sk183508 - Check Point Quantum R82.10 Resolved Issues and Enhancements

Check Point Quantum R82.10 Resolved Issues and Enhancements

Product Security Gateways, Security Management
Version R82.10
Last Modified 2026-07-16

Solution

This article lists all enhancements and issues that have been resolved in Check Point Quantum R82.10 Release.


List of Resolved issues, New Features and Enhancements in Quantum R82.10 Release

Enter the string to filter the below table:

ID Symptoms
Installation and Upgrade
PMTR-109123 Upgrades fail when policy contains groups with more than 32000 members.
Diagnostics
PMTR-91938 NEW: It is now possible to stop the kernel debug automatically - the specified number of seconds after the kernel debug started.
To enable this feature:
1. Configure the value "1" for the kernel parameter kiss_debug_disable_by_timer
2. Configure the required timeout (in seconds) as the value of the kernel parameter fwkdebug_timeout_seconds
The default value is 300 seconds.
PMTR-116323 Enhancement: The CPView tool now shows the CPU architecture (Intel, AMD, ARM, etc.) on the Overview > CPU tab.
PMTR-118287,
AAD-2695
Enhancement: CPView now shows counters for the number of active IKEv1 and IKEv2 tunnels for Site to Site VPN and for Remote Access VPN (Software-blades > VPN > Overview).
PMTR-120236 Apostrophes used in CPView strings cause CPDiag to fail.
PMTR-119580 In some scenarios, the cpd_admin -4 ver command only prints usage and exits.
Quantum Security Management
PMTR-119098,
PRHF-41677
Rulebase search for a specific user may fail to return rules that include user groups in which the user is a member.
PMTR-106428,
PMTR-103823
If no log-sharing exporter is created on the MLM Server before the upgrade, the log-sharing exporter is not created after the upgrade.
SmartConsole / Management Console
PMTR-112901,
MGMTPROD-1385
NEW: In SmartConsole and Management API, Access Control and NAT Policies now support Rulebase search for hitcount level values.
PMTR-116110 After adding or removing IP addresses in the JSON file, it may take a long time until SmartConsole shows these changes in the Generic Data Center object. Some IP addresses do not appear even after hours or even after restarting the Management Server services.
PMTR-115909 When navigating to "View Sessions" in SmartConsole connected to a Multi-Domain Management Server, SmartConsole may unexpectedly close and crash.
PMTR-109704 In some scenarios, when opening SmartConsole, the "Gateways & Servers" view displays the default columns instead of preserving the previously selected columns.
PMTR-108389 "SmartDashboard not able to connect to XXXX" error message when there is no connectivity or there are no users to fetch from the LDAP Server.
PMTR-95220 When clicking the "Logs & Events" view and opening a new Tab at the top, a black, empty background briefly appears.
PMTR-107789,
PRHF-35645
In SmartConsole, when users open an Identity Provider object all data appears as expected. After users close the object and then open it again, data is missing. Refer to sk182620.
Quantum Security Gateway
PMTR-118620 Enhancement: Improved the output of fw ctl debug -F / -H command - it will not print the debug modules usage.
PMTR-111735 The fw monitor -x <offset>,<val> command previously regarded the 2nd parameter ("val") as the end offset to be displayed. Now it regards that value as the length in bytes to be displayed.
For example, fw monitor -x 12,28 previously printed the content of bytes 12-28 of the captured traffic, but now prints 28 bytes, i.e. bytes 12-40.
PMTR-103024 HTTPS Inspection now supports Hardware Security Modules (HSM) when inspection of TLS 1.3 traffic is enabled.
Identity Awareness
PMTR-111031,
PRHF-36812
The Identity Awareness Gateway may fail to open a TCP connection to the LDAP server. Netcat command to the LDAP server IP address and port shows: "Error: Couldn't create connection (err=5): Cannot assign requested address."
Anti-Virus
PMTR-111877 Mail Transfer Agent (MTA) enabled SMTP/TLS might fail to load its certificate, resulting with disabled Anti-Virus enforcement for MTA traffic.
Gaia OS
PMTR-99279 Enhancement: Added the Expert mode sub-command "cp_conf sic state full" that, in addition to the field "Trust State" in the output of the command "cp_conf sic state", also shows these fields:
- Local SIC Name
- Remote SIC Name
- Remote ICA IP
- SIC Certificate Path
PMTR-118790 Enhancement: In Gaia Portal > Overview > "Network Configuration" section, increased the number of displayed interfaces from 30 to 100.
PMTR-119125 Enhancement: Added ability to use the '.', '@', '~', ',' characters for non-local users.
PMTR-115412 Enhancement: In the Gaia Portal login, added support for the period character (".") in RADIUS and TACACS usernames. This feature is disabled by default. Refer to sk183201.
PMTR-116391 After enabling a Cloning Group in ClusterXL, the Cloning Group Members fail to synchronize with each other.
PMTR-114078, PMTR-117713 "At least one subnet should be configured and enabled in order for the DHCP server to be enabled" error when enabling DHCP Server in a subnet assigned to a Bridge interface. Refer to sk183682.
PMTR-117092 After upgrade from R81.20, the configured GRUB password is not accepted anymore. See sk183772.
ClusterXL
PMTR-111975 Policy installation may fail on a Cluster Member in this scenario:
1. In the legacy file $FWDIR/conf/cpha_specific_vlan_data.conf, an interface was added without a VLAN ID
2. The value of the kernel parameter "fwha_monitor_specific_vlan" is "0"
SecureXL
PMTR-117427 Traffic capture with FW Monitor or CPPCAP on the Security Gateway shows that the Time To Live (TTL) value does not decrement in some packets. Refer to sk183728.
PMTR-113264 The fwaccel conns -l command does not count bytes that were accelerated in hardware and shows packets only handled by the host.
SD-WAN
PMTR-110145 Added support for ElasticXL Cluster in SD-WAN.
PMTR-104982 SD-WAN is now supported if a Security Gateway / Cluster runs SecureXL in the User Mode (UPPAK).
PMTR-104986 For inbound connections from the internet, SD-WAN now supports the symmetric return of packets through the same interface on which the connection was originally received, in case of multiple ISPs.
PMTR-105207 SD-WAN Overlay VPN now supports VPN peer Security Gateways connected over a Layer 2 line (SD-WAN Overlay VPN requires Layer 3 connectivity between VPN peers).
PMTR-105211,
PMTR-107550
SD-WAN Local Breakout is now supported for outbound connections configured with fixed Hide/Static NAT IP address, and which should be steered using more than one ISP.
VPN
PMTR-99188 Enhancement: Security Gateway now generates these logs for a failed login in Remote Access VPN that uses IKEv2:
- Access denied - wrong username or password
- User does not belong to the Remote Access community
- Machine certificate was required but not received
- Failed to match proposal
QoS
PMTR-117317 CoreXL SND instances may consume up to 100% CPU when the QoS Software Blade is enabled.
ElasticXL, Quantum Maestro and Scalable Chassis
PMTR-118534 NEW: Added support for different Check Point appliance models in the same ElasticXL Security Group. Refer to sk183513.
PMTR-110277 NEW: This release allows upgrade with a Gaia Fast Deployment image on Scalable Platforms (Maestro and ElasticXL), including the VSX and VSNext modes.
PMTR-93866 Enhancement: The command line for manual license installation in Scalable Platforms has become simpler. All commands run from SMO, including installing the license on a non-SMO member.
PMTR-115167 Many mhostatagent_get_port_label_data> port x seems not available logs in the /var/log/messages file on MHO (Maestro Orchestrator) may appear when SNMP is enabled.
PMTR-111443,
MBS-7914
Multiple Entry Points (MEP) configuration using Dead Peer Detection (DPD) are now supported on Maestro.
PMTR-107078 ElasticXL Cluster requires the supported Check Point appliance to run SecureXL in the Kernel Mode (KPPAK). The Gaia First Time Configuration Wizard automatically changes the SecureXL mode from UPPAK to KPPAK on the supported appliances.
PMTR-108738 During the upgrade of Scalable Platform Security Group Gateways, SSH keys are deleted.
PMTR-117409 On the Scalable Platform Security Group, the /var/log/messages file shows the daemon name "MHO_stateAgent" instead of "cpd".
PMTR-111391 On Maestro, added support for remote authentication for the Expert mode using RADIUS / TACACS+ Servers (the Gaia gClish command `set expert-authentication-method {
PMTR-111363 Correction is now supported for IPv6 local connections initiated from the Standby chassis.
Note: To activate the fix, enable the fwha_standby_hide_new_mode kernel parameter on all members or in the $FWDIR/boot/modules/fwkern.conf file. This kernel parameter silents the standby site and all local connections will go out via the SMO.
PMTR-113662 The Virtual System becomes to be standby on the Primary site and remains active on the Standby site or becomes to be active on both sites (split brain). In a dual-site VSX VSLS environment, when using MVC (Multi-Version cluster), it is required to change the site priority of the Virtual System on both sites in order to change the active site for a given Virtual System.
PMTR-115594 Access Control rules that contain the Generic Data Center object are not enforced on Maestro Security Group Members configured in the VSX mode.
PMTR-105038 On a Scalable Platform Security Group, although an SHA hash type was configured for Gaia OS passwords with the Gaia Global Clish command set password-controls password-hash-type, the Gaia Global Clish command set expert-password saves the password as an MD5 hash in the Gaia OS database. See sk182339.
PMTR-114355 In the VSNext mode (on ElasticXL and Maestro Security Groups), the Gaia gClish / Gaia Clish command "show interface" in the context of Virtual Switches fails with "CLINFR0699  Invalid command".
PMTR-117583 Connectivity issues may occur between Maestro Sites that are connected through Cisco OTV switches. Refer to sk183666.
PMTR-109197 VSNext Load Sharing (more than one member per site) is now supported in ElasticXL.
PMTR-109486 In ElasticXL, it is now supported to collect Gaia OS backup and restore it.
PMTR-97177 The set backup restore ftp command performed via gClish is now applied on all the Security Group members.
PMTR-106210 Multicast traffic routing over VTI Interface is now supported with ElasticXL in Load Sharing Mode.
PMTR-106079 Starting from R82.10, Maestro Security Groups support the SecureXL User Space (UPPAK) mode.
PMTR-106002 On Quantum Maestro, where Security Appliances are connected to two Maestro Orchestrators, rebooting one of these Orchestrators (or running the orchd restart command on one of these Orchestrators) causes a 10-second disruption in the sync traffic between Security Group Members. If a Security Group is configured in the VSX mode, this may affect the data traffic.
PMTR-109848 Scalable Platform Site grade is not affected by the number of active subordinate interfaces in a LACP bond interface. Therefore, LACP bond failover is not triggered if all of the subordinate interfaces become inactive in the LACP bond interface.
HCP-1082 HCP on MHO may fail because of timeout expiration since execution is on all MHOs in parallel.

Article Properties

Access Level General
Status Approved
Date Created 2025-05-28
Last Modified 2026-07-16