sk181128 - Check Point Quantum R82 Release Known Limitations

Header/footer test page

My Favorites

Solution ID: sk181128


Technical Level:

Basic

Email

Print

Check Point Quantum R82 Release Known Limitations

ProductSecurity Gateways, Security Management

VersionR82

OSGaia

Last Modified2026-06-15

Solution

This article lists all Quantum R82 Release specific known limitations and unsupported features, including limitations from the previous versions.

For more information about R82, see the R82 Release Notes, R82 Home Page and R82 Resolved Issues.

Visit Check Point CheckMates Community to ask questions or start a discussion and get our experts assistance.

Important notes:

Show the Entire Article

Unsupported Features Show this section

Table of Contents

- Installation and Upgrade

- Licensing

- Gaia OS

- Multi-Domain Management

- SmartConsole / Management Console

- Logging

- SmartProvisioning
- Security Gateway

- SD-WAN

- ClusterXL

- SecureXL

- Routing

- ICAP

- Threat Prevention
- Identity Awareness

- HTTPS Inspection

- Mobile Access

- VPN

- Zero Phishing

- ElasticXL, Maestro, and Scalable Chassis

Enter the string to filter the below table:

ID Description Found in version
Unsupported Features - Installation and Upgrade
PMTR-59345 Central Deployment in SmartConsole does not support:
- Connection from SmartConsole to the Management Server through a proxy Server. In this case, use the applicable API command
- ClusterXL in Load Sharing mode
- VRRP Cluster
- Installation of a package on a VSX VSLS Cluster that contains more than 3 members
- On Multi-Domain Servers: Global Domain, or the MDS context
- Standby Security Management Server or Multi-Domain Security Management
- Security Group in Maestro
- Security Group on Scalable Chassis 40000 / 60000
- ElasticXL Cluster
R81
Unsupported Features - Licensing
PMTR-47087 These products do not support the new licensing visibility features:
- Network Security: Advanced Networking and Clustering, Capsule Cloud and Capsule Workspace.
- Security Management: Endpoint Policy Management, SmartPortal, User Directory (LDAP).
- Multi-Domain Management: Security Domain
- Remote Access & Endpoint
R80
Unsupported Features - Gaia OS
PMTR-48258 The Gaia "Cloning Group" feature (all its modes) is not supported in a Multi-Version Cluster (while cluster members run different release versions). R80.40
Unsupported Features - Multi-Domain Management
PMTR-17365 The "Install Policy" action from a Multi-Domain Management Server (also through "Install Policy Presets") does not support QoS and Desktop policies. R80.20.M1
Unsupported Features - SmartConsole / Management Console
PMTR-101120 Login into SmartConsole with an IPv6 address using SAML is not supported. R81.20
PMTR-104470 SmartConsole does not support (or has a limited support) the High Contrast Theme in these sections and windows:
- "Gateways & Servers" view > select a Security Gateway / Cluster object > at the top, click the Actions menu > click Install Hotfix, or Version Upgrade
- "Gateways & Servers" view > select a Security Gateway / Cluster object > in the lower pane, click the Licenses tab
- "Gateways & Servers" view > at the top, click Changes
- "Security Policies" view > Autonomous Threat Prevention > click Policy, or File Protections
- "Security Policies" view > Access Control policy or Threat Prevention policy > at the top, click Changes
- "Manage & Settings" view > Sessions > View Sessions > at the top, click Changes
- "Manage & Settings" view > Sessions > Revisions > at the top, click Changes
- "Manage & Settings" view > Sessions > Revisions > select a revision > at the top, click the Actions menu > Revert to this Revision
- "Manage & Settings" view > Package Repository
R81.10
PMTR-58838 Changes (Diff) report does not support:
- A Standalone Server
- Changes made in the Legacy SmartDashboard
R81
PROV-2200 The "Get Interfaces" operation on the "Network Management" page of a Security Gateway (or Cluster) object only supports up to 500 interfaces of all types.
- **To resolve:**If the Security Gateway (or Cluster) has 500 or more interfaces of all types, use the API get-interfaces on the Management Server to pull this information.

Examples:

1)get-interfaces target-name <Name of Security Gateway> with-topоlogy false

2) get-interfaces target-name <Name of Cluster Object> with-topоlogy trueFor more information refer to Management API.
R81
PMTR-57122 Search for section titles is not supported. R80
- Changes to the Traditional Anti-Virus file types policy are not supported. Use the Anti-Virus blade to change the out-of-the-box Check Point policy. R80
Unsupported Features - Logging
PMTR-40514 In the SmartConsole > Logs & Monitor view > [ + ] New Tab > Views, sorting of the Favorites and Shared columns is not supported. R80.40
PMTR-47703 Purge, log switch and fetch log file tasks are not supported from SmartConsole.
- Fetch log files from a remote Server is available from the command line only. Run: fw fetchlogs <Gateway-Name/IP>
R80.10
Unsupported Features - SmartProvisioning
PMTR-109023 SmartProvisioning / SmartLSM is not supported in the VSNext mode. R82
PMTR-56758 It is not supported to remove an IP address from one interface and assign the same IP address to another interface in the device object in the same edit action. " Error field: ipAddr, Desc: IP address is in the subnet of an existing network" is displayed. R81
PMTR-54979 When managing devices with the SmartProvisioning Software Blade, on the devices you must configure the connection with the Security Management Server using the IPv4 address in the connect security-management mgmt-addr <IPv4 address of Security Management Server> command (it is not supported to use the FQDN of the Security Management Server in this command). R80.40
Unsupported Features - Security Gateway
PMTR-60143 The perf command is not supported on Threat Emulation appliances and on all other Check Point appliances that have only one or two CPU cores.
- On these appliances, use the top and turbostat commands to monitor the performance.
R81.10
PMTR-58361 Intra-Tunnel Inspection of GTP-U user traffic is not supported. R81
PMTR-58366 The "Produce extended logs on unmatched PDUs" option is not supported in the Security Gateway (Cluster) object > Carrier Security > Track.
As a result, it is not possible to generate informative logs for unmatched GTP-C control packets (except for a plain clean up rule logging).
R81
Unsupported Features - SD-WAN
PMTR-109701 SD-WAN Overlay does not support having multiple center gateways in a star community with no satellites, when "Mesh center gateways" checkbox is selected. R82
PMTR-108481 Anti-Spam, Threat Emulation and Threat Extraction Blades do not support Security Gateways with Dynamically Assigned IP (DAIP). R82
PMTR-108485 SD-WAN Overlay does not support VPN Tunnel between gateways while both sides behind CGNAT / Dynamic NAT. R82
PMTR-108281 SD-WAN does not support matching a "Local Breakout" rule to traffic in this scenario:
1. Traffic matches a Policy-Based Routing (PBR) rule that applies to traffic from a local network to "Default", and the next hop in this rule is set to a VPN Tunnel Interface (VTI).
2. The priority of this PBR rule is lower than 100.
R82
PMTR-106136 SD-WAN does not support Cluster configuration when Cluster Members are DAIP Security Gateways. R82
PMTR-107839 SD-WAN Overlay does not support the "Exclude gateway's external IP addresses from the VPN Domain" configuration. R82
PMTR-106717 In a Spoke-Hub-Spoke configuration, an encrypted connection from a Satellite SD-WAN DAIP Security Gateway to another Satellite Security Gateway VPN Domain is not supported when both conditions are met:
- The source IP is from a Dynamic IP interface
- The connection is routed through the central Security Gateway
R82
PMTR-106135 SD-WAN does not support Security Gateways running Gaia OS that have more than one DAIP interface. R82
PMTR-108004 SD-WAN does not support "Overlay - VPN" over Route Based VPN configured with unnumbered VPN Tunnel Interfaces (VTI). R82
PMTR-108010 For inbound connections from the Internet to the Security Gateway itself, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received if there are multiple ISPs. R82
PMTR-105725 In a cluster, SD-WAN does not support interfaces in which the "Network Type" is set to "Private" (Non-Monitored Interface). R82
PMTR-105211 SD-WAN Local Breakout is not supported for outbound connections configured with fixed Hide/Static NAT IP address, and which should be steered using more than one ISP.
The only option is "Hide behind gateway".
- Resolved in R82 Jumbo Hotfix Accumulator Take 14 (PRJ-56616)
R82
PMTR-105210 SD-WAN Local Breakout does not apply to connections that originate on the Security Gateway itself (for example, when an administrator connects from the Security Gateway to an FTP server). R82
PMTR-105208 SD-WAN Overlay VPN does not support Route Based VPN. R82
PMTR-105207 SD-WAN Overlay VPN does not support VPN peer Security Gateways connected over a Layer 2 line (SD-WAN Overlay VPN requires Layer 3 connectivity between VPN peers).
The external interfaces of SD-WAN Security Gateways cannot be in the same subnet, if they are configured for a VPN overlay.
R82
PMTR-105213 SD-WAN Overlay VPN is only supported between Check Point Security Gateways that are connected to the same infinity tenant. R82
PMTR-105370 SD-WAN Overlay VPN does not support the configuration of the probing IP address.
By default, SD-WAN Overlay VPN probing sends ICMP requests only to the IP addresses of the VPN Peers.
R82
PMTR-105209 SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Security Management Server. R82
PMTR-108031 SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Domain Management Server. R82
PMTR-108901 SD-WAN does not support using DAIP Security Gateway objects in Access Control rules (neither in the Source column, nor in the Destination column). R81.20
PMTR-104984 SD-WAN does not support VPN Route Injection Mechanism (RIM) configuration. R81.20
PMTR-104985 SD-WAN does not support VPN Explicit Multiple Entry Point (MEP) configuration. R81.20
PMTR-105215 SD-WAN does not support VPN Overlay with third-party VPN Peers (Check Point Security Gateway continues to use the existing Link Selection). R81.20
PMTR-104986 For inbound connections from the internet, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received, in case of multiple ISPs.
The return will be determined based on the OS routes.
R81.20
PMTR-104981 SD-WAN does not support IPv6 traffic. R81.20
PMTR-104980 Scalable Platform Security Groups (Maestro and Chassis) do not support SD-WAN configuration. R81.20
PMTR-105894 SD-WAN does not support ClusterXL in the Load Sharing Multicast mode. R81.20
PMTR-105895 SD-WAN does not support ClusterXL in the Active-Active mode. R81.20
PMTR-105533 SD-WAN does not support Security Gateways that are managed with SmartProvisioning / LSM Profiles. R81.20
PMTR-104576 SD-WAN does not support VPN Permanent Tunnels (SmartConsole > VPN Community object > Tunnel Management).
SD-WAN tunnels are kept up automatically by the probing.
R81.20
PMTR-105543 SD-WAN does not support Geo Cluster in Microsoft Azure. R81.20
PMTR-105542 SD-WAN does not support Geo Cluster in Amazon Web Services (AWS). R81.20
PMTR-105544 SD-WAN does not support Geo Cluster in Google Cloud Platform (GCP). R81.20
PMTR-104977 VSX Gateways and VSX Clusters do not support SD-WAN configuration. R81.20
PMTR-104982 SD-WAN is not supported if a Security Gateway / Cluster runs SecureXL in the User Mode (UPPAK) on supported appliances (Quantum LightSpeed and Quantum Force - see sk179432).
Note - Using SecureXL in the Kernel Mode (KPPAK) is supported.
R81.20
Unsupported Features - ClusterXL
PMTR-59404 Geo Cluster does not support IPv6 traffic. Therefore, it is not supported to configure an IPv6 address on the Cluster and Sync interfaces. R81
PMTR-48477 ICAP Client and ICAP Server are not supported with ClusterXL Load Sharing modes. R80.10
Unsupported Features - SecureXL
PMTR-87460 SecureXL Rate Limiting rules for DoS Mitigation do not support these parameters:
- cc:<COUNTRY_CODE>
- asn:<AUTONOMOUS_SYSTEM_NUMBER>
Refer to sk182350.
- Resolved in R82 Jumbo Hotfix Accumulator Take 44 (PRJ-60142)
R81.10
Unsupported Features - Routing
PMTR-100077,
PMTR-100198,
PMTR-100206
PIM routing for IPv6 is not supported. R82
Unsupported Features - ICAP
PMTR-28828 ICAP Client cannot forward traffic to an ICAP Server when the Security Gateway is configured to apply the Threat Prevention "Strict Hold" mode. See sk183785. R80.30
Unsupported Features - Threat Prevention
PMTR-59492 In a Multi-Domain Server environment, Infinity Threat Prevention does not support the Global Domain. Other Domains are supported. R81
PMTR-42537 Threat Prevention Software blades do not support files with the HTTP 206 partial format with multiple ranges in the same HTTP connection (multipart). R80.40
PMTR-59837 SSH Deep Packet Inspection limitations:
- SSH DPI is only supported for Security Gateways R80.40 and above, managed by Management Servers R80.40 and above.
- Inspection of IPv6 connections is not supported.
- Bridge Mode is not supported.
- Cluster members do not synchronize the data about the inspected SSH traffic.
- Cluster members do not synchronize the SSH DPI configuration.
- Inspection of SSH traffic generated by clients, which do not support the "Diffie-Hellman group exchange" algorithm, is not supported.
- These SSH clients are not supported:
- PuTTY versions 0.64 and lower.
- OpenSSH versions 2.5.2 and lower.
- WinSCP versions 5.7.4 and lower.
- SecureCRT versions 5.2 and lower.
R80.40
Unsupported Features - Identity Awareness
PMTR-64495 Identity Awareness does not support authentication of Primary Groups of user and computer accounts. By default, the Primary Groups are "Domain Users" and "Domain Computers".
Access roles that are defined with User groups do not work for users with which those user groups are their primary group.
- To use the entire Accounting Unit in an Access Role, use an LDAP group.
R7x
Unsupported Features - HTTPS Inspections
PMTR-103024,
CRYPTOIS-2197
HTTPS Inspection does not support Hardware Security Modules (HSM) when inspection of TLS 1.3 traffic is enabled.
With HTTPS Inspection, you can enable only one of these features - TLS 1.3 or HSM.
R81
Unsupported Features - Mobile Access
PMTR-60331 These limitations apply to the Guacamole feature:
1. A dedicated Apache Guacamole Server version 1.1.0 or higher is required.
2. The following Guacamole features are not supported:
- The VNC protocol
- RDP file transfer
- The SFTP protocol
- Session recording
3. RDP/SSH is not supported from Capsule Workspace.
4. RDP/SSH is supported only by web browsers with HTML5 support.
5. RDP and SSH applications can be configured only by using their corresponding service objects in SmartConsole:
- “Remote_Desktop_Protocol”
- “SSH”
- “SSH_version_2”
6. The Clipboard function in RDP sessions is supported with these limitations:
- Text only
- Supported browsers: Chrome and Explorer
7. This Single Sign-On option is not supported for Guacamole applications: "This application reuses the portal credentials. If authentication fails, Mobile Access prompts users and stores their credentials"
8. In a VSX environment where the "custom user directory attribute" feature is used, adding a new Virtual System requires manually adding the customUserRecordAttribute.conf file as well.
R81
PMTR-58003 Mobile Access rules in the Unified Access Policy do not support Native Applications that authorize non-TCP or non-UDP services (for example, " icmp-proto"). R81
PMTR-47745 The Mobile Access Portal does not support Web-Form SSO for Citrix StoreFront Web interface. R80.10
PMTR-47591 Mobile Access does not support viewing or editing files with " Office Online apps", Microsoft's browser-based Office applications. Outlook Web Access is supported, however you cannot open or edit Office Online app files from emails. R7x
Unsupported Features - VPN
PMTR-60396 Large Scale VPN (LSV) does not support:
- IPv6
- Route Based VPN (VTI)
- Two VPN peers behind the same NAT device
- Suite-B-GCM-128
- Suite-B-GCM-256 with IKEv1-only (it is necessary to change the global properties of Phase 1 for Remote Access VPN)
- Multiple Hubs
- Route Injection Mechanism (RIM)
- IKE Aggressive Mode
- Permanent Tunnel
- Multiple Entry Point (MEP) VPN
- Dead Peer Detection (DPD)
- Global VPN Community (GVC)
- Tunnel Per Security Gateway pair (Universal Tunnel)
R80.40
PMTR-47783 NAT-T initiator is not supported on VSX Gateways. R80.10
PMTR-47235 Converting Traditional VPN Policy to Simplified VPN Policy is not supported. R80
Unsupported Features - Zero Phishing
PMTR-81859 Browser Zero Phishing is not supported in CloudGuard Network Security Auto Scale solution. R81

ElasticXL, Maestro, and Scalable Chassis Unsupported Features

Enter the string to filter the below table:

ID Product Description Found in
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - General
PMTR-108783 ElasticXL DHCP Server is not supported on ElasticXL. R82
PMTR-107886 ElasticXL Interface Active Check (IAC) is not supported on ElasticXL. R82
PMTR-101283 Maestro,
Chassis
Maestro and Scalable Chassis Security Groups do not support SD-WAN configuration. R81.20
PMTR-84368 Maestro Configuring Auto Scaling Settings is not supported if a Maestro Security Group contains different appliance models. R81.20
PMTR-111387,
MBS-10252
All Zero Touch is not supported. R81
PMTR-111384,
MBS-12257
All Detection of IP address conflict in Gaia OS is not supported.. R81
PMTR-111368,
MBS-9128
All The Unique IP address per Chassis (UIPC) feature is not supported for IPv6 addresses. R80.20SP
PMTR-111382,
MBS-3001
All The fw fetchlog command on the Management Server is not supported.
- Use SmartConsole to fetch logs from Security Members.
R80.20SP
PMTR-111386,
MBS-3246
All DHCP Server configuration  in the VSNext mode is not supported. R80.20SP
PMTR-108605,
00824847
All OPSEC SDK is not supported. R76SP
PMTR-108606,
01800842
All Hide NAT for traffic initiated from the Management interface of a Security Group is not supported. R76SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Gaia OS
PMTR-101680 ElasticXL ElasticXL supports IP Broadcast Helper (iphelper) in Gaia OS only when two ElasticXL Sites are configured. R82
PMTR-108178 ElasticXL In the Gaia First Time Configuration Wizard, when configuring the first ElasticXL Cluster Member, it is possible to configure an IP address only on the "Mgmt" (Management) interface. This is done on the "Management Connection" page of the wizard. Configuring an IP address on any other interface, such as on the "Internet Connection" page of the wizard, is not supported. R82
PMTR-109486 ElasticXL In ElasticXL, it is not supported to collect Gaia OS backup and restore it. R82
PMTR-81746 All When Management Data Plane Separation (MDPS) is enabled (see sk138672), Gaia Portal is not supported on a Security Group. R81.20
PMTR-71560,
MBS-7145
Maestro Maestro does not support the Dynamic CLI. Refer to sk144112. R80.30SP
PMTR-111362,
MBS-13308
All The set iphelper (IP Broadcast Helper) commands are not supported in Gaia gClish. R80.20SP
PMTR-90800 Maestro It is not supported to use the set web ssl-port command to change the MHO's WebUI SSL port from the default port 443 (for example: set web ssl-port 4434). Changing it causes communication issues between Maestro devices. R80.20SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Hardware
PMTR-106636,
MBS-1244
All The Check Point Performance Sizing Utility cpsizeme (see sk88160) is not supported. R80.20SP
PMTR-111375,
MBS-4754
All Central Management of Gaia Device Settings is not supported:
1. In SmartConsole, click "Gateways & Servers" on the navigation panel.
2. Right-click the Maestro and Scalable Chassis Gateway object or the Maestro Security Appliance Gateway object.
3. The "Scripts" menu and "Actions" menu are not supported.
R80.20SP
PMTR-111360,
MBS-5227
Maestro It is not supported to install both of the following expansion cards in the same Security Appliance connected to a Maestro Hyperscale Orchestrator:
- 10 GbE and 40 GbE
- 10 GbE and 100 GbE
R80.20SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Licensing
PMTR-111374,
MBS-7929
Maestro Central License is not supported on Quantum Maestro. R80.20SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Cluster
PMTR-106210 ElasticXL Multicast traffic routing over VTI Interface is not supported with ElasticXL in Load Sharing Mode. R82
PMTR-99761 ElasticXL Bridge is not supported on ElasticXL in Load Sharing mode (more than one Cluster Member per Site). R82
PMTR-111390,
MBS-12227
All Active-Active cluster is not supported. R81
PMTR-111364,
MBS-7913
Maestro Cluster Control Protocol (CCP) Encryption is not supported. R80. 30SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - SecureXL
PMTR-106079 Maestro Maestro Security Groups do not support the SecureXL User Space (UPPAK) mode. R81.20
PMTR-111379,
MBS-5415
All Configuring the IPS protection "SYN Attack" in SmartConsole is not supported. You must only use the "fwaccel synatk" and "fwaccel6 synatk" CLI commands. R80.20SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - VSNext / VSX
PMTR-118023 ElasticXL ElasticXL in the VSNext configuration does not support the Load Sharing mode (more than one Cluster Member per Site).
- Resolved in R82 Jumbo Hotfix Accumulator Take 103
R82
PMTR-108696,
PMTR-110224
ElasticXL VSLS (Virtual System Load Sharing) is not supported in the VSNext mode on ElasticXL.
- Resolved in R82 Jumbo Hotfix Take 14 (PRJ-58348)
R82
PMTR-111371,
MBS-16945
All NAT46 is not supported in the VSNext / Traditional VSX modes. R80.20SP
PMTR-109340 All Virtual Gateway in Monitor Mode is not supported. R82
PMTR-109011 All The "Mirror and Decrypt" feature is not supported in the VSNext mode. R82
PMTR-109016 All VPN Enhanced Link Selection is not supported in the VSNext mode. R82
PMTR-119289,
HEC-2236
All In the VSNext mode, after you create a Numbered VTI and attach it to a Virtual Gateway, you must reboot the Security Group.
- Resolved in R82 Jumbo Hotfix Accumulator Take 103 (PRJ-65727)
R82
PMTR-109024 All Anti-Virus archive scanning is not supported in the VSNext mode. R82
PMTR-109025 All Threat Emulation archive scanning is not supported in the VSNext mode. R82
PMTR-109026 All Mail Transfer Agent (MTA) support for Threat Emulation is not supported in the VSNext mode. R82
PMTR-109028 All Alias / Secondary IP address is not supported in the VSNext mode. R82
PMTR-109029 All ECMP (Equal Cost Path Splitting - Static Routs) is not supported in the VSNext mode.. R82
PMTR-109032 All Web SmartConsole does not support Security Groups in the VSNext mode. R82
PMTR-109033 All Object Sharing from on-premises Management Server to Infinity Portal is not supported. R82
PMTR-109034 All Log Sharing from on-premises Management Server to Infinity Portal does not support Security Groups in the VSNext mode. R82
PMTR-109035 All Infinity Playblocks does not support Security Groups in the VSNext mode. R82
PMTR-108070 All ISP Redundancy is not supported in the VSNext mode. R82
PMTR-109023 All SmartProvisioning / SmartLSM is not supported in the VSNext mode. R82
PMTR-111386,
MBS-3246
All Maestro in the VSNext mode does not support DHCP Server configuration. R82
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Networking
PMTR-107585 ElasticXL ElasticXL does not support IPv6 in the Load Sharing mode (more than one Cluster Member per Site). R82
PMTR-60874,
ACCHA-736
Maestro VxLAN interfaces are not supported on Quantum Maestro. R80.20SP
PMTR-111442,
MBS-14222
All Dynamic Routing protocols over GRE tunnels is not supported. R81
PMTR-106619 All BGP confederations are not supported. R76SP
PMTR-111441,
MBS-14223
All BGP over VxLAN tunnels is not supported. R81
PMTR-111369,
MBS-3944
Chassis Asymmetric traffic between two chassis in Dual Chassis deployment is not supported. R80.20SP
PMTR-104455,
MBS-3946
All Carrier Security (LTE) is not supported. R80.20SP
PMTR-111367,
MBS-12823
All " 6in4 tunnel" interface is not supported. R80.20SP
PMTR-104437 Chassis TFTP connections do not survive failover when using SSM440 and the distribution matrix size of 16K. R80.20SP
MBS-8326,
PMTR-104452
All Central Deployment Tool is not supported. R80.20SP
PMTR-111363,
MBS-11398
Chassis Correction is not supported for IPv6 local connections initiated from the Standby chassis. R80.20SP
PMTR-111445,
MBS-14200
All RIPng (IPv6) is not supported. R76SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Firewall
PMTR-111383,
MBS-14173
All ConnectControl is not supported. R76SP.50
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - VPN
PMTR-111847,
MBS-12310
All Large Scale VPN (LSV) is not supported. R81
PMTR-111366,
MBS-14408
All Simultaneous Login Prevention (SLP) is not supported. R80.20SP
PMTR-111444.
MBS-4097
All - Site-to-Site VPN with IPv6 peers is not supported.
- Remote Access VPN from IPv6 clients is not supported.
R80.20SP
AAD-1653,
MBS-8316
All IPv6 VPN is not supported. R80.20SP
PMTR-111443,
MBS-7914
Maestro Multiple Entry Points (MEP) configuration using Dead Peer Detection (DPD) is not supported. R80.30SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Identity Awareness
PMTR-111378,
MBS-14460
Maestro Maestro Security Group does not support the Identity Awareness Captive Portal if the L4 distribution is enabled. R80.20SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - DLP
PMTR-111370,
MBS-13243
All The Data Loss Prevention Software Blade does not support rules with the Action "Ask". R80.20SP
PMTR-108607,
01157859, 01349731
All DLP Fingerprint is not supported. R76SP
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Threat Prevention
PMTR-111385,
MBS-12329
All Inspection of SMBv3 multi-channel with Anti-Virus and Threat Emulation Software Blades is not supported. R81
ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Mobile Access
PMTR-111377,
MBS-14368
All The Mobile Access Portal Agent is not supported. R80.20SP

Known Limitations

Installation and Upgrade

Enter the string to filter the below table:

ID Description Found in version
Installation and Upgrade
PMTR-109123 Because of postgres limitation, upgrades fail when policy contains groups with more than 32000 members.
- A verification that prevents the upgrade if oversized groups exist was added.
R82
PMTR-108824 The " Timeout waiting for response from database server" message may be shown when performing " set snapshot revert" and the member goes to reboot. The issue is cosmetic only. R82
PMTR-61069 SmartEvent upgrade is allowed only after all Multi-Domain Management Servers with Active Domain Management Servers are upgraded. R81

Licensing

Enter the string to filter the below table:

ID Description Found in version
Licensing
PMTR-47532 When loaded for the first time, web components such as the licensing or monitoring view can take up to thirty seconds to show. R80
PMTR-47101 In the License Status View, the Additional Info column, quota information and quota statuses are not available for pre-R80 Gateways and Servers. R80
PMTR-47103 Automatic license activation on Check Point appliances is not available on pre-R80 appliances. R80
PMTR-47308 The proxy that synchronizes license information with the User Center, must be at least R80 Server. R7x
PMTR-47531 On SmartEvent NGSE dedicated machine, license information is not automatically updated when Installing Database.
When you enable or disable a blade, one of the following will update the license information with the change:
- If you force a license update, changes occur immediately.

To force a license update: On the R81 Security Management Server, run the following command in Expert mode:

[Expert@HostName]# $CPDIR/bin/esc_db_complete_linux_50 bc_refresh <Name of Target Object>
- Automatic update at midnight
- If you manually change a license or contract on a dedicated machine, changes take effect within 20 minutes
R7x

Quantum Security Gateway   / Gaia OS / VSX (Traditional)/ VPN / QoS / ClusterXL

Quantum Security Gateway | Gaia OS | VSX (Traditional) | VPN | QoS | ClusterXL

Enter the string to filter the below table:

.

ID Description Found in version
Quantum Security Gateway
PMTR-107789 Upon reopening an IDP object, the previously entered data may not be visible. R81.20
PMTR-59152 Traffic on a single GRE tunnel cannot be distributed to multiple CoreXL Firewall instances.
Therefore, the maximum throughput of a single GRE tunnel is limited by the throughput of a single CoreXL Firewall instance.
R81
PMTR-38747 Output of the fw ctl zdebug + drop command shows messages about connection drops, in addition to Firewall drops. 
These are internal debug messages that do not reflect real Firewall drops. To avoid them, use one of these:
1. The fw ctl zdebug drop command without the "+" character in the syntax
2. The full debug procedure
R80.20
PMTR-42525 When Using a rule with legacy object, in or below a rule with one of the new features that are integrated in the unified policy, install policy on a Security Gateway fails with a verification message.
- To resolve: change the order of the rules so that rules with legacy objects are above rules with new features. Refer to sk115961.
R80.10
PMTR-109230,
PMTR-47316,
PMTR-17546
Logging session does not switch to the backup logging Server after connectivity loss. Refer to sk118697. R7x
Gaia OS
PMTR-51440 While the 4x10G Fiber NIC (CPAC-4-10F-B) is installed in the appliance, the HW Diagnostics "Network Test" fails with these messages:
Network Test: Failed
General Error
R81
PMTR-81308,
GAIA-3345
Changing the MTU on the directly connected switches may cause drops of fragmented traffic due to a MTU mismatch. R80.30
PMTR-47577 If the backup schedule is changed to an invalid date or time, all backup schedules are lost and " Backup schedule failed. The backup will not be scheduled" error message is displayed. R80.10
VSX (Traditional)
PMTR-60160 You can use the vsx_util downgrade command only if you did not make any configuration changes after you used the vsx_util upgrade command. R81
VPN
PMTR-101631 "IPSec VPN" page in the Security Gateway object still shows a selected VPN Community, although the configuration changes were discarded. Refer to sk182068. R82
PMTR-68228 If the Diffie-Hellman (DH) group configuration is changed (SmartConsole > Global Properties > Remote Access > VPN - Authentication and Encryption > Encryption algorithms > Edit > Phase 1 > Use Diffie-Hellman group) while an Endpoint VPN client is connected, the client disconnects during the next Phase 2 negotiation. R81
PMTR-55445 Site to Site VPN with a Large Scale VPN profile can drop traffic after decryption with the log " According to policy traffic shouldn't have been decrypted".
To prevent this traffic drop:
1. Edit the Large Scale VPN profile object:
1. On the VPN Domain page, in the section "IP addresses allowed in the VPN Domain" select "Restrict to these groups or networks"
2. Select the applicable "Host", "Network", and "Group" objects.
2. Edit the LSV peer object: 
1. In the VPN Domain (Encryption Domain), select the "Address Range" objects, whose IP addresses contain the IP addresses of the "Host", "Network", and "Group" objects you selected in the Large Scale VPN profile object.
3. Install the Security Policy.
R81
PMTR-25046,
PMTR-33694,
PMTR-44902
After running the cpstop ; cpstart commands, the " FW-1: fwconn_chain_get_opaque: invalid id -1" message appears repeatedly on the screen and in the dmesg. This is a cosmetic issue only. R80.20
PMTR-58668 If a Security Gateway with PIM configured is part of a VPN community, PIM service must be added to the Excluded Services in the VPN community object.
This only applies in one of these scenarios:
- Security Gateway is directly connected to a multicast sender
- Security Gateway is configured as a PIM Rendezvous Point
R80.10
PMTR-47752 The VPN client shows as " Not Compliant" when it is not compliant according to the local.scv file, even if SCV is disabled.
- To resolve: Configure the VPN site again on the client.
R80.10
PMTR-47501 When using a VPN client, activity logs are not generated for ICMP traffic. R7x
PMTR-32305 RADIUS authentication fails for LDAP users as the Security Gateway uses sAMAccountName and not UPN when UPN is needed. Refer to sk122477. R7x
PMTR-104094 If Perfect Forward Secrecy is enabled, Remote Access VPN client may disconnect from the Security Gateway in one hour. R82
QoS
PMTR-47566 No warning is displayed if an empty network group object appears in the source or destination column. R7x
ClusterXL
ACCHA-3403 Traffic outage may occur in a ClusterXL / VSX Virtual System configured in the Active/Standby Bridge Mode after a cluster failover that was caused by the disconnection of the direct bridge link. R80.10

Quantum Security Management   / Multi-Domain Security Management / Compliance / Logging / SmartEvent / SmartProvisioning

Quantum Security Management | Multi-Domain Security Management | Compliance | Logging | SmartEvent | SmartProvisioning

Enter the string to filter the below table:

ID Description Found in version
Quantum Security Management
PMTR-116108 Wildcard objects do not appear in the search results when searching by IP address. R82
PMTR-74025 In API commands like show-software-packages-per-targets and in the SmartConsole, the "installed" field remains empty. As a result, The Security Management is not aware of the specific image installed on SMB appliances, but only of the version. R81.20
PMTR-85908 When configuring the SD-WAN interface of the Security Gateway with the set_sdwan command and then perform "Get Interfaces" in SmartConsole while the interface has already been listed on the Network Management page (as internal), the interface may not turn to external as expected.
- To resolve: Remove this interface from the Network Management page and perform "Get Interfaces" again.
R81.10
PMTR-51456 The value configured in SmartConsole > Global properties > Advanced > Configure > Central Device Management > " device_settings_max_script_length_in_KB" field is not applied.
The upper limit is always 8 kilobytes.
R81.10
PMTR-56141 When fetching a VPN Tunnel Interface (VTI) from Cluster Members using the get-interfaces Management API command, you must configure the Cluster VIP address using the set simple-cluster API before publishing the session.
Examples:
1. mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "private"
2. mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "cluster" interfaces.update.ip-address 1.2.3.4 interfaces.update.ipv4-mask-length 24
R81
PMTR-60100 When creating a rule with the "Detailed Log" track without "Accounting" disabled, the "Accounting" still appears after you close and open SmartConsole.
- To resolve: Modify the rule to remove the "Accounting" setting.
R80.40
PMTR-50315 " Certificate with the same Distinguished Name already installed for another CA" message in SmartConsole in the following scenario:
1. A user started to create a new Trusted CA object with a certificate
2. A user discarded the session
3. A user tried to create a new Trusted CA object with the same certificate
R80.40
PMTR-81309,
PRHF-14607
Running a one time script on a Security Gateway (that reads files or outputs of commands) using a "One Time Script" feature in SmartConsole or with API may fail after 5 minutes with the "Operation timed out" error.
The limit for reading files is 9,730 lines or 730 KB (whichever is reached first).
R80.10
PMTR-54350 The API show access-rule with the specified values from-date or to-date in the hits-settingparameter, returns accurate data only when these timestamps cover more than the last 24 hours.
For example, on May 27th at 14:00, the query must not cover any part of the last 24 hours (between May 26th at 14:00 and May 27th at 14:00).
R80.10
PMTR-47133 Internal user names must contain only English characters. Names in other languages (unicode) will show as question marks in the Users and Administrators window. R80
PMTR-41764 The "URL" field shows " \\\* Confidential ***" in HTTPS Inspection logs on 3rd party LEA OPSEC client. R7x
Multi-Domain Security Management
PMTR-62123 In Multi-Domain Servers, you cannot create an install policy preset with a policy package that has an OSE device as the target, due to an internal error when trying to get target information. R81.10
PMTR-60856 To correlate logs from the Domain Management Server in a NAT environment, in which a Domain Management Server is hidden behind a NATed address, and a Domain Dedicated SmartEvent Server has an external IP address, an administrator must follow these steps:
1. Connect with SmartConsole to the Domain Management Server
2. Create a dummy Check Point Host object with the external IP address of the Domain Management Server
3. Enable the "Logging" Software Blade in this Check Point Host object
4. Install database on the Domain Management Server
5. Open the SmartEvent GUI and connect to the Dedicated SmartEvent Server
6. In the list of the log servers, from which the Correlation Unit reads the data: remove the Domain Management Server object with the real IP address and add the dummy Check Point Host object (with the external IP address)
7. Install the Event Policy and close the SmartEvent GUI
R81
Compliance
PMTR-47756 In a Multi-Domain Management environment, in the local Domain policy, some Compliance best practices, which validate the status of rules in the policy, incorrectly identify the section header, "Parent section for domain rules," as a rule, and report it as not valid.
- To resolve: Manually exclude this result from the Best Practices view. To do so, in the Best Practices view, select the practice. In the bottom pane > Relevant Object section > double-click the desired rulebase object and disable the rule/section from the list.
R80.10
02449324,
02478559,
PMTR-47761
In a Multi-Domain environment, policy changes in the Global Compliance Policy do not trigger a partial Compliance scan. R80.10
PMTR-47237 Compliance Blade does not contain Compliance Overview Report.
- To resolveand have the Compliance Overview Report, deploy a SmartEvent Server and enable SmartEvent. Then find it at Logs & Monitoring > new tab > Reports > Compliance Blade.
R80
Logging
PMTR-106428 When disconnecting the Security Management Server from the Infinity Portal and connecting to a different region, log sharing from Log Servers does not work until the Log Server restarts.
- Resolved in R82 Jumbo Hotfix Accumulator Take 25(PRJ-60574)
R82
PMTR-103823 if no log-sharing exporter is created on the MLM Server before the upgrade, the log-sharing exporter is not created after the upgrade.
- Resolved in R82 Jumbo Hotfix Accumulator Take 25 (PRJ-60574)
R82
PMTR-92829 The output of the commands cpstat mg -f log_server or cpstat ls -f logging on a Security Management Server or Log Server that receives logs from a Maestro Security Group displays Log Receive Rate only for the individual Security Group Member (SMO), and not the combined log receive rate for all Security Group Members in the group. R81.10
SmartEvent
PMTR-50435 On a dedicated SmartEvent Server, the user that was configured in the First Time Configuration wizard cannot share items and view shared items In the SmartView application. R81
PMTR-66532 SmartConsole > "Logs & Monitor" view > "Logs" tab may show duplicate log records with partial data, if log entries are spread over several log files due to a log switch.
Log switch operation occurs in these scenarios on a Management Server / Log Server:
- At midnight
- When the size of the active log file reaches 2 GB
- Based on user configuration (explicitly)
R80.20
PMTR-47559 On a R80.x dedicated SmartEvent Server which assigned to MDS, when you enable or disable a blade, the license information is not immediately updated. An automatic updates takes place at midnight.
- To resolve and update immediately, оn Server's command line, run:

$CPDIR/bin/esc_db_complete_linux_50 activation_data entitlement_dataIf you manually change a license or contract, the changes take effect immediately.
R80
SmartProvisioning
PMTR-56630 When you configure an LSM profile topology, do not reopen interface properties after you make a change.
Instead, close the Topology grid and click OK to close the editor.
When you reopen it, you will see the correct interface topology settings.
R81
PMTR-49235 A new object called "NewObject" is left in SmartConsole when an administrator creates a new object with same name as an object that exists in SmartProvisioning.
- To resolve: Either click "No" when SmartConsole shows "Do you want to keep changes anyway?"

or manually delete the new object called "NewObject".
R81
PMTR-45475 The status of an SMB device in SmartProvisioning may show " not responding" for a short time, even though the status is OK. R80.40
PMTR-1568 When working with LSM managed Security Gateways in a Management High Availability environment, creating and working with LSM Gateways must be consistent, they can only be used in the Security Management Server they are created in.
Using the secondary Security Management Server might lead to inconsistent actions/status related to LSM objects.
R80.20.M1
PMTR-70744 The "Enable Provisioning" checkbox is greyed out in SmartProvisioning > SmartLSM Security Gateway object properties > "General" tab > "Provisioning" section, if the user who logged into SmartConsole has a profile with assigned permissions other than "Read/Write All". R80.10
PMTR-8209 After a major upgrade to a Security Management Server, LSM profiles lose their installed policy and new devices attached to them are not able to fetch a policy.
- To resolve: Install policy on the LSM profiles.
R7x

SmartConsole   / Management Console / SmartLog  / SmartView

Enter the string to filter the below table:

ID Description Found in version
SmartConsole / Management Console
PMTR-109351 Changing language with Ctrl+F2 may cause SmartConsole to terminate unexpectedly. R82
PMTR-98504 There may be a latency in connecting to SmartConsole with an administrator configured on an AD (LDAP) server. R82
PMTR-116746 The Policy Insight dialog may have inconsistent behavior if the screen DPI settings are not set to 100%.
- Resolved in R82 SmartConsole Build 1065
R81.20
PMTR-86567 When using the Updatable objects picker, the search may retrieve previously selected item's additional information. R81.20
PMTR-62190 When creating a test user via the Mobile Access configuration page, the user's password is limited to 8 characters. R81.20
PMTR-81166 In a Multi-Domain Environment, when log in with SSO to a Domain behind NAT, the Security Gateway object will load but not open.
- To resolve: Connect to the Domain directly.
R81.20
PMTR-71266 In SmartConsole, the "Get Interfaces" operation in a cluster object does not fetch interfaces with IP addresses from the subnet 1.1.1.0.
- To resolve: Use the get-interfaces Management API.
R81.20
PMTR-108389 " SmartDashboard not able to connect to XXXX" error message when there is no connectivity or there are no users to fetch from the LDAP Server. R81.10
PMTR-70168 Open connections may not survive VSLS upgrade using SmartConsole Central Deployment. R81.10
PMTR-70829 Central Deployment Package Repository is local to the Multi-Domain Server. In a Multi-Domain High Availability environment, make sure to initiate Central Deployment operations on the Server to which the package was added. R81.10
PMTR-58448 When the screen resolution is low, changes in Log View widgets are not exported in PDF files:
1. In SmartConsole, from the left navigation panel click Logs & Monitoring.
2. Click + to open a new tab.
3. From the left, click Views, and open any view.
4. Click Options > Edit.
5. Make some layout changes - move, resize, delete, or add widgets, and click Done.
6. Click Options > Export > Export to PDF.
7. Download the PDF and open it.
8. The PDF file has the default layout.
R81.10
PMTR-68527 When you enter a search query that starts with “*” in various search fields (for example, *168.20), SmartConsole shows only objects that contain this partial string in their "Name", "Comment", or "IP Address" field. R81.10
PMTR-58272 In the "Gateways & Servers" view, the "Task" tab in the bottom pane does not show messages about a successful license attachment (shows messages only about a failed license attachment). R81.10
PMTR-60830 A link named " #.name" appears in a policy (above the Shared Policies section) in this scenario:
1. From the left navigation panel, click the Security Policies view
2. Open a policy with the HTTPS Inspection
3. Click Access Control > HTTPS Inspection
4. In the Certificate column, right-click a certificate and select Where Used
5. In the Where Used window, click the Policies tab
6. Double-click a policy that does not contain the Access Control (contains only Threat Prevention or QoS)
7. The policy opens, but instead of HTTPS Inspection section, a link named " #.name" appears
- To resolve:

1. Close the Where Used window
2. Manually open the affected policy
R81.10
PMTR-78482 If you delete an existing object of a Centrally Managed Quantum Spark appliance with the model 1800 or lower and some name (for example, "XXX"), then you cannot create another object of a Centrally Managed Quantum Spark appliance:
1. With the same name "XXX" - SmartConsole shows " Name already used!"
2. With the name of that contains the previous name (for example, "XXXnew") - SmartConsole shows " There is another network object [XXX] with the same IPv4 address"
R81
PMTR-58838 Changes (Diff) report:
- does not track rule numbers or rule positions in the policy (If a sub-rule is changed, the report only shows the number of the sub-rule and not the number of the parent rule).
- does not show changes made in: Inspection Settings, Software Blade Engine settings, Multi-Domain Management Server settings, and administrator settings (including permission profiles and all other options in Manage & Settings > Permissions & Administrators).
- In the Changes (Diff) report, there is inconsistency between the number of changes that appear in the session toolbar and the Revisions view.
R81
PMTR-42956 In HTTPS Inspection policy rules, when selecting the same action that already appears in the "Action" column, the Management Server counts it as part of the session changes. R80.40
PMTR-38804 The "Import Node" action (accessible from the SmartConsole Network Object tree > Nodes > Import) can fail with " Internal Error" message. R80.40
PMTR-31345 In languages other than English, the blades in the summary tab are not arranged correctly. R80.30
PMTR-27705 When installing a policy, " The policy included Blades that have an expired contract or a contract that is about to expire" warnings are displayed only for Application Control and URL Filtering and not for all Service Blades. R80.30
PMTR-31193 Search for disabled or expired rules in Access Control policy does not work. R80.30
PMTR-25063 The "Groups" page / tab is not shown if you edit a predefined service. R80.20.M2
PMTR-39387 Hitcount of Shared Inline Layer rules shows the sum of all rules it is used in as it is shared between all of them. R80.20
PMTR-50263 No warning is displayed, if an empty Network Group object appears in the "Source", "Destination", or "Protected Scope" column of a Threat Prevention policy rule. R80.10
PMTR-40848 When an inline layer appears more than once in an ordered layer, in logs that are generated from rules in that layer, the "Go to rule" link does not always navigate to the correct occurrence of the rule in the policy.
- To find the other occurrences of the rule, use the packet mode search with the rule's information. For more information about packet mode search, refer to sk118592.
R80.10
PMTR-82170 After upgrading the Security Management Server from to R80.x, users cannot add suggestions to add objects to group - the options are grayed out. Refer to sk118276. R80.10
PMTR-36940 When selecting a source or destination for a user object, cluster objects are not available for selection. R80.10
SmartLog / SmartView
PMTR-55182 In the Logs view, the sessions timeline widget is missing when connecting to the SmartView web interface of a Dedicated Log Server or a Domain Log Server. R81.10
PMTR-42730 When viewing logs in the SmartView Web portal, the description fields are empty. R80.40
PMTR-44559 When querying logs in the SmartView web Logs tab, the numbers shown in the timeline section do not correlate to the log list if the indexing retention policy in SmartEvent and the Log Server are not the same. R80.40
PMTR-45323 Updatable objects are not resolved in SmartLog/SmartEvent queries:
1. You cannot create a filter or SmartView query which contains an Updatable object name.
2. When viewing logs/events, the IP address of an Updatable object is not resolved to a name.
R80.20.M2
PMTR-47699 In a global SmartEvent configured in Multi-Domain environment, SAM rules are not created by events auto-reactions.
- To resolve: refer to sk86941.
R80.10
PMTR-47589 Users connected with SmartConsole to specific Domain, will not be able to see Global objects assigned to this Domain in SmartLog logs results, and cannot search by Global objects (but can search by IP address). R7x

Access Control   Mobile Access / DLP

Mobile Access | DLP

Enter the string to filter the below table:

ID Description Found in version
Mobile Access
PMTR-41608 Error: " Failed to generate RADIUS auth request" when a Mobile Access user browses to a resource that requires authentication. R80.40
PMTR-70 If you use Outlook Anywhere application with Mobile Access Reverse Proxy, and then want to disable Outlook Anywhere or Reverse Proxy, perform:
1. Delete Outlook Anywhere rule from reverse proxy.
2. Run cvpnrestart --with-pinger to close all Outlook Anywhere open connections.

If you do not perform step 2, open connections of Outlook Anywhere will not be closed and users can still work with it.
R80.10
PMTR-47782 After upgrading a Standalone (Management and Gateway) or VSX deployment with Mobile Access blade enabled, the " Allow Dynamic ID for mobile devices" option might be enabled by default, even if Dynamic ID was not configured prior to the upgrade.
- If you do not want Dynamic ID authentication for Capsule Workspace users, disable it in:

Gateway Properties > Mobile Access > Authentication > Compatibility with Older clients > Settings > Capsule Workspace section > clear Enable DynamicID.



For VSX, this configuration is done per Virtual System.
R80.10
PMTR-47499 When Mobile Access is included in the Unified Access Policy, in Mobile Access Authorization logs > Log Details > Matched Rules, the Mobile Access Application name and Category do not show. R7x
DLP
PMTR-47691 DLP can apply visible or hidden Watermark (for forensic tracking) to Office Open XML formats (DOCX, PPTX and XLSX) as a rule action in a DLP rule base.
Refer to sk117413 if DLP Watermark is used.
R80.10

Threat Prevention

Enter the string to filter the below table:

ID Description Found in version
Threat Prevention
PMTR-107710 The "DNS Mismatched replies" IPS protection does not work after upgrade to R82. R82
PMTR-107493 DNS NAT does not work on R82 Security Gateways. R82
PMTR-107712 In some scenarios, DNS Trap may fail to replace DNS replies with bogus IP addresses on certain connections, resulting in dropped connections. This prevents affected hosts from receiving the intended IP address but also limits the visibility into which host IPs are impacted. R82
PMTR-85353 When you activate Threat Emulation with the "Hold" mode, Threat Extraction, Zero Phishing, or Anti-Virus Deep Inspection, the Security Gateway downgrades the relevant connections from HTTP/2 to HTTP 1.1.
To force HTTP/2, run this command on the Security Gateway / Security Group / each Cluster Member:
fw ctl set -f int disable_http2_with_strict_hold 0
Limitation: Zero Phishing will keep downgrading HTTP/2 to HTTP 1.1.
R81.20
PMTR-80495 An exception in an Anti-Virus or Anti-Bot protection added manually to the rule base does not work.
- To add an exception in an Anti-Virus or Anti-Bot protection, open the corresponding Security Gateway log in SmartConsole and click the link "Add Exception".
R81.20
PMTR-76710 When Security Gateways use an Autonomous Threat Prevention policy:
- Compliance Best Practices do not support the checks for the Threat Prevention Software Blade.
- The Compliance Software Blade may show an incorrect status for the Threat Prevention checks.
R81.20
PMTR-19839 CRL validation is not supported in pure IPv6 environments (when IPv4 addresses are not configured on the Security Gateway's interfaces). R80.20

Endpoint Security

ID Description Found in version
Endpoint Security / SmartEndpoint
PMTR-68226 The Perfect Forward Secrecy (PFS) feature supports only Diffie-Hellman (DH) groups 2 and 14. R81.10

Quantum Spark Gateways

ID Description Found in version
Quantum Spark Gateways
PMTR-47520 " SIC error" status may occur when the Gateway object is defined in a "Management first" scenario before it is deployed, but the device's IP address is already accessible. The Security Management tries to create SIC with the Gateway's IP address. Instead of the policy ending in a "waiting for first connection" status, an error message states the SIC status must be rectified first. R7x

ElasticXL, Maestro, and Scalable Chassis

General Limitations | Gaia OS | VSX | CoreXL | Networking | VPN

Enter the string to filter the below table:

ID Product Description Found in version
ElasticXL, Maestro, and Scalable Chassis - General Limitations
PMTR-107075 ElasticXL ElasticXL Cluster supports only physical Check Point appliances (Virtual Machines or Open Servers are not supported). R82
PMTR-107076 ElasticXL ElasticXL Cluster supports only Check Point appliances of the same model. R82
PMTR-107077 ElasticXL ElasticXL Cluster requires each appliance to be after a Clean Install or restored to factory defaults. R82
PMTR-107078 All ElasticXL Cluster requires the supported Check Point appliance to run SecureXL in the Kernel Mode (KPPAK). The Gaia First Time Configuration Wizard automatically changes the SecureXL mode from UPPAK to KPPAK on the supported appliances. R82
PMTR-111692 Maestro If a Maestro Security Group (in the VSNext mode or Traditional VSX mode) is configured with MAGG, then adding a new Mgmt interface to this Security Group in Gaia gClish or with API may fail because the Gaia database lock is continuously lost.
During this issue, the /var/log/messages file repeatedly shows:
cmd by admin: Start executing : add bonding ...
cmd by admin: Start executing : delete bonding ...
Refer to sk183031.
R82
PMTR-109641 Maestro In rare scenarios, after installing R82 on Maestro Orchestrator, the LLDP daemon (lldpd) is running but paused, and therefore does not transmit or process LLDP PDUs. As a result, MHO cannot communicate with the gateways.
- **To resolve:**From the Expert mode, run on MHO:

lldpcli resume
R82
PMTR-109620 Maestro In rare scenarios, authentication between MHOs is not established. Trying to establish authentication manually fails with error: "TrustEstablishmentError: Failed to set up communication user on host 1_1: invalid literal for int() with base 10"
- To resolve:
- look for an available UID in the range 105-1000 using the command: `dbget -rv passwd
grep :uid
HCP-1082 Maestro HCP on MHO may fail because of timeout expiration since execution is on all MHOs in parallel R82
PMTR-97177 All The set backup restore ftp command performed via gClish is not applied on all the Security Group members but only on the SMO member.
- **To resolve:**to perform the restore action on all the Security Group members, run it via the local Clish on each member.
R82
PMTR-104761 Chassis On Scalable Chassis, after you move an SGM from one chassis to another, it is necessary to reboot the SGM. R82
PMTR-108738 All During the upgrade of Scalable Platform Security Group Gateways, SSH keys are deleted.
- Resolved in R82 Jumbo Hotfix Accumulator Take 14 (PRJ-58561)
R81.20
PMTR-109848 All Scalable Platform Site grade is not affected by the number of active subordinate interfaces in a LACP bond interface. Therefore, LACP bond failover is not triggered if all of the subordinate interfaces become inactive in the LACP bond interface. R81
PMTR-93476 All Management Aggregation (MAGG) bond mode is available only through the gClish of the Security Group (and not via the Gaia portal). R80.20SP
PMTR-111361,
MBS-6188
All - The Active-Backup bond is supported only when a Primary slave is configured (for example: set bonding group 1 primary eth1-05).
- The Active-Backup bond supports a maximum of 2 slaves.
R80.20SP
PMTR-111372,
MBS-14811
Maestro Maestro Orchestrators and Security Group CIN interfaces are configured in the subnet of 198.51.10<SG_ID>.0. You cannot use this subnet for data and management interfaces. R80.20SP
PMTR-109475,
02439227
Chassis Scalable Chassis 44000 support PXE installation on Slot 6 (SGM 2_06 / SGM 1_06) by changing the kdevice to eth3. R76SP.50
PMTR-109479,
00738754
Chassis If SGMs lose connectivity to the CMM, the asg stat command displays the most recent status of the system. For example, a chassis module that was "UP" before the CMM lost connectivity, continues to have the status "UP". The state of the CMM is changed to "DOWN". R76SP
PMTR-109467,
00894653
Chassis Transceivers for the Scalable Chassis are not interchangeable with transceivers from other Check Point appliances.
Only transceivers provided with the Scalable Chassis are certified for this system.
R76SP
ElasticXL, Maestro, and Scalable Chassis - Gaia OS
PMTR-114355 ElasticXL,
Maestro
In the VSNext mode (on ElasticXL and Maestro Security Groups), the Gaia gClish / Gaia Clish command "show interface" in the context of Virtual Switches fails with "CLINFR0699  Invalid command". R82
PMTR-107433 ElasticXL Adding an unassigned interface to or from Sync bond leads to the flags reset and, as a result, it disrupts the ElasticXL detection and ElasticXL drops the packets. R82
PMTR-109292 All Configuring a Unique IP per Site over the management interface is not possible if Management Data Plane Separation (MDPS) is enabled. R82
PMTR-71458 Maestro Collecting Gaia Backup and restoring Gaia Backup in Global Clish (gclish) is not supported on a Security Group that contains appliances of different models.
- To collect Gaia Backup and restore Gaia Backup, you must use Gaia Clish (clish) on each appliance in the Security Group.
R81.10
PMTR-111391,
MBS-7069
Maestro Remote authentication for the Expert mode using RADIUS / TACACS+ Servers with the Gaia gClish command "`set expert-authentication-method {shared-password user-password}`" is not supported.
PMTR-111365,
MBS-7593
Maestro On a Maestro Security Group, the Security Gateway does not show the correct speed of data and management interfaces. Run commands on the Orchestrator (the orch_stat -p command and Clish commands) to see the interface speed. R80.30SP
PMTR-111389,
MBS-964
All A Security Group cannot be configured as an NTP Server. R80.20SP
PMTR-111376,
MBS-5177
Maestro Maestro Security Groups do not support these Gaia Clish commands:
- set chassis id VALUE alert_threshold cpus_temperature_threshold_low VALUE
- set chassis id VALUE alert_threshold fans_threshold_high VALUE
- set chassis id VALUE alert_threshold fans_threshold_low VALUE
- set chassis id VALUE alert_threshold power_consumption_threshold_perc_high VALUE
- set chassis id VALUE alert_threshold power_consumption_threshold_perc_low VALUE
- set chassis id VALUE modules_amount cmm VALUE
- set chassis id VALUE modules_amount fans VALUE
- set chassis id VALUE modules_amount power_units VALUE
- show chassis high-availability factors sensor cmm
- show chassis high-availability factors sensor fans
- show chassis high-availability factors sensor power_supplies
- show chassis id VALUE alert_threshold cpus_temperature_threshold_high
- show chassis id VALUE alert_threshold cpus_temperature_threshold_low
- show chassis id VALUE alert_threshold fans_threshold_high
- show chassis id VALUE alert_threshold fans_threshold_low
- show chassis id VALUE alert_threshold power_consumption_threshold_perc_high
- show chassis id VALUE alert_threshold power_consumption_threshold_perc_low
- show chassis id VALUE modules_amount cmm
- show chassis id VALUE modules_amount fans
- show chassis id VALUE modules_amount power_units
R80.20SP
PMTR-111373,
MBS-14992
All To prevent the Gaia configuration mismatch between Security Group Members, it is not supported to change the user's password on a Security Group in these ways:
- In Gaia Portal > User Management > Change My Password
- In Gaia gClish with the command set selfpasswd
To change the user's password on a Security Group, run one of these commands in Gaia gClish:
- set user <UserName> password
- set user <UserName>password-hash <Password Hash>
R80.20SP
PMTR-111388,
MBS-6947
Maestro In Dual Site deployment, no warning is displayed when changing the "type" of the QSFP port in Gaia Clish on Maestro Hyperscale Orchestrators on the local site, while the Maestro Hyperscale Orchestrators on the remote site are down. R80.20SP
PMTR-109472,
02434343
Chassis On SSM440, the error "Dot3Ah: Failed getting variable from bm" may appear when running the system reload command. R76SP.50
PMTR-109473,
02169635
Chassis On SSM440, the MTU is limited to a maximum of 9000 bytes. R76SP.50
PMTR-109474,
01237799
All When you run multiple Gaia gClish set <...> commands, one after another, some of these commands can stop running.
When this happens, the message "Processing Transaction" shows in the output.
R76SP
PMTR-108599,
00738300
All The asg commands are an extension of native Gaia gClish commands.
The asg commands have different syntax and there is no auto-completion.
R76SP
PMTR-109471,
01255170
Chassis For monitoring Scalable Platforms over the SNMP, the only supported OIDs are under iso.org.dod.internet.private.enterprise.checkpoint.products.asg (OID 1.3.6.1.4.1.2620.1.48). R76SP
PMTR-108600,
00642401
All A CLI command that uses a range for the parameter can only operate if all the relevant SGMs are defined in the security group. R76SP
PMTR-108601,
00633262
All The arguments of the global commands are processed before the local (native) arguments, and this can cause the local arguments to be ignored. For example, the g_ls -l /tmp/ command is processed as ls /tmp/ on the local SGM instead of as ls -l /tmp/ on all SGMs.
Relocating the local arguments within the command (where applicable) can resolve the problem. For example, run the g_ls /tmp/ -l command instead of the g_ls -l /tmp/ command.
R76SP
PMTR-108602,
01089206
All Running the asg_hard_shutdown command on an SGM two times, one after the other, causes a reboot and not a shutdown.
It takes one minute for the SGM to shut down after running the asg_hard_shutdown command. During this interval, do not run the asg_hard_shutdown command again.
R76SP
ElasticXL, Maestro, and Scalable Chassis - VSX
PMTR-110224,
PMTR-108696
ElasticXL VSLS (Virtual System Load Sharing) is not supported in the VSNext mode.
- Resolved in R82 Jumbo Hotfix Take 14 (PRJ-58348)
R82
PMTR-106379 ElasticXL In ElasticXL in the VSNext mode (with 2 or more Security Appliances on one ElasticXL Site), VoIP UDP traffic is not supported between networks in this topology:
Network 1 - Virtual System 1 - Virtual Switch - Virtual System 2 - Network 2
R82
PMTR-108547 ElasticXL No information is shown on both servers when attempting to see the LLDP (lldpneighbors) between Security Management and a Virtual Gateway. R82
PMTR-113662 All In a Dual Site VSX VSLS environment, when using MVC (Multi-Version Cluster), it is required to change a site priority of the Virtual System on both sites in order to change the active site for a given Virtual System. R81.20
PMTR-111446,
MBS-6572
Maestro A change in the number of CoreXL Firewall instances (in a VSX Virtual System object in SmartConsole) in Dual Chassis VSLS setup requires a downtime, because the Virtual System must be restarted. During this restart, traffic cannot pass through the Virtual System. R80.20SP
PMTR-109478,
02024482
All After running the vsx_util reconfigure command on the Management Server, the VLAN interface on a Security Group in VSX mode may come up without an IP address if the VLAN's MTU was set to a value larger than 1500.
Refer to sk111513.
R76SP.40
PMTR-109469,
01812597
All No local configuration should be performed on a Security Group or on a Security Group Members while the vsx_util reconfigure command is running on the Management Server.
It is necessary to wait until all Security Group Members and Virtual Systems are up and running (otherwise, the local configuration will not be applied).
R76SP.30
PMTR-109468,
01620389
All You cannot configure Bond interfaces on chassis Management ports after you create the VSX object in SmartConsole. R76SP.20
PMTR-109477,
01087321
Chassis VSX Gateway creation in SmartConsole and the vsx_util reconfigure command are supported when only the left-most SGM is in the Security Group. R76SP
PMTR-108604,
01284809
Chassis To use the Sync Lost mechanism, you must keep the Management interfaces for both chassis connected. R76SP
PMTR-109476,
00922958
All The Alerts configuration wizard does not allow setting of performance thresholds per Virtual System.
- To resolve: You can manually configure thresholds for Virtual Systems using the dbset command from the Expert mode:

g_all dbset chassis:vs:0:alert_threshold: <alert_name> <value>



Where <value> is the percentage of the default threshold per Security Group Member.



Example:

[Expert@Host]# g_all dbset chassis:vs:0:alert_threshold:packet_rate_threshold_high 30



In this example, an alert is triggered when any Virtual System packet rate is higher than 30% x 1.8MB (1.8MB is the default packet rate threshold per SGM).

Note: One ratio applies to all Virtual Systems.
R76SP
PMTR-109465,
01097957
All If you lower the Connections Table limit of a Virtual System, and one of the SGMs has more or the same number of connections than the limit, the new value is rejected for that SGM. The new Connections Table limit may be accepted by other SGMs.
Notes:
- To see the current number of entries in the Connections Table, run the fw tab -t connections -s command in the Expert mode.
- To configure the Connections Table limit of a Virtual System: In SmartConsole, open the Virtual System object > Go to the "Capacity Optimization" pane > Set the value in the "Limit the maximum concurrent connections" field > click OK > Install the policy.
R76SP
PMTR-109466,
01341918
All You cannot enable IPv6 before you create and configure a new VSX Gateway. You must first create the new VSX Gateway and then enable and configure IPv6 using Gaia gClish. R76SP
ElasticXL, Maestro, and Scalable Chassis Known Limitations - CoreXL
PMTR-74532 All To make sure there is connectivity after changing the number of instances in the CoreXL configuration, follow these steps:
1. Reboot all Security Group Members one by one, except the SMO.

IMPORTANT: Traffic capacity is greatly reduced after you reboot all Security Group Members except the SMO, because only the SMO handles traffic until it is rebooted.

Examples:

In a Dual Site deployment with four Security Group Members (two on each Site), where the SMO is "1_1", reboot the Security Group Members in this order:


1. Reboot the Security Group Member 2_2 on Site 2 and wait for it to finish the reboot.
2. Reboot the Security Group Member 2_1 on Site 2 and wait for it to finish the reboot.
3. Reboot the Security Group Member 1_2 on Site 1 and wait for it to finish the reboot.
In a Single Site deployment with four Security Group Members, where the SMO is "1_1", reboot the Security Group Members in this order:
1. Reboot the Security Group Member 1_4 and wait for it to finish the reboot.
2. Reboot the Security Group Member 1_3 and wait for it to finish the reboot.
3. Reboot the Security Group Member 1_2 and wait for it to finish the reboot.
2. When a Security Group Member finishes the reboot, it enters the "DOWN" state because of a mismatch in the number of CoreXL Firewall instances with other Security Group Members. All other Security Group Members that were not rebooted yet, including the SMO, are in the "ACTIVE!" state (Active Attention) and handle traffic.

3. When all Security Group Members except the SMO have finished the reboot, you must reboot the SMO Security Group Member. A failover occurs immediately, and one of the other Security Group Members becomes the SMO. All other Security Group Members become "ACTIVE" and start to handle traffic.

4. When the last Security Group Member, which was the SMO, finishes the reboot, all Security Group Members become "ACTIVE" and full capacity is restored.
R80.20SP
ElasticXL, Maestro, and Scalable Chassis Known Limitations - Networking
PMTR-106002 Maestro On Quantum Maestro, where Security Appliances are connected to two Maestro Orchestrators, rebooting one of these Orchestrators (or running the orchd restart command on one of these Orchestrators) causes a 10-second disruption in the sync traffic between Security Group Members. If a Security Group is configured in the VSX mode, this may affect the data traffic. R81.10
PMTR-111381,
MBS-2199
All After a failover of the FTP control connection it is not possible to open an asymmetric FTP data connection. R80.20SP
PMTR-109470,
02487403
Chassis SSM Layer4 Distribution Mode is supported for IPv4 only. The IPv6 traffic will be distributed based on the Source/Destination IP addresses only.
Note: a system can use SSM Layer4 Distribution Mode while IPv4 and IPv6 are inspected by the Security Gateway. Each IP version will use a different mechanism to distribute traffic, as described above.
R76SP.50
ElasticXL, Maestro, and Scalable Chassis Known Limitations - VPN
PMTR-108430 All Performing Hide NAT on Remote Access VPN connection (on the decrypt connection) with L4 distribution enabled may lead to NAT port collisions. R81.10
PMTR-111380,
MBS-5242
All VPN traffic on a VSX Virtual System that is connected to a VSX Virtual Switch is supported only when the distribution mode configured for the WRP interface is the same as the distribution mode configured for the physical interface on the VSX Virtual Switch.
Example of a VSX topology:
(Virtual System) == wrp100 == (Virtual Switch) == (eth1-01)
The same distribution mode must be configured for the interface wrp100 as was configured for the interface eth1-01.
R80.20SP

Article Properties

Access LevelGeneral

StatusApproved

Date Created2023-06-14

Last Modified2026-06-15

Was this page helpful?YesNo

Haven't found what you're looking for?

Our customer support team is only a click away and ready to help you 24 hours a day.

Open a Service Request

reCAPTCHA

Recaptcha requires verification.

protected by reCAPTCHA