sk183675 - DHCP broadcast packets are not visible on the intended VLAN when working in SecureXL User Mode (UPPAK)
DHCP broadcast packets are not visible on the intended VLAN when working in SecureXL User Mode (UPPAK)
Product
Security Gateways
Version
R81.20, R82
OS
Gaia
Platform
19000, 29000, 3900, 9000, LightSpeed MLS, LightSpeed QLS
Last Modified
2025-09-14
Symptoms
- DHCP broadcast packets from DHCP Server/DHCP relay are not visible on the intended VLAN when operating in SecureXL User Mode (UPPAK).
- Broadcast packets from the Security Gateway may be routed to incorrect VLANs when multiple VLANs simultaneously handle broadcast traffic.
- Affected Appliances/Versions
- Quantum Force 19000, 29000, 9000, QLS Lightspeed and MLS Lightspeed appliances operating either in Security Gateway or in Maestro configurations and running SecureXL User Mode (UPPAK):
- Issue is relevant for Check Point R82
- Issue is relevant for R81.20 Jumbo Hotfix Accumulator Take 96 and higher
- Check Point Quantum Force 3900 Appliance
- Issue is relevant for Check Point Quantum Force 3900 Appliance factory image ( Check Point R82.10 Image for 3900 Appliances)
- Quantum Force 19000, 29000, 9000, QLS Lightspeed and MLS Lightspeed appliances operating either in Security Gateway or in Maestro configurations and running SecureXL User Mode (UPPAK):
- In Expert mode, the output of “ fwaccel tab -t nnexthop” includes rows with the IP address 255.255.255.255.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for Quantum Force 3900 Appliances starting from Take 22
- Jumbo Hotfix Accumulator for R82 starting from Take 34
- Jumbo Hotfix Accumulator for R81.20 starting from Take 111
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Article Properties
Access Level General
Status Approved
Date Created 2025-07-17
Last Modified 2025-09-14