sk178604

Check Point R81.10.X for 1500, 1600, 1800, 1900, and 2000 appliance Known Limitations

Product: Spark Firewall
Version: R81.10.X
OS: Gaia Embedded
Platform: 1500, 1570R, 1575R, 1595R, 1600, 1800, 1900, 2000
Last Modified: 2026-07-08

Solution

This article provides a list of Supported Features, Unsupported Features, and Known Limitations, for Check Point R81.10.x versions on Spark Firewall Appliances. For R81.10.X Resolved Issues, see sk181134.

For the complete list of R82.00.X Known Limitations, refer to sk183400.

This is a live document that may be updated without special notice.

This article contains two sections:

Important Notes:

Supported and Unsupported Features

Note: All features available on a Locally Managed appliance are also available in the Spark Management App on the Infinity Portal.

Enter the string to filter this table:

Blade / Feature Locally Managed Centrally Managed Comments
Access Rules Yes Yes
Application Control Blade Yes Yes
URL Filtering Blade Yes Yes
Content Awareness No No
QoS Yes Yes
Data Loss Prevention (DLP) Blade No No
Geo Protection Yes Yes
Network Address Translation (NAT) Yes Yes
HTTP/HTTPS proxy No No
UserCheck Yes Yes UserCheck client on endpoint computers is not supported
Hotspot portal Yes Yes
Rule Hit Count Yes Yes
Domain Object Yes Yes
Time Objects Yes Yes
Updatable Objects Yes Yes
Suspicious Activity Monitoring (SAM) Rules No No
Rule Base Layers No Yes
Security Zones No Yes
Data Center objects No Yes
SmartAccess Yes No
Inbound HTTPS Inspection No Yes
Probing Yes Yes
Categorization enabled with full SSL inspection Yes Yes
HTTPS layers No Yes
HTTP/2 Yes Yes
SSL bypass by FQDN / Updatable Object Yes Yes
TLS 1.3 No No
AD Query Yes Yes
Azure AD Yes Yes
RADIUS Accounting No No
Identity Collector Yes Yes
Identity Broker No No
IoT Protect for Enterprise Not Applicable Yes Available from R81.10.05
IoT Protect for SMBs Yes No Available from R81.10.10. Not supported in Ruggedized appliances 1570R, 1575R, 1595R.
SD-WAN for Enterprise Not Applicable Yes
SD-WAN for SMBs Yes No Available from R81.10.10. Supports application-based steering. No support for VPN overlay.
Central VPN Gateway in Star VPN communities Yes No Limited to serve 100 Satellite Gateways (starting from R81.10.10).
Satellite VPN Gateway in Star VPN communities Yes Yes
IPSec VPN Blade Yes Yes
Mobile Access Blade Partial Partial Remote Access VPN clients are supported (Endpoint, SNX). Mobile Access Web Portal is not supported.
VTI Yes Yes
Traditional VPN Mode No No
Secure Configuration Verification (SCV) and Desktop policy No No
Multiple Entry Points (MEP) No Yes
VPN Link Selection Yes Yes
Remote Access VPN client multifactor authentication Yes Yes Email, SMS, and Google/MS Authenticator as second factor authentication
NAT-T support for Site-to-Site VPN Yes Yes
VPN multicore performance with CoreXL Yes Yes
Different VPN encryption domains on a Security Gateway that is a member of multiple VPN communities No Yes
Machine certificate authentication No No
Different ciphers for external Gateways in a single VPN community No Yes
Support for SHA-512 Yes Yes
SAML for Remote Access VPN Yes Yes Available starting in R81.10.15
Autonomous Threat Prevention Not Applicable No
IPS Blade Yes Yes
Anti-Bot Blade Yes Yes
Anti-Virus Blade Yes Yes
Traditional Anti-Virus Blade Yes Yes
Threat Emulation Blade Yes Yes
Threat Extraction Blade No No Refer to sk101553
Anti-Spam and Email Security Blade Yes Yes
Mail Transfer Agent (MTA) support for Threat Emulation No No
IPS Packet Capture No No
Anti-Virus archive scanning No No
Threat Emulation archive scanning No Yes In Check Point Cloud only
Threat Prevention Indicators of Compromise (IoC) No Yes
Anti-Virus for FTP traffic Yes Yes
DNS tunneling protection Yes Yes
IoC Feeds Yes Yes In Locally Managed, supported in CLI only.
Enhanced support for password-protected documents No No
New file types and protocols No No
SSH inspection No Yes
Threat Prevention bypass by FQDN / Updatable Object Yes Yes
Monitoring Blade No No Other monitoring solutions are available
Compliance Blade No Yes Supported for Management Server R82 and higher versions. See sk181127.
SNMP Yes Yes
Central Deployment No Yes Supported in Management Server R81.20 and higher
SmartUpdate No Yes
SmartProvisioning / SmartLSM No Yes
CPView Yes Yes
Skyline ( sk178566) No No For Early Availability only
SecureXL Yes Yes
CoreXL Yes Yes Limitation - Security Gateway automatically changes the number of CoreXL Firewall instances based on current traffic
Smart Accel Yes No
Span Port Yes Yes
Monitor Mode Yes Yes Refer to sk112572
Netflow Yes Yes Configured only in Gaia Clish
ClusterXL High Availability mode Yes Yes
ClusterXL Load Sharing mode No No
VRRP cluster No No
3rd-party cluster mode No No
Connectivity Upgrade No No
ISP Redundancy Yes Yes
Dynamic Routing Yes Yes
Policy-Based Routing (PBR) Yes Yes
IPv6 Yes Yes
IP Helper No No
DHCP Client Yes Yes For external interfaces
DHCP Relay Yes Yes For internal interfaces
DHCP Server Yes Yes For internal interfaces
Jumbo Frames Yes Yes Early Availability level
Bond / Link aggregated interface Yes Yes
Alias / Secondary IP address Yes Yes
OS Web Management Portal (Gaia Portal) Yes Yes
NTP Client Yes Yes
NTP Server Yes Yes
General
IPv6 packet inspection Yes Yes Refer to sk174348 for limitations
'All-In-One' license Yes Yes
Evaluation license Yes Yes
MAC filtering on WiFi Yes Yes
MAC filtering on LAN Yes Yes
Anti-ARP spoofing No No
802.1x based authentication Yes Yes
802.1w RSTP (Rapid Spanning Tree Protocol) No No

Known Limitations

The following limitations are known in R81.10 for Spark Firewall Appliances.

Important Notes:

Enter the string to filter the below table:

ID Description Found In
SMBGWY-17712 After upgrade from R81.10.10 to R81.10.17, the gateway reverts back to the previous version. See sk184034. R81.10.17
SMBGWY-11897 The Interactive front panel view (2D), which was introduced in version R81.10.15, is not available on Centrally Managed or Ruggedized appliances. For more information, refer to the "Viewing System Information" section in the R81.10.X Locally Managed Administration Guide (refer to the table entry for the "Interactive front panel view").
SMBGWY-13190 For 15XX appliances, you can create a maximum of 10 Internet connections. On 1600, 1800, 1900, and 2000 appliances the maximum number is 20. This includes alias IP connections.
SMBGWY-5463 To upgrade from R80.20.35 (or lower), you must follow this two-step upgrade path:
1. Upgrade from R80.20.35 (or lower) to R80.20.60:

See sk181079  "Upgrade from R80.20 Versions" section.
2. Upgrade to version R81.10.08 (or higher).
SMB-12119 A USB storage device used for clean installation of a new image on the 1500 series must be formatted with FAT32 file-system. R81.10.00
SMB-10086 Certain CLISH commands allow configuration of a DMZ interface even though there is no DMZ port on the appliance (relevant to V0 only). R81.10.00
SMBGWY-12678 Disabling Threat Emulation inspection for an FTP connection from a specific IP address is not supported. R81.10.10
SMB-12009 In a rare scenario, malicious emails detected by IMAP inspection are not deleted from the client. Note: The malicious content is NOT downloaded. R81.10.00
SMB-13721 SNORT rules are not supported. R81.10.00
SMB-9988 The "Import IPS protections" option fails if done via the WebUI. Offline updates can be installed via CLI. R81.10.00
SMB-12965 Anti-Spam is supported only when SMTP is outside the branch. In case SMTP is inside the branch, then it should work with port forwarding. R81.10.00
SMB-10433 In Centrally Managed Gateways, you can not fetch the IPS package from Management.
Workaround:
To install the package:
1. Enter expert mode.
2. Copy $FWDIR/state/local/AMW/local.sd_updates to /storage partition.
3. Run: online_update_cmd -b IPS -o offlineUpdate -f storage/local.sd_updates
R81.10.00
SMBGWY-1388 Policy installation in SmartConsole might fail with the "Error code 1-2000232" after a firmware upgrade from R81.10.00 to R81.10.05. To avoid the error, in the "Install Policy" window, right-click the Spark Firewall object and select the option "Do not use Install Policy Acceleration for all targets". This is only needed one time after a firmware upgrade. R81.10.05
SMBGWY-2442 When configuring the First Time Configuration Wizard from the WAN interface, you cannot set the SIC One-Time-Password immediately after the FTW. To set it you need to refresh your web browser first. R81.10.00
SMBGWY-21652 External USB cellular modem is not supported. R81.10.08
SMB-14272 SFP-DSL is supported in Automatic mode only. R81.10.00
SMB-19564 Use of the EXT port on 1800 Spark Firewall appliance is currently not supported. R80.20
SMB-14263 To disable the "Connect to the appliance by name from the Internet (DDNS)" option, it is necessary to enter the DDNS password again. R81.10.00
SMB-13955 These statistics are not available from the SFP DSL modem:
- RS Code Words
- RS Corrected Errors
- Configured G.Inp
- Vectoring
- HEC Errors
R81.10.00
SMB-13373 In 1800 appliances: When working in manual mode on the DMZ port, only 100Mbps and 10Mbps link speed are supported. R81.10.00
SMB-12254 1570R, 1600 and 1800 WAN and DMZ ports support copper RJ45 and fiber interfaces. Each port can only use one interface. If both the copper and fiber of the same port are plugged in, the port may experience stability issues. R81.10.00
SMBGWY-2441 We recommend that you configure DNS to resolve both internal and external domains.
DNS that does not resolve external domains may impact gateway operations.
R81.10.00
SMBGNG-19621 Dynamic Routing for IPv6 is not supported in a locally managed cluster, only on single gateways.
Dynamic Routing for IPv6 is supported for a centrally managed cluster.
R81.10.00
SMBGWY-2482 File related configuration (certificates, customized logo for portals) is not supported. R81.10.00
SMBGWY-2520 The VPN Advanced option to perform an organized shutdown of tunnels upon gateway restart is not supported. R81.10.00
SMBGWY-2521 Install policy fails on Centrally Managed appliances when a rule contains an action set to User authentication. R81.10.00
SMBGWY-2522 The "Monitoring" blade (Real Time Monitoring) is not supported. R81.10.00
SMBGWY-19702 The configuration of a second DHCP server in a VPN instance (by stepping into DHCP relay and setting the DHCP server's settings) fails. Enable DHCP server from the main DHCP server (The appliance manages it internally). R81.10.00