sk181134 - Check Point R81.10.X Resolved Issues and Enhancements

Header/footer test page

My Favorites

Solution ID: sk181134


Technical Level:

Basic

Email

Print

Check Point R81.10.X Resolved Issues and Enhancements

ProductSpark Firewall

VersionR81.10.X

OSGaia Embedded

Platform1500, 1570R, 1600, 1800, 1900, 2000

Last Modified2026-07-08

Solution

This article lists all Resolved Issues and Enhancements for R81.10.X releases on 1500, 1600, 1800, 1900, and 2000 appliances.

- R81.10.17
- R81.10.15
- R81.10.10
- R81.10.08

Show the Entire Article

R81.10.17 Resolved Issues and Enhancements

Show / Hide this section

Enter the string to filter this table:

ID Category Description
Build 996004914
SMBGWY-20729 Anti-Spam Anti-Spam exception rules may not be applied correctly to messages with unusually long headers.
SMBGWY-21606 2FA After upgrading to R81.10.17 Build 996004892, the Two-Factor Authentication SMS and email message templates appear garbled .
SMBGWY-21155 Users and Objects When more than 40 local users are created, the most recently added user does not appear in the WebUI user list under Users and Objects > Users, although it can still be found via the search box or the CLI command "show local-users." Each time a new user is added, the previously missing user is displayed but the newest one does not appear.
SMBGWY-21478 2FA The email for setting up Two-Factor Authentication is not sent after enabling Two-Factor Authentication through the WebUI through an RMD link via Spark Management.
SMBGWY-21467 VPN After upgrading to R81.10.17 Build 996004901, Capsule VPN clients fail to connect and show an error that the server sent an invalid response.
SMBGWY-21331 Logs On a Spark Firewall appliance, only logs from the past day can load. On Spark Management, all the logs are displayed but it is not possible to filter for the desired time frame.
PRJ-69655,
PMTR-128753
VPN UPDATE:
- Resolved CVE-2026-50751 - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange. Refer to sk185033.
- Resolved CVE-2026-50752 VPN site-to-site certificate bypass vulnerability in deprecated IKEv1 key exchange. Refer to sk185035.
Build 996004892
PRJ-67985,
PMTR-126652
Security Gateway UPDATE: Resolved CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero. Refer to sk184981.
PRJ-67840,
PMTR-126457
Security Gateway UPDATE: Resolved CVE-2026-48132 - VPN process may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP. Refer to sk184982.
PRJ-67875,
PMTR-126538
Security Gateway UPDATE: Resolved CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion. Refer to sk184993.
PRJ-68010,
PMTR-126694
Security Gateway UPDATE: Resolved CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests. Refer to sk184991.
SMBGWY-17467 General The Spark appliance may fail to download the Certificate Revocation List (CRL) in SSL inspection (SSLi).
SMBGWY-17071 General Hosts located behind the bridge interface are unable to access internal servers using the appliance’s external IP address on the server’s port.
SMBGWY-17401 General When the Local NTP Server is enabled, it is accessible from the WAN, allowing external clients to receive NTP responses, instead of being restricted to local/internal networks.
SMBGWY-19701 General IPv4 over IPv6 (IPIP) Internet connection settings cannot be modified.
SMBGWY-19651 General Periodic backup fails when configured in Spark Management.
SMBGWY-19465 General The Connected Remote Users page may not display all connected users.
SMBGWY-19473 General SmartConsole reports and the output of the cpstat command do not display scanned files. The scanned file counter remains at 0 even after Threat Emulation scans files.
SMBGWY-20724 General Periodic backups are not scheduled when configured from Spark Management after an upgrade to R82.00.05, R82.00.10 (up to Build 998001645), or R81.10.17 (between Builds 996004668 and 998002171).
SMBGWY-19347 General After a cluster failover in Locally Managed environments, proxy ARP may not function correctly, causing loss of access to internal servers using proxy ARP–defined IP addresses.
SMBGWY-18298 General The Spark Management dashboard displays a Connected (no probing) status for PPPoE and flexiport connections, and does not show Internet probing statistics even when probing data is available on the Gateway.
SMBGWY-19116 General The disable-sd-logging command does not function correctly.
SMBGWY-17977 General Enabling NT LAN Manager Version 2 (NTLMv2) for Identity Awareness in Centrally Managed Mode does not work, causing authentication issues even when AD is configured to require NTLMv2 and the ad_log_override.C file is set to enforce NTLMv2.
SMBGWY-18704 General Updating the IP address or subnet of a Local Network object is not applied in the backend under certain conditions, causing firewall rules that reference this object to continue using the old IP address or subnet.
SMBGWY-19001 General No logs are available in the Infinity Portal for 1600, 1800, 1900, and 2000 Gateways managed via Spark Management.
SMBGWY-19280 General The sfp-diag tool reports incorrect SFP diagnostics for the DMZ port on Quantum Spark 1600 V2 (D0) appliances.
SMBGWY-18339 General The "Firmware Upgrade Completed" notification is not sent to or displayed in the Spark Management Events tab during a manual firmware upgrade via the WebUI, even when the notification is enabled.
SMBGWY-19014 General Anti-Virus fails to process files in Centrally Managed Mode when the Enable deep inspection scanning option is selected.
SMBGWY-18622 General The system does not display injected routes in the output of the show route command, although it displays them in the output of the route -n command.
SMBGWY-18227 General When the Gateway is in IPv6 Bridge mode (dual-stack IPv4/IPv6), a firmware upgrade initiated from Quantum Spark Management in the Infinity Portal does not start, although manual upgrades via the local WebUI function correctly.
SMBGWY-20812 Firewall SCTP services with port number configurations cannot be defined in the firewall policy.
SMBGWY-17645 Firewall The IPv4 MAP‑E service does not function correctly. Inbound IPIP (IP-in-IP tunneling protocol) encapsulated return traffic is dropped due to local interface address spoofing, resulting in only outbound traffic working despite an active tunnel.
SMBGWY-18134 Firewall Clusters configured with strict or restrictive custom Firewall policies allow unrestricted traffic between cluster members over the Synchronization network.
SMBGWY-17848 Firewall During an ISP redundancy failover triggered by Gateway probing failure, NAT Hide rules use the primary connection's IP address instead of the active secondary connection's IP address.
SMBGWY-18654 Firewall The fwConnectionsStat ConnectionRate SNMP OID returns a No Such Instance error on Quantum Spark appliances.
SMBGWY-17626 Firewall No network connectivity is observed on the DMZ fiber port.
SMBGWY-17486 Firewall A firewall rule configured with any but specific services is incorrectly converted to only specific services after an upgrade to a version that includes the multiple objects feature
SMBGWY-19319 CPOS After upgrading to R81.10.17, the Gateway allocates an incorrect number of CoreXL firewall instances on first boot.
SMBGWY-19361 CPOS GRE cannot be configured on an external interface that uses an automatic Internet connection (for example, DHCP).
SMBGWY-17627 CPOS Some 1600/1800 appliances do not establish a link on SFP ports.
SMBGWY-17852 CPOS IPv6 Prefix Delegation cannot be enabled on LAN, DMZ, or WLAN interfaces, even though these interfaces support IPv6 Prefix Delegation. A validation mechanism incorrectly prevents activation of Prefix Delegation on these interface types.
SMBGWY-18836 CPOS System logs are not written to the SD card after a boot.
SMBGWY-19633 SD-WAN In rare cases, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) populate incompletely, causing SD-WAN rules to match traffic incorrectly.
PRHF-42303 SD-WAN Spark Firewall fails to install SD-WAN Policy with the event Failed to Initialize VPN Transports. See sk184225.
SDWANGW-5963 SD-WAN AWS cross-availability-zone (XAZ) peer identification is handled incorrectly in SD-WAN overlay configurations.
SMBGWY-17317 SD-WAN SD‑WAN link "up" event notifications are not generated under certain conditions, preventing administrators from receiving alerts when an interface recovers.
SMBGWY-17819 CPOS Cellular internet connection behavior may not meet the requirements of certain Canadian carriers, causing overly aggressive retry attempts when the connection fails to establish.
SMBGWY-18743 CPOS On wireless Quantum Spark models, the Enable Zero‑Wait DFS setting in the Wireless Radio settings is not retained after an appliance reboot (the setting reverts to disabled).
SMBGWY-19093 Identity Awareness Even after disabling User Awareness in the WebUI, Identity Awareness still appears as enabled in enabled_blades / active_blades.txt.
SMBGWY-18011 GUI - Deleting the static Office Mode IP from the WebUI triggers a system error and does not remove the entry from the ipassignment.conf file.
- Modifying the static Office Mode IP for usernames containing special characters creates duplicate entries in the ipassignment.conffile.
- Multiple users can be assigned the same Office Mode IP address.
SMBGWY-19749 GUI Adding categories to the Other Undesired Applications group fails, resulting in an empty application name.
SMBGWY-17897 GUI When clicking Force Member Down on the High Availability page for a Locally Managed Quantum Spark appliance, the member correctly changes to Down, but the button does not switch to Disable Manual Failover.
SMBGWY-18323 GUI The option to upload a signed certificate for the Web Portal is unavailable when the appliance is in Centrally Managed Mode, although it is available in Locally Managed mode.
SMBGWY-18277 GUI After a Gateway reboot, the PPPoE interface is automatically disabled as a steering candidate in the SD-WAN steering object.
SMBGWY-17475 GUI The Incoming Rules page displays unsupported action options, and selecting them triggers this system error: Current action is not supported for the selected services.
SMBGWY-20829 GUI Offline IPS signature updates uploaded via the WebUI are not applied.
SMBGWY-18682 GUI LAN1 is not available as a selectable interface in the WebUI when configuring a Link Aggregation Group (LAG) for Internet connectivity.
SMBGWY-18184 GUI IPv6 addresses cannot be assigned using Prefix Delegation (PD) on WLAN (wireless) interfaces, while ND‑Proxy remains available.
SMBGWY-18788 GUI When operating in strict mode with the APPI policy – Bypass Check Point products advanced setting enabled, an AppiBypass rule is automatically generated.
SMBGWY-17728 GUI The WebUI displays an incorrect Internet connection mode after switching from High Availability to Load Balancing via Clish.
SMBGWY-19641 GUI Certain application categories cannot be added to the Other Undesired Applications group under URL Filtering / Application Control. Attempts to add these categories via the WebUI do not complete successfully.
SMBGWY-19301 GUI Automatically generated application groups are not created properly.
SMBGWY-19381 VPN New: Support for Perfect Forward Secrecy (PFS) mode on VPN sites of type “Only remote site initiates VPN” and “Hostname” in Locally Managed Mode.
SMBGWY-17494 VPN When a client establishes an L2TP connection with Route Internet traffic from connected clients through this Security Gateway enabled, the client receives an IP address but does not receive DNS server information. As a result, external IP connectivity works, but hostname resolution fails.
SMBGWY-18850 VPN After upgrading to R81.10.17, Remote Access VPN clients cannot connect to the Gateway and receive a no response from gateway for 1st packet error. In some cases, site-to-site VPN tunnels also go down.
SMBGWY-18484 VPN SNMPWalk queries for IPSec tunnel monitoring OIDs return No Such Instance errors.
SMBGWY-18624 VPN Unable to configure All-Day or Multi-Day schedule via Remote Access VPN WebUI.
SMBGWY-18529 VPN Remote Access VPN Phase 2 cannot be configured to use custom encryption and authentication methods.
SMBGWY-19565 VPN SNMPwalk queries for VPN-related OIDs hang on a Centrally Managed cluster’s standby member, though they work correctly on the active member.
SMBGWY-20107 VPN L2TP Remote Access VPN connections fail when Site-to-Site VPN options are disabled.
SMBGWY-20681 VPN The fw load_sigs -b APCL command fails
SMBGWY-18012 VPN PCI compliance scan fails with these error messages (see sk184658):
- Weak Diffie-Hellman groups on UDP/500.
- 3DES encryption on UDP/500.
SMBGWY-19097 VPN On Quantum Spark appliances (Locally Managed and Centrally Managed) the IKE daemon and VPN port listeners (UDP ports 500, 4500, 30500, and 34500) run continuously, regardless of whether the VPN feature is enabled or disabled.
SMBGWY-17613 VPN When Route Internet traffic from connected clients through this Security Gateway is disabled (Split Tunnel mode) and the Local Encryption Domain is set to Automatic (default), the L2TP client does not receive the automatic encryption domain subnet route in its routing table.
Build 996004721
SMBGWY-17136 General UPDATE: Updated CRL and OCSP validation in Remote Access VPN, Site-to-Site VPN, and HTTPS Inspection to use HTTP/1.1 instead of HTTP/1.0. This ensures continued compatibility with DigiCert's updated requirements and prevents certificate validation failures. Refer to sk183884.
SMBGWY-16556 General NEW: Advanced Settings – Third NTP Server
- Added a checkbox in Advanced Settings to enable or disable the use of a third NTP server.
- When enabled, an input field appears to specify the third NTP server address. The default value is time.google.com, and it is editable.
Fallback Usage Collector
- Added a field in the NTP collector to track the last time both NTP Server 1 and NTP Server 2 failed, and the system successfully used NTP Server 3.
SMBGWY-16544 General Immediately after a cluster member reboots, it sends RIP/BGP/OSPF advertisements using its physical IP address instead of its Virtual IP (VIP) address.
SMBGWY-16775 General In an Outgoing Internet Access Policy, the Action and Log settings of the CP_Products_Bypass_Rule cannot be changed.
SMBGWY-16636 General LAN interface MAC address could be incorrectly assigned to a LANX interface during configuration.
SMBGWY-16936 General Policies created in R77.20.xx and restored to R80.20.xx change behavior after upgrading to R81.10.17. A rule containing both a URL and services is treated as AND. However, after the unification into a single field appsAndServies, the rule effectively became OR.
SMBGWY-16459 General When a Locally Managed appliance has more than 350 manual Access Policy rules configured, upgrading to R81.10.17 completes but reverts to the previous version after 15 minutes.
SMBGWY-16697 General LANX cannot be used for a bridged internet connection on 1900/2000 appliances.
SMBGWY-16829 General VLANs created on non-LAN ports were incorrectly assigned the MAC address of a LAN port.
SMBGWY-17369 General Possible database corruption after upgrading from R81.10.10 or R81.10.15 to R81.10.17 Build 532–716 may cause internet connection errors or WebUI unresponsiveness.
SMBGWY-16468 GUI The show configuration command fails with the error Illegal characters in administrator password-hash.
SMBGWY-16623 GUI The Categories option does not appear in the WebUI.
SMBGWY-16896 GUI When editing an internet connection with a WAN interface, selecting LANX and returning to WAN automatically enables the Disable auto negotiation checkbox.
SMBGWY-16650 GUI Attempting to view host logs from the Threat Prevention > Infected Devices section in the WebUI results in a Page Not Found error.
SMBGWY-16679 GUI The thoroughput values displayed in the Quantum Spark WebUI are incorrect when compared to the actual performance.
SMBGWY-16538 GUI In the Security Logs page in the WebUI, the IP column is too narrow for the IP addresses to be properly displayed.
SMBGWY-12630 VPN Internet Key Exchange Security Association (IKE SA) information is stored in the kernel before the authentication exchange completes, which could trigger asynchronous flows, cause mismatched states with the peer, and result in outages.
SMBGWY-16733 VPN A confirmation dialog for unsaved items appears in this specific scenario.
1. From the Manually choose a VPN certificate dropdown, select Cloud Services provider certificate.
2. Click Save.
3. Move to another page.
4. Return to VPN > Advanced Settings > Remote Access Advanced Settings, and a confirmation dialog appears.
SMBGWY-17064 VPN When the appliance is in the Centrally Managed mode and uses MEP in a VPN star community as a satellite, failover between MEP centers causes the tunnel to either go down or remain connected to the non-active center.
SMBGWY-16831 VPN When the pfrm2.0 partition becomes exhausted due to SAML Portal logs, VPN connections fail. The VPN attempts to authenticate with the Identity Provider (for example, Microsoft Entra ID) but eventually times out.
SMBGWY-17220 VPN Routes are not added in MEP RIM configuration when the tunnel is created again after a reboot or failover\failback.
SMBGWY-16941 VPN In a rare scenario, the Gateway fails to find a valid certificate for a Remote Access (RA) VPN connection.
SMBGWY-17072 VPN Previously, it was not possible to configure the parameter internet-traffic-through-this-gw for VPN Site-to-Site in Clish.
It is now configurable with these Clish commands:
- set vpn site <SITE_NAME> internet-traffic-through-this-gw true
- set vpn site <SITE_NAME> internet-traffic-through-this-gw false
SMBGWY-17195 IPS IPs protections added with IPS signatures are not displayed in the Logging and Monitoring Security Report.
SMBGWY-16306 Routing In some scenarios, access to internal servers via bridge does not work properly. You can now restore the original  behavior with this FW parameter: fw_br_route_use_in_ifn=1
SMBGWY-16383 Routing When ND-proxy is enabled in the WebUI on an existing IPv6 internet-connection used by MAP-E, an old route is not deleted, causing connectivity issues.
SMBGWY-16685 Access Policy A Network Object's group name or description cannot contain special characters.
SMBGWY-17055 Networking After receiving DHCPv6 prefix via prefix delegation, the internal interface(example: LAN1) is assigned an IPv6 address/prefix, but SLAAC remains disabled.
Workaround: Change IPv6 Auto Assignment to "SLAAC" manually.
SMBGWY-17282 VLANS Deleting VLANs from a disabled port incorrectly enables the port while still displaying the port as disabled in the WebUI.
Build 996004653
SMBGWY-10943 General New: support for configuring IPv6 internet connections over LAN and LANX ports.
SMBGWY-16325 General Quantum Spark Gateway fails to connect to Smart-1 Cloud through a Proxy server.
SMBGWY-15868 General After removing an item from the Infected Devices page, the list becomes empty until the WebUI page is refreshed.
SMB-18388 General SmartConsole sometimes shows inaccurate license information for Software Blades on Quantum Spark Appliances running R80.20.X: No License or About to Expire.
SMBGWY-16040 GUI When configuring an IPv6 bridge composed of both LAN and WAN interfaces, the WAN interface does not appear as active in the 2D model interface statistics on the Home tab.
SMBGWY-15926 GUI WebUI and Gaia Clish do not support configuring static routes with a 31-bit subnet mask (as specified in RFC 3021).
SMBGWY-15475 GUI Security Log columns (Action, Source, Destination, and Service) are not visible in the WebUI when viewed on small screens.
SMBGWY-15970 GUI The Japanese text for "Probing Settings" in Quantum Spark Management is truncated.
SMBGWY-15720 GUI In the WebUI, the entire SD-WAN page becomes blank in this scenario:
1. In the WebUI, go to the Access Policy view > Firewall section > SD-WAN page
2. In the Policy section, click New
3. In the column Application / Services, click +
4. At the bottom, click Add > URL
5. Enter the Name and the URL and click Save
6. The entire SD-WAN page becomes blank
SMBGWY-16369 VPN Site to Site VPN tunnel between a Centrally Managed Quantum Spark Gateway and a VPN peer with a Dynamic IP address (DAIP) goes down after policy installation.
SMBGWY-16334 VoIP When renaming a VoIP Network Group, this error appears when saving the configuration:
Cannot edit VoIP network object group.
SMBGWY-15716 IoT This error may appear in the WebUI Access Policy view > Firewall section, when clicking the IoT page:
Internal error has occurred. If the problem persists, contact Check Point Technical Assistance Center.
SMBGWY-16191 IoT When upgrading a Quantum Spark appliance with IoC Feeds enabled from R81.10.17 Build 996004508 to Build 996004620, the appliance reboots after 10–15 minutes and reverts to the previous firmware version.
Build 996004620
SMBGWY-15367 General New: Added MAP-E and IPIP support for the BIGLOBE vendor in Japan.
SMBGWY-15461 General Enhancement: Improved update handling for IPS, Anti-Malware, and Application Control: if an update fails, the system will retry after 24 hours or at the next scheduled update time, whichever occurs first.
SMBGWY-15339 General Enhancement: Increased the minimum update interval for IOC feeds to 30 minutes. Administrators can manually reduce the interval using the ioc_feeds force_interval command, though shorter intervals may affect device performance and are not recommended.
SMBGWY-14643 General When querying a Quantum Spark Gateway with SNMP, the values of OIDs with the 'Counter64' type are returned with the type 'String'. For example, OID 'memFreeReal64'.
SMBGWY-14877 General In the Locally Managed mode, selecting Citrix Cloud Services in the source or destination columns of the Access Policy rulebase may result in a firewall policy error.
SMBGWY-13017 General When a Quantum Spark Gateway is disconnected from Cloud Services, all settings options are grayed out, and the Managed Services - Disable Logging to SD option is set to true. However, logs continue to be saved on the SD card despite this setting. After reconnecting the Quantum Spark Gateway to Cloud Services, the settings options become available, but the Disable Logging to SD option remains unmodifiable.
SMBGWY-15884 General After an upgrade, a Quantum Spark Gateway may fail to load the configuration for the enabled Software Blades in this scenario (the configload_status command shows fw (Failed)):
1. You performed a clean install of a firmware image.
2. The Application Control package was updated.
3. In the Access Policy view > Firewall section > Policy page, in the Applications and Services column you selected a category that was not part of the default Application Control package that is built into the original firmware.
4. You upgraded the firmware image to a higher version that does not contain this Application Control category in its default Application Control package.
SMBGWY-15425 General Periodic backups via FTP may fail for some FTP servers.
SMBGWY-13203 General When creating a High Availability (HA) WAN Bond, the primary slave interface in the Bond is not always set according to the user's selection.
SMBGWY-15101,
SMBGWY-15102
General When a Quantum Spark Gateway is located behind a Network Address Translation (NAT) device and uses a Dynamically Assigned IP address (DAIP), it does not encrypt traffic that originates from the Gateway itself and is destined for the internal network of the VPN peer. In this configuration, the Gateway sends clear-text traffic through the NAT device before it enters the Site-to-Site VPN tunnel. This issue does not affect traffic originating from the Gateway’s internal network.
SMBGWY-14782,
SMBGWY-14923
General In a rare scenario, the Quantum Spark Gateway may crash with these messages::
;fwchain_is_non_inline: chain dir X, XXX -> XXX IPP XXX has invalid ifnum (-1)
Unable to handle kernel NULL pointer dereference at virtual address XXX
...
PC is at fg_is_qos_active_on_chain+XXX
LR is at fg_is_qos_active_on_chain+XXX
...
fg_is_qos_active_on_chain+XXX
fw_ipsec_encrypt_ex+XXX
vpn_encrypt_chain+XXX
fwchain_do_ex+XXX
...
Starting crashdump kernel..
SMBGWY-14883 CPOS Resolved an issue in which spaces are not allowed in Wireless Network Names (SSIDs).
SMBGWY-15222 VPN In rare scenarios, VPN stops working because the iked process fails to start.
SMBGWY-15853 VPN The vpn tu tlist -p <IP Address> command returns no information.
SMBGWY-15484 VPN Configuring a VTI IP address with a last octet greater than 223 (e.g., 10.0.0.224) fails.
SMBGWY-14114 VPN Remote Access (RA) VPN users lose internet access even though the route all traffic to the gateway field is enabled.
SMBGWY-15534 VoIP One-way audio issue during calls when Session Initiation Protocol (SIP) inspection is enabled.
SMBGWY-15073 GUI When trying to access a blocked website, the expected Check Point block page does not appear. Instead, this generic browser error appears: This site can’t be reached.
SMBGWY-14158 GUI The Destination field in existing SSL inspection policy rules is grayed out and cannot be edited.
SMBGWY-14966 GUI After upgrading to R81.10.17, DSL interfaces were incorrectly shown as "disabled" in the WebUI, even though they were active. This status appeared in the 2D view on the Overview screen.
SMBGWY-15494 GUI In the Japanese WebUI > Access Policy > Servers > New > select Mail Server > click Edit, the Edit Mail Server Ports window does not show the fields POP3 and IMAP.
SMBGWY-14861 GUI Manual Upgrade results show overlapping Japanese fonts.
SMBGWY-14985 GUI In the Firewall Access Policy, an "Auto Generated" rule may show the Service object "ANY",  which is not supported in "Auto Generated" rules.
SMBGWY-14964,
SMBGWY-14963
GUI When editing an existing IPv4 over IPv6 internet connection (DS-Lite, IPIP, or MAP-E) alongside another IPv4 connection (examples: PPPoE, Static IP, or DHCP), the associated IPv6 Linked connection does not appear.
SMBGWY-15215 GUI In the Firewall Access Policy, an "Auto Generated" rule may show an incorrect Service object.
SMBGWY-15374 GUI The "Edit Rule" option for Incoming, Internal, and VPN traffic does not display all configuration settings. Specifically, the "Match only for encrypted traffic" option is missing.
SMBGWY-15660 GUI After an upgrade from R81.10.10 to R81.10.17, when editing a local user group in the User Management tab, all previously assigned users are removed, and only the newly added user is retained.
SMBGWY-15785 GUI In Home-> Cloud Services -> Reports-> Settings, only "Daily" and "Weekly" reports are displayed even though "Monthly" reports are enabled in Quantum Spark Management.
SMBGWY-12026 WebUI If a new Administrator user was configured to change the password at first login, then during the first login, clicking the Cancel button leads to an empty page.
SMBGWY-13303 Firewall Quantum Spark Gateway may crash with a core dump file when installing the SD-WAN policy. This applies to the Locally Managed mode and the Centrally Managed mode.
SMBGWY-15515 Firewall SIP inspection is disabled after an upgrade.
SMBGWY-15518 Firewall The "Protection Name" field is not displayed in the IPS security logs.
SMBGWY-15714 Firewall On the Users & Objects > Services page, when editing the port number of a system default service and clicking Save, the following error message appears: Cannot change prototype of system default services. Additionally, when the protocol type is set to None, the Disable Inspection checkbox is disabled.
SMBGWY-15816 Firewall In the Device view > Network section > Wireless page, when clicking Clone > Save, this error message appears: Field must have a value.
SMBGWY-12486 Firewall In a Quantum Spark Cluster, it is possible to add additional interfaces to the SYNCBOND interface and to delete interfaces from the SYNCBOND interface in Gaia Clish.
SMBGWY-12903 Firewall In a Quantum Spark cluster setup, changes made to DHCP advanced settings (example: DNS) on the Active Member's local connection are not synchronized with the Standby Member. As a result, hosts in the internal network of the Quantum Spark cluster could receive incorrect DHCP configurations after a cluster failover.
Build 996004508
SMBGWY-13472 General Enhancement: Added the Export to CSV option in WebUI > Device view > Cloud Services section > Extended Monitoring page > Remote Access VPN tab > widget Top users by duration.
SMBGWY-12801 General In some scenarios, upgrading to version R81.10.15 fails.
SMBGWY-12492 General Logs are not sent to the Log Server when the connection between the Quantum Spark Gateway and the Log Server is over IPv6.
SMBGWY-13038 General If one of the connected internal hosts (that receives its IP address from the Quantum Spark appliance's DHCP server) does not report its hostname to the Quantum Spark appliance, then it is not possible to show the DHCP Lease information for all connected internal hosts:
- The Home view > Troubleshooting section > Tools page > command "DHCP leases" shows "No items found".
- The Gaia Clish command "show dhcp-leases table" shows "No items found".
SMBGWY-13717 General A Quantum Spark appliance fails to boot in this scenario:
1. The appliance is restored to default settings.
2. IPv6 support is enabled in the Gaia Embedded OS settings.
SMBGWY-11460 General The Quantum Spark Gateway does not get the correct time zone when connected to Quantum Spark Management with the Automatic GMT setting enabled.
SMBGWY-13258 General The Quantum Spark Gateway fails to synchronize with the NTP server. Synchronization fails with this error: "no server suitable for synchronization found."
SMBGWY-12404 General Retrieving the asset interface with the "arp -a" command takes too long in some environments. The process now uses the connection table instead, improving response time.
SMBGWY-14099 General In rare cases, the SIM switch may fail on the 1575RWL appliance model.
SMBGWY-12804 General On 1600/1800/1900/2000 Quantum Spark Appliances, Internet connections of type "MAP-E dynamic" are stuck in the "connecting..." stage.
SMBGWY-13369 General In Quantum Spark Management, logs from the Gateway are not received after a cluster failover event.
SMBGWY-12262 General A cellular appliance with two SIMs configured with different carrier configuration packages fails to switch SIMs. The issue occurs only on old LTE systems (1570/1590/1570R).
SMBGWY-13483 General When a Mapping of Address and Port with Encapsulation (MAP-E) connection is configured as dynamic and the actual environment is static, or when a MAP-E connection is configured as static and the actual environment is dynamic, the connection fails, but no clear error message appears in the system logs.
SMBGWY-14324 General When used on 1900 and 2000 Quantum Spark Appliances, the "show sfp-diag" Clish command returns the following message:
"<port name, e.g., DMZ> port has no SFP support."
SMBGWY-12495 General The Gaia Clish command "show configuration" shows all Internet Connections as type "pppoa".
SMBGWY-13927 General You can now configure one or more aliases on the same subnet as the physical interface where the alias is configured. Previously, UI validation blocked this configuration.
SMBGWY-11002 CPOS Enhancement: Added support for probing in the static default route, in which the next hop is a VTI or a GRE interface.
SMBGWY-12614 CPOS Configuring DHCP relay on more than 50 interfaces causes the DHCP relay agent to stop working.
SMBGWY-12043 CPOS After rebooting a Quantum Spark appliance, the MAC address for a bond interface changes. The fix enables MAC address override for WAN bond interfaces. Previously, the override could be set in the UI but was ignored.
SMBGWY-14213 CPOS On Quantum Spark Cellular Appliances 1595 and 1595R, system logs repeatedly display these messages: "No SIM in slot" and "SIM failure".
SMBGWY-13809 CPOS When restoring the configuration from a Quantum Spark appliance with a different number of ports, some static routes can point to invalid interfaces. For example, restoring a backup from a Quantum Spark 1400 appliance that has six switch ports on a Quantum Spark 1570R appliance that has eight switch ports.
SMBGWY-12414 CPOS When using the "set wlan radio operation-mode" Clish command, you cannot change the radio band on Gateways with a single wireless module.
SMBGWY-13437 VPN Enhancement: Improved the description of the advanced setting "Remote Access VPN - Legacy NAT traversal" to show "Accept NAT traversal (affects both VPN Site to Site and Remote Access)".
SMBGWY-11699 VPN The following error appears when you run the "add/set administrator" command or reconfigure Remote Access (RA) VPN local users on a new Quantum Spark Gateway using the configuration from your previous Gateway.
Could not set local-user password-hash: Not valid password hash.
The command only validates password hashes when they use the DES or MD5 hash functions.
SMBGWY-13325 VPN In rare scenarios, a connection over a Site-to-Site VPN tunnel passing through a Quantum Spark Gateway may experience interruptions. This occurs when the connection is initiated by a host that is not directly connected to the Quantum Spark Gateway.
Example of an affected topology:
[Site to Site VPN source] === [Router] === [Quantum Spark Gateway] === [Site to Site VPN destination]
SMBGWY-12306 VPN The Security Logs do not contain the "Key Install" log when a Site to Site VPN Tunnel is established.
SMBGWY-13386 VPN When creating a new VPN site, the configuration page fails to load and continues spinning indefinitely until the user exits the window.
SMBGWY-13932 VPN On 1900/2000 appliances, a GRE interface is not created properly and does not appear in the output of the "ifconfig" command.
SMBGWY-11643 VPN In a Site to Site VPN, a Quantum Spark cluster does not hide the VPN probing packets (RDP) behind the cluster Virtual IP. The cluster sends the RDP packets with the source IP address of a cluster member instead of the VIP address, and with a source port from an internal pool instead of source port 259.
SMBGWY-12538 GUI In a specific case, WebUI > Device view > Advanced Routing section > Routing Table page does not show the configured VTI interface in the column Next Hop in static routes.
SMBGWY-12044 GUI The right-click menu does not appear for rules in WebUI > Access Policy view > Firewall section > Policy page.
SMBGWY-12766 GUI In WebUI > Device view > Network section > Internet page > edit an Internet connection > in the Type field, select IPv4 over IPv6 (IPIP). The field titles of " BR address" / " AFTR address" do not change correctly when selecting values in the section VNE Settings in the field Service name.
SMBGWY-13563 GUI "Web server error" and "An internal error has occurred" popups when creating a new Network Object on a Locally Managed Quantum Spark Gateway. See sk183210.
SMBGWY-13206 GUI In a rare case, disabling IoT in the WebUI (in Access Policy view > Firewall section > IoT page) may cause traffic issues.
When logging into the WebUI, the " System Error" popup appears with these lines:
An Internal error has occurred
If the problem persists, contact Check Point Technical Assistance Center
Web server error
SMBGWY-11766,
PRHF-33612
Firewall UPDATE: Optimized the Generic Data Center JSON file processing on the Security Gateways to improve performance when handling a large number of IP ranges.
SMBGWY-14054 Firewall Centrally Managed Quantum Spark Gateway does not send "Bypass" logs for HTTPS Inspection of white-listed categories and services.
SMBGWY-14090 Firewall - Traffic sent to the Quantum Spark Cluster Virtual IP addresses is not matched to rules that include the Dynamic Object "This Gateway" in the "Destination" column.
- Traffic sent from the Quantum Spark Cluster Virtual IP addresses is not matched to rules that include the Dynamic Object "This Gateway" in the "Source" column.
SMBGWY-14171 Firewall Improved the way system logs are saved on an SD card:
1. When an SD card is detected, a system log is written on the SD card, in addition to the /var/log/messages file.
2. When the system log's size reaches 200KB, a backup of it is compressed (in the gzip format) and saved on the SD card. The log is then truncated.
3. Up to 100 of the most recent backups are kept.
SMBGWY-12323 Firewall The body of Check Point emails with the subject " Spark Notification Service - Attention Required: Administrator logged in to Expert Shell" contains the string "(null)" instead of the administrator username and contact information:
A connection of type SSH initiated by administrator <Name-of-Gateway>, +(null), (null), from XXX to Expert Shell on <Name-of-Gateway>
SMBGWY-13288 Firewall Quantum Spark Appliance upgrade in SmartConsole fails if there is insufficient free space in the /storage partition. See sk183082.
SMBGWY-13332 Firewall "idapi_load_data_impl: session id XXX not found in client_db, although ip XXX was assigned to it" appears repeatedly in the /var/log/messages file. See sk167174.
SMBGWY-13252 Firewall A Locally Managed Quantum Spark cluster member may go down when using OSPF and configuring the Access Policy in Strict mode ( Access Policy > Firewall > Blade Control).
SMBGWY-14395 Firewall When configuring two or more Internet Connections in the High Availability mode, the directly-attached subnets of the non-active Internet Connections may not be reachable.
SMBGWY-14115 Firewall In WebUI > Logs and Monitoring view > Logs section > System Logs,the page repeatedly shows "Error" entries like these for some interfaces:
[CPOSD] Error: Illegal value <interface name>_enable for field: mode
[CPOSD] Error: Failed to set object: network
SMBGWY-12348 Firewall The Identity Awareness Blade displays the error message "At least one server has many disconnection occurrences in the last hour" in SmartConsole on the standby member of a centrally managed Spark cluster.
SMBGWY-12952 Firewall During policy installation, the CPU could reach 100% usage for extended periods (up to several minutes) due to how large batches of IPs were processed in updatable objects.
SMBGWY-12940 WebUI Enhancement: Customizable popup windows. 
A new Advanced Settings parameter allows users to configure whether clicking outside a popup closes it or keeps it open. By default, popups close when users click outside them.
Key Features:
- Customizable Behavior – Choose whether background clicks dismiss popups.
- Easy Configuration – Adjust this setting in the Advanced Settings panel.
SMP-8666 WebUI In Quantum Spark Management, in Remote access > Statistics, a Gateway on which Two-Factor Authentication (2FA) was enabled shows 2FA as disabled.
SMBGWY-12523 WebUI The WebUI stops working when you edit an IPv6 interface.
SMBGWY-12892 IPS When you switch the mode of the IPS Software Blade to Intrusion Detection System (IDS), some protections (examples: command injection, SQL injection) remain active even though the IDS mode should set all protections to "Detect."
SMBGWY-13818 Cluster A cluster member stops sending multicast PIM traffic after failover or a reboot.
SMBGWY-13489 Cluster A cluster configured with Virtual MACs (VMACs) may silently drop traffic arriving to the Internet Connection.
SMBGWY-12365 IoT After an asset was recognized as working with a randomized MAC Address ("Locally Administered Address (LAA) MAC), when this asset connects again, the Quantum Spark Gateway does not send this asset again for recognition.

R81.10.15 Resolved Issues and Enhancements

Show / Hide this section

Enter the string to filter this table:

ID Category Description
Build 996003913
SMB-19844 General Enhancement: OpenSSH has been upgraded to version 9.8p1, which contains the fix for CVE-2024-6387.
SMBGWY-10328,
SMBGWY-10327
General Improved the stability of the "sfwd" daemon when the IPS blade is enabled on a Centrally Managed Quantum Spark Gateway.
SMBGWY-6374 General Locally Managed Quantum Spark Gateway generates "Accept" logs for all TCP DNS queries to external DNS servers.
SMBGWY-10470 General Restarting (for example, disabling/enabling) an Internet connection causes other Internet connections on the same interface to restart.
SMBGWY-11425 General On some Wired 1500 series models, the 802.1x authentication may not work.
SMBGWY-8050 General The default behavior is to forward DNS requests to all configured DNS servers. Starting in this build, you can change the behavior to forward the DNS requests only to the DNS servers configured in the Primary Internet connection. For more information, refer to the R81.10.X Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances Locally Managed Administration Guide (section: Managing the Device > Configuring the DNS Server).
SMBGWY-9678 General Monthly report is sent two times in one month.
SMBGWY-10494 General Error 00351 when creating a Custom Service Object/Group.
SMBGWY-11136 CPOS High CPU use on a Locally Managed Quantum Spark appliance with a bridge interface configuration after an upgrade from R80.20.xx to R81.10.xx.
SMBGWY-10892 CPOS After enabling MAC Filtering, instead of opening the WebUI on a Quantum Spark Gateway, the web browser shows an empty page with this error: "Either invalid input was specified or an internal error has occurred. If the problem persists contact Check Point Technical Assistance Center". This issue occurs on 1600 / 1800 / 1900 / 2000 models with an advanced LAN configuration (for example, Bridge, Bond).
SMBGWY-9881 CPOS Wireless channel 169 is missing from the list of channels that should not participate in Automatic Channel Selection (ACS). As a result, the automatic mechanism may select this unsupported channel, and the WebUI would show this error: "Value is not valid" when configuring a Wireless connection".
SMBGWY-10877 VPN Manual selection of a Remote Access VPN certificate for the strongSwan client does not work on a Locally Managed Quantum Spark Gateway.
SMBGWY-9889,
SMBGWY-9391
VPN Site to Site VPN may fail to work on a Locally Managed Quantum Spark Cluster (because the VPN Tunnel Test packets are not sent as expected).
SMBGWY-10109 VPN Site to Site VPN may fail to work on a Centrally Managed Quantum Spark Gateway after establishing SIC for the second time.
SMBGWY-9297 VPN IKE negotiations in a Site to Site VPN might fail in IKE Packet #3 on a Centrally Managed Quantum Spark Gateway managed with SmartProvisioning.
Immediate Workaround:
On a Quantum Spark Gateway, run these commands in the Expert mode:
1. fw ctl set int ike_in_separate_daemon 0
2. sfwd_restart
SMBGWY-9562 VPN A Remote Access VPN connection with the strongSwan client using IKEv2 does not work.
SMBGWY-11491 VPN Multiple packets that enter the same VPN tunnel may be encrypted with the same sequence number. As a result, the VPN peer may treat this traffic as a replay attack.
SMBGWY-11356 GUI After you add more than eight Network objects into the Network Object Group object and save it, when you open this Network Object Group object, it shows only eight objects. To see other objects, you must click the last object and then press the down arrow key on the keyboard.
SMBGWY-10490 GUI The Configure Cluster button in the WebUI may not open the wizard.
SMBGWY-10707 GUI The WebUI shows the status "No Internet access (probing failed)" for monitoredInternet connections when ISP Redundancy is disabled.
SMBGWY-10750 Firewall MAC Filtering may stop working on 1500 models (traffic may be blocked for allowed MAC addresses).
SMB-19803 Firewall Disabling an internet connection that uses one of the LAN ports in 1600/1800/1900/2000 might cause the switch configuration to be partially applied.
SMBGWY-10713 VoIP Error "sip_any-tcp service has overlapping ports" when editing the " SIP_TCP" service object in the Users & Objects view > Network Resources section > Services page.
Error "SIP_TCP service has overlapping ports" when editing the " sip_any-tcp" service object in the Users & Objects view > Network Resource s section > Services page.
SMBGWY-10301 VoIP After a policy modification, there is a brief interruption of NAT connections from the Internet to internal hosts.
SMBGWY-10650 ClusterXL After a cluster failover, a Quantum Spark Cluster Member may stop sending its logs to the Infinity Portal > Quantum Spark Management service.
SMBGWY-10769 WebUI It is not possible to configure the same VLAN ID on different Internet connections.
SMBGWY-11758,
SMBGWY-11429
WebUI Instead of opening the WebUI, the web browser shows "500 Internal Error" and "There was an unusual problem serving the requested URL".
SMBGWY-9842 IoT On a Centrally Managed Quantum Spark Gateway, many IoT assets appear in the Unrecognized section of the WebUI > Home view > Monitoring section > Assets page.
SMBGWY-11602 IoT In a cluster of Locally Managed Quantum Spark Gateways, IoT Discovery may not work when the Firewall blade is configured in the Strict Mode.
SMBGWY-10429 IoT "Assets discovery is at maximum. All newly connected assets will appear as unrecognized" warning in the WebUI because there are too many IoT log entries in the /tmp/log/iot_lmm.elg file.
SMBGWY-10649 IoT High CPU utilization when the IoT blade is enabled because multiple domain objects are created automatically in the Network Group objects used for the IoT policy.

R81.10.10 Resolved Issues and Enhancements

Show / Hide this section

Enter the string to filter this table:

ID Category Description
Build 996002993
SMB-19844 General Enhancement: OpenSSH has been upgraded to version 9.8p1, which contains the fix for CVE-2024-6387.
Build 996002945
SMBGWY-9641 VPN Added the protection against CVE-2024-24919 - a vulnerability in Security Gateways with Remote Access VPN enabled. Refer to sk182357.
SMBGWY-7140,
SMBGWY-7476
GUI NEW: Ability to configure messages for the CLI login:
- A Banner message - a message that appears before the user enters their credentials.
- A Message-of-the-Day (MOTD) - a message that appears after a user logs in.
These messages appear only in CLI for an SSH connection and a Serial (Console) connection.
In the R81.10.X CLI Guide, refer to these commands:
- set message banner
- set message motd
SMBGWY-8593 General NEW: Support for Wildcards on Locally Managed Quantum Spark appliances. Wildcards represent IP addresses that share a common pattern (for example: all IP hosts with the IP address 250 on different networks: 192.168.*.250 / 24). You can use these Wildcard objects in the Access Policy in the "Source" or the "Destination" columns.
SMBGWY-8276 General Enhancement: In the Logs & Monitoring view > Status section > Assets page > Actions > Export assets to a csv file > added these new columns MAC Address, IP Address, Interface, Blocked('true' or 'false')
SMBGWY-8816 General Enhancement: Added new Gaia Clish commands :
- set interface-type <Internal Name of Interface>
- show interface-type <Internal Name of Interface>
SMBGWY-7530 General Implemented fail-accept ability for parser errors.
SMBGWY-8248 General Expired certificates are not removed completely from the appliance when deleted manually.
SMBGWY-9423 General Configuring the custom logo does not work in R81.10.10. It is not possible to configure the logo through the WebUI (in WebUI > Device > Advanced Settings > Web Interface Settings and Customizations - Use a company logo in the appliance's web interface) or through Clish.
SMBGWY-9004 General SSL Inspection stops working for some HTTPS web sites because Trusted CA certificates are not updated automatically (WebUI > Access Policy > SSL Inspection > Advanced page).
SMBGWY-8895 General Quantum Spark Gateway may crash.
SMBGWY-9298 General A "System Error" popup appears with this message when opening the Home view > System page:
An internal error has occurred.
If the problem persists, contact Check Point Technical Assistance Center
Web server error
SMBGWY-8959 General On the 1535 model, the error "Value is not valid" appears in WebUI > System section > Device page in the Web portal certificate field when selecting a previously uploaded 3rd-party Root CA certificate and clicking Apply. Refer to sk182293.
SMBGWY-9553 General Gaia OS Scheduled Backups to an SCP server fail.
SMBGWY-8507 General SNMP query for memory utilization OID .1.3.6.1.4.1.2620.1.6.7.4 returns an Active Virtual Memory (memActiveVirtual64) value that is less than the Active Real Memory (memActiveReal64) value.
SMBGWY-9493 General It is not possible to modify your own admin unless you are a Super Admin.
SMBGWY-8331 VPN SNMP query for OID "tunnelTable" (the list of VPN Tunnels) returns "CHECKPOINT-MIB::tunnelTable: No entries".
SMBGWY-7712 VPN In rare cases, when using ISP Redundancy in the High Availability mode, and there is an ISP Link failover from the cellular ISP to the regular ISP, the VPN tunnel recovery mechanism might fail.
Immediate Workaround:
1. Connect to the command line on the Quantum Spark Gateway.
2. Log in to the Expert mode.
3. Set the value of the kernel parameter "vpn_force_configload_upon_failover" to 1:

fw ctl set int vpn_force_configload_upon_failover 1
4. Clear the VPN cache:

vpn tu tlist del all
SMBGWY-9297 VPN IKE negotiations in a Site to Site VPN might fail in IKE Packet #3 on a Centrally Managed Quantum Spark Gateway that is managed with SmartProvisioning.
Immediate Workaround:
On a Quantum Spark Gateway, run these commands in the Expert mode:
1. fw ctl set int ike_in_separate_daemon 0
2. sfwd_restart
SMBGWY-9440 GUI 1. Go to Device > Network section > Internet.
2. Edit the Internet connection of type IPv4 over IPv6 (IPIP).
3. In the section VNE Settings, in the field Service name select v6plus Static IP service.
4. The checkbox Unnumbered IP address does not appear.
Immediate Workaround:
1. In the section VNE Setting s, in the field Service name select another service.
2. In the section VNE Settings, in the field Service name select v6plus Static IP service again.
SMBGWY-9560 GUI Error "The settings overlap with those of another network or bridge" in the WebUI when configuring a LAN interface with the same IPv4 address as was assigned in an Internet connection of type IPv4 over IPv6 (IPIP) in the field BR addres s.
SMBGWY-8512 Firewall When a cluster of Quantum Spark appliances is connected to Smart-1 Cloud, and an administrator configures the interface "maas_tunnel" as "Non-monitored" in SmartConsole in the cluster object, the cluster configuration may not recognize the interface "maas_tunnel" as "Non-monitored" ("Disconnected"). As a result, the cluster changes the state of this interface to "DOWN".
Immediate Workaround:
On each cluster member, manually add the interface "maas_tunnel" to the configuration file.
Run this command in the Expert mode:
echo "maas_tunnel" >> $FWDIR/conf/discntd.if
SMB-19803 Firewall Disabling an internet connection that uses one of the LAN ports in 1600/1800/1900/2000 might cause the switch configuration to be partially applied.
SMBGWY-9513 Threat Prevention The "Categorized HTTPS Sites" option does not classify specific websites when "TLS 1.3 hybridized Kyber support" is enabled in the browser. Refer to sk182318.
Build 996002906
SMBGWY-8050 General The default behavior is to forward DNS requests to all configured DNS servers. Starting in this build, you can change the behavior to forward the DNS requests only to the DNS servers configured in the Primary Internet connection. For more information, refer to the R81.10.X Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances Locally Managed Administration Guide (section: Managing the Device > Configuring the DNS Server)
SMBGWY-8630 General The IoT Protection remains enabled after an administrator enabled the IoT Protection in the Locally Managed mode and changed the configuration to the Centrally Managed mode.
SMBGWY-6194 General "'Web server error" in the First Time Wizard while trying to move forward from "Step 6 - Wireless Network" to the next step.
SMBGWY-8176 General CPU load may increase on a Locally Managed appliance with enabled IoT protection if an IoT device changes its MAC address repeatedly.
SMBGWY-8336 General Text in System Logs that are related to Cloud configuration (Quantum Spark Management, Smart-1 Cloud, and so on) may contain internal parameter names instead of the parameter values.
SMB-17498 Access Policy "Error has occurred while applying the Firewall settings (error 00351)" when saving a Firewall Access Policy rule that contains a Group object (in Source or Destination) that contains a Network object of type 'Device'. Such unsupported configuration is now blocked.
SMBGWY-8288 VPN The "vpn tu" command fails to delete VPN IPsec SAs and VPN IKE SAs when using Visitor Mode.
SMBGWY-8519 VPN A Remote Access VPN client cannot connect to a Quantum Spark in the Centrally Managed mode because the DynamicID authentication fails to send an email with a one-time password.
The Remote Access VPN client:
1. Shows the "Connecting to site" progress bar
2. Shows the authentication window:
> Authenticating user 'XXX'. Please fill the required input.
>
> User XXX authenticated by FireWall-1 authentication
>
> DynamicID timeout failure. To retry, please type r and select Submit.
SMBGWY-8212 CPOS DHCP Server functionality may not work on tagged-based VLANs configured on LANX interfaces.
SMBGWY-7819 GUI When editing an interface in the WebUI, the Advanced tab in the Link speed field shows an unsupported value 1 Gbps/Half duplex.
SMBGWY-8028 GUI In First Time Wizard, on the Wireless Network page, even though the checkbox Protected network is cleared, it is still necessary to enter a password.
SMBGWY-8256 GUI The WebUI shows N/A for the ranks of OSPF routes.
SMBGWY-2120 GUI To disable the "Connect to the appliance by name from the Internet (DDNS)" option, it is necessary to enter the DDNS password again.
SMBGWY-8189 Firewall Security Gateway may reboot unexpectedly after a policy installation.
SMBGWY-8052 Firewall The cluster state of a Standby cluster member constantly changes between "Down" and "Standby".
SMB-19803 Firewall Disabling an internet connection that uses one of the LAN ports in 1600/1800/1900/2000 might cause the switch configuration to be partially applied.
SMBGWY-8556 Firewall The Gaia Clish command "show configuration" shows the string "nil" instead of the interface name in commands for configuring DHCP Options.
Example:
set dhcp server interface "nil" custom-option name ...
SMBGWY-8631 Firewall New Feature: In the ioc_feeds command on a Centrally Managed Gateway, added support for IoC Feed from a custom CSV format.
Supported IoC types: IP Address, Domain Name, MD5 Hash, SHA1 Hash, SHA256 Hash.
Build 996002845
SMBGWY-7839 General The SFWD daemon crashes in this scenario:
1. SNMP Trap is configured to send a trap when a VPN tunnel is down (OID 1.3.6.1.4.1.2620.1.2000.8.1)
2. Multiple VPN tunnels are in the down state
SMBGWY-8103 General When configuring BGP with "local-address" (for both AS and the peer), the BGP peering is stuck in the "Idle" state:
set bgp external remote-as <AS> local-address <IP Address>
set bgp external remote-as <AS> peer <IP Address> local-address <IP Address>
SMBGWY-7135 General After you fetch the policy from the cloud, the new policy might not be applied.
SMBGWY-7083 General The Quantum Spark appliance automatically removes files from the "/tmp" partition if the file becomes full.
SMBGWY-6870 General If multiple internet connections are configured on the appliance, associating an internet connection during the configuration of an unnumbered VTI interface results in the association of an incorrect internet connection.
SMBGWY-6711 General The /tmp directory becomes full when the "cloud_update_gw_stats.xml" file grows too large. This file is created for cloud updates in cpdiag, but is not applicable to Quantum Spark.
SMBGWY-7576 General If no IPv6 address/prefix is acquired through SLACC/DHCPv6, the Internet connection is not established, even if an IPv6-prefix was acquired through PD (Prefix-Delegation).
SMBGWY-7486 General Although in Infinity Portal > in Quantum Spark Management > Plans view > edit a Plan > in the " Services" section > on the " Firmware" page, the option " The firmware version is managed locally on the device" is selected, the managed Quantum Spark appliances automatically upgrade their firmware.
SMBGWY-6296 CLI Creating a VPN site in Gaia Clish fails with the error "Incomplete command".
SMBGWY-8154 CPOS In some scenarios, a misconfiguration on a DNS Server may lead to the exhaustion of ephemeral ports on the Security Gateway.
SMBGWY-6029 VPN On centrally managed Quantum Spark appliances, when you query the status of a permanent VPN tunnel with the "snmpwalk" command, the command prints duplicate statuses for the tunnel.
SMBGWY-7153 VoIP SIP calls do not work when the internal PBX and the external VoIP provider use different signaling ports.
SMBAUTO-57 VoIP Add Gaia Clish commands to configure and view VoIP settings:
- set voip (press the Tab key to see the options)
- show voip
SMBGWY-7529 Gaia Embedded OS If in version R81.10.00 or versions R80.20.xx, you added a static route with enabled monitoring (with the Gaia Clish command "add static-route ... monitored-ip <Monitored IP Address> on"), then after an upgrade to version R81.10.05 or version R81.10.07, the configured probing fails because the configured monitored IP address became corrupted in the Gaia Embedded OS configuration.
SMBGWY-7197 GUI When you connect to Cloud Services and change some advanced settings, this web server error appears:
An internal error has occurred.<br>If the problem persists, contact Check Point Technical Assistance Center
SMBGWY-8115 Firewall In a cluster connected to Smart-1 Cloud, local probing may start on the "maas_tunnel" interface, although it is not monitored by the cluster (output of the Expert command "cphaprob -i list" or the Gaia Clish command "show cluster members pnotes problem" shows that the Critical Device "Local Probing" reports its state as "problem").
SMBGWY-7902 Firewall The output of the "fw ver" and "cpstat os" commands on a 1555 model shows the model as '1550'.
SMBGWY-7084 Firewall A Quantum Spark cluster member in the Active state loses its OSPF neighbors if its cables are disconnected and then connected again, even though its cluster state changes to Standby.
SMBGWY-6348 Firewall When you enable Virtual MAC (VMAC) mode on a centrally managed cluster, the standby member sends GARP packets.
SMBGWY-6690 Firewall MAC address flapping occurs between cluster members when a bridge interface is configured in the cluster. See sk181859.
SMBGWY-7775 Firewall Quantum Spark appliance drops multicast traffic on a Bridge interface with the log "IP routing failed (bridge routing failure)". See sk182050.
SMBGWY-6869 Core On 1600/1800 Quantum Spark appliances, the size of the Firewall memory pool's initial allocation (hmem) is too high. As a result, the available memory is lower than expected.
SMBGWY-7782 WebUI When the WebUI language is changed to Japanese, some notifications are not displayed in Japanese.
SMBGWY-7954 WebUI In WebUI, in the Device view > System section > Tools page > added " FW Monitor Tool".
Warning - When you select this option, the CPU load increases.
SMBGWY-7955 WebUI In WebUI, in the Device view > System section > Tools page > added " Firewall Ctl Tool".
Warning - When you run this tool, the CPU load increases.
SMBGWY-7957 WebUI In WebUI, in the Device view > System section > Tools page > added " VPN Debug Tool".
Warning - When you run this tool, the CPU load increases.
SMBGWY-6588 WebUI In WebUI, in the Device view -> System section > Tcpdump Tool - it takes a long time to start showing the output if you expand the Advanced section and select VPN.

R81.10.08 Resolved Issues and Enhancements

Show / Hide this section

Enter the string to filter this table:

ID Category Description
Build 996001750
SMBGWY-9641 VPN Added the protection against CVE-2024-24919 - a vulnerability in Security Gateways with Remote Access VPN enabled. Refer to sk182357.
SMBGWY-8593 General New: Support for Wildcards on Locally Managed Quantum Spark appliances. Wildcards represent IP addresses that share a common pattern (for example: all IP hosts with the IP address 250 on different networks: 192.168.*.250 / 24).
SMBGWY-7839 General The SFWD daemon crashes in this scenario:
1. SNMP Trap is configured to send a trap when a VPN tunnel is down (OID 1.3.6.1.4.1.2620.1.2000.8.1)
2. Multiple VPN tunnels are in the down state
SMBGWY-9513 Threat Prevention The "Categorized HTTPS Sites" option does not classify specific websites when "TLS 1.3 hybridized Kyber support" is enabled in the browser. Refer to sk182318.
SMBGWY-8050 General The default behavior is to forward DNS requests to all configured DNS servers. Starting in this build, you can change the behavior to forward the DNS requests only to the DNS servers configured in the Primary Internet connection. For more information, refer to the R81.10.X Quantum Spark 1500, 1600, 1800, 1900, 2000 Appliances Locally Managed Administration Guide (section: Managing the Device > Configuring the DNS Server)
SMBGWY-8103 General When configuring BGP with "local-address" (for both AS and the peer), the BGP peering is stuck in the "Idle" state:
set bgp external remote-as <AS> local-address <IP Address>
set bgp external remote-as <AS> peer <IP Address> local-address <IP Address>
SMBGWY-7135 General After you fetch the policy from the cloud, the new policy might not be applied.
SMBGWY-7083 General The Quantum Spark appliance automatically removes files from the "/tmp" partition if the file becomes full.
SMBGWY-6870 General If multiple internet connections are configured on the appliance, associating an internet connection during the configuration of an unnumbered VTI interface results in the association of an incorrect internet connection.
SMBGWY-6711 General The /tmp directory becomes full when the "cloud_update_gw_stats.xml" file grows too large. This file is created for cloud updates in cpdiag, but is not applicable to Quantum Spark.
SMBGWY-7576 General If no IPv6 address/prefix is acquired through SLACC/DHCPv6, the Internet connection is not established, even if an IPv6-prefix was acquired through PD (Prefix-Delegation).
SMBGWY-7486 General Although in Infinity Portal > in Quantum Spark Management > Plans view > edit a Plan > in the " Services" section > on the " Firmware" page, the option " The firmware version is managed locally on the device" is selected, the managed Quantum Spark appliances automatically upgrade their firmware.
SMBGWY-6296 CLI Creating a VPN site in Gaia Clish fails with the error "Incomplete command".
SMBGWY-8154 CPOS In some scenarios, a misconfiguration on a DNS Server may lead to the exhaustion of ephemeral ports on the Security Gateway.
SMBGWY-6029 VPN On centrally managed Quantum Spark appliances, when you query the status of a permanent VPN tunnel with the "snmpwalk" command, the command prints duplicate statuses for the tunnel.
SMBGWY-7712 VPN In rare cases, when using ISP Redundancy in the High Availability mode, and there is an ISP Link failover from the cellular ISP to the regular ISP, the VPN tunnel recovery mechanism might fail.
Immediate Workaround:
1. Connect to the command line on the Quantum Spark Gateway.
2. Log in to the Expert mode.
3. Set the value of the kernel parameter "vpn_force_configload_upon_failover" to 1:

fw ctl set int vpn_force_configload_upon_failover 1
4. Clear the VPN cache:

vpn tu tlist del all
SMBGWY-8519 VPN A Remote Access VPN client cannot connect to a Quantum Spark in the Centrally Managed mode because the DynamicID authentication fails to send an email with a one-time password.
The Remote Access VPN client:
1. Shows the "Connecting to site" progress bar
2. Shows the authentication window:
> Authenticating user 'XXX'. Please fill the required input.
>
> User XXX authenticated by FireWall-1 authentication
>
> DynamicID timeout failure. To retry, please type r and select Submit.
SMBGWY-7153 VoIP SIP calls do not work when the internal PBX and the external VoIP provider use different signaling ports.
SMBAUTO-57 VoIP Add Gaia Clish commands to configure and view VoIP settings:
- set voip (press the Tab key to see the options)
- show voip
SMBGWY-7529 Gaia Embedded OS If in version R81.10.00 or versions R80.20.xx, you added a static route with enabled monitoring (with the Gaia Clish command "add static-route ... monitored-ip <Monitored IP Address> on"), then after an upgrade to version R81.10.05 or version R81.10.07, the configured probing fails because the configured monitored IP address became corrupted in the Gaia Embedded OS configuration.
SMBGWY-7197 GUI When you connect to Cloud Services and change some advanced settings, this web server error appears:
An internal error has occurred.<br>If the problem persists, contact Check Point Technical Assistance Center
SMBGWY-8115 Firewall In a cluster connected to Smart-1 Cloud, local probing may start on the "maas_tunnel" interface, although it is not monitored by the cluster (output of the Expert command "cphaprob -i list" or the Gaia Clish command "show cluster members pnotes problem" shows that the Critical Device "Local Probing" reports its state as "problem").
SMBGWY-7902 Firewall The output of the "fw ver" and "cpstat os" commands on a 1555 model shows the model as '1550'.
SMBGWY-7084 Firewall A Quantum Spark cluster member in the Active state loses its OSPF neighbors if its cables are disconnected and then connected again, even though its cluster state changes to Standby.
SMBGWY-7530 General Implemented fail-accept ability for parser errors.
SMBGWY-6348 Firewall When you enable Virtual MAC (VMAC) mode on a centrally managed cluster, the standby member sends GARP packets.
SMBGWY-6690 Firewall MAC address flapping occurs between cluster members when a bridge interface is configured in the cluster. See sk181859.
SMBGWY-7775 Firewall Quantum Spark appliance drops multicast traffic on a Bridge interface with the log "IP routing failed (bridge routing failure)". See sk182050.
SMBGWY-6869 Core On 1600/1800 Quantum Spark appliances, the size of the Firewall memory pool's initial allocation (hmem) is too high. As a result, the available memory is lower than expected.
SMBGWY-7782 WebUI When the WebUI language is changed to Japanese, some notifications are not displayed in Japanese.
SMBGWY-7954 WebUI In WebUI, in the Device view > System section > Tools page > added " FW Monitor Tool".
Warning - When you select this option, the CPU load increases.
SMBGWY-7955 WebUI In WebUI, in the Device view > System section > Tools page > added " Firewall Ctl Tool".
Warning - When you run this tool, the CPU load increases.
SMBGWY-7957 WebUI In WebUI, in the Device view > System section > Tools page > added " VPN Debug Tool".
Warning - When you run this tool, the CPU load increases.
SMBGWY-6588 WebUI In WebUI, in the Device view -> System section > Tcpdump Tool - it takes a long time to start showing the output if you expand the Advanced section and select VPN.
Build 996001683
SMBGWY-6117 General It is not possible to access services accelerated by SmartAccel when the Internet connection MTU value is below the default
SMBGWY-6234 General Removing "external Custom Intelligence Feeds" from SmartConsole and installing the policy do not take effect, and traffic is blocked as if the feeds were not removed.
SMBGWY-5785 General In some scenarios, the SD-WAN next hop is not reachable, which causes link failure.
SMBGWY-5297 Firmware When Anti-Virus blade is enabled, it is possible to fetch a maximum of only 4 emails with POP3 (110).
SMBGWY-6026 Firmware The output of the fw ctl affinity -l is incomplete and contains this error regarding the IRQs of network devices:
No such file or directory
fwaff_read_ifn_irq: error in getting irq values
SMBGWY-6620 Firmware A malicious email notification shows the protocol as SMTP regardless of the actual protocol used.
SMBGWY-5328 CLI The output of the ips stat command shows " Failed to read IPS profiles".
SMBGWY-5856 CLI The output of the Gaia Clish command show configuration stops with this text:
HostName> show configuration
... ...
# Fonic settings allow traffic to pass directly between two network ports (bridged by hardware) even if power is out
/pfrm2.0/bin/lua: /pfrm2.0/bin/cli/showConfig.lua:0: attempt to index a nil value
stack traceback:
    /pfrm2.0/bin/cli/showConfig.lua: in main chunk
    /pfrm2.0/bin/cli/showConfig.lua: in main chunk
    [C]: at 0x00013625
HostName>
SMBGWY-6443 CLI The output of the Gaia Clish command show configuration stops with this text:
HostName> show configuration
... ...
delete static-routes
/pfrm2.0/bin/lua: /usr/local/share/lua/5.1/sys/model.lua:0: staticRoutes.1.getCalculated_interfaceWrapper property or method does not exist.
stack traceback:
    [C]: in function 'error'
    /usr/local/share/lua/5.1/sys/model.lua: in function '__index'
    /usr/local/share/lua/5.1/app/model/staticRoutes.lua: in function ''
    /usr/local/share/lua/5.1/sys/LCM.lua: in main chunk
    /usr/local/share/lua/5.1/sys/CDL.lua: in function 'smartGetByPath'
    /pfrm2.0/bin/cli/showConfig.lua: in function 'command name'
    /pfrm2.0/bin/cli/showConfig.lua: in function 'showConfig_staticRoutes'
    /pfrm2.0/bin/cli/showConfig.lua: in main chunk
    [C]: at 0x00013625
HostName>
SMBGWY-6381 Backup - Restore In the centrally managed mode, after you restore settings from a backup, performing an additional settings backup may fail.
SMBGWY-5034 CPOS For some Internet connection types, it is not possible to change the MTU value.
SMBGWY-5591 CPOS In some scenarios, the process in charge of dynamic routing ( routed) starts before the process in charge of the OS ( cposd).
SMBGWY-5969
SMBGWY-5945
CPOS When a cellular Internet connection with only one SIM loses its DHCP lease, it may stay stuck trying to get a new DHCP lease.
SMBGWY-5552 Logging & Monitoring It is not possible to disable the sending of specific notifications to SMS/Mail.
SMBGWY-5596 Logging & Monitoring It is not possible to disable the sending of specific notifications to the Watch WatchTower application.
SMBGWY-5759 VPN The VPN Passthrough feature introduced in R81.10.08 does not work.
SMBGWY-6180 VPN When handling UDP packets with identical source and destination ports (example: 3343), the S2C packet is dropped if it arrives first.
SMBGWY-5508 VoIP Incoming traffic is dropped on a cleanup rule instead of matching the SIP rule.
SMBGWY-5272 WebUI During the configuration of IPv6 static routes in the WebUI, a message appears to reload the page.
SMBGWY-5640 WebUI The WebUI does not display some images (branding fix).
SMBGWY-5531 WebUI The WebUI homepage and login do not correctly show white labeling texts and images for features.
Build 996001608
SMBGWY-5760 WebUI The " fwtmp partition is about to be full" notification in the WebUI is not translated correctly and shows the system variable.

Article Properties

Access LevelGeneral

StatusApproved

Date Created2023-06-15

Last Modified2026-07-08

Was this page helpful?YesNo

Haven't found what you're looking for?

Our customer support team is only a click away and ready to help you 24 hours a day.

Open a Service Request

reCAPTCHA

Recaptcha requires verification.

protected by reCAPTCHA