> Source: [sk157492](https://support.checkpoint.com/results/sk/sk157492)

# sk157492 - CME (Cloud Management Extension) for Cloud Firewall Release Updates

| Property | Value |
|----------|-------|
| Solution ID | sk157492 |
| Date Created | 2019-07-10 |
| Last Modified | 2026-08-09 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server, Cloud Firewall |
| Versions | R82.10, R82, R81.20, R82.10, R82.10, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R81.20, R82 |
| OS | Gaia |
| Platform | AWS, Azure, GCP, VMWare NSX-T |

## Solution

**Introduction \| Installation \| Availability \| Documentation \| List of Resolved Issues \| Installation Troubleshooting**

Introduction {#Introduction}
----------------------------

The **Cloud Management Extension (CME)** is a utility that runs on Check Point Security Management Servers and Multi-Domain Security Management Servers that are deployed in a cloud or on-premises.

This utility allows integration between Check Point Cloud Firewall solutions (formerly known as CloudGuard Network) and cloud platforms such as AWS (Amazon Web Services), Azure, and GCP (Google Cloud Platform).
**Important Notes:**   

* It is important to keep CME up to date with Automatic Updates. To get CME with Automatic Updates, remove any CME installation you did with CPUSE (refer to [sk92449](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449) for detailed uninstall instructions).
* Before installing the package, check the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm) \> **Limitations.**

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk170636/CME architcture1202305281203214.jpg)  
Scale sets are a way to automatically adjust the number of virtual machines (VMs) based on how much the application needs. When the demand for the application increases, scale sets add more VM instances (scale-out). On the other hand, when the demand decreases, scale sets reduce the number of VM instances (scale-in).  

CME continuously checks the load of the application. On each check, CME decides whether a scale-out or scale-in event should happen. If the demand is neither too high nor too low for the current size of the VM set, then there is no change made. CME basically ensures that the number of VMs matches the needs of the application at any given time.

Installation {#Installation}
----------------------------

The CME package is installed automatically on all relevant Check Point devices when Automatic Update downloads are enabled (see [sk175504](https://support.checkpoint.com/results/sk/sk175504), section 2-B). Follow the steps of the *Installation Procedure for Online Package* below to complete the setup.

If Automatic Updates are disabled, you must first manually install the latest [AutoUpdater](https://support.checkpoint.com/results/sk/sk165653) Take and then install the CME package manually using the *Installation Procedure for Offline Package* below.  

**Installation Procedure for Online Package**  
Show / Hide this section  
>
> 1. Connect to the Security Management Server terminal and enter Expert mode.
> 2. Run the `autoupdatercli enable CME` command   
>    Command Result Example  
>    > `[Expert@mgmt-aws:0]# autoupdatercli enable CME`  
>    > `updates state changed to on for component CME`
>
> You can verify if CME is installed using one of these commands:  
>
> * Run the `autoprov-cfg -v` command. If the command is recognized and returns CME's installed version, then CME is installed.  
>   Command Result Example  
>   > `[Expert@mgmt-aws:0]# autoprov_cfg -v`  
>   > `CME Version: Build: 991592434 Take: 286`
>
> <!-- -->
>
> * Run the `autoupdatercli show | grep -A 30 CloudGuard` command. CME should be listed in the list of products with enabled autoupdating.   
>   Command Result Example  
>   > `[Expert@mgmt-aws:0]# autoupdatercli show | grep -A 30 CloudGuard`  
>   > ` product-name: CloudGuard_IaaS`  
>   > ` `  
>   > ` component-name: CME`  
>   > ` component-branch: cme_AutoUpdate`  
>   > ` GA-Version: 0`  
>   > ` download-scheduler-active: true`  
>   > ` install-scheduler-active: true`  
>   > ` download-action: idle`  
>   > ` install-revert-action: idle`  
>   > ` `  
>   > ` installation-date: 2024-11-18_14:39:15`  
>   > ` package-branch-name: cme_AutoUpdate`  
>   > ` package-version: 286`  
>   > ` package-name: Check_Point_CME_AUTOUPDATE_Bundle_T286_FULL.tgz`  
>   > ` package-installed: true`  
>   > ` package-installable: true`  
>   ` package-previously-installed: false`  

<br />

**Installation Procedure for Offline Package**  
Show / Hide this section  
> 1. Transfer the offline package to your Management Server (to some directory).
>
> 2. Connect to the command line on the Management Server.
>
> 3. Log in to the Expert mode.
>
> 4. Run:
>
>    `autoupdatercli install /<Full Path>/<Name of Package>`
>    Example:  
>    `[Expert@Host]# autoupdatercli install /var/log/Check_Point_CME_AUTOUPDATE_Bundle_T144_AutoUpdate.tar`  
>    On the Scalable Platform Security Group:`g_all autoupdatercli install <full path to TAR file>`
>
>    <br />
>
>    To make sure the installation was successful, examine this log file:
>
`/opt/CPInstLog/AutoUpdateLogs/CME `  
**Important Notes for Management High Availability** :  

* In a Management High Availability environment, install the CME package on all servers one after another. All servers must run the same version.
* After completing the installation, verify that all servers run the same version. Run the command "*autoprov-cfg -v*" on each server with CME installed.

Availability {#Availability}
----------------------------

|--------------|------------------|------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------|
| **Take #**   | **Release Type** | **Release Date** | **Download Package Link**                                                                                                                             |
| **Take 325** | **Recommended**  | 19 Jul 2026      | [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk157492/download-m1907081212.png)](https://support.checkpoint.com/results/download/144352) (TAR) |

Documentation {#Documentation}
------------------------------

* [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm)

List of Resolved issues and New Features per CME Update {#List of Resolved Issues}
----------------------------------------------------------------------------------

Enter the string to filter this table:

|--------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID                                                                                                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Take 325 Gradual deployment from 19 Jul 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| CGNSPC-1491, CGNSPC-1495, CGNSPC-2111, CGNSPC-1961, CGNSPC-2027, CGNSPC-2064, CGNSPC-2317, CGNSPC-3140 | Enhancement: Added CME support for Alibaba Cloud auto scale.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CGNSPC-1942, CGNSPC-3113                                                                               | Enhancement: Added support for Alibaba Cloud in CME API version 1.4.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| CGNSPC-2199, CGNSPC-2205, CGNSPC-2156, CGNSPC-195                                                      | Additional improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Take 324 Gradual deployment from 17 May 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| CGNSPC-1485                                                                                            | Enhancement: Improved CME health check orchestration to ensure configuration is applied in a proper sequence with the Repository Gateway script.                                                                                                                                                                                                                                                                                                                                                                                                                          |
| CGNSPC-2028                                                                                            | Enhancement: CME API v1.3.2 is released. Refer to [SWAGGERHUB](https://app.swaggerhub.com/apis-docs/Check-Point/cme-api/v1.3.2).                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-11996, CGNSPC-203                                                                               | Added support for dual-arm (2-arm) GWLB gateway deployments.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CGNSPC-1483, CGNSPC-2036, CGNSPC-1925                                                                  | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 323 Gradual deployment from 26 April 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||
| HAAN-2410                                                                                              | Enhancement: Added support for multi-compartment deployment for OCI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| CGNSPC-1314 CGNSPC-925, CGNSPC-224, CGNSPC-241, CGNSPC-653                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 321 Gradual deployment from 05 April 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||
| CGNSPC-1366                                                                                            | Enhancement: Improved GCP Automatic Health Probe provisioning compatibility for R81.20 Security Gateways managed by R82.10 or higher Security Management Servers.                                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-11996                                                                                           | Enhancement: Improved the resilience to AWS sub?account scan failures.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| CGNSPC-1473                                                                                            | Enhancement: Improved the Security Gateway provisioning stability on platforms that do not support Health Check configuration (such as NSX-T).                                                                                                                                                                                                                                                                                                                                                                                                                            |
| CGNSPC-1368                                                                                            | Enhancement: Improved liveness check reliability during scale-in events.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| CGNSPC-941, CGNSPC-331, CGNSPC-548                                                                     | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 320 Offline release - 16 February 2026 Gradual deployment from 08 March 2026**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             ||
| CGNSPC-833, CGNSPC-323, VSECPC-11578, CGNSPC-969                                                       | Enhancement: Added Dual-Stack support for Azure, GCP, OCI and AWS Autoscale.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CGNSPC-374                                                                                             | Enhancement: GCP management name comparison is now case-insensitive.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| VSECPC-12530                                                                                           | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 319 (02 February 2026)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-12679 VSECPC-12204 VSECPC-11857 VSECPC-11163 VSECPC-11164                                       | Enhancement: Added CME events integration with AIOps for improved monitoring.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-12232                                                                                           | Enhancement: Added support for RFC 7231 4.3.6 behavior when using proxy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-11222, VSECPC-11221, VSECPC-12217                                                               | Enhancement: Enhanced AWS Sub-Account Scanning CME now automatically skips failed AWS sub-accounts and continues scanning the remaining sub-accounts and the main account, ensuring uninterrupted coverage and improved reliability.                                                                                                                                                                                                                                                                                                                                      |
| VSECPC-10949, VSECPC-11996, VSECPC-12862                                                               | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 318 (02 December 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-10977                                                                                           | Enhancement: R82.10 version is now supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-10511                                                                                           | Enhancement: Added support for Shared VPC deployments in GCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-11691, VSECPC-11324, VSECPC-11178                                                               | Enhancement: Added CME reporting integration with AIOps for improved visibility and monitoring.                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECC-2994, VSECPC-12191, VSECPC-11694                                                                 | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 317 (19 November 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-11587                                                                                           | Enhancement: Added support for the "universe_domain" field in CME API GCP service account validation, allowing configuration of custom Universe Domains.                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECNSX-1979                                                                                           | Enhancement: Nutanix controller now supports paginated discovery of more than 20 agent VM entities, removing the previous entity limit.                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-11679                                                                                           | Some rules may have duplicates when the source is "Any" and when using "aws-automatic-policy".                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11845, PMTR-120941, VSECPC-12000                                                                | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 311 (06 November 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11587                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (New Zealand).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-11695, VSECPC-11373                                                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 310 (07 August 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-11150                                                                                           | Enhancement: Identity Sharing configuration is now supported on provisioned Security Gateways that are using PDP Clusters.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-11184                                                                                           | Enhancement: Added a deprecation notice to CLI utilities -- *autoprov_cfg* , *cme_menu* , *tgw_menu* . Users are advised to transit to the CME GUI or CME API for configuration as detailed in the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm).                                                                                                                                                                                                                                     |
| VSECPC-11189                                                                                           | Setting the "*health-check-ip-range*" parameter for an AWS template and using a CME API command fails with an exception during the configuration validation process.                                                                                                                                                                                                                                                                                                                                                                                                      |
| VSECPC-11139, VSECPC-11125                                                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 308 (21 July 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-10993                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (Taipei).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-10891, VSECPC-11065, VSECPC-10935, VSECPC-10569                                                 | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 307 (22 June 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-10493                                                                                           | Enhancement: Extended STS role field validation to include support for role IDs in AWS China and AWS GovCloud regions.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-10879, VSECPC-10932                                                                             | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-10171                                                                                           | Migrating AWS controller to the new "aws-automatic-policy" causes duplicated Access Rules to appear in the resulting policy.                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 304 (29 May 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-10480                                                                                           | Enhancement: CME API v1.3.1 is released. Refer to [SWAGGERHUB](https://app.swaggerhub.com/apis-docs/Check-Point/cme-api/v1.3.1).                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-10374                                                                                           | Enhancement: Added the "*scan_subnets_6*" parameter for IPv6 support in AWS Gateway Load Balancer (GWLB).                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Take 303 (11 May 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-10236, VSECPC-10003, VSECPC-9307, VSECPC-10374, VSECPC-10715, VSECPC-10602                      | Enhancement: CloudGuard Network for AWS Gateway Load Balancer Auto Scaling Group now supports IPv6 traffic enforcement, including subnets scan. Refer to [Cloud Firewall Network for AWS Gateway Load Balancer Auto Scaling Group Deployment Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CloudGuard_Network_for_AWS_Gateway_Load_Balancer_ASG/Default.htm) \> Traffic Enforcement in Servers Subnets with CME.                                                                                                                                  |
| **Take 301 (17 April 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-7167                                                                                            | Enhancement: To prevent the accidental installation of restrictive policies on all gateways, the installation targets are now changed to "specific gateway" by default.                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-10309                                                                                           | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 300 (18 March 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-5770                                                                                            | Enhancement: Disabled the ability to change CME configuration from Standby members in a High Availability environment.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-10332                                                                                           | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-10290                                                                                           | An issue related to GCP. Updated the *user.def* file path to ensure compatibility with R82 Security Management.                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-10377                                                                                           | An incorrect Gateway kernel parameter is addressed in the Health Check process during auto provisioning.                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Take 299 (23 February 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-10315                                                                                           | Enhancement: * Added CME support for OCI (Oracle Cloud Infrastructure) auto scale. * Updated CME schema version to v1.1.8. * Added support for Azure IAM in CME API version 1.3.                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-10249                                                                                           | Enhancement: In Azure vWAN Ingress, increased the Load Balancer rule provisioning timeout.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Take 297 (30 January 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-10157, VSECPC-9974                                                                              | Enhancement: Updated CME schema version to v1.1.7                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-9990, VSECPC-9989, VSECPC-9841, VSECPC-9842, VSECPC-9843                                        | Enhancement: Added support for Azure IAM in CME API version 1.2.3.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-10206                                                                                           | Enhancement: Added support for the new AWS region: Asia Pacific (Thailand).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-10285                                                                                           | Enhancement: Added support for the new AWS region: Mexico (Central).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| VSECPC-10074                                                                                           | When using Azure vWAN Automatic Provisioning through CME API, the Autonomous Threat Prevention and Identity Awareness Blades are configured even when the flags are set to "false".                                                                                                                                                                                                                                                                                                                                                                                       |
| **Take 294 (20 January 2025)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-9739                                                                                            | Enhancement: Improved CME API performance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-8960                                                                                            | Enhancement: CME is no longer supported on R80.40 Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-9853                                                                                            | Minor fix.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Take 289 (9 December 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-9178                                                                                            | Enhancement: Added support to configure Identity Sharing settings on provisioned Security Gateways. Refer to [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/CME_Structure_and_Configurations.htm#IdentitySharing).                                                                                                                                                                                                                                                               |
| VSECPC-9519                                                                                            | Enhancement: Improved validations for various API requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-8409, VSECPC-8886                                                                               | Enhancement: Optimized AWS account scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-9317                                                                                            | Enhancement: Updated CME schema version to v1.1.6.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-9745, VSECPC-9782, VSECPC-9793, VSECPC-9885                                                     | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 288 (18 November 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-8826                                                                                            | Enhancement: Each "gwConfiguration" is now limited to a single "account" association.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-9109                                                                                            | Enhancement: Optimized the AWS account scan time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-9144                                                                                            | Enhancement: Improved error messaging when creating gwConfiguration without the required "related_account" parameter in CME API. Instead of a generic "*Internal Server Error* " with "*Got Exception from type Exception*", the command output now provides a clear type error message indicating the missing parameter.                                                                                                                                                                                                                                                 |
| VSECPC-8186                                                                                            | Enhancement: Azure vWAN Automatic Provisioning through CME API is now generally available.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-7267                                                                                            | Enhancement: Azure vWAN Ingress configuration through CME API is now generally available.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-9472, VSECPC-9597                                                                               | Enhancement: Improved validation for the CME API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-9430                                                                                            | Enhancement: Improved stability for CME API versioning.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-9603, VSECPC-9382                                                                               | Enhancement: Updated CME API to support unconnected templates.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-9581                                                                                            | Enhancement: CME API v1.2.1 is released. Refer to [SWAGGERHUB](https://app.swaggerhub.com/apis-docs/Check-Point/cme-api/v1.2.1).                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Take 286 (7 November 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-9401, VSECPC-9274, VSECPC-9363                                                                  | Cosmetic fixes in Azure vWAN Ingress menu.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-9273, VSECPC-9082                                                                               | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 285 (22 October 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-9330                                                                                            | Enhancement: Improved scale-in handling for Smart-1 Cloud token release scenarios.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-9362                                                                                            | Enhancement: Improved the CME API on the MDS level to support the section names functionality.                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-8950                                                                                            | Enhancement: Improved Azure vWAN ingress validation and logging in CME menu.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-9002                                                                                            | Enhancement: The default bridge interface aging is now set to zero to ensure that the Gateways do not retain any MAC addresses passing through the VXLAN tunnel, thereby preventing packet drops with "IP routing failed".                                                                                                                                                                                                                                                                                                                                                |
| **Take 282 (23 September 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| VSECPC-9080 VSECPC-9073                                                                                | Enhancement: Script execution notifications during Security Gateway removal are now disabled to prevent notification overload in SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-9089                                                                                            | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 279 (13 August 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| VSECPC-8607                                                                                            | Enhancement: AWS Regions list for account configuration is now updated automatically. Note: ec2:DescribeRegions permission addition is required.                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-7306                                                                                            | Enhancement: CME API v1.2 is released. Refer to [SWAGGERHUB](https://app.swaggerhub.com/apis-docs/Check-Point/cme-api/v1.2).                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-8304                                                                                            | Enhancement: Added Default Features support for CME API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-9011 VSECPC-9016                                                                                | Enhancement: Improved account name validation for CME API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-8249                                                                                            | Enhancement: The Ingress Menu now has validation for the number of ports.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-8916 VSECPC-8899                                                                                | Enhancement: Improved Log the duration of Server configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-8932                                                                                            | Enhancement: Updated CME schema version to v1.1.5.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-8364                                                                                            | In Ingress Menu, the backspace key may not work on some terminals for the name field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Take 276 (15 July 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-8914                                                                                            | Enhancement: In CME API, improved input validation STS Assume Role.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| VSECPC-8624                                                                                            | Enhancement: Improved logging for GWLB Auto Scaling Solution.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-8666                                                                                            | Enhancement: When enabling the "autonomous-threat-prevention" feature, certain ATP (Autonomous Threat Prevention) blades are automatically disabled for Autoscaling Gateways if they are not supported. This applies to: * Threat Extraction (for R81.10 and higher) * Zero Phishing (for R81.20 and higher)                                                                                                                                                                                                                                                              |
| VSECPC-8849, VSECPC-7948, VSECPC-8857                                                                  | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 275 (21 June 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-6756                                                                                            | Enhancement: In the *autoprov_cfg* utility, added a validation for the CME controller name against reserved words (see [sk40179](https://support.checkpoint.com/results/sk/sk40179) for more details regarding reserved words).                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-8656, VSECPC-8764, VSECPC-8750, VSECPC-8686, VSECPC-8402                                        | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-8651                                                                                            | Network Groups are removed if the CME configuration contains two or more controllers: one for AWS and another for a non-AWS environment (for example, an Azure controller).                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-7675                                                                                            | Gaia Portal (WebUI) of the Security Gateway is not accessible when Identity Awareness is enabled by CME.                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Take 271 (23 May 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-8841                                                                                            | Enhancement: Enhanced Azure Virtual WAN Ingress traffic by using section-based rules.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Take 269 (15 May 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-8467                                                                                            | In an AWS Auto Scaling Group solution with multiple Load Balancer sets, when the aws-automatic-policy is configured in the Gateway Configuration, CME may not create all the matching access rules as expected.                                                                                                                                                                                                                                                                                                                                                           |
| VSECNSX-1861                                                                                           | Updating an existing NSX-T controller that uses Remote Authentication and changing the authentication method to "Regular" fails.                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Take 268 (10 Apr 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-8554                                                                                            | Enhancement: The exception message is now updated to clarify that it relates to the ports of external target groups, not internal load balancer listeners. Additionally, the port checks now focus on the target group ports instead of the listener ports.                                                                                                                                                                                                                                                                                                               |
| VSECPC-7883                                                                                            | Enhancement: The Gateway Load Balancer (GWLB) Automatic Policy now supports the distribution of GWLB endpoints across multiple Availability Zones.                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-8453                                                                                            | Misleading error message may be shown when there is a route configuration issue.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-8399                                                                                            | Minor fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 267 (17 Mar 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-8179                                                                                            | Enhancement: In AWS GWLB, added support for Health Check IP address range with one subnet.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-8142                                                                                            | Enhancement: Added support for a new region Canada (Calgary) - *ca-west-1* .                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-7884                                                                                            | Enhancement: Changed the Gateway provisioning flow for install database failure on the Backup Log Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-7531                                                                                            | Enhancement: Removed R80.20 and R80.30 from *tgw_menu.*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-7996                                                                                            | Enhancement: Added support for service port ranges.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| VSECPC-7838                                                                                            | Enhancement: Blocked CME installation on Log Servers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| **Take 261 (28 Feb 2024)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-7721                                                                                            | Enhancement: In Azure vWAN configuration, added vWAN identifier comment to the Security Gateway object.                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-7720                                                                                            | Enhancement: Azure vWAN object names now include additional identifiers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-8022, VSECPC-7955                                                                               | Enhancement: Added MDS support for Azure vWAN metering and configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-7819                                                                                            | Enhancement: In CME API, added support for list of repository scripts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-7267                                                                                            | Enhancement: In the CME menu, added Azure vWAN ingress menu.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-7794                                                                                            | In CME API, when using the "*PUT /gwConfigurations/\<platform\>*" request with the same related account given as payload, the Security Gateway configuration is removed from the related account.                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-7793                                                                                            | In CME API, when sending a PUT request to remove an attribute with *"scan-subnets": false*, the attribute is not removed.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-7785                                                                                            | In CME API, add an AWS account with two or more sub accounts may fail.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-7899                                                                                            | CME cycle fails when the AWS account contains a target group of the "Application Load Balancer" type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-7559, VSECPC-7423                                                                               | Minor code improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-7194                                                                                            | When using the "*-cg* " flag to run scripts in each new instance with *$FWDIR,*the script path is not changed after the version upgrade by CME.                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Take 255 (4 Dec 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| VSECPC-7684                                                                                            | Enhancement: Improved logging message for port conflict in Auto Scale Group for AWS solution.                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-6730, VSECPC-7550                                                                               | Enhancement: Added the "*Do not delete* " banner for every object created by CME in the Security Management Server and Multi-Domain Security Management Server. Refer to [Cloud Management Extension R80.10 and Higher Administration Guide \> CME Structure and Configurations](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/Overview.htm) \> Objects Banner.                                                                                                                                                                   |
| VSECPC-6734                                                                                            | Enhancement: The Security Gateway deletion is now possible only after verifying its activity status to prevent accidental loss of connected Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-7231                                                                                            | Enhancement: CME API V1.1 is released. Refer to the [SWAGGERHUB](https://app.swaggerhub.com/apis-docs/Check-Point/cme-api/v1.1).                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-7145                                                                                            | Enhancement: Updated CME schema version to v1.1.4.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECNSX-1869                                                                                           | Enhancement: In NSX-T Manager, when adding new VMware service, the service name will now have the "*CloudGuard \<Checkpoint version\> id*" format.                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-7649                                                                                            | Enhancement: Added Azure vWAN metering menu in the CME menu.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-7068                                                                                            | When a Gateway is deleted from SmartConsole, a "*Failed to return gateway IP address to Maas IP addresses pool* " message may be printed in the *cme.log*.                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Take 250 (26 Oct 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-6811                                                                                            | Enhancement: Removed restrictive policy from the Gateway provisioning flow. Refer to the Implied Rules and Restrictive Policy section in [Cloud Management Extension R80.10 and Higher Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/Overview.htm).                                                                                                                                                                                                                                                         |
| VSECPC-6529                                                                                            | Enhancement: Extended the Log Servers Gateway configurations. Refer to the Log Server parameters section in [Cloud Management Extension R80.10 and Higher Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/Overview.htm).                                                                                                                                                                                                                                                                                      |
| **Take 248 (12 Oct 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-7290 VSECPC-7282, VSECPC-6739, VSECPC-7238                                                      | Enhancement: Improved the CME cycle performance when the Security Management Server is idle (no changes were published).                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-5876                                                                                            | In some scenarios, the Security Gateway with a name that includes another account name may get deleted.                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-7270                                                                                            | Enhancement: Added support for AWS Asia Pacific (Melbourne) Region.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Take 246 (07 Sep 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-7410, VSECPC-7158, VSECPC-7186, VSECPC-7123, VSECPC-6908, VSECPC-7012, VSECPC-6946              | Minor fixes and stability improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Take 245 (24 Aug 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-7232, VSECPC-7121, VSECPC-7129, VSECPC-6896, VSECPC-6737, VSECPC-7007                           | Minor fixes and stability improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Take 243 (14 Aug 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-7063                                                                                            | Enhancement: Updated CME schema version to v1.1.3.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-6894                                                                                            | Enhancement: Added the "AWS automatic policy" flag for improved automatic rules creation. Refer to [Cloud Management Extension R80.10 and Higher Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/Overview.htm) \> Configuration Templates (gateway-configurations) \> Parameters for AWS only.                                                                                                                                                                                                                |
| VSECPC-7206                                                                                            | Enhancement: Added support for AWS Israel (Tel Aviv) Region.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 240 (30 July 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-6910                                                                                            | Enhancement: Added support to configure GCP account using the service account content.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-6837                                                                                            | Enhancement: Added support to configure Autonomous Threat Prevention for Azure vWAN.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| VSECPC-6694                                                                                            | Enhancement: Added support to configure Azure vWAN from the CME menu.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-6640                                                                                            | Enhancement: Optimization of the synchronous and asynchronous CME API requests infrastructure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| VSECPC-6597                                                                                            | Enhancement: Updated CME schema version to v1.1.2.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-6402                                                                                            | Enhancement: Optimized the CME cycle.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-5974                                                                                            | Enhancement: Removed support for R80.30 and lower Security Management and Multi-Domain Security Management Servers. * Existing customers running R80.30 will still be able to manually download and install the last unblocked R80.30 CME Take - *Take 238.* * New customers will not be able to install CME.                                                                                                                                                                                                                                                             |
| **Take 238 (4 July 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-6891                                                                                            | Enhancement: Stability improvement.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Take 236 (12 June 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-6444                                                                                            | Enhancement: Unified the CME warnings between Cloud vendors.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECNSX-1859                                                                                           | Authentication to NSX-T controller with Remote Authentication fails with "*Status: Disconnected - User is not authorized to perform this operation on the application. Please contact the system administrator to get access.*"                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-6567                                                                                            | Automatic Access and NAT policy rules are not created for CloudGuard Auto Scale for AWS solution when scan subnets (-ss) flag are defined.                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Take 234 (9 May 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| VSECPC-5842                                                                                            | Enhancement: Enhanced the CME API infrastructure to support versioning.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-6297                                                                                            | Enhancement: Improved CME API validations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-6372                                                                                            | Enhancement: Added an automatic configuration script for Azure vWAN NVA.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| CGIS-694                                                                                               | Enhancement: Added telemetry diagnostics to *cme_no_proxy*.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| **Take 231 (16 Apr 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-6135                                                                                            | Enhancement: CME schema version is update to version v1.1.1.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| CGIS-686                                                                                               | Enhancement: Added "*no_proxy*" to private controllers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-4838                                                                                            | Enhancement: Improved CME log messages for throttling.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-6173                                                                                            | Enhancement: Improved the platform logic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-4320                                                                                            | Enhancement: Added validation to prevent using IP addresses with incorrect CIDR Prefix.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-3846                                                                                            | Dash at the beginning of the "*autoprov_cfg params"* value is not accepted.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-5771                                                                                            | If the one-time-password is wrongly set in the configuration template, CME will try at each iteration to run: "*set-simple-gateway ... one-time-password \<wrong password\>* " until the Gateway *sic-state* is "communicating".                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-6133                                                                                            | During CME start, CME may create redundant revisions in the data base.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Take 227 (7 Mar 2023)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| VSECPC-6252                                                                                            | Enhancement: CME installation will now be blocked on R80.30 Jumbo Hotfix Accumulator Take 255 and lower.                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-6113                                                                                            | Enhancement: Added support for Data Centers in AWS eu-central-2 (Spain) and eu-south-2 (Zurich) and ap-south-2 (Hyderabad) regions.                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| VSECPC-5958                                                                                            | Enhancement: Enhanced Health Probe Agent configuration on the Multi-Domain Server to manage MIG in GCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-5885                                                                                            | Enhancement: Optimized the CME cycle.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-6038                                                                                            | Enhancement: Deprecated Azure Virtual Machine Scale Sets (VMSS) for Remote Access VPN.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-5976                                                                                            | Enhancement: The default Management API version used by CME is now v1.6 (for R80.40 and higher).                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-6268                                                                                            | CME may not start because of a corrupted password encryption file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Take 222 (11 Dec 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-6056                                                                                            | Enhancement: Increased CME schema to v1.1.0. For more details about CME schema versions, refer to [Cloud Management Extension R80.10 and Higher Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/CME_Structure_and_Configurations.htm?TocPath=CME%20Structure%20and%20Configurations%7C_____9#Schema).                                                                                                                                                                                                         |
| VSECPC-5424                                                                                            | Enhancement: Upgraded the CME Password Encryption method.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| PRHF-26808                                                                                             | Stability issue of the V2T tool (NSXT to NSXV).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECNSX-1838                                                                                           | NIC order in CloudGuard Gateways for NSX-T Manager v3 and higher may be incorrect.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Take 219 (6 November 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-6043                                                                                            | After a CME update, CME may fail to initiate SIC with new Security Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| **Take 216 (19 October 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-5663                                                                                            | Enhancement: Added support for Quantum R81.20 (Titan).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-6029                                                                                            | A SIC initialization issue.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-6031                                                                                            | Stability issue of the CME Network Group feature.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECNSX-1820 VSECNSX-1822 VSECNSX-1826                                                                 | Stability issue of the V2T tool (NSXT to NSXV).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Take 212 (6 October 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| VSECPC-5990                                                                                            | Enhancement: Added support for Jakarta and UAE AWS regions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-5827                                                                                            | Enhancement: Added support for CME configuration schema versioning. Current configurations supported by this CME Take are defined as schema version v1. Refer to [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm).                                                                                                                                                                                                                                                                       |
| VSECPC-5953                                                                                            | Enhancement: Added several Autonomous Threat Prevention stability fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-5879                                                                                            | Enhancement: The CME Network Group names were renamed: 1. When "prefix-name" flag is enabled 2. For AWS Autoscale Groups                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Take 205 (8 August 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-5694                                                                                            | Enhancement: Added support for Network Group management object. Refer to [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm).                                                                                                                                                                                                                                                                                                                                                               |
| **Take 200 (6 July 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-5769                                                                                            | Enhancement: It is no longer possible to change CME configuration on the Standby Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| VSECPC-5658                                                                                            | Enhancement: Added support for Autonomous Threat Prevention.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECNSX-1822                                                                                           | NSX-V to NSX-T (V2T) migration related issue.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| **Take 194 (2 June 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-5735                                                                                            | Enhancement: Added AWS Cross Accounts support for GWLB endpoints.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-5351                                                                                            | Enhancement: The "*-sg* " (sync gateways) flag of the "*autoprov-cfg*" command will no longer be supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECNSX-1813                                                                                           | Enhancement: N/S Cluster HA NICs order change for R81.10+ versions, following a change in VMware vcenter 7.0+ infrastructure.                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-4660                                                                                            | Enhancement: Removed a limitation. The CME feature is now supported when the Endpoint Policy Management Software Blade is enabled on the Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                      |
| VSECPC-5245                                                                                            | Automatic Hotfix Deployment may not perform as expected on the Multi-Domain Server HA when the Active Domain is not in the primary server.                                                                                                                                                                                                                                                                                                                                                                                                                                |
| VSECPC-5642                                                                                            | The "*missing IPv4 Gateway address*" error may be displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECNSX-1818                                                                                           | While creating a new NSX-T template for R81.10+ versions, the OVF name may appear incompatible and another version may be added.                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Take 186 (20 April 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-5118                                                                                            | Enhancement: Added AWS GWLB subnets for Health Check IP range instead of VPC CIDR.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-5613                                                                                            | Enhancement: Added timeout for http/https requests requests.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-4941                                                                                            | When CME tries to login to standby Domains, the "*KeyError: uid*" error is shown.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-5655                                                                                            | Log Collector may not recognize available memory.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Take 181 (8 February 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-5556                                                                                            | An auto-HF deployment issue may occur when using Multi-Domain Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-5353                                                                                            | A post-customize failure is shown in the CME log.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Take 179 (24 January 2022)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-4935                                                                                            | Enhancement: Added CME logs to Smart Console. Refer to the CME-Monitoring section in [Cloud Management Extension R80.10 and Higher Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Content/Topics-CME/CME_Structure_and_Configurations.htm?tocpath=CME%20Structure%20and%20Configurations%7C_____0#The_CME_Logs).                                                                                                                                                                                                                |
| VSECPC-5537                                                                                            | Enhancement: Added support for Instance Metadata service (IMDSv2) in AWS.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| VSECPC-5312                                                                                            | Enhancement: CME Log Collector update.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-5359                                                                                            | Added missing validations for CME API parameters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Take 175 (23 December 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-5359                                                                                            | Enhancement: CME API validations improvement.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-5312                                                                                            | Enhancement: Log collector enhancements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-5255                                                                                            | Enhancement: Added Azure Gateway Load Balancer automatic support for scenarios when implied rules are disabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-5339                                                                                            | Enhancement: Added internal diagnostic support.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Take 168 (02 November 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-5214                                                                                            | Enhancement: Added support for Azure Gateway Load Balancer automatic configuration. For additional information, refer to [Cloud Firewall Network for Azure VMSS Gateway Load Balancer Public Preview R81.10 Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_Azure_VMSS_GWLB/Default.htm).                                                                                                                                                                                                                                            |
| VSECNSX-1740                                                                                           | Enhancement: Added ability to migrate Check Point Security Management NSX-V objects to NSX-T security policy objects.                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| VSECPC-5031                                                                                            | Enhancement: Improved the CME log collector mechanism.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-5029, VSECPC-5228, VSECPC-4987                                                                  | Enhancement: CME API code improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VSECPC-5116                                                                                            | Remote Access VPN code limitation that blocked the configuration of DNS suffixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Take 164 (13 October 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-4971                                                                                            | Enhancement: Added support for configuring "Content Awareness" blade via autoprov_cfg.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-4921                                                                                            | Enhancement: For AWS: Added support for configuring GWLB Health Check IP range via autoprov_cfg                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-4942                                                                                            | In Multi-Domain HA, CME configurations are blocked for not primary domains.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-4977                                                                                            | Custom gateway script fails to run with arguments.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Take 157 (14 July 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-4894                                                                                            | Enhancement: Added CME API validations improvement.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Take 155 (07 July 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| VSECPC-4530                                                                                            | Enhancement: CME API integration. Refer to the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm).                                                                                                                                                                                                                                                                                                                                                                                         |
| VSECPC-4628                                                                                            | Enhancement: Added support for CPDiag.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-4682                                                                                            | Enhancement: Added GCP MIG Health Check reply support (for R81.10 only).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| MAAS-1836                                                                                              | Enhancement: Added support to R81 VMSS, MIG and ASG in Smart-1 Cloud environments.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-4747                                                                                            | Enhancement: Added the Log collector for CME.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-4820                                                                                            | post-customize script fails when CME runs on secondary Multi-Domain Management.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-4781                                                                                            | CME for Azure does not work due to upper/lower cases inconsistency in Azure REST API responses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| VSECPC-4835                                                                                            | In some scenarios, a memory leak may occur on CME.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| VSECPC-4800                                                                                            | In some scenarios on in R80.30 and below, CME fails to add access and NAT rules.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| VSECPC-4661                                                                                            | CME installation fails when the *autoprovision.json* file is empty.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Take 147 (09 May 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| VSECPC-4697                                                                                            | The *x-chkp-topology* tag on CloudGuard AWS instance does not affect interface configuration in SmartConsole instance object.                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-4698                                                                                            | Azure Controller fails to poll resources when Scale Set tag x-chkp-template value is set to template that is missing from the CME Configuration Templates.                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Take 144 (22 April 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-4346                                                                                            | Enhancement: Added an Exception handling when creating an Azure Instance with IPv6.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| VSECPC-4630                                                                                            | Repeated Access and NAT rules may be created for AWS Auto Scaling solution.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-4617                                                                                            | CME performs publish every cycle and creates management revisions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Take 138 (15 March 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-4565, ODU-96                                                                                    | Enhancement: Added support for CME Auto-Configuration of *cloud_balancer_ip1\&ip2* and *cloud_balancer_port* parameters in *fwkern.con*f file.                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **Take 137 (09 March 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| VSECPC-4032                                                                                            | Enhancement: Added CME as CPM session description. CME will not disconnect other CPM root sessions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| VSECPC-4127                                                                                            | Enhancement: Added XFF support to CME.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| VSECPC-4218                                                                                            | Enhancement: Added support for AWS Security Hub. See the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm) for more details.                                                                                                                                                                                                                                                                                                                                                              |
| VSECPC-4588                                                                                            | Enhancement: Added support for Auto NAT in Azure. See the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm) for more details.                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-4346                                                                                            | Enhancement: Added IPv6 support for Azure VMSS. Refer to [sk170760](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170760).                                                                                                                                                                                                                                                                                                                                                                                  |
| VSECPC-4514                                                                                            | Enhancement: Added validation for not using CDT 1.9 because this version is not compatible with the CME Automatic HF deployment feature.                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Take 133 (07 February 2021)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-4197                                                                                            | Enhancement: Added support for AWS Gateway Load Balancer (GWLB). See [this page](https://blog.checkpoint.com/2020/11/10/check-point-cloudguard-integrates-with-aws-gateway-load-balancer-at-launch/) for more details about CloudGuard Network Security integration with AWS Gateway Load Balancer.                                                                                                                                                                                                                                                                       |
| **Take 126 (29 November 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-4289                                                                                            | Enhancement: Updated Azure certificate bundle correlated to Microsoft announcement on Azure TLS certificate change. For details, refer to [this Microsoft article](https://docs.microsoft.com/en-us/azure/security/fundamentals/tls-certificate-changes).                                                                                                                                                                                                                                                                                                                 |
| **Take 125 (24 November 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| VSECPC-4284                                                                                            | In some scenarios, provisioning issues may appear for environments with AWS Gateway Load Balancer.                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **Take 122 (13 October 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| VSECPC-4083                                                                                            | Enhancement: Added support for GCP Multi-Domain Management.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| VSECPC-3711                                                                                            | Added CSCC fixes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Take 121 (25 August 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| VSECPC-4050, VSECPC-3889                                                                               | Enhancement: Added support for Azure VMSS with Scalable Remote Access VPN. Main Features: * Public Cloud-oriented Remote Access solution. * Remote Access Client connectivity for AutoScaling Gateways. * Integration with Azure DNS using Azure function: Azure function updates DNS according to available Scale Set instances. For more information, see [Scalable Remote Access VPN with CloudGuard IaaS: Video, Slides, and Q\&A.](https://community.checkpoint.com/t5/Remote-Access-VPN/Scalable-Remote-Access-VPN-with-CloudGuard-IaaS-Video-Slides-and/m-p/91643) |
| **Take 119 (12 July 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| -                                                                                                      | Enhancement: Improved AWS provisioning cycle duration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| -                                                                                                      | Enhancement: Added new AWS Regions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| -                                                                                                      | Enhancement: Added option to provision R81 Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Take 108 (25 May 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| -                                                                                                      | Enhancement: Automatic Updates support - CME now has the ability to update itself with the release of any new version automatically without interfering with the customers' work.                                                                                                                                                                                                                                                                                                                                                                                         |
| **Take 83 (19 Mar 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| -                                                                                                      | Enhancement: Migration from Py2 to Py3.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| -                                                                                                      | Enhancement: With this new CME take, CME requires Jumbo Hotfix installed with minimum version * R80.10 - Jumbo HFA Take 249 * R80.20 - Jumbo HFA Take 117.                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Take 79 (5 Jan 2020)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ||
| -                                                                                                      | Minor code improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Take 76 (18 Dec 2019)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| -                                                                                                      | Enhancement: Added support for NSX-T 2.5                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| -                                                                                                      | CME service does not come up after reboot.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Take 66 (22 Oct 2019)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| -                                                                                                      | Enhancement: For all platforms: * Set a prefix to all SmartConsole objects created by the CME. For more information run '*autoprov_cfg set template -h* ' and look under '-*pn*'. * Added the CME take number to version's information (through '*autoprov-cfg -v* ' and *cme_menu*).                                                                                                                                                                                                                                                                                     |
| -                                                                                                      | Enhancement: For Azure: Improved handling of API request throttling                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| -                                                                                                      | Enhancement: For AWS: * Autoscaling: integration with Network Load Balancer new listeners: UDP and UDP_TCP * Transit VPC: spoke-routes and export-routes are now configured via the *autoprov_cfg* tool. * TGW: The Gateway can be configured to re-advertise desired spoke routes over BGP back to the TGW (for Direct Connect). * TGW: Gateways can be configured to automatically set static routes on their instance route table.                                                                                                                                     |
| -                                                                                                      | Fixed degradation inserted in Take 55 - Custom Gateway script (-cg Flag) is now supported on AWS and GCP, not just Azure.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Take 55 (06 Aug 2019)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| -                                                                                                      | Enhancement: Added support for Security Management Servers and Multi-Domain Security Management Servers deployed in Azure and AWS.                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| -                                                                                                      | Enhancement: Added support for NSX-T. For more information, refer to [sk139213](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk139213).                                                                                                                                                                                                                                                                                                                                                                      |
| -                                                                                                      | Enhancement: First release of Automatic Hotfix Deployment for autoscaling solutions in Azure, AWS, and GCP. CME Automatic Hotfix Deployment allows automatic deployment of Hotfixes and Jumbo Hotfix Accumulators on scaled-out instances. Refer to the [Cloud Management Extension Administration Guide](https://sc1.checkpoint.com/documents/IaaS/WebAdminGuides/EN/CP_CME/Default.htm) for more information.                                                                                                                                                           |
| -                                                                                                      | Minor fixes and stability improvements.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Take 45 (05 Jul 2019)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| -                                                                                                      | First release of CME (Cloud Management Extension). * Supports only GCP MIG (Multi Instance Group) solution. * Supports Security Management Servers deployed in Google Cloud Platform only.                                                                                                                                                                                                                                                                                                                                                                                |

{#Unique_IDTable}

<br />

Installation Troubleshooting {#Installation Troubleshooting}
------------------------------------------------------------

Issues described below may occur when you run the CME installation script. Error messages may be similar to those listed below.

* **Issue 1: "Failed to download latest CME package. If you have no internet access please follow the instructions for offline installation in sk157492."**  
  > Solution: CME package failed to download. Make sure there is a connection to the Internet, or follow these steps for offline installation:
  > 1. Connect to the command line on the Management Server.
  >
  > 2. Log in to the Expert mode.
  >
  > 3. Get the AutoUpdater Build Number:
  >
  >    *cpvinfo /opt/AutoUpdater/latest/bin/AutoUpdater \| grep "Build Number"*
  >
  >    If the value of the "*Build Number* " in the output is lower than 990180162, do the procedure for **Issue # 3** and only then continue with the next steps below.
  > 4. Get the latest CME version from the "Availability" section.
  >
  > 5. Transfer the CME package to the Management Server (to some directory).
  > 6. Run:
  >
  >    *autoupdatercli install /\<Full Path\>/\<Name of Package\>*

  <br />

* **Issue 2: "A version of CME is already installed via AutoUpdater..."**  
  > **Solution** : CME has already been installed for the first time and is configured to receive updates automatically. If you have no internet access, follow the instructions for offline installation as described in the solution to **Issue # 1** above.

  <br />

* **Issue 3: "AutoUpdater is not installed on the machine - please install the minimal JHF version as described in sk157492 and try again."**  
  > **Solution**: Install the correct Jumbo Hotfix Accumulator as described in the beginning of the Known Limitations section. If the correct Jumbo Hotfix Accumulator is installed, but the issue persists, the follow these steps and then try again:
  > 1. [Get this AutoUpdater RPM](https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&eventSubmit_doGetdcdetails=&fileid=106362).
  >
  > 2. Transfer the package to your Management Server (to some directory).
  >
  > 3. Connect to the command line on the Management Server.
  >
  > 4. Log in to the Expert mode.
  >
  > 5. Updated the current RPM package:
  >
  >    *rpm -Uhv --force \<Full Path to AutoUpdater RPM\>*
  > 6. Stop the AutoUpdater service:
  >
  >    *autoupdatercli stop*

  <br />

* **Issue 4: "Failed to verify if CME installation completed successfully..."**  
  > The installation could not verify if CME has been successfully downloaded and installed.
  >
  > **Solution** : Contact [Check Point Support](https://www.checkpoint.com/support-services/contact-support/) and attach these log files:
  > * */opt/CPInstLog/AutoUpdateLogs/CME*
  > * */var/log/CPcme/cme_installation.log*

  <br />

* **Issue 5: When you run the script you get an output that instructs you to contact Check Point Support.**  
  > **Solution** : Contact [Check Point Support](https://www.checkpoint.com/support-services/contact-support/) and attach these log files:
  > * */opt/CPInstLog/AutoUpdateLogs/CME*
  > * */var/log/CPcme/cme_installation.log*

  <br />

* **Issue 6: I want to return to previous version of CME**  
  > **Solution**: It is highly recommended that you use the latest take of CME.
  >
  > If you still want to revert to the previous take, run this command in the Expert mode on the Management Server:
  >
  > *autoupdatercli revert CME*
  >
  > The revert takes up to 1 minute.
  >
  > To make sure CME was reverted to the previous take, run this command in the Expert mode on the Management Server:
  >
  > *cpinfo -y CPUpdates 2\>\&1 \| grep BUNDLE_CME_AUTOUPDATE*
  >
  > The take number in the output must be the one to which you reverted.
  >
  > **Notes**:
  > * CME is upgraded automatically each time a new take is released.
  > * You can revert only to the previous version. A revert to older versions reverts CME completely and removes it from the Management Server.

  <br />

* **Issue 7: I want to totally remove CME**  
  > **Solution**: Run this command in the Expert mode on the Management Server:
  >
  > *autoupdatercli revert-completely CME*
  >
  > The revert takes up to 1 minute.
  >
  > To make sure the CME was reverted completely, run this command in the Expert mode on the Management Server:
  >
  > *cpinfo -y CPUpdates 2\>\&1 \| grep -c BUNDLE_CME_AUTOUPDATE*
  >
  > The output must show "0".
  >
  > If you also wish to stop receiving future updates of CME after the removal, run this command in the Expert mode on the Management Server:
  >
  > *autoupdatercli disable CME*

  <br />

* **Issue 8: CME cannot start or cannot revert to an old CME take**  
  > **Symptoms** :  
  > 1) "*Starting cme: failed to run* " error appears during CME revert.  
  > 2) CME installation fails after CME revert-completely.  
  > 3) CME fail to start, and */var/log/CPcme/cme.log* contains "*bad decrypt* " or "*Failed to load CME configuration due to incompatible schema* " error.  
  > 4) CME from take 212 or higher is installed only on the active server, and CME on the standby member fails to start.  
  >
  > **Cause** :  
  > 1) Starting CME take 212 CME configuration has a schema version  
  > 2) The schema version attribute ensures that only compatible CME runs with the given CME configuration.  
  > 3) CME does not run when the CME configuration schema version is incompatible.  
  > 4) Example scenarios that can cause incompatibility:  
  >
  > a. Revert to older CME take.  
  > b. Upgrade -- export configuration and import it on a server with an older CME take.  
  > c. High Availability Management/Multi-Domain servers where the CME on the two members is not from the same take.  
  >
  > **Note** - CME configuration file is not reverted.  
  >
  > **High Availability Scenario** :  
  >
  > 1) CME configuration file is synchronized between the members.  
  > 2) CME loads the configuration during CME boot.  
  > 3) If the CME on the standby member is from an older take, it will fail to start because CME is not compatible with the schema version.  
  >
  > **Notes** :  
  > * Because CME configurations are stored in *$MDSDIR/conf*, the active server is the member with the active global domain.
  > * CME must not run on the standby member of a Security Management Server.
  >
  > <br />
  >
  > **Downgrade scenario** :   
  > When reverting to old CME take (revert or revert-completely + install) and the old CME is not compatible with the schema version, CME does not start.   
  >
  > **Solution** :  
  >
  > **High Availability scenario** :   
  > Install the same CME take in all the High Availability servers.  
  >
  > **Downgrade scenario** :   
  > Run "*autoprov_cfg show all* " and examine the schema version value, install a CME that supports the existing schema version value.  
  >
  <br />

  <br />

* **Issue 9: CME upgrade fails with error "*Step Install Hotfix Action verification failed*"**  
  > **Symptoms** :  
  > 1)The "*Step Install Hotfix Action verification failed* " error when running CME upgrade with installation script on Management HA environment, and the upgrade fails.  
  > 2) A CME upgrade with the Offline package procedure based on [sk157492](https://support.checkpoint.com/results/sk/sk157492)fails.  
  > 3) Review of the log in */opt/CPInstLog/AutoUpdateLogs/CME* shows installation fails with this message:  
  > *"Error: Action Install Bundle Action aborted: step Install Hotfix Action verification failed".*   
  > 4) Happens for CME package online or for offline installation.  
  >
  > **Cause** :  
  > 1) A RPM installation fails, causing the CME installation to fail.  
  > TheIssue only relevant for machines running with last Deployment installer Take 26.   
  >
  > **Solution** :  
  >
  > **To verify the component version** on the machine, run this command in Expert mode:  
  >
  > `# cpvinfo /opt/CPDepInst/latest/bin/da_installer`  
  >
  > The issue will be resolved in Deployment installer higher than Take 26. Refer to [sk181911](https://support.checkpoint.com/results/sk/sk181911).  
  >
  > **To upgrade the CME** , use this workaround:  
  >
  > 1. Revert the CME installation and install the new CME package manually.   
  > 2. To revert the current CME package run:   
  > `# autoupdatercli revert-completely CME`  
  > 3. Install the new package manually or run "`autoupdatercli stop`" to restart the autoupdate process and run the installation again. For details, refer to [sk157492](https://support.checkpoint.com/results/sk/sk157492).   
  >
  > **Note** : You can safely revert the CME. It does not delete the current configuration.  
  >
  <br />

  <br />

* **Issue 10: CME GUI shows "*CME is not available*"**  
  > **Symptoms** :  
  > 1)When openning the CME GUI, there is a warning banner that says that CME is not available.  
  >
  > **Cause** :  
  > 1) CME is not installed.  
  > 2) CME does not meet the minimum requirement (Take 288).  
  > 3) CME API is not running.  
  >
  > **Solution** :  
  >
  > 1) Connect to the Security Management Server in Expert mode.  
  > 2) Verify that you installed CME Take 288 or later. For installation instructions, follow this sk.  
  > 3) After the CME installation, run `wsc restart`.  
  > 4) Make sure CME API is running with `service cme_api status`. If the service is not running, start it with `service cme_api start`.  
  >
  <br />

  <br />

* **Issue 11: R81.10 Management Server does not get the latest CME online package**  
  > **Symptoms** :  
  > 1)This error shows in the */opt/CPInstLog/Autoupdater.log* file:  
  > `Problem with local certificate Error code: 10`  
  > `...Abandoned file removed from the system`  
  > `...Failed to download metadata package for component auto_updater`  
  >
  > **Solution** :  
  >
  > Refer to [sk184474](https://support.checkpoint.com/results/sk/sk184474).  
  >
If your issue could not be resolved by any of the above solutions, contact [Check Point Support](https://www.checkpoint.com/support-services/contact-support/) and attach log files located in */opt/CPInstLog/AutoUpdateLogs/CME*folder.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
