sk183507 - Check Point Quantum R82.10 Release Known Limitations

Header/footer test page

My Favorites

Solution ID: sk183507


Technical Level:

Basic

Email

Print

Check Point Quantum R82.10 Release Known Limitations

ProductSecurity Gateways, Security Management

VersionR82.10

Last Modified2026-07-23

Solution

This article lists all Quantum R82.10 Release specific known limitations and unsupported features, including limitations from the previous versions.

For more information about R82.10, see the R82.10 Release Notes, R82.10 Home Page and R82.10 Resolved Issues.

Visit Check Point CheckMates Community to ask questions or start a discussion and get our experts assistance.

Important notes:

Show the Entire Article

Unsupported Features Show this section

Table of Contents

- Installation and Upgrade

- Licensing

- Gaia OS

- Multi-Domain Management

- SmartConsole / Management Console

- Logging

- SmartProvisioning
- Security Gateway

- SD-WAN

- ClusterXL

- ICAP

- VSNext

- Threat Prevention
- Identity Awareness

- Mobile Access

- VPN

- Zero Phishing

- CloudGuard Network

- ElasticXL and Maestro

Enter the string to filter the below table:

ID Description Found in version
Unsupported Features - Installation and Upgrade
PMTR-110069 The R82.10 release is not supported on the Threat Emulation Appliances. R82
PMTR-59345 Central Deployment in SmartConsole does not support:
- Connection from SmartConsole to the Management Server through a proxy Server. In this case, use the applicable API command
- ClusterXL in Load Sharing mode
- VRRP Cluster
- Installation of a package on a VSX VSLS Cluster that contains more than 3 members
- On Multi-Domain Servers: Global Domain, or the MDS context
- Standby Security Management Server or Multi-Domain Security Management
- Quantum Maestro
R81
Unsupported Features - Licensing
PMTR-47087 These products do not support the new licensing visibility features:
- Network Security: Advanced Networking and Clustering, Capsule Cloud and Capsule Workspace.
- Security Management: Endpoint Policy Management, SmartPortal, User Directory (LDAP).
- Multi-Domain Management: Security Domain
- Remote Access & Endpoint
R80
Unsupported Features - Gaia OS
PMTR-48258 The Gaia "Cloning Group" feature (all its modes) is not supported in a Multi-Version Cluster (while cluster members run different release versions). R80.40
Unsupported Features - Multi-Domain Management
PMTR-17365 The "Install Policy" action from a Multi-Domain Management Server (also through "Install Policy Presets") does not support QoS and Desktop policies. R80.20.M1
Unsupported Features - SmartConsole / Management Console
PMTR-101120 Login into SmartConsole with an IPv6 address using SAML is not supported. R81.20
PMTR-104470 SmartConsole does not support (or has a limited support) the High Contrast Theme in these sections and windows:
- "Gateways & Servers" view > select a Security Gateway / Cluster object > at the top, click the Actions menu > click Install Hotfix, or Version Upgrade
- "Gateways & Servers" view > select a Security Gateway / Cluster object > in the lower pane, click the Licenses tab
- "Gateways & Servers" view > at the top, click Changes
- "Security Policies" view > Autonomous Threat Prevention > click Policy, or File Protections
- "Security Policies" view > Access Control policy or Threat Prevention policy > at the top, click Changes
- "Manage & Settings" view > Sessions > View Sessions > at the top, click Changes
- "Manage & Settings" view > Sessions > Revisions > at the top, click Changes
- "Manage & Settings" view > Sessions > Revisions > select a revision > at the top, click the Actions menu > Revert to this Revision
- "Manage & Settings" view > Package Repository
R81.10
PMTR-58838 Changes (Diff) report does not support:
- A Standalone Server
- Changes made in the Legacy SmartDashboard
R81
PROV-2200 The "Get Interfaces" operation on the "Network Management" page of a Security Gateway (or Cluster) object only supports up to 500 interfaces of all types.
- **To resolve:**If the Security Gateway (or Cluster) has 500 or more interfaces of all types, use the API get-interfaces on the Management Server to pull this information.

Examples:

1)get-interfaces target-name <Name of Security Gateway> with-topоlogy false

2) get-interfaces target-name <Name of Cluster Object> with-topоlogy trueFor more information refer to Management API.
R81
PMTR-57122 Search for section titles is not supported. R80
- Changes to the Traditional Anti-Virus file types policy are not supported. Use the Anti-Virus blade to change the out-of-the-box Check Point policy. R80
Unsupported Features - Logging
PMTR-40514 In the SmartConsole > Logs & Monitor view > [ + ] New Tab > Views, sorting of the Favorites and Shared columns is not supported. R80.40
PMTR-47703 Purge, log switch and fetch log file tasks are not supported from SmartConsole.
- Fetch log files from a remote Server is available from the command line only. Run: fw fetchlogs <Gateway-Name/IP>
R80.10
Unsupported Features - SmartProvisioning
PMTR-109023 SmartProvisioning / SmartLSM is not supported in VSNext mode. R82
PMTR-56758 It is not supported to remove an IP address from one interface and assign the same IP address to another interface in the device object in the same edit action. " Error field: ipAddr, Desc: IP address is in the subnet of an existing network" is displayed. R81
PMTR-54979 When managing devices with the SmartProvisioning Software Blade, on the devices you must configure the connection with the Security Management Server using the IPv4 address in the connect security-management mgmt-addr <IPv4 address of Security Management Server> command (it is not supported to use the FQDN of the Security Management Server in this command). R80.40
Unsupported Features - Security Gateway
PMTR-60143 The perf command is not supported on Threat Emulation appliances and on all other Check Point appliances that have only one or two CPU cores.
- On these appliances, use the top and turbostat commands to monitor the performance.
R81.10
PMTR-58361 Intra-Tunnel Inspection of GTP-U user traffic is not supported. R81
PMTR-58366 The "Produce extended logs on unmatched PDUs" option is not supported in the Security Gateway (Cluster) object > Carrier Security > Track.
As a result, it is not possible to generate informative logs for unmatched GTP-C control packets (except for a plain clean up rule logging).
R81
Unsupported Features - SD-WAN
PMTR-109701 SD-WAN Overlay does not support having multiple center gateways in a star community with no satellites, when "Mesh center gateways" checkbox is selected. R82
PMTR-108481 Anti-Spam, Threat Emulation and Threat Extraction Blades do not support Security Gateways with Dynamically Assigned IP (DAIP). R82
PMTR-108485 SD-WAN Overlay does not support VPN Tunnel between gateways while both sides behind CGNAT / Dynamic NAT. R82
PMTR-108281 SD-WAN does not support matching a "Local Breakout" rule to traffic in this scenario:
1. Traffic matches a Policy-Based Routing (PBR) rule that applies to traffic from a local network to "Default", and the next hop in this rule is set to a VPN Tunnel Interface (VTI).
2. The priority of this PBR rule is lower than 100.
R82
PMTR-106136 SD-WAN does not support Cluster configuration when Cluster Members are DAIP Security Gateways. R82
PMTR-107839 SD-WAN Overlay does not support the "Exclude gateway's external IP addresses from the VPN Domain" configuration. R82
PMTR-106717 In a Spoke-Hub-Spoke configuration, an encrypted connection from a Satellite SD-WAN DAIP Security Gateway to another Satellite Security Gateway VPN Domain is not supported when both conditions are met:
- The source IP is from a Dynamic IP interface
- The connection is routed through the central Security Gateway
R82
PMTR-106135 SD-WAN does not support Security Gateways running Gaia OS that have more than one DAIP interface. R82
PMTR-108004 SD-WAN does not support "Overlay - VPN" over Route Based VPN configured with unnumbered VPN Tunnel Interfaces (VTI). R82
PMTR-108010 For inbound connections from the Internet to the Security Gateway itself, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received if there are multiple ISPs. R82
PMTR-105725 In a cluster, SD-WAN does not support interfaces in which the "Network Type" is set to "Private" (Non-Monitored Interface). R82
PMTR-105210 SD-WAN Local Breakout does not apply to connections that originate on the Security Gateway itself (for example, when an administrator connects from the Security Gateway to an FTP server). R82
PMTR-105208 SD-WAN Overlay VPN does not support Route Based VPN. R82
PMTR-105207 SD-WAN Overlay VPN does not support VPN peer Security Gateways connected over a Layer 2 line (SD-WAN Overlay VPN requires Layer 3 connectivity between VPN peers).
The external interfaces of SD-WAN Security Gateways cannot be in the same subnet, if they are configured for a VPN overlay.
R82
PMTR-105213 SD-WAN Overlay VPN is only supported between Check Point Security Gateways that are connected to the same infinity tenant. R82
PMTR-105370 SD-WAN Overlay VPN does not support the configuration of the probing IP address.
By default, SD-WAN Overlay VPN probing sends ICMP requests only to the IP addresses of the VPN Peers.
R82
PMTR-105209 SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Security Management Server. R82
PMTR-108031 SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Domain Management Server. R82
PMTR-108901 SD-WAN does not support using DAIP Security Gateway objects in Access Control rules (neither in the Source column, nor in the Destination column). R81.20
PMTR-104984 SD-WAN does not support VPN Route Injection Mechanism (RIM) configuration. R81.20
PMTR-104985 SD-WAN does not support VPN Explicit Multiple Entry Point (MEP) configuration. R81.20
PMTR-105215 SD-WAN does not support VPN Overlay with third-party VPN Peers (Check Point Security Gateway continues to use the existing Link Selection). R81.20
PMTR-104986 For inbound connections from the internet, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received, in case of multiple ISPs.
The return will be determined based on the OS routes.
R81.20
PMTR-104981 SD-WAN does not support IPv6 traffic. R81.20
PMTR-104980 Maestro Security Groups do not support SD-WAN configuration. R81.20
PMTR-105894 SD-WAN does not support ClusterXL in the Load Sharing Multicast mode. R81.20
PMTR-105895 SD-WAN does not support ClusterXL in the Active-Active mode. R81.20
PMTR-105533 SD-WAN does not support Security Gateways that are managed with SmartProvisioning / LSM Profiles. R81.20
PMTR-104576 SD-WAN does not support VPN Permanent Tunnels (SmartConsole > VPN Community object > Tunnel Management).
SD-WAN tunnels are kept up automatically by the probing.
R81.20
PMTR-105543 SD-WAN does not support Geo Cluster in Microsoft Azure. R81.20
PMTR-105542 SD-WAN does not support Geo Cluster in Amazon Web Services (AWS). R81.20
PMTR-105544 SD-WAN does not support Geo Cluster in Google Cloud Platform (GCP). R81.20
PMTR-104977 VSX Gateways and VSX Clusters do not support SD-WAN configuration. R81.20
Unsupported Features - ClusterXL
PMTR-59404 Geo Cluster does not support IPv6 traffic. Therefore, it is not supported to configure an IPv6 address on the Cluster and Sync interfaces. R81
PMTR-48477 ICAP Client and ICAP Server are not supported with ClusterXL Load Sharing modes. R80.10
Unsupported Features - ICAP
PMTR-28828 ICAP is not supported when Anti-Virus Deep Scan, Threat Extraction over HTTP or Threat Emulation hold mode is set. R80.30
Unsupported Features - VSNext
PMTR-109340 Virtual Gateway / Virtual System in Monitor Mode is not supported. R82
PMTR-118023 ElasticXL in the VSNext configuration does not supports the Load Sharing mode (more than one Cluster Member per Site).
- Resolved in R82.10 Jumbo Hotfix Accumulator Take 19
PMTR-109011 The "Mirror and Decrypt" feature is not supported in VSNext mode. R82
PMTR-119289,
HEC-2236
In the VSNext mode, after you create a Numbered VTI and attach it to a Virtual Gateway, you must reboot the Security Group. R82
PMTR-109016 Enhanced Link Selection is not supported. R82
PMTR-109024 Anti-Virus archive scanning is not supported. R82
PMTR-109025 Threat Emulation archive scanning is not supported. R82
PMTR-109026 Mail Transfer Agent (MTA) for Threat Emulation is not supported in VSNext mode. R82
PMTR-109028 Alias / Secondary IP address is not supported in VSNext mode. R82
PMTR-109029 ECMP (Equal Cost Path Splitting - Static Routs) is not supported. R82
PMTR-109032 Web SmartConsole is not supported when working in VSNext mode. R82
PMTR-109033 Object Sharing from on-premises Management Server to Infinity Portal is not supported. R82
PMTR-109034 Log Sharing from on-premises Management Server to Infinity Portal is not supported. R82
PMTR-109035 Infinity Playblocks is not supported in VSNext mode. R82
PMTR-108070 ISP Redundancy is not supported in VSNext mode. R82
PMTR-109023 SmartProvisioning / SmartLSM is not supported. R82
PMTR-111386 Maestro in VSNext mode do not support DHCP Server configuration. R82
Unsupported Features - Threat Prevention
PMTR-59492 In a Multi-Domain Server environment, Infinity Threat Prevention does not support the Global Domain. Other Domains are supported. R81
PMTR-42537 Threat Prevention Software blades do not support files with the HTTP 206 partial format with multiple ranges in the same HTTP connection (multipart). R80.40
PMTR-59837 SSH Deep Packet Inspection limitations:
- SSH DPI is only supported for Security Gateways R80.40 and above, managed by Management Servers R80.40 and above.
- Inspection of IPv6 connections is not supported.
- Bridge Mode is not supported.
- Cluster members do not synchronize the data about the inspected SSH traffic.
- Cluster members do not synchronize the SSH DPI configuration.
- Inspection of SSH traffic generated by clients, which do not support the "Diffie-Hellman group exchange" algorithm, is not supported.
- These SSH clients are not supported:
- PuTTY versions 0.64 and lower.
- OpenSSH versions 2.5.2 and lower.
- WinSCP versions 5.7.4 and lower.
- SecureCRT versions 5.2 and lower.
R80.40
Unsupported Features - Identity Awareness
PMTR-64495 Identity Awareness does not support the authentication of Primary Groups of user and computer accounts. By default, the Primary Groups are "Domain Users" and "Domain Computers".
Access roles defined with User groups do not work for users who are members of those user groups and have them as their primary group.
- To use the entire Accounting Unit in an Access Role, use an LDAP group.
R7x
Unsupported Features - Mobile Access
PMTR-60331 These limitations apply to the Guacamole feature:
1. A dedicated Apache Guacamole Server version 1.1.0 or higher is required.
2. The following Guacamole features are not supported:
- The VNC protocol
- RDP file transfer
- The SFTP protocol
- Session recording
3. RDP/SSH is not supported from Capsule Workspace.
4. RDP/SSH is supported only by web browsers with HTML5 support.
5. RDP and SSH applications can be configured only by using their corresponding service objects in SmartConsole:
- “Remote_Desktop_Protocol”
- “SSH”
- “SSH_version_2”
6. The Clipboard function in RDP sessions is supported with these limitations:
- Text only
- Supported browsers: Chrome and Explorer
7. This Single Sign-On option is not supported for Guacamole applications: "This application reuses the portal credentials. If authentication fails, Mobile Access prompts users and stores their credentials"
8. In a VSX environment where the "custom user directory attribute" feature is used, adding a new Virtual System requires manually adding the customUserRecordAttribute.conf file as well.
R81
PMTR-58003 Mobile Access rules in the Unified Access Policy do not support Native Applications that authorize non-TCP or non-UDP services (for example, " icmp-proto"). R81
PMTR-47745 The Mobile Access Portal does not support Web-Form SSO for Citrix StoreFront Web interface. R80.10
PMTR-47591 Mobile Access does not support viewing or editing files with " Office Online apps", Microsoft's browser-based Office applications. Outlook Web Access is supported, however you cannot open or edit Office Online app files from emails. R7x
Unsupported Features - VPN
PMTR-60396 Large Scale VPN (LSV) does not support:
- IPv6
- Route Based VPN (VTI)
- Two VPN peers behind the same NAT device
- Suite-B-GCM-128
- Suite-B-GCM-256 with IKEv1-only (it is necessary to change the global properties of Phase 1 for Remote Access VPN)
- Multiple Hubs
- Route Injection Mechanism (RIM)
- IKE Aggressive Mode
- Permanent Tunnel
- Multiple Entry Point (MEP) VPN
- Dead Peer Detection (DPD)
- Global VPN Community (GVC)
- Tunnel Per Security Gateway pair (Universal Tunnel)
R80.40
PMTR-47783 NAT-T initiator is not supported on VSX Gateways. R80.10
PMTR-47235 Converting Traditional VPN Policy to Simplified VPN Policy is not supported. R80
Unsupported Features - Zero Phishing
PMTR-81859 Browser Zero Phishing is not supported in CloudGuard Network Security Auto Scale solution. R81
Unsupported Features - CloudGuard Network
PMTR-117752 Microsoft Azure Gateway Load Balancer solution is not supported in R82.10. R82.10

ElasticXL and Quantum Maestro Unsupported Features

Enter the string to filter the below table:

ID Product Description Found in version
ElasticXL and Quantum Maestro Unsupported Features - General
PMTR-108783 ElasticXL DHCP Server is not supported on ElasticXL. R82
PMTR-107886 ElasticXL Interface Active Check (IAC) is not supported on ElasticXL. R82
PMTR-84368 Maestro Configuring Auto Scaling Settings is not supported if a Maestro Security Group contains different appliance models. R81.20
PMTR-111387,
MBS-10252
Maestro Maestro does not support Zero Touch. R81
PMTR-111384,
MBS-12257
Maestro Maestro does not support the detection of IP address conflict in Gaia OS. R81
PMTR-111368,
MBS-9128
All The Unique IP address per Chassis (UIPC) feature is not supported for IPv6 addresses. R80.20SP
PMTR-111382,
MBS-3001
All The fw fetchlog command on the Management Server is not supported.
- Use SmartConsole to fetch logs from Security Members.
R80.20SP
PMTR-111386,
MBS-3246
Maestro Maestro in VSNext mode does not support DHCP Server configuration R80.20SP
PMTR-108605 All OPSEC SDK is not supported. R76SP
PMTR-108606 All Hide NAT for traffic initiated from the Management interface of a Security Group is not supported. R76SP
ElasticXL and Quantum Maestro Unsupported Features - Gaia OS
PMTR-101680 ElasticXL ElasticXL supports IP Broadcast Helper (iphelper) in Gaia OS only when two ElasticXL Sites are configured. R82
PMTR-108178 ElasticXL In the Gaia First Time Configuration Wizard, when configuring the first ElasticXL Cluster Member, it is possible to configure an IP address only on the "Mgmt" (Management) interface. This is done on the "Management Connection" page of the wizard. Configuring an IP address on any other interface, such as on the "Internet Connection" page of the wizard, is not supported. R82
PMTR-71560,
MBS-7145
Maestro Maestro does not support the Dynamic CLI. Refer to sk144112. R80.30SP
PMTR-111362,
MBS-13308
All The set iphelper (IP Broadcast Helper) commands are not supported in Gaia gClish. R80.20SP
PMTR-90800 Maestro It is not supported to use the set web ssl-port command to change the MHO's WebUI SSL port from the default port 443 (for example: set web ssl-port 4434). Changing it causes communication issues between Maestro devices. R80.20SP
ElasticXL and Quantum Maestro Unsupported Features - Hardware
PMTR-106636,
MBS-1244
All The Check Point Performance Sizing Utility cpsizeme (see sk88160) is not supported. R80.20SP
PMTR-111375,
MBS-4754
All Central Management of Gaia Device Settings is not supported:
1. In SmartConsole, click "Gateways & Servers" on the navigation panel.
2. Right-click the Gateway object or the Maestro Security Appliance Gateway object.
3. The "Scripts" menu and "Actions" menu are not supported.
R80.20SP
PMTR-111360,
MBS-5227
Maestro It is not supported to install both of the following expansion cards in the same Security Appliance connected to a Maestro Hyperscale Orchestrator:
- 10 GbE and 40 GbE
- 10 GbE and 100 GbE
R80.20SP
ElasticXL and Quantum Maestro Unsupported Features - Licensing
PMTR-111374,
MBS-7929
Maestro Central License is not supported on Quantum Maestro. R80.20SP
ElasticXL and Quantum Maestro Unsupported Features - Cluster
PMTR-99761 ElasticXL Bridge is not supported on ElasticXL in Load Sharing mode. R82
PMTR-111390,
MBS-12227
Maestro Active-Active cluster does not support Maestro. R81
PMTR-111364,
MBS-7913
Maestro Cluster Control Protocol (CCP) encryption is not supported. R80. 30SP
PMTR-106619 All BGP confederations are not supported. R76SP
ElasticXL and Quantum Maestro Unsupported Features - SecureXL
PMTR-122236 ElasticXL Policy-Based Routing (PBR) with ElasticXL requires configuring the incoming interface and any PBR rules. R82
PMTR-111379,
MBS-5415
All Configuring the IPS protection "SYN Attack" in SmartConsole is not supported. You must only use the fwaccel synatk and fwaccel6 synatk CLI commands. R80.20SP
ElasticXL and Quantum Maestro Unsupported Features - VSX
PMTR-60874,
ACCHA-736
Maestro VxLAN interfaces are not supported on Quantum Maestro. R80.20SP
PMTR-111371,
MBS-16945
All NAT46 is not supported in VSX. R80.20SP
ElasticXL and Quantum Maestro Unsupported Features - Networking
PMTR-111442,
MBS-14222
Maestro Maestro does not support Dynamic Routing protocols over GRE tunnels. R81
PMTR-111441,
MBS-14223
Maestro Maestro does not support BGP over VXLAN tunnels. R81
PMTR-104455,
MBS-3946
Maestro Maestro does not support Carrier Security (LTE). R80.20SP
PMTR-111367,
MBS-12823
All " 6in4 tunnel" interface is not supported. R80.20SP
PMTR-111445,
MBS-14200
Maestro Maestro does not support RIPng (IPv6). R76SP
ElasticXL and Quantum Maestro Unsupported Features - Firewall
PMTR-111383,
MBS-14173
All ConnectControl is not supported. R76SP.50
ElasticXL and Quantum Maestro Unsupported Features - VPN
PMTR-111847,
MBS-12310
Maestro Maestro does not support Large Scale VPN (LSV). R81
PMTR-111366,
MBS-14408
All Simultaneous Login Prevention (SLP) is not supported. R80.20SP
PMTR-111444,
MBS-4097
All - Site-to-Site VPN with IPv6 peers is not supported.
- Remote Access VPN from IPv6 clients is not supported.
R80.20SP
AAD-1653,
MBS-8316
All IPv6 VPN is not supported. R80.20SP
ElasticXL and Quantum Maestro Unsupported Features - Identity Awareness
PMTR-111378,
MBS-14460
Maestro Maestro Security Group does not support the Identity Awareness Captive Portal if the L4 distribution is enabled. R80.20SP
ElasticXL and Quantum Maestro Unsupported Features - DLP
PMTR-111370,
MBS-13243
All The Data Loss Prevention Software Blade does not support rules with the Action "Ask". R80.20SP
PMTR-108607 All DLP Fingerprint is not supported. R76SP
ElasticXL and Quantum Maestro Unsupported Features - Threat Prevention
PMTR-111385,
MBS-12329
All Inspection of SMBv3 multi-channel with Anti-Virus and Threat Emulation Software Blades is not supported. R81
ElasticXL and Quantum Maestro Unsupported Features - Mobile Access
PMTR-111377,
MBS-14368
All The Mobile Access Portal Agent is not supported. R80.20SP

Known Limitations

Installation and Upgrade

Enter the string to filter the below table:

ID Description Found in version
Installation and Upgrade
PMTR-108824 The " Timeout waiting for response from database server" message may be shown when performing " set snapshot revert" and the member goes to reboot. The issue is cosmetic only. R82
PMTR-61069 SmartEvent upgrade is allowed only after all Multi-Domain Management Servers with Active Domain Management Servers are upgraded. R81

Quantum Security Gateway   / Identity Awareness / Gaia OS / VSX (Traditional) & VSNext / VPN / QoS / ClusterXL / SecureXL

Identity Awareness

Quantum Security Gateway | Identity Awareness | Gaia OS | VSX (Traditional) / VSNext | VPN | QoS | ClusterXL | SecureXL

Enter the string to filter the below table:

.

ID Description Found in version
Quantum Security Gateway
PMTR-92527 The enabled_blades command shows these errors instead of the expected output when running this command multiple times in parallel:
cat: /tmp/bladesStatus/blades_list: No such file or directory
sed: can't read /tmp/bladesStatus/local_obj: No such file or directory
R82
PMTR-117260 Security Gateway drops FTP "Extended Passive Mode" traffic on a Clean Up rule, although an explicit Access Control rule is configured. See sk183853.
- Resolved in R82.10 Jumbo Hotfix Accumulator Take 36
R81.10
PMTR-59152 Traffic on a single GRE tunnel cannot be distributed to multiple CoreXL Firewall instances.
Therefore, the maximum throughput of a single GRE tunnel is limited by the throughput of a single CoreXL Firewall instance.
R81
PMTR-38747 Output of the fw ctl zdebug + drop command shows messages about connection drops, in addition to Firewall drops. 
These are internal debug messages that do not reflect real Firewall drops. To avoid them, use one of these:
1. The fw ctl zdebug drop command without the "+" character in the syntax
2. The full debug procedure
R80.20
PMTR-42525 When Using a rule with legacy object, in or below a rule with one of the new features that are integrated in the unified policy, install policy on a Security Gateway fails with a verification message.
- To resolve: change the order of the rules so that rules with legacy objects are above rules with new features. Refer to sk115961.
R80.10
PMTR-109230,
PMTR-47316,
PMTR-17546
Logging session does not switch to the backup logging Server after connectivity loss. Refer to sk118697. R7x
Identity Awareness
PMTR-117380 When working in parallel with the Management API and SmartConsole, sometimes you cannot navigate to/from the Sharing Identity page. 
- To resolve: close and reopen the SmartConsole.
R82.10
Gaia OS
PMTR-122146 If there are multiple snapshots stored on the Gateway server, new snapshot creation fails with the error "Cannot create snapshot, insufficient space in /boot", although there is enough unpartitioned space.
- To resolve: delete or export some of the locally stored snapshots.
R82.10
PMTR-120025 The Ansible Playbook role "check_point.gaia.cp_gaia_role" may fail on every several attempts. R82
PMTR-116563 The 3600 and 3800 appliances continue to send the SNMP Trap "powerSupplyFailure" even after disabling the alarm LED activation as described in sk166000. R82
PMTR-51440 While the 4x10G Fiber NIC (CPAC-4-10F-B) is installed in the appliance, the HW Diagnostics "Network Test" fails with these messages:
Network Test: Failed
General Error
R81
PMTR-81308,
GAIA-3345
Changing the MTU on the directly connected switches may cause drops of fragmented traffic due to a MTU mismatch. R80.30
PMTR-47577 If the backup schedule is changed to an invalid date or time, all backup schedules are lost and " Backup schedule failed. The backup will not be scheduled" error message is displayed. R80.10
VSX (Traditional) / VSNext
PMTR-120495 It is not recommended to run the fw unloadolcal command on a VSX/VSNext, as this may break packet forwarding on all virtual switches. R82
PMTR-60160 In VSX, you can use the vsx_util downgrade command only if you did not make any configuration changes after you used the vsx_util upgrade command. R81
VPN
PMTR-104094 If Perfect Forward Secrecy is enabled, Remote Access VPN client may disconnect from the Security Gateway in one hour. R82
PMTR-101631 "IPSec VPN" page in the Security Gateway object still shows a selected VPN Community, although the configuration changes were discarded. Refer to sk182068. R82
PMTR-68228 If the Diffie-Hellman (DH) group configuration is changed (SmartConsole > Global Properties > Remote Access > VPN - Authentication and Encryption > Encryption algorithms > Edit > Phase 1 > Use Diffie-Hellman group) while an Endpoint VPN client is connected, the client disconnects during the next Phase 2 negotiation. R81
PMTR-55445 Site to Site VPN with a Large Scale VPN profile can drop traffic after decryption with the log " According to policy traffic shouldn't have been decrypted".
To prevent this traffic drop:
1. Edit the Large Scale VPN profile object:
1. On the VPN Domain page, in the section "IP addresses allowed in the VPN Domain" select "Restrict to these groups or networks"
2. Select the applicable "Host", "Network", and "Group" objects.
2. Edit the LSV peer object: 
1. In the VPN Domain (Encryption Domain), select the "Address Range" objects, whose IP addresses contain the IP addresses of the "Host", "Network", and "Group" objects you selected in the Large Scale VPN profile object.
3. Install the Security Policy.
R81
PMTR-33694,
PMTR-44902
After running the cpstop ; cpstart commands, the " FW-1: fwconn_chain_get_opaque: invalid id -1" message appears repeatedly on the screen and in the dmesg. This is a cosmetic issue only. R80.20
PMTR-58668 If a Security Gateway with PIM configured is part of a VPN community, PIM service must be added to the Excluded Services in the VPN community object.
This only applies in one of these scenarios:
- Security Gateway is directly connected to a multicast sender
- Security Gateway is configured as a PIM Rendezvous Point
R80.10
PMTR-47752 The VPN client shows as " Not Compliant" when it is not compliant according to the local.scv file, even if SCV is disabled.
- To resolve: Configure the VPN site again on the client.
R80.10
PMTR-47501 When using a VPN client, activity logs are not generated for ICMP traffic. R7x
PMTR-50210 RADIUS authentication fails for LDAP users as the Security Gateway uses sAMAccountName and not UPN when UPN is needed. Refer to sk122477. R7x
QoS
PMTR-47566 No warning is displayed if an empty network group object appears in the source or destination column. R7x
ClusterXL
ACCHA-3403 Traffic outage may occur in a ClusterXL / VSX Virtual System configured in the Active/Standby Bridge Mode after a cluster failover that was caused by the disconnection of the direct bridge link. R80.10
SecureXL
PMTR-120253 In VSX mode, when running performance tests at higher CPS (Connections per second) across different sources and destinations, the Security Gateway will experience drops because that source-based routing is enabled in VSX mode by default.
- To resolve: Disable source-based routing to reduce the number of cache entries created and deleted during CPS test and improves the performance. Run: 

fw ctl set -f int cphwd_enable_ecmp 0 -a
R82.10
PMTR-121309,
PMTR-121673
If appliance includes one of the following line cards (CPAC-2-40F-B, CPAC-2-40F-C, CPAC-2-100/25F-B), then use this upgrade procedure to R82.10:
1. Install R82 
2. Upgrade to R82.10
Ensure the correct firmware version is installed on card:
1. Connect to the command line on the appliance.
2. Log in.
3. If the default shell is Gaia Clish, go to the Expert mode:

expert
4. Get the current firmware version:

ethtool -i <Name of Line Card Interface>



Example output:



[Expert@MyGW:0]# ethtool -i eth1-01

driver: mlx5_pci

version: DPDK 20.11.7.4.0 (14 Nov 24)

firmware-version: 12.26.6402



Check that the firmware-version is either 12.26.6402 or 12.28.2700 
- Resolved in R82.10 Jumbo Hotfix Accumulator Take 6
R82.10

Quantum Security Management   / Multi-Domain Security Management / Compliance / Logging / SmartEvent / SmartProvisioning

Quantum Security Management | Multi-Domain Security Management | Compliance | Logging | SmartEvent | SmartProvisioning

Enter the string to filter the below table:

ID Description Found in version
Quantum Security Management
PMTR-116108 Wildcard objects do not appear in the search results when searching by IP address. R82
PMTR-74025 In API commands like show-software-packages-per-targets and in the SmartConsole, the "installed" field remains empty. As a result, The Security Management is not aware of the specific image installed on SMB appliances, but only of the version. R81.20
PMTR-85908 When configuring the SD-WAN interface of the Security Gateway with the set_sdwan command and then perform "Get Interfaces" in SmartConsole while the interface has already been listed on the Network Management page (as internal), the interface may not turn to external as expected.
- To resolve: Remove this interface from the Network Management page and perform "Get Interfaces" again.
R81.10
PMTR-51456 The value configured in SmartConsole > Global properties > Advanced > Configure > Central Device Management > " device_settings_max_script_length_in_KB" field is not applied.
The upper limit is always 8 kilobytes.
R81.10
PMTR-56141 When fetching a VPN Tunnel Interface (VTI) from Cluster Members using the get-interfaces Management API command, you must configure the Cluster VIP address using the set simple-cluster API before publishing the session.
Examples:
1. mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "private"
2. mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "cluster" interfaces.update.ip-address 1.2.3.4 interfaces.update.ipv4-mask-length 24
R81
PMTR-60100 When creating a rule with the "Detailed Log" track without "Accounting" disabled, the "Accounting" still appears after you close and open SmartConsole.
- To resolve: Modify the rule to remove the "Accounting" setting.
R80.40
PMTR-50315 " Certificate with the same Distinguished Name already installed for another CA" message in SmartConsole in the following scenario:
1. A user started to create a new Trusted CA object with a certificate
2. A user discarded the session
3. A user tried to create a new Trusted CA object with the same certificate
R80.40
PMTR-81309,
PRHF-14607
Running a one time script on a Security Gateway (that reads files or outputs of commands) using a "One Time Script" feature in SmartConsole or with API may fail after 5 minutes with the "Operation timed out" error.
The limit for reading files is 9,730 lines or 730 KB (whichever is reached first).
R80.10
PMTR-54350 The API show access-rule with the specified values from-date or to-date in the hits-settingparameter, returns accurate data only when these timestamps cover more than the last 24 hours.
For example, on May 27th at 14:00, the query must not cover any part of the last 24 hours (between May 26th at 14:00 and May 27th at 14:00).
R80.10
PMTR-41764 The "URL" field shows " \\\* Confidential ***" in HTTPS Inspection logs on 3rd party LEA OPSEC client. R7x
Multi-Domain Security Management
PMTR-62123 In Multi-Domain Servers, you cannot create an install policy preset with a policy package that has an OSE device as the target, due to an internal error when trying to get target information. R81.10
PMTR-60856 To correlate logs from the Domain Management Server in a NAT environment, in which a Domain Management Server is hidden behind a NATed address, and a Domain Dedicated SmartEvent Server has an external IP address, an administrator must follow these steps:
1. Connect with SmartConsole to the Domain Management Server
2. Create a dummy Check Point Host object with the external IP address of the Domain Management Server
3. Enable the "Logging" Software Blade in this Check Point Host object
4. Install database on the Domain Management Server
5. Open the SmartEvent GUI and connect to the Dedicated SmartEvent Server
6. In the list of the log servers, from which the Correlation Unit reads the data: remove the Domain Management Server object with the real IP address and add the dummy Check Point Host object (with the external IP address)
7. Install the Event Policy and close the SmartEvent GUI
R81
Compliance
PMTR-47756 In a Multi-Domain Management environment, in the local Domain policy, some Compliance best practices, which validate the status of rules in the policy, incorrectly identify the section header, "Parent section for domain rules," as a rule, and report it as not valid.
- To resolve: Manually exclude this result from the Best Practices view. To do so, in the Best Practices view, select the practice. In the bottom pane > Relevant Object section > double-click the desired rulebase object and disable the rule/section from the list.
R80.10
PMTR-47761 In a Multi-Domain environment, policy changes in the Global Compliance Policy do not trigger a partial Compliance scan. R80.10
Logging
PMTR-120903 In some scenarios when trying to export logs, operation fails and the log_indexer process crashes.
- Resolved in R82.10 Jumbo Hotfix Accumulator Take 6 (PRHF-42386)
R82
PMTR-92829 The output of the commands cpstat mg -f log_server or cpstat ls -f logging on a Security Management Server or Log Server that receives logs from a Maestro Security Group displays Log Receive Rate only for the individual Security Group Member (SMO), and not the combined log receive rate for all Security Group Members in the group. R81.10
SmartEvent
PMTR-50435 On a dedicated SmartEvent Server, the user who was configured in the First Time Configuration wizard cannot share items and view shared items in the SmartView application. R81
PMTR-66532 SmartConsole > "Logs & Events" > "Logs" tab may show duplicate log records with partial data for connection logs if log entries are spread over several log files due to a log switch.
Log switch operation occurs in these scenarios on a Management Server / Log Server:
- At midnight
- When the size of the active log file reaches 2 GB
- Based on user configuration (explicitly)
R80.20
PMTR-47559 On a dedicated SmartEvent Server which assigned to MDS, when you enable or disable a blade, the license information is not immediately updated. An automatic updates takes place at midnight.
- To resolve and update immediately, оn Server's command line, run:

$CPDIR/bin/esc_db_complete_linux_50 activation_data entitlement_dataIf you manually change a license or contract, the changes take effect immediately.
R80
SmartProvisioning
PMTR-56630 When you configure an LSM profile topology, do not reopen interface properties after you make a change.
Instead, close the Topology grid and click OK to close the editor.
When you reopen it, you will see the correct interface topology settings.
R81
PMTR-49235 A new object called "NewObject" is left in SmartConsole when an administrator creates a new object with same name as an object that exists in SmartProvisioning.
- To resolve: Either click "No" when SmartConsole shows "Do you want to keep changes anyway?"

or manually delete the new object called "NewObject".
R81
PMTR-45475 The status of an SMB device in SmartProvisioning may show " not responding" for a short time, even though the status is OK. R80.40
PMTR-1568 When working with LSM managed Security Gateways in a Management High Availability environment, creating and working with LSM Gateways must be consistent, they can only be used in the Security Management Server they are created in.
Using the secondary Security Management Server might lead to inconsistent actions/status related to LSM objects.
R80.20.M1
PMTR-70744 The "Enable Provisioning" checkbox is greyed out in SmartProvisioning > SmartLSM Security Gateway object properties > "General" tab > "Provisioning" section, if the user who logged into SmartConsole has a profile with assigned permissions other than "Read/Write All". R80.10
PMTR-8209 After a major upgrade to a Security Management Server, LSM profiles lose their installed policy and new devices attached to them are not able to fetch a policy.
- To resolve: Install policy on the LSM profiles.
R7x

SmartConsole   / Management Console / SmartLog  / SmartView

Enter the string to filter the below table:

ID Description Found in version
SmartConsole / Management Console
PMTR-120528 When upgrading from SmartConsole, the upgrade of the second cluster member may fail during the automatic policy installation with "Installation failed. Reason: TCP connectivity failure ( port = 18191 )( IP = <IP address> )[ error no. 10 ]" error.
- To resolve: upgrade of the second member manually using the local CPUSE web page.
R82.10
PMTR-120942 The Management API commands "add/set data-type-weighted-keywords" and "add data-type-file-attributes" do not save the "description" field in the object. R82.10
PMTR-121727 When object is updated in the cloud environment (Smart-1 Cloud), the update may not be shown in the SmartConsole.
Registration of Data Center assets with a numeric, non-UID unique identifier may fail, potentially causing performance impact on the Security Management Server.
- Resolved in R82.10 Jumbo Hotfix Accumulator Take 19 (PRJ-65014)
R82.10
PMTR-121600 Sync interfaces may not be fetched in the Maestro Security Group Member. R82
PMTR-98504 There may be a latency in connecting to SmartConsole with an administrator configured on an AD (LDAP) server. R82
PMTR-121999 When executing a SmartTask that is configured to send an email notification, it pulls the Submitter Email from the Contact Details instead of the Email field. R81.20
PMTR-121954 In some scenarios, the wrong interface window opens in SmartConsole after you want to edit an interface. R81.20
PMTR-122000 When updating the time object for an Access Control rule, the summary tab does not update. R81.20
PMTR-121843 Best Practices might be missing or show incorrect results in the Security Best Practices view of Compliance blade. R81.20
PMTR-86567 When using the Updatable objects picker, the search may retrieve previously selected item's additional information. R81.20
PMTR-62190 When creating a test user via the Mobile Access configuration page, the user's password is limited to 8 characters. R81.20
PMTR-81166 In a Multi-Domain Environment, when log in with SSO to a Domain behind NAT, the Security Gateway object will load but not open.
- To resolve: Connect to the Domain directly.
R81.20
PMTR-71266 In SmartConsole, the "Get Interfaces" operation in a cluster object does not fetch interfaces with IP addresses from the subnet 1.1.1.0.
- To resolve: Use the get-interfaces Management API.
R81.20
PMTR-119587 On Multi-Domain Security Management Servers, custom Compliance Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level.
- Resolved in R82.10 Jumbo Hotfix Accumulator Take 6 (PRHF-41803)
R81.10
PMTR-70829 Central Deployment Package Repository is local to the Multi-Domain Server. In a Multi-Domain High Availability environment, make sure to initiate Central Deployment operations on the Server to which the package was added. R81.10
PMTR-58448 When the screen resolution is low, changes in Log View widgets are not exported in PDF files:
1. In SmartConsole, from the left navigation panel click Logs & Monitoring.
2. Click + to open a new tab.
3. From the left, click Views, and open any view.
4. Click Options > Edit.
5. Make some layout changes - move, resize, delete, or add widgets, and click Done.
6. Click Options > Export > Export to PDF.
7. Download the PDF and open it.
8. The PDF file has the default layout.
R81.10
PMTR-68527 When you enter a search query that starts with “*” in various search fields (for example, *168.20), SmartConsole shows only objects that contain this partial string in their "Name", "Comment", or "IP Address" field. R81.10
PMTR-58272 In the "Gateways & Servers" view, the "Task" tab in the bottom pane does not show messages about a successful license attachment (shows messages only about a failed license attachment). R81.10
PMTR-60830 A link named " #.name" appears in a policy (above the Shared Policies section) in this scenario:
1. From the left navigation panel, click the Security Policies view
2. Open a policy with the HTTPS Inspection
3. Click Access Control > HTTPS Inspection
4. In the Certificate column, right-click a certificate and select Where Used
5. In the Where Used window, click the Policies tab
6. Double-click a policy that does not contain the Access Control (contains only Threat Prevention or QoS)
7. The policy opens, but instead of HTTPS Inspection section, a link named " #.name" appears
- To resolve:

1. Close the Where Used window
2. Manually open the affected policy
R81.10
PMTR-78482 If you delete an existing object of a Centrally Managed Quantum Spark appliance with the model 1800 or lower and some name (for example, "XXX"), then you cannot create another object of a Centrally Managed Quantum Spark appliance:
1. With the same name "XXX" - SmartConsole shows " Name already used!"
2. With the name of that contains the previous name (for example, "XXXnew") - SmartConsole shows " There is another network object [XXX] with the same IPv4 address"
R81
PMTR-58838 Changes (Diff) report:
- does not track rule numbers or rule positions in the policy (If a sub-rule is changed, the report only shows the number of the sub-rule and not the number of the parent rule).
- does not show changes made in: Inspection Settings, Software Blade Engine settings, Multi-Domain Management Server settings, and administrator settings (including permission profiles and all other options in Manage & Settings > Permissions & Administrators).
- In the Changes (Diff) report, there is inconsistency between the number of changes that appear in the session toolbar and the Revisions view.
R81
PMTR-42956 In HTTPS Inspection policy rules, when selecting the same action that already appears in the "Action" column, the Management Server counts it as part of the session changes. R80.40
PMTR-38804 The "Import Node" action (accessible from the SmartConsole Network Object tree > Nodes > Import) can fail with " Internal Error" message. R80.40
PMTR-31345 In languages other than English, the blades in the summary tab are not arranged correctly. R80.30
PMTR-27705 When installing a policy, " The policy included Blades that have an expired contract or a contract that is about to expire" warnings are displayed only for Application Control and URL Filtering and not for all Service Blades. R80.30
PMTR-31193 Search for disabled or expired rules in Access Control policy does not work. R80.30
PMTR-25063 The "Groups" page / tab is not shown if you edit a predefined service. R80.20.M2
PMTR-39387 Hitcount of Shared Inline Layer rules shows the sum of all rules it is used in as it is shared between all of them. R80.20
PMTR-50263 No warning is displayed, if an empty Network Group object appears in the "Source", "Destination", or "Protected Scope" column of a Threat Prevention policy rule. R80.10
PMTR-40848 When an inline layer appears more than once in an ordered layer, in logs that are generated from rules in that layer, the "Go to rule" link does not always navigate to the correct occurrence of the rule in the policy.
- To find the other occurrences of the rule, use the packet mode search with the rule's information. For more information about packet mode search, refer to sk118592.
R80.10
PMTR-82170 After upgrading the Security Management Server from to R80.x, users cannot add suggestions to add objects to group - the options are grayed out. Refer to sk118276. R80.10
PMTR-36940 When selecting a source or destination for a user object, cluster objects are not available for selection. R80.10
SmartLog / SmartView
PMTR-111298 Query for the "drop_reason" field in SmartConsole / SmartView > Logs & Events view > Logs tab does not return data because this log field is not indexed in Security Gateway traffic logs. R82
PMTR-118511 When searching the logs by source or destination and using URL Filtering, the screen go blank when certain logs are supposed to appear. R81.20
PMTR-55182 In the Logs view, the sessions timeline widget is missing when connecting to the SmartView web interface of a Dedicated Log Server or a Domain Log Server. R81.10
PMTR-42730 When viewing logs in the SmartView Web portal, the description fields are empty. R80.40
PMTR-44559 When querying logs in the SmartView web Logs tab, the numbers shown in the timeline section do not correlate to the log list if the indexing retention policy in SmartEvent and the Log Server are not the same. R80.40
PMTR-45323 Updatable objects are not resolved in SmartLog/SmartEvent queries:
1. You cannot create a filter or SmartView query which contains an Updatable object name.
2. When viewing logs/events, the IP address of an Updatable object is not resolved to a name.
R80.20.M2
PMTR-47699 In a global SmartEvent configured in Multi-Domain environment, SAM rules are not created by events auto-reactions.
- To resolve: refer to sk86941.
R80.10
PMTR-47589 Users connected with SmartConsole to specific Domain, will not be able to see Global objects assigned to this Domain in SmartLog logs results, and cannot search by Global objects (but can search by IP address). R7x

Access Control   Mobile Access / DLP

Mobile Access | DLP

Enter the string to filter the below table:

ID Description Found in version
Mobile Access
PMTR-41608 Error: " Failed to generate RADIUS auth request" when a Mobile Access user browses to a resource that requires authentication. R80.40
PMTR-70 If you use Outlook Anywhere application with Mobile Access Reverse Proxy, and then want to disable Outlook Anywhere or Reverse Proxy, perform:
1. Delete Outlook Anywhere rule from reverse proxy.
2. Run cvpnrestart --with-pinger to close all Outlook Anywhere open connections.

If you do not perform step 2, open connections of Outlook Anywhere will not be closed and users can still work with it.
R80.10
PMTR-47782 After upgrading a Standalone (Management and Gateway) or VSX deployment with Mobile Access blade enabled, the " Allow Dynamic ID for mobile devices" option might be enabled by default, even if Dynamic ID was not configured prior to the upgrade.
- If you do not want Dynamic ID authentication for Capsule Workspace users, disable it in:

Gateway Properties > Mobile Access > Authentication > Compatibility with Older clients > Settings > Capsule Workspace section > clear Enable DynamicID.



For VSX, this configuration is done per Virtual System.
R80.10
PMTR-47499 When Mobile Access is included in the Unified Access Policy, in Mobile Access Authorization logs > Log Details > Matched Rules, the Mobile Access Application name and Category do not show. R7x
DLP
PMTR-47691 DLP can apply visible or hidden Watermark (for forensic tracking) to Office Open XML formats (DOCX, PPTX and XLSX) as a rule action in a DLP rule base.
Refer to sk117413 if DLP Watermark is used.
R80.10

Threat Prevention

Enter the string to filter the below table:

ID Description Found in version
Threat Prevention
PMTR-107710 The "DNS Mismatched replies" IPS protection does not work after upgrade. R82
PMTR-107493 DNS NAT does not work on R82 Security Gateways. R82
PMTR-107712 In some scenarios, DNS Trap may fail to replace DNS replies with bogus IP addresses on certain connections, resulting in dropped connections. This prevents affected hosts from receiving the intended IP address but also limits the visibility into which host IPs are impacted. R82
PMTR-85353 When you activate Threat Emulation with the "Hold" mode, Threat Extraction, Zero Phishing, or Anti-Virus Deep Inspection, the Security Gateway downgrades the relevant connections from HTTP/2 to HTTP 1.1.
To force HTTP/2, run this command on the Security Gateway / Security Group / each Cluster Member:
fw ctl set -f int disable_http2_with_strict_hold 0
Limitation: Zero Phishing will keep downgrading HTTP/2 to HTTP 1.1.
R81.20
PMTR-80495 An exception in an Anti-Virus or Anti-Bot protection added manually to the rule base does not work.
- To add an exception in an Anti-Virus or Anti-Bot protection, open the corresponding Security Gateway log in SmartConsole and click the link "Add Exception".
R81.20
PMTR-76710 When Security Gateways use an Autonomous Threat Prevention policy:
- Compliance Best Practices do not support the checks for the Threat Prevention Software Blade.
- The Compliance Software Blade may show an incorrect status for the Threat Prevention checks.
R81.20
PMTR-19839 CRL validation is not supported in pure IPv6 environments (when IPv4 addresses are not configured on the Security Gateway's interfaces). R80.20

Endpoint Security

ID Description Found in version
Endpoint Security / SmartEndpoint
PMTR-68226 The Perfect Forward Secrecy (PFS) feature supports only Diffie-Hellman (DH) groups 2 and 14. R81.10

Quantum Spark Gateways

ID Description Found in version
Quantum Spark Gateways
PMTR-47520 " SIC error" status may occur when the Gateway object is defined in a "Management first" scenario before it is deployed, but the device's IP address is already accessible. The Security Management tries to create SIC with the Gateway's IP address. Instead of the policy ending in a "waiting for first connection" status, an error message states the SIC status must be rectified first. R7x

ElasticXL and Quantum Maestro

General Limitations | Gaia OS | VSX | CoreXL | Networking | VPN

Enter the string to filter the below table:

ID Product Description Found in
ElasticXL and Quantum Maestro - General Limitations
PMTR-122558 Maestro SIC fails on SMO with "Failed to connect to the Security Gateway" error after SIC reset on Maestro with MDPS enabled.
- To resolve: An SMO reboot is required after an SIC reset on Maestro with MDPS enabled.



After SIC reset from cpconfig, wait for all non-SMO members to reboot.

After the reboot is complete, reboot SMO and wait for it to complete boot. Then re-establish SIC from SmartConsole.
R82.10
PMTR-107075 ElasticXL ElasticXL Cluster supports only physical Check Point appliances (Virtual Machines or Open Servers are not supported). R82
PMTR-107076 ElasticXL ElasticXL Cluster supports only Check Point appliances of the same model. R82
PMTR-107077 ElasticXL ElasticXL Cluster requires each appliance to be after a Clean Install or restored to factory defaults. R82
PMTR-109641 Maestro In rare scenarios, after installing R82 on Maestro Orchestrator, the LLDP daemon (lldpd) is running but paused, and therefore does not transmit or process LLDP PDUs. As a result, MHO cannot communicate with the gateways.
- **To resolve:**From the Expert mode, run on MHO:

lldpcli resume
R82
PMTR-121616 Maestro When a Maestro Security Group runs SecureXL in the UPPAK mode, the asg perf command fails with this error: "can't read "stats(system_total,traffic,bps)": no such element in array".
- **To resolve:**Use theCPView utility.
R81.10
PMTR-113582 All On non-SMO members, QoS is enabled after policy installation despite being disabled. R81.10
PMTR-93476 All Management Aggregation (MAGG) bond mode is available only through the gClish of the Security Group (and not via the Gaia portal). R80.20SP
PMTR-111361 All - The Active-Backup bond is supported only when a Primary slave is configured (for example: set bonding group 1 primary eth1-05).
- The Active-Backup bond supports a maximum of 2 slaves.
R80.20SP
PMTR-111372 Maestro Maestro Orchestrators and Security Group CIN interfaces are configured in the subnet of 198.51.10<SG_ID>.0. You cannot use this subnet for data and management interfaces. R80.20SP
ElasticXL and Quantum Maestro - Gaia OS
PMTR-119680 All On a Scalable Platform Security Group, the Gaia gClish command "add user username uid <ID> homedir <PATH>" does not stop if a home directory with the specified path already exists. R82.10
PMTR-107433 ElasticXL Adding an unassigned interface to or from Sync bond leads to the flags reset and, as a result, it disrupts the ElasticXL detection and ElasticXL drops the packets. R82
PMTR-109292 All Configuring a Unique IP per Site over the management interface is not possible if Management Data Plane Separation (MDPS) is enabled. R82
PMTR-71458 Maestro Collecting Gaia Backup and restoring Gaia Backup in Global Clish (gclish) is not supported on a Security Group that contains appliances of different models.
- To collect Gaia Backup and restore Gaia Backup, you must use Gaia Clish (clish) on each appliance in the Security Group.
R81.10
PMTR-111365 Maestro On a Maestro Security Group, the Security Gateway does not show the correct speed of data and management interfaces. Run commands on the Orchestrator (the orch_stat -p command and Clish commands) to see the interface speed. R80.30SP
PMTR-111389 All A Security Group cannot be configured as an NTP Server. R80.20SP
PMTR-111373 All To prevent the Gaia configuration mismatch between Security Group Members, it is not supported to change the user's password on a Security Group in these ways:
- In Gaia Portal > User Management > Change My Password
- In Gaia gClish with the command set selfpasswd
To change the user's password on a Security Group, run one of these commands in Gaia gClish:
- set user <UserName> password
- set user <UserName>password-hash <Password Hash>
R80.20SP
PMTR-111388 Maestro In Dual Site deployment, no warning is displayed when changing the "type" of the QSFP port in Gaia Clish on Maestro Hyperscale Orchestrators on the local site, while the Maestro Hyperscale Orchestrators on the remote site are down. R80.20SP
PMTR-109474 All When you run multiple Gaia gClish set <...> commands, one after another, some of these commands can stop running.
When this happens, the message "Processing Transaction" shows in the output.
R76SP
PMTR-108599 All The asg commands are an extension of native Gaia gClish commands.
The asg commands have different syntax and there is no auto-completion.
R76SP
PMTR-108600 All A CLI command that uses a range for the parameter can only operate if all the relevant SGMs are defined in the security group. R76SP
PMTR-108601 All The arguments of the global commands are processed before the local (native) arguments, and this can cause the local arguments to be ignored. For example, the g_ls -l /tmp/ command is processed as ls /tmp/ on the local SGM instead of as ls -l /tmp/ on all SGMs.
Relocating the local arguments within the command (where applicable) can resolve the problem. For example, run the g_ls /tmp/ -l command instead of the g_ls -l /tmp/ command.
R76SP
PMTR-108602 All Running the asg_hard_shutdown command on an SGM two times, one after the other, causes a reboot and not a shutdown.
It takes one minute for the SGM to shut down after running the asg_hard_shutdown command. During this interval, do not run the asg_hard_shutdown command again.
R76SP
ElasticXL and Quantum Maestro - VSX
PMTR-106379 ElasticXL In ElasticXL in the VSNext mode (with 2 or more Security Appliances on one ElasticXL Site), VoIP UDP traffic is not supported between networks in this topology:
Network 1 - Virtual System 1 - Virtual Switch - Virtual System 2 - Network 2
R82
PMTR-108547 ElasticXL No information is shown on both servers when attempting to see the LLDP (lldpneighbors) between Security Management and a Virtual Gateway. R82
PMTR-111446 Maestro A change in the number of CoreXL Firewall instances (in a VSX Virtual System object in SmartConsole) in Dual Chassis VSLS setup requires a downtime, because the Virtual System must be restarted. During this restart, traffic cannot pass through the Virtual System. R80.20SP
PMTR-109478 All After running the vsx_util reconfigure command on the Management Server, the VLAN interface on a Security Group in VSX mode may come up without an IP address if the VLAN's MTU was set to a value larger than 1500.
Refer to sk111513.
R76SP.40
PMTR-109469 All No local configuration should be performed on a Security Group or on a Security Group Members while the vsx_util reconfigure command is running on the Management Server.
It is necessary to wait until all Security Group Members and Virtual Systems are up and running (otherwise, the local configuration will not be applied).
R76SP.30
PMTR-109468 All You cannot configure Bond interfaces on chassis Management ports after you create the VSX object in SmartConsole. R76SP.20
PMTR-109476 All The Alerts configuration wizard does not allow setting of performance thresholds per Virtual System.
- To resolve: You can manually configure thresholds for Virtual Systems using the dbset command from the Expert mode:

g_all dbset chassis:vs:0:alert_threshold: <alert_name> <value>



Where <value> is the percentage of the default threshold per Security Group Member.



Example:

[Expert@Host]# g_all dbset chassis:vs:0:alert_threshold:packet_rate_threshold_high 30



In this example, an alert is triggered when any Virtual System packet rate is higher than 30% x 1.8MB (1.8MB is the default packet rate threshold per SGM).

Note: One ratio applies to all Virtual Systems.
R76SP
PMTR-109465 All If you lower the Connections Table limit of a Virtual System, and one of the SGMs has more or the same number of connections than the limit, the new value is rejected for that SGM. The new Connections Table limit may be accepted by other SGMs.
Notes:
- To see the current number of entries in the Connections Table, run the fw tab -t connections -s command in the Expert mode.
- To configure the Connections Table limit of a Virtual System: In SmartConsole, open the Virtual System object > Go to the "Capacity Optimization" pane > Set the value in the "Limit the maximum concurrent connections" field > click OK > Install the policy.
R76SP
PMTR-109466 All You cannot enable IPv6 before you create and configure a new VSX Gateway. You must first create the new VSX Gateway and then enable and configure IPv6 using Gaia gClish. R76SP
ElasticXL and Quantum Maestro Known Limitations - CoreXL
PMTR-74532 All To make sure there is connectivity after changing the number of instances in the CoreXL configuration, follow these steps:
1. Reboot all Security Group Members one by one, except the SMO.

IMPORTANT: Traffic capacity is greatly reduced after you reboot all Security Group Members except the SMO, because only the SMO handles traffic until it is rebooted.

Examples:

In a Dual Site deployment with four Security Group Members (two on each Site), where the SMO is "1_1", reboot the Security Group Members in this order:


1. Reboot the Security Group Member 2_2 on Site 2 and wait for it to finish the reboot.
2. Reboot the Security Group Member 2_1 on Site 2 and wait for it to finish the reboot.
3. Reboot the Security Group Member 1_2 on Site 1 and wait for it to finish the reboot.
In a Single Site deployment with four Security Group Members, where the SMO is "1_1", reboot the Security Group Members in this order:
1. Reboot the Security Group Member 1_4 and wait for it to finish the reboot.
2. Reboot the Security Group Member 1_3 and wait for it to finish the reboot.
3. Reboot the Security Group Member 1_2 and wait for it to finish the reboot.
2. When a Security Group Member finishes the reboot, it enters the "DOWN" state because of a mismatch in the number of CoreXL Firewall instances with other Security Group Members. All other Security Group Members that were not rebooted yet, including the SMO, are in the "ACTIVE!" state (Active Attention) and handle traffic.

3. When all Security Group Members except the SMO have finished the reboot, you must reboot the SMO Security Group Member. A failover occurs immediately, and one of the other Security Group Members becomes the SMO. All other Security Group Members become "ACTIVE" and start to handle traffic.

4. When the last Security Group Member, which was the SMO, finishes the reboot, all Security Group Members become "ACTIVE" and full capacity is restored.
R80.20SP
ElasticXL and Quantum Maestro Known Limitations - Networking
PMTR-111381 All After a failover of the FTP control connection, it is not possible to open an asymmetric FTP data connection. R80.20SP
ElasticXL and Quantum Maestro Known Limitations - VPN
PMTR-108430 All Performing Hide NAT on Remote Access VPN connection (on the decrypt connection) with L4 distribution enabled may lead to NAT port collisions. R81.10
PMTR-111380 All VPN traffic on a VSX Virtual System that is connected to a VSX Virtual Switch is supported only when the distribution mode configured for the WRP interface is the same as the distribution mode configured for the physical interface on the VSX Virtual Switch.
Example of a VSX topology:
(Virtual System) == wrp100 == (Virtual Switch) == (eth1-01)
The same distribution mode must be configured for the interface wrp100 as was configured for the interface eth1-01.
R80.20SP

Article Properties

Access LevelGeneral

StatusApproved

Date Created2025-05-28

Last Modified2026-07-23

Was this page helpful?YesNo

Haven't found what you're looking for?

Our customer support team is only a click away and ready to help you 24 hours a day.

Open a Service Request

reCAPTCHA

Recaptcha requires verification.

protected by reCAPTCHA