sk181129 - Check Point Quantum R82 Resolved Issues and Enhancements

Check Point Quantum R82 Resolved Issues and Enhancements

Product Security Gateways, Security Management
Version R82
OS Gaia
Last Modified 2026-05-26

Solution

This article lists all new features and issues that have been resolved in Check Point Quantum R82 Release.

List of Resolved issues, New Features and Enhancements in Quantum R82 Release

Enter the string to filter the below table:

ID Symptoms
Quantum Security Management
PMTR-47450 UPDATE: Added support for login, logout, discard and publish commands in the SmartConsole's CLI.
PMTR-89544 Enhancement: The import-management command now includes a new change-ip parameter, which replaces the JSON change-ip configuration file, allowing administrators to inform all Servers in a Security Management environment about IP address changes when one or more Servers migrate to new IP addresses.
PMTR-105561 When passing a group parameter to the set-host command, and the host is already a part of this group, the host will no longer be removed and re-added to it. This prevents a redundant change from occurring.
PMTR-37712 It is now possible to add updatable objects to network groups.
PMTR-87634 Connecting a Quantum Security Management Server to Infinity Portal is now supported in the Full High Availability Cluster (when each Cluster Member runs a Security Management Server and a Security Gateway).
PMTR-68625,
PMTR-90912,
PMTR-76791,
PMTR-76792
When installing the Access Control Policy on a Security Gateway with an enabled VPN blade, the policy installation succeeds but shows this message: " dlopen: /opt/CPsuite-R8x.x/fw1/tmp/install_policy//FW1/lib/libcpatlas.so: cannot open shared object file: No such file or directory".
PMTR-59442 SmartConsole may show the popup " SmartDashboard component failed to connect to server " if you upgraded a Management Server and you open a Security Gateway / Cluster object for the first time after the Server's upgrade.
PMTR-95294 SAML login in SmartConsole fails when Gaia Portal on the Management Server runs on a different port than 443. See sk182032.
PMTR-47116 After installation, the Device License Status shows N/A and the Device License View is not accessible until policy or database are installed.
When blades are enabled or disabled, the changes are not visible in the Device License Views and Status until policy or database are installed.
PMTR-47108 Automatic license activation on a Multi-Domain Management Server machine works only on the MDS level and not on the Domain level.
PMTR-105923 SmartConsole may get disconnected when installing a policy on more than five hundred targets.
Management High Availability
PMTR-47159 When a secondary Management Server is added, the initial synchronization task starts automatically. Until it completes, the secondary peer status shows as " Failed to communicate with peer".
SmartConsole / Management Console
PMTR-94041 Enhancement: Added the CLI tool $FWDIR/scripts/api_log_to_json.py to get the API usage information (common calls, calls per unit time, and so on) from the API logs. See sk181906.
PMTR-91293 Enhancement: Added support of Smart-1 Cloud in the "Show Policy Package" tool. Use new flags: --cloud-mgmt-id and --api-key to authenticate with the Smart-1 Cloud Server.
PMTR-92425 Enhancement: When a SmartConsole update is ready to be installed, the user can opt to have the version skipped by the automatic update process.
It is still possible to install the update manually by selecting "Check for Update" from the main menu.
PMTR-89334,
PMTR-90112
Enhancement: The "Change Report" feature in SmartConsole now supports all SmartConsole languages.
PMTR-93105 Enhancement: The Management Console is updated to .NET 4.8.
PMTR-104160 Enhancement: Improved the load time of a large number (above 4500 objects) of satellite and participant gateways view in the VPN Community tab.
PMTR-82157 Update: HTTP Inspection view was moved to SmartConsole.
PMTR-87494 Update: Added the "High Availability" section to the Security Gateway Editor > ClusterXL > Cluster Member Priority.
PMTR-101601 When creating a Custom Report in SmartConsole, the "Malware Action" entry appears two times. Refer to sk182049.
PMTR-105768 In some scenarios, when an authorized administrator loads the information about a submitted change, the change report may get stuck.
PMTR-94546,
PRHF-29733
When there are more than 100,000 network objects on a Security Management Server or within a Domain on a Multi-Domain Security Management Server, certain applications, such as Mobile Access SmartDashboard, SmartView Monitor, and the GUI Dbedit tool, may fail to load or may close shortly after starting.
PMTR-81158 In Desktop SmartConsole, rule can expire even in the Expiration status is set to "Never".
PMTR-88932 In the past, when a user cloned a network object in an Access Control rule, the cloned object was created but not shown in the rulebase. Now, the cloned object also appears in the Access Control rule.
PMTR-98514 In the Threat Emulation first time activation flow, there is no option to ignore warnings. The "Next" button is disabled.
PMTR-57122 Searching part of a phrase surrendered by asterisks now highlights only the relevant text.
PMTR-97420 Desktop SmartConsole may freeze when selecting a client in the "RADIUS Accounting Settings" window in a Security Gateway object with the Identity Awareness Software Blade enabled. See sk181630.
PMTR-42889 The " Could not locate an appropriate editor for the target object" message appears in SmartConsole in the HTTPS Inspection Policy, when double-clicking a certificate object.
PMTR-48072 The "Restore all messages" button is disabled in Manage & settings > Preferences > User Preferences > "Restore all messages".
PMTR-44457 Error: " Error while trying to open certificate : The specified network password is not correct." when attempting to view a new HTTPS certificate that uses a password different from the previous one.
PMTR-62419 When you add an Updatable Object in a rule, you must wait for the object to load its data (see the sign for loading near the object).
If you add an Updatable Object before it loads its data, all the sub-objects are added in the rule cell instead.
PMTR-91258 Added support for Management API calls to configure "Limit" objects (Object Explorer > New > Limit).
PMTR-81196 After renewing the outbound HTTPS Inspection certificate, the "View certificate" button in the Security Gateway object editor may show the " Error while trying to open certificate: The specified network password is not correct" error.
PMTR-83632,
PMTR-86822
Management API call get-interfaces (available in API v1.7.1 and above) now supports a Security Gateway object that represents a Security Group on Maestro or Scalable Chassis.
PMTR-87666,
PMTR-87667
If in a Network Feed object or IoC Feed object, you select the object of a Full High Availability cluster and click "Test Feed", the test fails with this error:
"Connection failed for
Make sure that the machine is up and running, and that SIC has been established"
PMTR-97179 When configuring an LDAP Account Unit object in SmartConsole, clicking the "Fetch branches" button on the "Objects Management" tab does not populate the section "Branches in use" if the LDAP Server runs on Windows 10.
PMTR-99014 Еnabling/disabling rules in a rule base, followed by switching to another layer of the policy, incorrectly displays rules in the other layer as "enabled/disabled".
PMTR-47540 SCTP or Diameter objects cannot be the service of a manual NAT rule. Static NAT will still be applied for rules that match SCTP if the service is set to "Any". All NAT methods can be applied for Diameter over TCP traffic if the service is set to "Any".
PMTR-98148 Partial search without a wildcard character in SmartConsole Objects Explorer and Objects sidebar does not find objects. Refer to sk182006.
Multi-Domain Security Management
- Enhancement: Configuring an IPv6 address in addition to the configured IPv4 address is now supported.
PMTR-47622 In some scenarios, re-assign or removal of global assignments succeeds, but changes that were not yet published at the Domain become conflicted. The SmartConsole for the Domain becomes unstable and can show: " Could not load selected policy".
PMTR-47629 When running Global Domain Assignment on one Multi-Domain Server for a Domain that is active on a different Multi-Domain Server, the task can stall at 5%. After a few minutes a message shows: " _timeout during task progress: Could not get information regarding task completion from MDS_1 'MDS_2".
Logging
PMTR-93080 Enhancement: Export to CSV limit in SmartView for Smart-1 Cloud and Harmony Endpoint has been raised from 1K to 10K logs.
PMTR-79606 Update: You can now add tcp_state and tcp_flag fields when editing column profiles in the Logging tab and see them in the Access Log Details view.
PMTR-84784 The Log tab in the Logs & Monitor view repeatedly shows a " Query failed" message.
To resolve this, log field values are replaced with "N/A" if the original value includes unsupported XML characters that cannot be parsed.
PMTR-92968 SmartEvent does not send an automatic reaction email for Pre-Defined Generic IPS events.
PMTR-96010 Log card in SmartConsole shows a port number in the "Service" field for the ICMP traffic.
PMTR-83576 In rare scenarios, SmartConsole unexpectedly closes when opening the Logs & Monitor view.
Compliance
PMTR-103227 Enhancement: Added ISO/IEC 27001 2022 regulation to Compliance blade.
Quantum Security Gateway
PMTR-56389 " Authentication failure: check your username and password" message on a Security Gateway when raising the "TACP" privileges of a TACACS user in the following scenario:
1. Configured the Management Data Plane Separation (MDPS) as described in sk138672.
2. Configured Gaia OS roles with different privileges for TACACS users.
3. Configured a TACACS Server.
4. Logged in with a TACACS user.
5. Raised the "TACP" privileges in Gaia Portal (at the top of the "Overview" page, clicked "Enable") or in Gaia Clish (with the tacacs_enable <Role> command).
6. Entered the TACACS user password.
PMTR-56297 In a rare scenario, the Security Gateway may crash and reboot if multiple slave interfaces are deleted at the same time from an 802.3AD bond interface (for example, with the clish -f command).
Identity Awareness
PMTR-98732 Enhancement: In the Identity Awareness PDP daemon, some CPU-intensive tasks were moved to a dedicated thread ("pdp update all", "pdp update specific", automatic group update).
Threat Prevention
PMTR-89387 Enhancement: Improved performance for some connections in Threat Prevention.
PMTR-87269 Installation of Threat Prevention Policy fails with the error " No profile defined on GW " in this scenario:
1. The "Install On" column of a Threat Prevention rule contains a Group object (Group #1)
2. This Group object (Group #1) contains another Group object (Group #2)
3. This nested Group object (Group #2) contains the Security Gateway object
Mobile Access
PMTR-87907 Mobile Access ignores a Web application object's GuiDBedit attribute " enable_floating_navigation_bar", which controls whether the Web application's pages render a Floating Navigation Bar (FNB).
PMTR-102830 SmartView shows " Error in disconnecting user" message with the description " SNX connection failed" every time the user opens the main page of the Mobile Access portal.
SSL Network Extender
PMTR-87429 When trying to connect SSL Network Extender inside Secure Workspace, the portal page may stuck in the "Connecting" state, while outside Secure Workspace it works.
PMTR-83342 When HTTPS Inspection is enabled, the Security Gateway generates a log that includes the message " Certificate Chain is not signed by a Trusted CA" when an end-user connects to an HTTP site or a site with an untrusted SSL certificate. But, in some cases, the log does not include this text.
Gaia OS
PMTR-78528 When TACACS and RADIUS Servers are configured together, TACACS users fail.
PMTR-89795 In Gaia portal > Network interfaces, when configuring an IPv4 interface without entering a Subnet mask, the OK button does not respond and the " IPv4 address is empty" error pops up.
PMTR-87844 Cpview history displays "N/A" value for the "Dynamic Balancing Status" field of the Configuration Information in SysInfo.
Routing
PMTR-71868 OSPF route flags are now synchronized between cluster members.
PMTR-100454 The Gaia Clish command set ospf instance default rfc1583-compatibility is missing the on parameter.
VPN
PMTR-92197 Endpoint Security VPN / Check Point Mobile / Remote Access clients fail to connect using Machine Certificate Authentication when the certificate has OCSP and CRL, but the Security Gateway is unable to resolve the OCSP or to get a proper answer from the OCSP Server.
PMTR-91711 It is now possible to configure SHA-384 and SHA-512 algorithms for IKE negotiation.
VSX (Traditional)
PMTR-87534 Enhancement: Added a column for IP/Mask length for Virtual System in Bridge mode to the table in vsx_util view_vs_conf.
PMTR-104867 UPDATE: Added Automatic Onboarding to Check Point Nano-Agent Installation.
PMTR-106133 When Hyperflow is enabled, after reboot, the outputs of vsx stat -v command shows that virtual systems loaded default filter. Refer to sk182453.
PMTR-88875 In vsx_util vsls command, when setting priority and weight manually, VSs are chosen by typing the full name of the VS instead of choosing from a list.
PMTR-88874 In vsx_util command, old interface cannot be removed when changes are applied to both Security Management and Security Gateway.
PMTR-87205 When running vsx_fetch from a context that is not VS0, this confusing output is displayed:
...
Management rejected fetch for this module - sic name does not match.
Couldn't fetch VSX configuration by IPs, trying to fetch by names
SecureXL
PMTR-107557 IPX traffic over the bridge interface in UPPAK mode is now allowed.
CoreXL
PMTR-58368 CoreXL Dynamic Dispatcher is now supported with CGNAT (Global NAT).
CloudGuard Controller
PMTR-100851 Enhancement: Added ability to configure separately the timeout parameter of CloudGuard Controller's scanner for HTTP call and the timeout for vsec.py process in the vsec.conf file.
PMTR-85367,
VSECC-1097
IPv6 information is now imported for Data Center Objects in the Public Cloud.
VSECC-346 Problems in Data Center will not always change the status of the Security Management Server in SmartConsole.
Quantum Maestro and Scalable Chassis
PMTR-105637 Enhancement: In case MHO certificates are expired, a message indicating this will be displayed.
PMTR-95631 Enhancement: QSFP ports can now be configured with 10G, 1G and 4x1G QSFP port modes.
MBS-4098,
PMTR-60868
Enhancement: Added support for GRE tunnels.
PMTR-91737 Enhancement: When creating a Security Group, it is now possible to configure SGMs to save logs when they exit or change the Security Group.
PMTR-99920 Enhancement: The output of the orchd start command on the Maestro Orchestrator shows more information if the orchd daemon is already running or stopping.
PMTR-101544 Enhancement: Improved the Gaia Clish command show maestro port <ID> optic-info on the Maestro Orchestrator to show information about the CPAC-TR-100SR-D and CPAC-TR-100CWDM4-D transceivers.
PMTR-71298 Enhancement: You must disable the SMO Image Cloning in the Security Group before you assign an appliance of a model that is different from models of other appliances already assigned in this Security Group.
MBS-11278 Enhancement: Unique IP address per Chassis (UIPC) feature is now supported.
MBS-13635 Enhancement: Gaia Message of the Day (MOTD) and banner messages now support the pound (#) character.
PMTR-102638 In an environment where the Security Gateway is connected to the Maestro Orchestrator through two downlinks, disconnecting and connecting a downlink, physically or through the Orchestrator, causes an outage of 10 seconds between them.
PMTR-94043 After upgrade:
- Output of the asg diag verify command shows in the "System Components" section that the status of the "Software Provision" test is "Failed".
- Output of the asg diag print <ID of "Software Provision"> command shows a shell script code.
- Output of the asg_provision command shows a shell script code.
PMTR-96243 In Scalable Platforms, in a Dual Site configuration, ping fails from a Standby site to a host on the network connected to the Management interface of the Security Group. Refer to sk182629.
PMTR-95470 These errors appear in Gaia Clish on a Maestro Security Group during the installation of a Hotfix / Jumbo Hotfix Accumulator:
[ERROR] Failed to clear DB values.
[ERROR] Failed to clear package_progress value from Gaia DB.
Note that this was a cosmetic issue.
PMTR-80541 The "asgKernelVer" OID is now removed from the SNMP "ASG" tree because it is not supported.
PMTR-58383 Maestro and Scalable Chassis now support CGNAT (Global NAT) with the Layer 4 distribution.
PMTR-98172 The Gaia Clish command set web daemon-enable off on a Maestro Orchestrator now shows a warning and refers to sk166692.
PMTR-82182 When configuring proxy NDP according to sk91905 using interface name instead of MAC address, policy installation fails to add it to the ndp_table.
PMTR-89996 With this release, when orchd process is down, the /var/log/messages file no longer contains the logs like " The value of sensor could not be read".
PMTR-47869 The vsx stat -v command does not work after reverting to Gaia Autosnapshot (a snapshot created automatically by the CPUSE Upgrade).
PMTR-33894 When configuring a Maestro Security Gateway object in SmartConsole, you must select only the R80.20SP version.
MBS-11339 Maestro Orchestrator Clish command set maestro port X/Y/Z admin-state <down/up> does not survive reboot.
MBS-2049 After installation, a static route to 192.168.1.254 is automatically created due to the preconfigured subnet for the e th1-Mgmt4 interface.
MBS-9105 Added ability to disable the "Drop out of state TCP packets" setting in SmartConsole > Global properties > Stateful Inspection when IPv6 traffic passes through Security Groups.
MBS-9713 " Failed to set MTU 9000 on interface magg0. Maximum value allowed is 9710." error when running the Gaia gClish command set interface magg0 mtu <Value> for a Management Aggregation (MAGG) interface.
MBS-7744 In a Dual Site deployment, the external synchronization connection between the Orchestrators on different sites must be a direct Layer 2 link.
MBS-5216 When VLAN traffic needs to traverse the Security Group in Bridge mode, you must configure all relevant VLAN IDs on the Uplink ports assigned to the Security Group in the Gaia Portal on the Maestro Orchestrator.
MBS-13867 On Quantum Maestro, the snmpwalk and snmpget commands executed for the IP address of the Security Group on OIDs that have prefixes other than 1.3.6.1.4.1.2620.1.44 or 1.3.6.1.4.1.2620.1.48 return information only for the current SMO Security Group Member.
To get the same information from non-SMO Security Group Members, connect to the command line of each non-SMO Security Group Member and run the snmpwalk or snmpget command for the "localhost".
MBS-11339 The Maestro Orchestrator Clish command set maestro port X/Y/Z admin-state <down/up> does not survive reboot.
MBS-11504 Scalable Platforms now support the configuration of different VPN encryption domains on a Security Gateway that is a member of multiple VPN communities.
MBS-2379 The SMO Image Cloning feature only supports Security Group Members that run the same major version.
When you add a new Security Group Member to the R80.20SP Security Group (with the add smo security-group command), it must have the same version as SMO.
01052419 Connections may break when you change the System Distribution Mode using either the set distribution configuration command or the set distribution interface command.
01255170 For monitoring the 60000 / 40000 Scalable Chassis over the SNMP, the only supported OIDs are under iso.org.dod.internet.private.enterprise.checkpoint.products.asg (OID 1.3.6.1.4.1.2620.1.48).
Endpoint Security
PMTR-84345 In Harmony Endpoint Web Management interface, when you enter the percent "%" character in Search fields, the backslash "\" character is added repetitively in front of the percent "%" character.
PMTR-92866 Installation of the Endpoint Security Client package "EPS.msi" signed with a custom certificate and exported from SmartEndpoint on Windows 11 is now possible
PMTR-62510 It is now possible to scan user certificates from the Active Directory when you create a new Active Directory Scanner in the Endpoint Server Web Management Portal. "Scan user certificated from Active Directory" checkbox was added.

Article Properties

Access Level General
Status Approved
Date Created 2023-06-14
Last Modified 2026-05-26