Content Awareness | No | No | |
| QoS | Yes | Yes | |
| Data Loss Prevention (DLP) Blade | No | No | |
| Geo Protection | Yes | Yes | |
| Network Address Translation (NAT) | Yes | Yes | |
| HTTP/HTTPS proxy | No | No | |
| UserCheck | Yes | Yes | UserCheck client on endpoint computers is not supported |
| Hotspot portal | Yes | Yes | |
| Rule Hit Count | Yes | Yes | |
| Domain Object | Yes | Yes | |
| Time Objects | Yes | Yes | |
| Updatable Objects | Yes | Yes | |
| Suspicious Activity Monitoring (SAM) Rules | No | No | |
| Rule Base Layers | No | Yes | |
| Security Zones | No | Yes | |
| Data Center objects | No | Yes | |
| SmartAccess | Yes | No | |
| Inbound HTTPS Inspection | No | Yes | |
| Probing | Yes | Yes | |
| Categorization enabled with full SSL inspection | Yes | Yes | |
| HTTPS layers | No | Yes | |
| HTTP/2 | Yes | Yes | |
| SSL bypass by FQDN / Updatable Object | Yes | Yes | |
| TLS 1.3 | No | No | |
| AD Query | Yes | Yes | |
| Azure AD | Yes | Yes | |
| RADIUS Accounting | No | No | |
| Identity Collector | Yes | Yes | |
| Identity Broker | No | No | |
| IoT Protect for Enterprise | Not Applicable | Yes | Available from R81.10.05 |
| IoT Protect for SMBs | Yes | No | Available from R81.10.10. Not supported in Ruggedized appliances 1570R, 1575R, 1595R. |
| SD-WAN for Enterprise | Not Applicable | Yes | |
| SD-WAN for SMBs | Yes | No | Available from R81.10.10. Supports application-based steering. No support for VPN overlay. |
| Central VPN Gateway in Star VPN communities | Yes | No | Limited to serve 100 Satellite Gateways (starting from R81.10.10). |
| Satellite VPN Gateway in Star VPN communities | Yes | Yes | |
| IPSec VPN Blade | Yes | Yes | |
| Mobile Access Blade | Partial | Partial | Remote Access VPN clients are supported (Endpoint, SNX). Mobile Access Web Portal is not supported. |
| VTI | Yes | Yes | |
| Traditional VPN Mode | No | No | |
| Secure Configuration Verification (SCV) and Desktop policy | No | No | |
| Multiple Entry Points (MEP) | No | Yes | |
| VPN Link Selection | Yes | Yes | |
| Remote Access VPN client multifactor authentication | Yes | Yes | Email, SMS, and Google/MS Authenticator as second factor authentication |
| NAT-T support for Site-to-Site VPN | Yes | Yes | |
| VPN multicore performance with CoreXL | Yes | Yes | |
| Different VPN encryption domains on a Security Gateway that is a member of multiple VPN communities | No | Yes | |
| Machine certificate authentication | No | No | |
| Different ciphers for external Gateways in a single VPN community | No | Yes | |
| Support for SHA-512 | Yes | Yes | |
| SAML for Remote Access VPN | Yes | Yes | Available starting in R81.10.15 |
| Autonomous Threat Prevention | Not Applicable | No | |
| IPS Blade | Yes | Yes | |
| Anti-Bot Blade | Yes | Yes | |
| Anti-Virus Blade | Yes | Yes | |
| Traditional Anti-Virus Blade | Yes | Yes | |
| Threat Emulation Blade | Yes | Yes | |
| Threat Extraction Blade | No | No | Refer to sk101553 |
| Anti-Spam and Email Security Blade | Yes | Yes | |
| Mail Transfer Agent (MTA) support for Threat Emulation | No | No | |
| IPS Packet Capture | No | No | |
| Anti-Virus archive scanning | No | No | |
| Threat Emulation archive scanning | No | Yes | In Check Point Cloud only |
| Threat Prevention Indicators of Compromise (IoC) | No | Yes | |
| Anti-Virus for FTP traffic | Yes | Yes | |
| DNS tunneling protection | Yes | Yes | |
| IoC Feeds | Yes | Yes | In Locally Managed, supported in CLI only. |
| Enhanced support for password-protected documents | No | No | |
| New file types and protocols | No | No | |
| SSH inspection | No | Yes | |
| Threat Prevention bypass by FQDN / Updatable Object | Yes | Yes | |
| Monitoring Blade | No | No | Other monitoring solutions are available |
| Compliance Blade | No | Yes | Supported for Management Server R82 and higher versions. See sk181127. |
| SNMP | Yes | Yes | |
| Central Deployment | No | Yes | Supported in Management Server R81.20 and higher |
| SmartUpdate | No | Yes | |
| SmartProvisioning / SmartLSM | No | Yes | |
| CPView | Yes | Yes | |
| Skyline ( sk178566) | No | No | For Early Availability only |
| SecureXL | Yes | Yes | |
| CoreXL | Yes | Yes | Limitation - Security Gateway automatically changes the number of CoreXL Firewall instances based on current traffic |
| Smart Accel | Yes | No | |
| Span Port | Yes | Yes | |
| Monitor Mode | Yes | Yes | Refer to sk112572 |
| Netflow | Yes | Yes | Configured only in Gaia Clish |
| ClusterXL High Availability mode | Yes | Yes | |
| ClusterXL Load Sharing mode | No | No | |
| VRRP cluster | No | No | |
| 3rd-party cluster mode | No | No | |
| Connectivity Upgrade | No | No | |
| ISP Redundancy | Yes | Yes | |
| Dynamic Routing | Yes | Yes | |
| Policy-Based Routing (PBR) | Yes | Yes | |
| IPv6 | Yes | Yes | |
| IP Helper | No | No | |
| DHCP Client | Yes | Yes | For external interfaces |
| DHCP Relay | Yes | Yes | For internal interfaces |
| DHCP Server | Yes | Yes | For internal interfaces |
| Jumbo Frames | Yes | Yes | Early Availability level |
| Bond / Link aggregated interface | Yes | Yes | |
| Alias / Secondary IP address | Yes | Yes | |
| OS Web Management Portal (Gaia Portal) | Yes | Yes | |
| NTP Client | Yes | Yes | |
| NTP Server | Yes | Yes | |
| General | |||
| IPv6 packet inspection | Yes | Yes | Refer to sk174348 for limitations |
| 'All-In-One' license | Yes | Yes | |
| Evaluation license | Yes | Yes | |
| MAC filtering on WiFi | Yes | Yes | |
| MAC filtering on LAN | Yes | Yes | |
| Anti-ARP spoofing | No | No | |
| 802.1x based authentication | Yes | Yes | |
| 802.1w RSTP (Rapid Spanning Tree Protocol) | No | No |
Known Limitations
The following limitations are known in R81.10 for Spark Firewall Appliances.
Important Notes:
- All previous limitations are relevant to the following version unless stated as resolved.
- For Resolved Issues in R81.10.05 and higher versions, see sk181134 - Check Point R81.10.X for 1500, 1600, and 1800 appliance Resolved Issues.
Enter the string to filter the below table:
| ID | Description | Found In |
|---|---|---|
| SMBGWY-17712 | After upgrade from R81.10.10 to R81.10.17, the gateway reverts back to the previous version. See sk184034. | R81.10.17 |
| SMBGWY-11897 | The Interactive front panel view (2D), which was introduced in version R81.10.15, is not available on Centrally Managed or Ruggedized appliances. For more information, refer to the "Viewing System Information" section in the R81.10.X Locally Managed Administration Guide (refer to the table entry for the "Interactive front panel view"). | |
| SMBGWY-13190 | For 15XX appliances, you can create a maximum of 10 Internet connections. On 1600, 1800, 1900, and 2000 appliances the maximum number is 20. This includes alias IP connections. | |
| SMBGWY-5463 | To upgrade from R80.20.35 (or lower), you must follow this two-step upgrade path: 1. Upgrade from R80.20.35 (or lower) to R80.20.60: See sk181079 "Upgrade from R80.20 Versions" section. 2. Upgrade to version R81.10.08 (or higher). |
|
| SMB-12119 | A USB storage device used for clean installation of a new image on the 1500 series must be formatted with FAT32 file-system. | R81.10.00 |
| SMB-10086 | Certain CLISH commands allow configuration of a DMZ interface even though there is no DMZ port on the appliance (relevant to V0 only). | R81.10.00 |
| SMBGWY-12678 | Disabling Threat Emulation inspection for an FTP connection from a specific IP address is not supported. | R81.10.10 |
| SMB-12009 | In a rare scenario, malicious emails detected by IMAP inspection are not deleted from the client. Note: The malicious content is NOT downloaded. | R81.10.00 |
| SMB-13721 | SNORT rules are not supported. | R81.10.00 |
| SMB-9988 | The "Import IPS protections" option fails if done via the WebUI. Offline updates can be installed via CLI. | R81.10.00 |
| SMB-12965 | Anti-Spam is supported only when SMTP is outside the branch. In case SMTP is inside the branch, then it should work with port forwarding. | R81.10.00 |
| SMB-10433 | In Centrally Managed Gateways, you can not fetch the IPS package from Management. Workaround: To install the package: 1. Enter expert mode. 2. Copy $FWDIR/state/local/AMW/local.sd_updates to /storage partition. 3. Run: online_update_cmd -b IPS -o offlineUpdate -f storage/local.sd_updates |
R81.10.00 |
| SMBGWY-1388 | Policy installation in SmartConsole might fail with the "Error code 1-2000232" after a firmware upgrade from R81.10.00 to R81.10.05. To avoid the error, in the "Install Policy" window, right-click the Spark Firewall object and select the option "Do not use Install Policy Acceleration for all targets". This is only needed one time after a firmware upgrade. | R81.10.05 |
| SMBGWY-2442 | When configuring the First Time Configuration Wizard from the WAN interface, you cannot set the SIC One-Time-Password immediately after the FTW. To set it you need to refresh your web browser first. | R81.10.00 |
| SMBGWY-21652 | External USB cellular modem is not supported. | R81.10.08 |
| SMB-14272 | SFP-DSL is supported in Automatic mode only. | R81.10.00 |
| SMB-19564 | Use of the EXT port on 1800 Spark Firewall appliance is currently not supported. | R80.20 |
| SMB-14263 | To disable the "Connect to the appliance by name from the Internet (DDNS)" option, it is necessary to enter the DDNS password again. | R81.10.00 |
| SMB-13955 | These statistics are not available from the SFP DSL modem: - RS Code Words - RS Corrected Errors - Configured G.Inp - Vectoring - HEC Errors |
R81.10.00 |
| SMB-13373 | In 1800 appliances: When working in manual mode on the DMZ port, only 100Mbps and 10Mbps link speed are supported. | R81.10.00 |
| SMB-12254 | 1570R, 1600 and 1800 WAN and DMZ ports support copper RJ45 and fiber interfaces. Each port can only use one interface. If both the copper and fiber of the same port are plugged in, the port may experience stability issues. | R81.10.00 |
| SMBGWY-2441 | We recommend that you configure DNS to resolve both internal and external domains. DNS that does not resolve external domains may impact gateway operations. |
R81.10.00 |
| SMBGNG-19621 | Dynamic Routing for IPv6 is not supported in a locally managed cluster, only on single gateways. Dynamic Routing for IPv6 is supported for a centrally managed cluster. |
R81.10.00 |
| SMBGWY-2482 | File related configuration (certificates, customized logo for portals) is not supported. | R81.10.00 |
| SMBGWY-2520 | The VPN Advanced option to perform an organized shutdown of tunnels upon gateway restart is not supported. | R81.10.00 |
| SMBGWY-2521 | Install policy fails on Centrally Managed appliances when a rule contains an action set to User authentication. | R81.10.00 |
| SMBGWY-2522 | The "Monitoring" blade (Real Time Monitoring) is not supported. | R81.10.00 |
| SMBGWY-19702 | The configuration of a second DHCP server in a VPN instance (by stepping into DHCP relay and setting the DHCP server's settings) fails. Enable DHCP server from the main DHCP server (The appliance manages it internally). | R81.10.00 |