> Source: [sk166717](https://support.checkpoint.com/results/sk/sk166717)

# sk166717 - Check Point R81 Known Limitations

| Property | Value |
|----------|-------|
| Solution ID | sk166717 |
| Date Created | 2020-05-07 |
| Last Modified | 2026-06-14 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, SmartConsole, Cloud Firewall, Multi-Domain Security Management Server |
| Versions | R81 (EOS), R81 (EOS), R81 (EOS), R81 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

This article lists all of the **R81** **GA** specific known limitations and unsupported features, including limitations from the previous versions.  
![](https://sc1.checkpoint.com/uc/images/Information_icon1.gif)This is a live document that may be updated without special notice. We recommend registering to our weekly updates in order to stay up to date. To register go to [UserCenter](https://usercenter.checkpoint.com/) \> ASSETS / INFO \> MY INFO \> My Subscriptions.

For more information on R81, see the [R81 Release Notes](https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RN/Default.htm), [R81 Home Page](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715) and [R81 Resolved Issues](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166716).  
Visit [Check Point CheckMates Community](https://community.checkpoint.com) to ask questions or start a discussion and get our experts assistance.

**Important notes:**

* To see if an issue has been fixed in other releases or Jumbo Hotfixes, search for the issue ID in Support Center.

* To get a fix for an issue listed below [contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) with the issue ID.

Click Here to Show the Entire Article

<br />

<br />

Unsupported Features
>
> Enter the string to filter the below table:
>
> {#Gaia}{#QoS}{#Gaia}{#Security Management}{#Multi-Domain Security Management}{#SmartConsole}{#CoreXL}{#CoreXL}{#CoreXL}{#Networking}{#CoreXL}{#CoreXL}{#QoS}{#CoreXL}{#QoS}{#Identity Awareness}{#Identity Awareness}{#Unsupported-HTTPS Inspection}{#QoS}{#QoS}
>
> |---------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                              | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Found in version |
> | Unsupported Features - Installation and Upgrade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
> | PMTR-60066                      | When upgrading an R77.x Multi-Domain Server environment to R81 (requires a 2 step upgrade path via R80.40), if there are Domains with a Security Management Server configured for High Availability in R77.x, you must perform a Clean Install of an R81 Secondary Security Management Server and reconfigure the High Availability for these Domains. For more information, refer to "Creating a High Availability Environment using the Security Management Server" section in [R81 Multi-Domain Security Management Administration Guide](https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Multi-DomainSecurityManagement_AdminGuide/Default.htm).                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81              |
> | PMTR-59345                      | Central Deployment in SmartConsole does not support: * Connection from SmartConsole Client to the Management Server through a proxy server. In this case, use the applicable API command * ClusterXL in Load Sharing mode * VRRP Cluster * Installation of a package on a VSX VSLS Cluster that contains more than 3 members. * On Multi-Domain Servers: Global Domain, or the MDS context * Standalone server * Standby Security Management Server or Multi-Domain Security Management * Security Group in Maestro * Security Group on Scalable Chassis 40000 / 60000 * Quantum Spark Appliances                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-45775                      | From R80.40, Management Servers do not support UTM-1 Edge devices. Upgrade Verification fails with "*The Database includes UTM-1 Edge objects. The upgrade process cannot be performed while the database contains references to UTM-1 Edge objects* ." * To delete the UTM-1 Edge objects from the database, use the LSMcli "Remove" command (see the CLI Reference Guide for your Management Server version).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.40           |
> | PMTR-46427                      | Central Deployment in SmartConsole does not support installation of a Hotfix or a Jumbo Hotfix Accumulator on a ClusterXL in the Load Sharing mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.40           |
> | Unsupported Features - Licensing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
> | PMTR-47087                      | These products do not support the new licensing visibility features: * Network Security: Advanced Networking and Clustering, Capsule Cloud and Capsule Workspace. * Security Management: Endpoint Policy Management, SmartPortal, User Directory (LDAP). * Multi-Domain Management: Security Domain * Remote Access \& Endpoint                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80              |
> | Unsupported Features - Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | PMTR-59328                      | Multi-Version Cluster (MVC) does not support the restart of BGP, OSPF, OSPFv3, and PIM protocols while the cluster members run different software versions. This applies to the Gaia Clish commands "*restart \<protocol\>*" and to the "Restart" option in the Gaia Portal on the applicable protocol pages.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81              |
> | PMTR-48258                      | The Gaia "Cloning Group" feature (all its modes) is not supported in a Multi-Version Cluster (while cluster members run different release versions).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.40           |
> | PMTR-42987                      | Running Hardware Diagnostic Tool on 3100 \& 3200 appliances is not supported for loopback test on eth1 through eth4.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.40           |
> | PMTR-40973                      | It is not supported to downgrade with CPUSE from R81 with kernel 3.10 to R80.x with kernel 2.6. Refer to [sk170954](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170954).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | PMTR-29460                      | Gaia Snapshot operations for importing files larger than 4GB are not supported with Internet Explorer 11.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.30           |
> | PMTR-53785                      | These strings are forbidden for use in Gaia Portal and Gaia Clish (they cannot be part of any name or any user input): *eval, after, apply, catch, subset, exec.*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.20           |
> | PMTR-13683                      | Saving the Hardware Diagnostic Tool logs to a USB stick is not supported if the USB stick is formatted as NTFS.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20.M1        |
> | GAIA-3267, GAIA-2907, GAIA-2909 | Hardware Diagnostic Tool is not supported using Disk on Key (USB).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.10           |
> | Unsupported Features - Security Management / Management High Availability                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-58843                      | Revert to Revision is not supported in these scenarios: * The Endpoint Security Management Server is enabled. * If SmartConsole and the Security Management Server are connected through a proxy server, the GUI for this feature is not supported. In this case, use the applicable API command. * VSX configuration or related networks differ between the source and target revisions. * A new Domain Management Server or a Check Point object was created or deleted after the target revision date. * The corresponding revision of the Global Domain, or the IPS or Application Control components was purged.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.40           |
> | PRHF-15143                      | The SmartConsole "Extensions" feature is supported only when SmartConsole connects to the IP address defined as the main IP address of the Management Server object. Example: If a Security Management Server or Multi-Domain Server has more than one interface with assigned IP addresses, SmartConsole must connect to the main IP address defined in the Management Server object.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.20           |
> | PMTR-47633                      | The ability to edit the list of additional information fields that can be added to a Domain, administrator, and gateway is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.10           |
> | CPM-1167                        | Management High Availability is supported only between Management High Availability servers with the same build number. To see the build number, run *cpinfo -y FW1*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.             |
> | PMTR-47144                      | Security Gateway / VSX gateway conversion, or conversion in the opposite direction, is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80              |
> | PMTR-47450                      | These commands are not supported in the SmartConsole's CLI: *login* , *logout* , *discard* and *publish*. Use the SmartConsole GUI instead.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R7x              |
> | PMTR-47313                      | IPv6 addresses for management interface are not supported on Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R7x              |
> | Unsupported Features - Multi-Domain Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | PMTR-60851                      | Connecting with SmartConsole to the Domain Dedicated Log Server to see Security Policies is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
> | PMTR-17365                      | The "Install Policy" action from a Multi-Domain Server (also through "Install Policy Presets") does not support QoS and Desktop policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.20.M1        |
> | PMTR-14989                      | Multi-Domain Security Management does not support IPv6 address configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20.M1        |
> | PMTR-45085                      | The "*p1shell*" command is not supported on Multi-Domain Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80              |
> | PMTR-47182                      | Administrator groups and Domain groups are not supported and cannot be viewed or used in the SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80              |
> | PMTR-4311, CPM-1174             | SNMP is not supported on Multi-Domain Management / Multi-Domain Log servers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R7x              |
> | Unsupported Features - SmartConsole / Management Console                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | -                               | Changes (Diff) report does not support: * A Standalone server * Changes made in the Legacy SmartDashboard                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PROV-2200                       | The "Get Interfaces" operation on the "Network Management" page of a Security Gateway (or Cluster) object only supports up to 500 interfaces of all types. * **To resolve:**If the Security Gateway (or Cluster) has 500 or more interfaces of all types, use the API "*get-interfaces* " on the Management Server to pull this information. Examples: 1)*get-interfaces target-name \<Name of Security Gateway\> with-top?logy false* 2) *get-interfaces target-name \<Name of Cluster Object\> with-top?logy true* For more information refer to [Management API](https://sc1.checkpoint.com/documents/latest/APIs/index.html#introduction~v1.6%20).                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81              |
> | PMTR-31556                      | Detaching a cluster member from a cluster is not supported, it cannot be converted into a regular Security Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.30           |
> | PMTR-20430                      | R80.x SmartConsole is not supported for case-sensitive installation folder. Installation of SmartConsole complets successfully, but SmartConsole fails to start with this error message: *\[Window Title\] C:\\Program Files (x86)\\CheckPoint\\SmartConsole\\R80.20\\PROGRAM\\SmartConsole.exe \[Content\] C:\\Program Files (x86)\\CheckPoint\\SmartConsole\\R80.20\\PROGRAM\\SmartConsole.exe* *The application has failed to start because its side-by-side configuration is incorrect. Please see the application event log or use the command-line sxstrace.exe tool for more detail.*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.20           |
> | PMTR-12437                      | In Full HA cluster, the "Install Database" operation is supported only on the Cluster object (and not on the individual cluster member objects). If you try to install database on the cluster member objects, it would fail with the message "Installation failed. Reason: No policy to install."                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.20.M1        |
> | ACM-1140                        | Creating new services in R80.x is not supported via Embedded Dashboard. New service creation can be done only from SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.10           |
> | PMTR-57122                      | * Search for section titles is not supported.\| * Search strings that contain non-alphanumeric character (whitespace, underscore, and so on) are not supported. Example: If you enter a search string "*obj_ho* ", the search results show all strings that contain "*obj* " and "*ho* ", such as: "*obj_host* ", "*object1* ", "*host*2". The search does not highlight the results as expected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80              |
> | -                               | Changes to the Traditional Anti-Virus file types policy are not supported starting from R80. Use the Anti-Virus blade to change the out-of-the-box Check Point policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80              |
> | Unsupported Features - Logging / SmartLog                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-54765                      | In a Multi-Domain Server environment, configuring the same SmartEvent Server on the Global Domain and on another Domain is not supported. This configuration causes duplication of the logs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81              |
> | PMTR-59739                      | Filtering and TLS configurations for Log Exporter are not supported in SmartConsole, but are supported when you configure Log Exporter manually on the CLI. For more information, see [sk122323](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122323).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81              |
> | PMTR-59736                      | In a Multi-Domain Server environment, Log Exporter configuration in SmartConsole is not supported on: * The MDS level (applies to Multi-Domain Server and Multi-Domain Log Server) * The Global SmartEvent Server                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-40514                      | In the SmartConsole -\> Logs \& Monitor view -\> \[ + \] New Tab -\> Views, sorting of the Favorites and Shared columns is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.40           |
> | PMTR-47703                      | Purge, log switch and fetch log file tasks are not supported from SmartConsole. * Fetch log files from a remote server is available from command line only. Run: *fw fetchlogs \<Gateway-Name/IP\>*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.10           |
> | Unsupported Features - SmartProvisioning                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-56758                      | It is not supported to remove an IP address from one interface and assign the same IP address to another interface in the device object in the same edit action. "*Error field: ipAddr, Desc: IP address is in the subnet of an existing network*" is displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81              |
> | PMTR-54979                      | When managing devices with the SmartProvisioning Software Blade, on the devices you must configure the connection with the Security Management Server using the IPv4 address in the "c*onnect security-management mgmt-addr \<IPv4 address of Security Management Server\>*" command (it is not supported to use the FQDN of the Security Management Server in this command).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.40           |
> | Unsupported Features - SmartEvent                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-39873                      | Login to SmartView Web application is supported only using Check Point Password authentication.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80              |
> | -                               | SmartEvent is not supported on Full HA environment.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R7x              |
> | Unsupported Features - Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | PMTR-66296                      | The [Management Data Plane Separation (MPDS)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk138672) does not support the Gaia OS "LLDP" feature.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81              |
> | PMTR-68338                      | TLS 1.3 is not supported in HTTPS Inspection when the Security Gateway is configured as an ICAP client or as an HTTP proxy server. HTTPS Inspection remains limited to TLS 1.2 in this configuration even if TLS 1.3 support was enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PMTR-58361                      | Intra-Tunnel Inspection of GTP-U user traffic is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81              |
> | PMTR-58366                      | The "Produce extended logs on unmactched PDUs" option is not supported in the Security Gateway (Cluster) object \> 'Carrier Security' pane \> 'Track' section. As a result, it is not possible to generate informative logs for unmatched GTP-C control packets (except for a plain clean up rule logging).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81              |
> | PMTR-60382                      | ISP Redundancy is not supported with CGNAT.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81              |
> | PMTR-68991                      | ISP Redundancy is not supported if Dynamic Routing is configured (because the ISP Redundancy feature must create a static default route that overrides the default route created by dynamic routing).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R7x              |
> | Unsupported Features - ClusterXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
> | PMTR-60458                      | Changing the ClusterXL mode to Load Sharing Multicast with the Management REST API is not supported. You must change the mode only in SmartConsole in the cluster object.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PMTR-59604                      | Multi-Version Cluster (MVC) Upgrade procedure does not support ClusterXL in Load Sharing modes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81              |
> | PMTR-59404                      | Geo Cluster does not support IPv6 traffic. Therefore, it is not supported to configure an IPv6 address on the Cluster and Sync interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
> | PMTR-70257                      | In an Active-Active cluster, all multi-portals are not supported (Mobile Access Portal, Identity Awareness Captive Portal, Data Loss Prevention Portal, and so on).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.40           |
> | PMTR-70258                      | In an Active-Active cluster, NAT on the IP addresses that belong to cluster interfaces is not supported (because it does not survive cluster failover).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80.40           |
> | PMTR-70259                      | In an Active-Active cluster, in the cluster object properties, go the Network Management page, select a cluster interface and click Edit. In the Network Type field, it is not supported to select "Cluster+Sync" when you deploy a cluster in a cloud (for example: AWS, Azure).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.40           |
> | CLUS-1582, CLUS-1775            | Site-to-Site (IPSec VPN) is not supported with ClusterXL in Load Sharing mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.40           |
> | MB-30, PMTR-21154, PMTR-48562   | Load Sharing mode is not supported starting from ClusterXL R80.20. For more information about this configuration, refer to [sk162637](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk162637).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.30           |
> | PMTR-48477                      | ICAP Client and ICAP Server are not supported with ClusterXL Load Sharing modes. ICAP Server is not supported with VSX Virtual System Load Sharing (VSLS).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.10           |
> | Unsupported Features - CoreXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
> | PMTR-58368                      | CoreXL Dynamic Dispatcher is not supported with CGNAT. Before you install a policy with CGNAT rules, you must disable the CoreXL Dynamic Dispatcher. Refer to [sk105261](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105261).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81              |
> | Unsupported Features - Dynamic Routing / Advanced Routing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-19481                      | PIM is not supported on a Security Gateway / Cluster, when Route Based VPN is configured.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.20           |
> | Unsupported Features - ICAP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-28828                      | ICAP Client cannot forward traffic to an ICAP Server when the Security Gateway is configured to apply the Threat Prevention "Strict Hold" mode. See [sk183785](https://support.checkpoint.com/results/sk/sk183785).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.30           |
> | PMTR-16958                      | The ICAP Server feature is not supported in VSX mode deployment.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.20           |
> | Unsupported Features - VSX                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-66295                      | VSX does not support the Gaia OS "LLDP" feature.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81              |
> | PMTR-60113                      | Configuration with a Non-Dedicated Management Interface (Non-DMI, shared interface) is deprecated and not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81              |
> | PMTR-59810                      | Dynamic Balancing is not supported on VSX Gateways and VSX Clusters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.40           |
> | PMTR-47590                      | Explicit conversion is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80              |
> | Unsupported Features - Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-59492                      | In a Multi-Domain Server environment, R81 Infinity Threat Prevention does not support the Global Domain. Other Domains are supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81              |
> | PMTR-59491                      | R81 Infinity Threat Prevention does not support MTA. Users can manage Security Gateways configured as MTA only in the Traditional Threat Prevention mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PMTR-56237                      | R81 Security Gateways and Clusters no longer support Traditional Anti-Virus. Use the Anti-Virus Software Blade.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81              |
> | PMTR-59837                      | SSH Deep Packet Inspection limitations: * SSH DPI is only supported for Security Gateways R80.40 and above, managed by Management Servers R80.40 and above. * Inspection of IPv6 connections is not supported. * Bridge Mode is not supported. * Cluster members do not synchronize the data about the inspected SSH traffic. * Cluster members do not synchronize the SSH DPI configuration. * Inspection of SSH traffic generated by clients, which do not support the 'Diffie-Hellman group exchange' algorithm, is not supported. * These SSH clients are not supported: * PuTTY versions 0.64 and lower. * OpenSSH versions 2.5.2 and lower. * WinSCP versions 5.7.4 and lower. * SecureCRT versions 5.2 and lower.                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | Unsupported Features - Identity Awareness                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | -                               | Using Identity Awareness Captive Portal with an external SAML identity provider is not supported with Internet Explorer version 10 or lower.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.40           |
> | PMTR-44737                      | Multi-User Host (MUH) version 2 is not supported with IPv6 and does not initiate a connection to an IPv6 Security Gateway. It stays in "Disconnected" state and users are not identified.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.40           |
> | PMTR-64495                      | Identity Awareness does not support authentication of Primary Groups of user and computer accounts. By default, the Primary Groups are 'Domain Users' and 'Domain Computers'. Access roles that are defined with User groups do not work for users with which those user groups are their primary group. * To use the entire Accounting Unit in an Access Role, use an LDAP group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R7x              |
> | Unsupported Features - HTTPS Inspections                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | CRYPTOIS-2197                   | HTTPS Inspection does not support Hardware Security Modules (HSM) when inspection of TLS 1.3 traffic is enabled. With HTTPS Inspection, you can enable only one of these features - TLS 1.3 or HSM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81              |
> | Unsupported Features - Mobile Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
> | PMTR-60331                      | These limitations apply to the Guacamole feature: 1. A dedicated Apache Guacamole Server version 1.1.0 or higher is required. 2. The following Guacamole features are not supported: * The VNC protocol * RDP file transfer * The SFTP protocol * Session recording 3. RDP/SSH is not supported from Capsule Workspace. 4. RDP/SSH is supported only by web browsers with HTML5 support. 5. RDP and SSH applications can be configured only by using their corresponding service objects in SmartConsole: * "Remote_Desktop_Protocol" * "SSH" * "SSH_version_2" 6. The Clipboard function in RDP sessions is supported with these limitations: * Text only * Supported browsers: Chrome and Explorer 7. This Single Sign-On option is not supported for Guacamole applications: 'This application reuses the portal credentials. If authentication fails, Mobile Access prompts users and stores their credentials' 8. In a VSX environment where the 'custom user directory attribute' feature is used, adding a new Virtual System requires manually adding the *customUserRecordAttribute.conf* file as well. | R81              |
> | PMTR-58003                      | Mobile Access rules in the Unified Access Policy do not support Native Applications that authorize non-TCP or non-UDP services (for example, "*icmp-proto*").                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81              |
> | PMTR-47745                      | The Mobile Access Portal does not support Web-Form SSO for Citrix StoreFront Web interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.10           |
> | PMTR-47591                      | Mobile Access does not support viewing or editing files with '*Office Online apps*', Microsoft's browser-based Office applications. Outlook Web Access is supported, however you cannot open or edit Office Online app files from emails.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R7x              |
> | PMTR-62828, 02302626            | Mobile Access Portal supports Outlook Web App 2013 / 2016 only with the Path Translation (PT) method. The Hostname Translation (HT) method is supported when cookies on the endpoint machine are configured. The URL Translation (UT) method is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R7x              |
> | Unsupported Features - VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-60396                      | Large Scale VPN (LSV) does not support: * IPv6 * Route Based VPN (VTI) * Two VPN peers behind the same NAT device * Suite-B-GCM-128 * Suite-B-GCM-256 with IKEv1-only (it is necessary to change the global properties of Phase 1 for Remote Access VPN) * Multiple Hubs * Route Injection Mechanism (RIM) * IKE Aggressive Mode * Permanent Tunnel * Multiple Entry Point (MEP) VPN * Dead Peer Detection (DPD) * Global VPN Community (GVC) * Tunnel Per Security Gateway pair (Universal Tunnel)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.40           |
> | PMTR-47783                      | NAT-T initiator is not supported on VSX Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.10           |
> | PMTR-47235                      | Convert Traditional VPN to Simplified is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80              |

> {#limitationTable}

*** ** * ** ***

Installation and Upgrade
>
> Enter the string to filter the below table:
>
> {#Installation and Upgrade}
>
> |-----------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                                | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Found in version |
> | Installation and Upgrade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-60610                        | R81 includes the new mechanism for log indexing. Before you upgrade a Management Server or Log Server that uses an external storage device to keep the log data, you must follow the instructions in [sk66003](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk66003) to change the location of the existing log indexes. This applies only if it is necessary to keep the existing log indexes and use them after the upgrade. This applies to Security Management Server, Log Server, Multi-Domain Security Management Server, Multi-Domain Log Server, SmartEvent Server, StandAlone Server. | R81              |
> | GNG-1259, PMTR-52941              | R81 includes new logs indexing mechanism, so when upgrading Management server/Log Server/Multi-Domain Server/Multi-Domain Log Server/SmartEvent from R80.x, old log indexes are not upgraded. The indexing mechanism will re-index the last 24 hours automatically. To increase the period of offline indexing (how far in the past to re-index the logs), see [sk111766](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111766).                                                                                                                                                              | R81              |
> | PMTR-61069                        | SmartEvent upgrade is allowed only after all Multi-Domain Servers with Active Domain Management Servers are upgraded.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
> | PMTR-46384                        | Hotfix central deployment depends on the status reports from the gateways. Therefore, it is recommended to wait for 2 minutes after the gateways are up before running any operation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.40           |
> | SMCUPG-1248                       | In case of a failure in one of the Domains, during an upgrade of a Multi-Domain Server from R80.20.M1, R80.20, R80.20.M2, or R80.30 using an Advanced upgrade, the entire upgrade process stops and does not continue to upgrade additional Domains. * **To resolve**: 1. Follow the instructions in the HTML upgrade report. 2. After the issue is resolved, start the entire upgrade again.                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-13035                        | When you perform a clean install of an R81 on top of an existing previous version, the following error might appear after the keyboard layout selection screen: *Warning: /dev/sda contains GPT signatures, indicating that it has a GPT table. However, it does not have a valid fake msdos partition table, as it should. Perhaps it was corrupted - possibly by a program that doesn't understand GPT partition tables. Or perhaps you deleted the GPT table, and are now using an msdos partition table. Is this a GPT partition table?* In such case, select "*Yes*" several times to continue with the installation.                                  | R80.20           |
> | SMCUPG-457, PMTR-48574            | To upgrade an R80.x Multi-Domain Management Server with configured Global Policies to the next available version: 1. Connect with SmartConsole to the Global Domain on your R80.x Multi-Domain Server. 2. Reassign all Global Policies to all applicable Domains. 3. Do not publish any changes in the Global Domain until you complete the upgrade to the next available version. Note: This is necessary to avoid any potential issues caused by different policy revisions on the Global Domain and on the Domains. 4. Perform the upgrade from the R80.x to the next available version.                                                                 | R80.20.M1        |
> | VSECPC-1341, TP-1790, TP-1953     | It is not supported to perform an in-place upgrade to R80.40 Security Management Server or Multi-Domain Security Management Server that runs in CloudGuard for Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), or any other cloud providers.                                                                                                                                                                                                                                                                                                                                                                                       | R80.20.M1        |
> | -                                 | R80.x supports only ext3 \& ext4 file systems on Red Hat Enterprise Linux.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.10           |
> | PMTR-47047                        | After upgrade ?f R7X Stand Alone Server, SmartConsole disconnects from the server during the first policy install. * **To resolve**, before a first policy installation on Standalone servers, allow the CPM service in the Services \& Applications column of the rulebase.                                                                                                                                                                                                                                                                                                                                                                                | R80              |
> | PRHF-7325, PMTR-27422, PMTR-47257 | Clean install from USB device fails on Open Server because the installation process (anaconda) includes the USB installation media as part of the installation target. Refer to [sk100566](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100566).                                                                                                                                                                                                                                                                                                                                             | R7x              |

> {#UpgradeTable}

*** ** * ** ***

Licensing
>
> Enter the string to filter the below table:
>
> {#Licensing}
>
> |------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | Found in version |
> | Licensing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |||
> | PMTR-47089 | "*Licensing status not available for current OS*" message shows in the Logs \& Monitoring view. SmartConsole does not support licensing information for Windows, SecurePlatform and Virtual Systems. Use the licenses tab in SmartUpdate to see the licensing information for the OS.                                                                                                                                                                                                                                                                                                                                                                     | R80              |
> | PMTR-47091 | If the SmartEvent Software Blade is activated, but only the SmartEvent Intro license is installed, the License Status shows "N/A".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80              |
> | PMTR-47095 | The Device and License Status of Threat Emulation is incorrect. Use the Logging -\> License Status view.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80              |
> | PMTR-47532 | When loaded for the first time, web components such as the licensing or monitoring view can take up to thirty seconds to show.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80              |
> | PMTR-47101 | In the License Status View, the Additional Info column, quota information and quota statuses are not available for pre-R80 gateways and servers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80              |
> | PMTR-47103 | Automatic license activation on Check Point appliances is not available on pre-R80 appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80              |
> | PMTR-47105 | On pre-R80 gateways, license information is updated every 20 minutes. * **To resolve**, force a license update, perform *one* of the following actions: <!-- --> * * Either install security policy on the pre-R80 gateway * Or on the R81 Management Server, run the following command in Expert mode: * On Security Management Server: *\[Expert@HostName\]# $CPDIR/bin/esc_db_complete_linux_50 bc_refresh \<Name of Target Object\>* * On Multi-Domain Security Management Server: *\[Expert@HostName\]# mdsenv \<Name of Domain Management Server\>* *\[Expert@HostName\]# $CPDIR/bin/esc_db_complete_linux_50 bc_refresh \<Name of Target Object\>* | R80              |
> | PMTR-47108 | Automatic license activation on a Multi-Domain Management Server machine works only on the MDS level and not on the Domain level. Add licenses manually for each Domain.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80              |
> | PMTR-47116 | After installation, the Device License Status shows*N/A* and the Device License View is not accessible until policy or database are installed. When blades are enabled or disabled, the changes are not visible in the Device License Views and Status until policy or database are installed.                                                                                                                                                                                                                                                                                                                                                            | R80              |
> | PMTR-47308 | The proxy that synchronizes license information with the User Center, must be at least R80 server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R7x              |
> | PMTR-47531 | On SmartEvent NGSE dedicated machine, license information is not automatically updated when Installing Database. When you enable or disable a blade, one of the following will update the license information with the change: * If you force a license update, changes occur immediately. To force a license update: On the R81 Security Management Server, run the following command in Expert mode: *\[Expert@HostName\]# $CPDIR/bin/esc_db_complete_linux_50 bc_refresh \<Name of Target Object\>* * Automatic update at midnight * If you manually change a license or contract on a dedicated machine, changes take effect within 20 minutes        | R7x              |

> {#LicensingTable}

*** ** * ** ***

Security Gateway and Gaia OS Networking / Security Gateway / Gaia OS / Hardware / CoreXL / SecureXL / ClusterXL / Routing / VSX / VPN / LTE / QoS
>
> Enter the string to filter the below table:
>
> {#Security Gateway}{#Gaia}{#Hardware}{#CoreXL}{#SecureXL}{#ClusterXL}{#Routing}{#VSX}{#VPN}{#LTE}{#QoS}
>
> |------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Found in version |
> | Networking                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-50502             | On a CloudGuard Security Gateway for Google Cloud Platform (GCP), KVM, or OpenStack, outputs of these commands show empty RX and TX statistics for VirtIO: *# ethtool -S \<name of interface that uses the 'virtio' driver\>* *# cat /proc/interrupts* *# mq_mng --show -v*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.40           |
> | Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | PMTR-58364             | During policy installation, reverse rules are not generated. See the [R81 Carrier Security Administration Guid](https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CarrierSecurity_AdminGuide/Default.htm)e.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PMTR-54110             | Proxy ARP entries are not generated automatically for CGNAT translated Address Ranges. * **To resolve**: Configure the Proxy ARP entries manually. Refer to [sk30197](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk30197).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81              |
> | PMTR-59152             | Traffic on a single GRE tunnel cannot be distributed to multiple CoreXL Firewall instances. Therefore, the maximum throughput of a single GRE tunnel is limited by the throughput of a single CoreXL Firewall instance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81              |
> | PMTR-56389             | "*Authentication failure: check your username and password* " message on a Security Gateway when raising the "TACP" privileges of a TACACS user in the following scenario: 1. Configured the Management Data Plane Separation (MDPS) as described in sk138672 2. Configured Gaia OS roles with different privileges for TACACS users 3. Configured a TACACS server 4. Logged in with a TACACS user 5. Raised the "TACP" privileges in Gaia Portal (at the top of the "Overview" page, clicked "Enable") or in Gaia Clish (with the "t*acacs_enable \<Role\>*" command) 6. Entered the TACACS user password **To resolve**: 1. Log in to Gaia Clish on the Security Gateway 2. Add the Gaia OS "confd" process to the Management Plane. Run: add mdps task process confd 3. Save changes. Run: *save config*                                                                                                                                        | R81              |
> | PMTR-56297             | In a rare scenario, the Security Gateway may crash and reboot if multiple slave interfaces are deleted at the same time from an 802.3AD bond interface (for example, with the "*clish -f*" command).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-37712             | It is not possible to add updatable objects to network groups.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.40           |
> | GAIA-1953              | Multi-Queue configuration is not preserved during a Security Gateway upgrade from a Gaia OS with the Linux 2.6 kernel to a Gaia OS with the Linux 3.10 kernel. After the upgrade, it is necessary to configure Multi-Queue again ([sk153373](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153373)). Example: Upgrade from R80.20 to R80.30 v3.10, from R80.20 to R80.40, and so on.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.30           |
> | PMTR-38747             | Output of the "*fw ctl zdebug + drop* " command shows messages about connection drops, in addition to Firewall drops. These are internal debug messages that do not reflect real Firewall drops. To avoid them, use one of these: 1. The "*fw ctl zdebug drop*" command without the "+" character in the syntax 2. The full debug procedure                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.20           |
> | PMTR-42525             | When Using a rule with legacy object, in or below a rule with one of the new features that are integrated in the unified policy, install policy on a Security Gateway fails with a verification message. * **To resolve**: change the order of the rules so that rules with legacy objects are above rules with new features. Refer to [sk115961](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115961).                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.10           |
> | PMTR-47866             | "*Get Interfaces* " action on gateway returns error "*Failed to save cpmi interfaces* " if interface name includes space. Gateway interface names must not include spaces. Refer to [sk124813](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk124813).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80              |
> | PMTR-17546             | Logging session does not switch to the backup logging server after connectivity loss. Refer to [sk118697](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk118697).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R7x              |
> | PRHF-66                | SAM rules generate large amount of "*fwsam_v1_filter: matched rule is not found* " messages. Refer to [sk105347](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105347).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R7x              |
> | PMTR-38815             | In some scenarios, Security Gateway sends wrong format BSD Syslog logs. Refer to [sk122952](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122952).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R7x              |
> | PMTR-47567             | "*No Such Instance currently exists at this OID* " error message may appear after installing Jumbo Hotfix. Refer to [sk117353](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117353).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R77x             |
> | Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | PMTR-60804             | Bond interface in XOR mode or 802.3AD (LACP) mode may experience suboptimal performance, if on the Bond interface the Transmit Hash Policy is configured to "Layer 3+4" and Multi-Queue is enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-18774             | To upgrade a 21000 series appliance with the SAM card ([sk107157](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107157)) from R80.10 (or lower) to R80.40 (or higher), you must disable the SAM Mode on all the interfaces before the upgrade: 1. Disable the SAM mode on **all** the interfaces in either Gaia Portal or Gaia Clish: * In Gaia Portal: In the Network Management section, click Network Interfaces \> edit each interface \> go to the SAM tab \> clear the box Enable SAM Mode \> click OK * In Gaia Clish: *set interface \<Name of Interface\> sam-mode off* *save config* 2. Reboot the appliance 3. Upgrade the appliance 4. Reboot the appliance                                                                                                                                                                                                              | R80.40           |
> | PMTR-45939             | When the system goes into reboot, the message "*umount: /var/log: target is busy*" appears on the console, as the system attempts to unmount partitions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.40           |
> | GAIA-6676, GAIA-7215   | When using the '*set-time-and-date*' API call, the administrator may be reacquired to log in again if the session expires.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | PMTR-46932             | The default value of the Linux kernel parameter */proc/sys/net/ipv6/conf/all/accept_dad* is set to '0'. The IPv6 Duplicate Address Detection (DAD) feature is still enabled by default ('*set neighbor duplicate-detection state on*').                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.40           |
> | GAIA-5737              | Duplicate ping messages may appear when configuring bonding groups (\~30 sec), one over the X722 based network interfaces and the other on Intel X710 Based network interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.30           |
> | GAIA-3490              | 10GbE i40e NICs determine their link-speed based on the type of connected transceiver (1G ot 10G) and cannot be changed manually.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.30           |
> | GAIA-3345              | Changing the MTU on the directly connected switches may cause drops of fragmented traffic due to a MTU mismatch.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.30           |
> | GAIA-3205              | Cannot change interface link speed to 1000MB after it is changed to 100MB.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.30           |
> | GAIA-3180              | On HP Open servers with onboard NIC, the Interface status in the switch might be shown as "Connected" even though the state in Gaia is "off".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.30           |
> | GAIA-2650              | On CloudGuard for AWS, speed and duplex information is not available when using the *ethtool*.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.30           |
> | PMTR-17540, GAIA-2926  | The Linux "*iotop* " utility might stop working when pressing the "i" key in the following rare scenarios: * Working in virtual environments (such as Hyper-V) * Terminal application uses specific virtual terminal settings (such as specific SecureCRT terminal settings)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20.M1        |
> | PMTR-13029, PMTR-13021 | "*\[Firmware Bug\]: the BIOS has corrupted hw-PMU resources* " message may appears in the output of "*dmesg* " command on any HP ProLiant Server running Gaia. * You can safely ignore this message - it does not indicate an issue with the functionality or performance of the Operating System or the server. For details, see Hewlett Packard Enterprise Customer Advisory [c03265132](https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-c03265132).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.20.M1        |
> | PMTR-47577             | If the backup schedule is changed to an invalid date or time, all backup schedules are lost and "*Backup schedule failed. The backup will not be scheduled*" error message is displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.10           |
> | PMTR-47574             | The *Maintenance -\> Maintenance* page in the Gaia Portal was removed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.10           |
> | PMTR-47120             | When connecting to the network interfaces page in the Gaia Portal, an "*Unable to connect to server* " error shows. * **To resolve**: disable the Adblock EasyPrivacy extension of the Adblock plus add-on and try again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80              |
> | PMTR-47126             | If you change the members of a Gaia Cloning Group with many members down, you are logged out of the Gaia Portal with an incorrect error message: "*Unable to connect to server* ". The correct message is: "*An error occurred while applying configuration change to all cloning group members*" - the operation was successful only for online members. This is the normal behavior of the cloning group. This error does not indicate a critical failure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80              |
> | PMTR-47335             | The last stage of the First Time Configuration Wizard takes a long time on some machines. To see the progress of the First Time Configuration Wizard, the user must check if these files were created on the machine: * */etc/.wizard_accepted* - means that the First Time Configuration Wizard has finished. * */var/log/ftw_install.log* - means the First Time Configuration Wizard has started and the user must wait until the file */etc/.wizard_accepted* is created.                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R7x              |
> | PMTR-47323             | Newly configured user (with UID that is not 0) is not able to log in from Gaia Clish to Expert mode on VSX Gateway. Refer to [sk115221](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115221).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R7x              |
> | PMTR-47328             | "*WARNING The following features: NameOfFeature, , provide a privilege level equivalent to that of 'adminRole'* " message in Clish when adding some read-only commands to RBA role. Refer to [sk110772](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110772).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R7x              |
> | PMTR-29320             | Saving the configuration on Gaia OS times out with "*NMSCFD0026 Timeout waiting for response from database server* " error. Refer to [sk113746](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113746)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R7x              |
> | Hardware                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
> | HCL-12                 | The HP ProLiant DL380 Gen10 does not detect all USB devices, including various USB flash drives (regardless of its content). This is not a software issue. If a bootable USB device (with Check Point Gaia, CentOS or any other OS) is not recognized by this server, try a different USB device vendor.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.20           |
> | ACCHA-802              | On a Check Point appliance with an Expansion Line Card installed, the output of the "dmesg" command shows these errors: `pci 0000:XX:00.X: BAR <NUMBER>: failed to assign [mem size 0x<NUMBER> 64bit pref]` * You can safely ignore these messages.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.10           |
> | CoreXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
> | PMTR-50242             | Changes in CoreXL configuration are not preserved after a reboot on a CloudGuard Security Gateway in AWS or Azure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.40           |
> | SecureXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
> | PMTR-18774             | SAM is supported only for non-accelerated usage. Traffic connected to the Acceleration-ready 10G Interface Card (CPAC-ACCL-4-10F-21000) is handled by the host. 10G Ports on the CPAC-ACCL-4-10F-21000 cannot be assigned as SAM ports.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.20           |
> | ClusterXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
> | PMTR-59990             | GRE traffic fails to pass through a cluster after all cluster members are rebooted. Refer to [sk169672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk169672).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
> | PMTR-59397             | If a Geo Cluster is deployed on-premises (and not in a cloud - e.g., AWS, Azure), then it is **not** supported to configure IP addresses from different subnets on these cluster interfaces: * Interfaces with the Network Type "Cluster". * Interfaces with the Network Type "Cluster+Sync".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81              |
> | PMTR-70255             | In an Active-Active cluster, only these Software Blades are supported: * Firewall * IPS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.40           |
> | PMTR-70251             | In an Active-Active cluster, only two cluster members are supported - one cluster member on each site.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.40           |
> | PMTR-70256             | In an Active-Active cluster, names of interfaces that belong to the same "side" must be identical on all cluster members. Example: If you connected the interface eth1 to Switch #A on one Cluster Member, then you must connect the interface eth1 to Switch #A on all other Cluster Members.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.40           |
> | PMTR-70260             | In an Active-Active cluster, in the cluster object properties, go the Network Management page, select a cluster interface and click Edit. In the Topology section, only these options are supported for cluster interfaces: * * Override \> Network defined by routes (this is the default). * Override \> Specific \> select the applicable Network object or Network Group object.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-68064             | TCP connections initiated from a Standby cluster member are not supported in a Multi-Version Cluster when: 1. The Standby cluster member runs version R77.30 or R80.10 2. IPS is enabled in the cluster                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.40           |
> | PROV-1645              | In the output of the "*show-simple-cluster* " API command, the "*last-modify-time* " is not updated when the cluster member object is changed (for example: the IP address is changed or a comment is added). This field is only updated when a cluster member is added to a cluster object.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.40           |
> | PROV-1953, PROV-1958   | * The "*show-gateways-and-servers* " API shows the Cluster Member object type as "*type": "CpmiClusterMember*". * The "*show-gateways-and-servers* " API shows the Cluster object type as "*type": "CpmiGatewayCluster*". * The "*show-simple-cluster* " API (or "show-simple-clusters" API) shows the Cluster object type as "*type":* "*simple-cluster*".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.40           |
> | PROV-2054              | The "*cphaprob -a if* " command does not recognize ClusterXL VIP addresses in this scenario: 1. The cluster object was created with Cluster API 2. The Cluster VIP addresses and the Cluster Members' IP addresses belong to different subnets 3. Policy was installed on the cluster object **To resolve** , perform one of the below solutions: 1. Create this cluster object in SmartConsole instead of Cluster API. 2. Use GuiDBEdit Tool / dbedit / Generic API to change the value of the "*member_network*" field in the cluster object to contain the subnet of cluster members.                                                                                                                                                                                                                                                                                                                                                           | R80.40           |
> | PMTR-41292             | In an Active-Active cluster, if you enabled Dynamic Routing on each Cluster Member, you must enable the Bidirectional Forwarding Detection (BFD - '*ip-reachability-detection*') on each interface that is configured for dynamic routing.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | PMTR-57258             | Connections do not survive failover in a ClusterXL configured in the Active/Standby Bridge mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.30 3.10      |
> | Dynamic Routing / Advanced Routing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-4925              | When advertising IPv4 routes over an IPv6 BGP session, one of the following needs to be true: 1. Routemap is used to set the nexthop of the IPv4 routes 2. The interface used for the BGP session needs to have an IPv4 address When advertising IPv6 routes over an IPv4 BGP session, one of the following needs to be true: 1. Routemap is used to set the nexthop of the IPv6 routes 2. The interface used for the BGP session needs to have an IPv6 address                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20           |
> | PMTR-47725             | On a Security Gateway that is configured with DHCP relay and automatic Hide NAT for the network(s) that the DHCP requests come from, DHCP offers are dropped at the gateway. This message shows: *fw_log_drop_ex: Packet proto=17 40.81.81.3:67 -\> 44.81.81.6:67 dropped by fw_conn_inspect Reason: post lookup verification failed;* * **To resolve**: before the Hide NAT rule, add a NAT rule that prevents the translation when traffic is on port 67, and is going to the DHCP server. Make the NAT similar to this: |-------------------------------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------| | Original Packet: *Source = Source network(s) for DHCP requests* *Destination = DHCP server* *Service = UDP_bootp* | Translated Packet: *Source = Original* *Destination= Original* *Service = Original* | | R80.10           |
> | VSX                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-60160             | You can use the "*vsx_util downgrade* " command only if you did not make any configuration changes after you used the "*vsx_util upgrade*" command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-59845             | Installation or upgrade of Mobile Access Portal Agent on an end-user's computer may fail on a VSX Gateway or VSX Cluster. Refer to [sk169614](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk169614).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.40           |
> | PMTR-47869             | The "*vsx stat -v* " command does not work after reverting to Gaia Autosnapshot (a snapshot created automatically by the CPUSE Upgrade). * **To resolve**: Use the "*fw vsx stat -v*" command instead.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.40           |
> | PMTR-65592             | The name of the VSX Gateway / VSX Cluster object must be shorter than 27 characters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.10           |
> | PMTR-47563             | In SmartView Monitor, Firewall History and System History system counters do not show any data.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R7x              |
> | VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-68228             | If the Diffie-Hellman (DH) group configuration is changed (SmartConsole \> Global Properties \> Remote Access \> VPN - Authentication and Encryption \> Encryption algorithms \> Edit \> Phase 1 \> Use Diffie-Hellman group) while an Endpoint VPN client is connected, the client disconnects during the next Phase 2 negotiation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81              |
> | PMTR-55445             | Site to Site VPN with a Large Scale VPN profile can drop traffic after decryption with the log "*According to policy traffic shouldn't have been decrypted* ". **To prevent this traffic drop**: 1. Edit the Large Scale VPN profile object: 1. On the 'VPN domain' page, in the section 'IP addresses allowed in the VPN Domain' select 'Restrict to these groups or networks' 2. Select the applicable 'Host', 'Network', and 'Group' objects. 2. Edit the LSV peer object: 1. In the VPN Domain (Encryption Domain), select the 'Address Range' objects, whose IP addresses contain the IP addresses of the 'Host', 'Network', and 'Group' objects you selected in the Large Scale VPN profile object. 3. Install the Security Policy.                                                                                                                                                                                                          | R81              |
> | PMTR-25046, PMTR-33694 | After running the "*cpstop ; cpstart* " commands, the "*FW-1: fwconn_chain_get_opaque: invalid id -1*" message appears repeatedly on the screen and in the dmesg. This is a cosmetic issue only.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.20           |
> | PMTR-15415, PMTR-48563 | Communication errors occur between the Security Gateways managed by R80.20 M1 Multi-Domain Server and participating in Global VPN Communities when there are more than one certificate for the same Internal CA.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.20           |
> | PMTR-58668             | If a Security Gateway with PIM configured is part of a VPN community, PIM service must be added to the Excluded Services in the VPN community object. This only applies in one of these scenarios: * Security Gateway is directly connected to a multicast sender * Security Gateway is configured as a PIM Rendezvous Point                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.10           |
> | PMTR-47752             | The VPN client shows as "*Not Compliant* " when it is not compliant according to the local.scv file, even if SCV is disabled. * **To resolve**: Configure the VPN site again on the client.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.10           |
> | PMTR-47501             | When using a VPN client, activity logs are not generated for ICMP traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R7x              |
> | PMTR-17557, PMTR-17565 | Client Setting "*Calculate IP based on topology* " breaks when using host. Refer to [sk120121](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk120121).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R7x              |
> | PMTR-32305             | RADIUS authentication fails for LDAP users as the gateway uses *sAMAccountName* and not UPN when UPN is needed. Refer to [sk122477](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122477).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R7x              |
> | LTE                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-47540             | SCTP or Diameter objects cannot be the service of a manual NAT rule. Static NAT will still be applied for rules that match SCTP if the service is set to "Any". All NAT methods can be applied for Diameter over TCP traffic if the service is set to "Any".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R7x              |
> | QoS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-26017             | Values set for Maximum rule weight and Default weight of rule in the QoS Global properties window in SmartConsole are not applied when creating a new QoS rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.30           |
> | PMTR-47566             | No warning is displayed if an empty network group object appears in the source or destination column.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R7x              |

> {#GatewayTable}

*** ** * ** ***

Security Management / Management HA / Multi-Domain Management / SmartConsole / Compliance / Logging / SmartLog / SmartEvent / SmartProvisioning
>
> Enter the string to filter the below table:
>
> {#Security Management}{#Management HA}{#Multi-Domain Security Management}{#SmartConsole}{#Compliance}{#Logging / SmartLog}{#SmartEvent}{#SmartProvisioning}
>
> |--------------------------------|------------------|
> | ID                             | Found in version |
> | Security Management                              ||
> | PMTR-54256                     | R81              |
> | PMTR-76791, PMTR-68625         | R81              |
> | PMTR-59442                     | R80.40           |
> | PMTR-68323                     | R80.40           |
> | PMTR-50315                     | R80.40           |
> | PMTR-56332                     | R80.40           |
> | PMTR-41786, PMTR-48965         | R80.40           |
> | PMTR-45593                     | R80.40           |
> | PMTR-63264                     | R80.20.M2        |
> | PMTR-25696                     | R80.20.M2        |
> | PRHF-14607                     | R80.10           |
> | PMTR-54350                     | R80.10           |
> | PMTR-47579                     | R80.10           |
> | PMTR-47620                     | R80.10           |
> | PMTR-47622                     | R80.10           |
> | PMTR-47777                     | R80.10           |
> | PMTR-47133                     | R80              |
> | PMTR-47140                     | R80              |
> | PMTR-41764                     | R7x              |
> | PMTR-47457                     | R7x              |
> | PMTR-47438                     | R7x              |
> | PMTR-47453                     | R7x              |
> | Management High Availability                     ||
> | PMTR-14327                     | R80.20.M1        |
> | PMTR-47624                     | R80.10           |
> | PMTR-15291                     | R80              |
> | PMTR-47159                     | R80              |
> | Multi-Domain Management                          ||
> | PMTR-79917                     | R81              |
> | PMTR-60051                     | R81              |
> | PMTR-60201                     | R81              |
> | PMTR-60854                     | R81              |
> | PMTR-60856                     | R81              |
> | PMTR-60855                     | R81              |
> | PMTR-60853                     | R81              |
> | PMTR-60852                     | R81              |
> | PMTR-17303                     | R80.20           |
> | PMTR-19623                     | R80.20           |
> | PMTR-15294                     | R80.20.M1        |
> | PMTR-14479, PMTR-48566         | R80.20.M1        |
> | PMTR-12257                     | R80.20.M1        |
> | PMTR-47629                     | R80.10           |
> | PMTR-47631                     | R80.10           |
> | PMTR-47778                     | R80.10           |
> | PMTR-47638                     | R80.10           |
> | PMTR-47642                     | R80.10           |
> | PMTR-47173                     | R80              |
> | PMTR-47546                     | R80              |
> | PMTR-47177                     | R80              |
> | PMTR-47548                     | R80              |
> | PMTR-47551                     | R7x              |
> | SmartConsole / Management Console                ||
> | PMTR-58954                     | R81              |
> | PMTR-60476                     | R81              |
> | PMTR-58838                     | R81              |
> | PMTR-60910                     | R81              |
> | PMTR-59400                     | R81              |
> | -                              | R81              |
> | -                              | R81              |
> | PRHF-11063                     | R81              |
> | PMTR-78482                     | R81              |
> | PMTR-82157                     | R80.40           |
> | PMTR-47434                     | R80.40           |
> | PMTR-42956                     | R80.40           |
> | PMTR-44804                     | R80.40           |
> | PMTR-39807                     | R80.40           |
> | PMTR-32873                     | R80.40           |
> | PMTR-48072                     | R80.40           |
> | PMTR-44457                     | R80.40           |
> | PMTR-45924                     | R80.40           |
> | PMTR-45567                     | R80.40           |
> | PMTR-38804                     | R80.40           |
> | PMTR-32595                     | R80.30           |
> | PMTR-27705                     | R80.30           |
> | PMTR-31193                     | R80.30           |
> | PMTR-25063                     | R80.20.M2        |
> | PMTR-65106                     | R80.20           |
> | PMTR-39387                     | R80.20           |
> | PMTR-24110                     | R80.20           |
> | PMTR-12439                     | R80.20           |
> | PMTR-20287, TP-1939            | R80.20.M1        |
> | PMTR-42889                     | R80.10           |
> | PMTR-50263                     | R80.10           |
> | PMTR-42458                     | R80.10           |
> | PMTR-40848                     | R80.10           |
> | PMTR-47652                     | R80.10           |
> | PMTR-23836, PMTR-23835         | R80.10           |
> | PMTR-45007                     | R80.10           |
> | CIS-68                         | R80.10           |
> | PMTR-34983                     | R80.10           |
> | PMTR-47646                     | R80.10           |
> | PMTR-47650                     | R80.10           |
> | PMTR-47654                     | R80.10           |
> | PMTR-47658                     | R80.10           |
> | PMTR-36940                     | R80.10           |
> | PMTR-47666                     | R80.10           |
> | -                              | R80              |
> | MB-933                         | R80              |
> | PMTR-70637                     | R80              |
> | PMTR-66532                     | R80              |
> | PMTR-57122                     | R80              |
> | PMTR-48835                     | R80              |
> | PMTR-47553                     | R80              |
> | PMTR-47465                     | R7x              |
> | Compliance                                       ||
> | PMTR-9124                      | R80.20.M1        |
> | PMTR-47756                     | R80.10           |
> | 02449324, 02478559, PMTR-47761 | R80.10           |
> | PMTR-47592                     | R80              |
> | PMTR-47237                     | R80              |
> | PMTR-47239                     | R80              |
> | Logging / SmartLog / SmartView                   ||
> | PMTR-67490                     | R81              |
> | PMTR-54949                     | R81              |
> | PMTR-44559                     | R80.40           |
> | PMTR-48225                     | R80.40           |
> | PMTR-34649, PMTR-42613         | R80.40           |
> | PMTR-45323                     | R80.20.M2        |
> | PMTR-22189                     | R80.20           |
> | PMTR-22007                     | R80.20           |
> | PMTR-12100                     | R80.20.M1        |
> | PMTR-12635                     | R80.20.M1        |
> | PMTR-44569                     | R80.10           |
> | PMTR-47696                     | R80.10           |
> | PMTR-47706                     | R80.10           |
> | PMTR-47694                     | R80.10           |
> | PMTR-47699                     | R80.10           |
> | PMTR-47708                     | R80.10           |
> | PMTR-47587                     | R80              |
> | PMTR-47212                     | R80              |
> | PMTR-47586                     | R80              |
> | PMTR-47589                     | R7x              |
> | PMTR-47558                     | R7x              |
> | SmartEvent                                       ||
> | PMTR-50435                     | R81              |
> | PMTR-60038                     | R81              |
> | PMTR-47608                     | R80.40           |
> | PMTR-47989, PMTR-45259         | R80.40           |
> | PMTR-71408                     | R80.20           |
> | PMTR-21615                     | R80.20           |
> | PMTR-5701                      | R80.20.M1        |
> | PMTR-47715                     | R80.10           |
> | PMTR-47721                     | R80.10           |
> | PMTR-47227                     | R80              |
> | PMTR-47215                     | R80              |
> | PMTR-47559                     | R80              |
> | MPTT-265                       | R80              |
> | SmartProvisioning                                ||
> | PMTR-53925                     | R81              |
> | PMTR-56630                     | R81              |
> | PMTR-49235                     | R81              |
> | PMTR-46217, PMTR-46259         | R80.40           |
> | PMTR-48496                     | R80.40           |
> | PMTR-45475                     | R80.40           |
> | PMTR-49044                     | R80.40           |
> | PMTR-1568                      | R80.20.M1        |
> | PMTR-3724                      | R80.20.M1        |
> | PMTR-15599                     | R80.20.M1        |
> | PMTR-70744                     | R80.10           |
> | PMTR-8209                      | R7x              |

> {#ManagementTable}

*** ** * ** ***

Access Control Mobile Access / Content Awareness / DLP
>
> Enter the string to filter the below table:
>
> {#Mobile Access}{#Content Awareness}{#DLP}
>
> |------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Found in version |
> | Mobile Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-59234, PMTR-58638 | SmartView shows "*Error in disconnecting user* " with the description "*SNX connection failed*" every time the user opens the main page of Mobile Access portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81              |
> | PMTR-41608             | Error: "*Failed to generate RADIUS auth request*" when a Mobile Access user browses to a resource that requires authentication.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-70                | If you use Outlook Anywhere application with Mobile Access Reverse Proxy, and then want to disable Outlook Anywhere or Reverse Proxy, perform: 1. Delete Outlook Anywhere rule from reverse proxy. 2. Run "*cvpnrestart --with-pinger* " to close all Outlook Anywhere open connections. If you do not perform step 2, open connections of Outlook Anywhere will not be closed and users can still work with it.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.10           |
> | PMTR-47748             | When users are connected to the Mobile Access Gateway with SSL Network Extender in Application Mode, Downloaded-from-Gateway applications do not work inside Endpoint Security On Demand Secure Workspace.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.10           |
> | PMTR-47782             | After upgrading a Standalone (Management and Gateway) or VSX deployment with Mobile Access blade enabled, the "*Allow Dynamic ID for mobile devices* " option might be enabled by default, even if Dynamic ID was not configured prior to the upgrade. * If you do not want Dynamic ID authentication for Capsule Workspace users, disable it in: Gateway Properties -\> Mobile Access -\> Authentication -\> Compatibility with Older clients -\> Settings -\> Capsule Workspace section -\> clear Enable DynamicID. For VSX, this configuration is done per Virtual System.                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.10           |
> | PMTR-47499             | When Mobile Access is included in the Unified Access Policy, in Mobile Access Authorization logs -\> Log Details -\> Matched Rules, the Mobile Access Application name and Category do not show.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R7x              |
> | Content Awareness                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
> | PMTR-17156             | The following apply to the "Archive File" Data Type: The Content Awareness blade inspects the "Archive File" Data Type. The "Archive File" Data Type is extracted, and its inner files are separately inspected together with the Data Type. Therefore, during the policy configuration, administrator has to pay attention when using the "Archive File" Data Type in a Compound/Group Data Type and in an Inline layer parent rule. * Using a Compound/Group of "Archive File" with, for example, "PCI - Credit Card Numbers", does not match the archive that contains a file with the credit card numbers. You can use a specific File Type with "PCI - Credit Card Numbers" in this rule. * Using the "Archive File" in a rule that leads to Inline Layer does not match the Data Type inside that layer. You can use a specific File Type in this rule. * If the "Archive File" is located above other Data Types, the lower rule can be matched for some of the inner files, in addition to the rule that contains the "Archive File". | R80.20           |
> | PMTR-47670             | Binary Certificate *\*.cer* files are not properly matched to the 'Certificates and Private Keys' Data Type.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.10           |
> | PMTR-47675             | Content Awareness supports HTTP, HTTPS, SMTP and FTP protocols on any ports and it is fully integrated with the Access Control unified rule base. Traffic over QUIC and WebSocket is not inspected. However, it is possible to use 'Quic protocol' / 'WebSocket protocol' in a new Application rule to either block or allow this traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.10           |
> | PMTR-47785             | Content Awareness supports more than 60 character sets for text files, including Japanese, Korean, Greek, and Arabic. If the inspected traffic does not include a supported character set, Content Awareness uses UTF-8 for decoding. To see the list of supported charsets, and to learn how to change the default charset, see [sk116155](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116155).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.10           |
> | PMTR-47678             | Content Awareness supports Data Types based on file name. In specific HTTP traffic where the file name is not part of the URL or content-disposition header, the file name may be incorrect.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.10           |
> | DLP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
> | PMTR-47691             | DLP can apply visible or hidden Watermark (for forensic tracking) to Office Open XML formats (DOCX, PPTX and XLSX) as a rule action in a DLP rule base. Refer to [sk117413](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117413) if DLP Watermark is used.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.10           |

> {#AccessTable}

*** ** * ** ***

Threat Prevention
> {#Anti-Malware}{#IPS}
>
> |------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                 | Found in version |
> | Threat Prevention                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-73043 | "*Unauthorized: Access is denied due to invalid credentials (401)*" error in SmartConsole when clicking "Test Connectivity" in a custom IoC feed object.                                                                                                                                                                    | R81              |
> | PMTR-42100 | SHA-1 and SHA-256 Indicators Of Compromise (IOC) are only supported with Gateway version R80.40 and higher.                                                                                                                                                                                                                 | R80.40           |
> | PMTR-39388 | In some scenarios, during a file download, Packet Captures do not appear in Security gateway logs when the Strict-Hold setting is enabled.                                                                                                                                                                                  | R80.40           |
> | PMTR-50420 | FTP inspection with the Anti-Virus, Threat Emulation, or Content Awareness blade is not supported when Security Gateway works in Monitor Mode (SPAN port).                                                                                                                                                                  | R80.30           |
> | PMTR-19839 | CRL validation is not supported in pure IPv6 environments (when IPv4 addresses are not configured on the Security Gateway's interfaces).                                                                                                                                                                                    | R80.20           |
> | PMTR-43623 | In some cases, Packet Captures do not appear in Security Gateway logs (from Anti-Virus, Anti-Bot, and IPS blades): * When detection is done by RAD cloud (not using the RAD cache on the Security Gateway) for Reputation and MD5 * When detection is done by the DeepScan engine * When connections undergo SSL encryption | R80.10           |
> | PMTR-47684 | On pre-R80.10 gateways managed by R80.x Security Management server, Access Roles and CloudGuard are not supported in all Threat Prevention and IPS rules on the gateway. This limitation does not apply to R80.x gateways.                                                                                                  | R80.10           |
> | IPS                                                                                                                                                                                                                                                                                                                                                       |||
> | PMTR-47471 | "*Internal error occured* " message may be displayed when trying to assign/reassign a Global Configuration at the same time that an IPS update is running on a local Domain. * **To resolve**: First run the IPS update on the local Domain. Then assign/reassign the Global configuration.                                 | R7x              |

*** ** * ** ***

Endpoint Security (SmartEndpoint)
> {#Endpoint Security}
>
> |------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                       | Found in version |
> | Endpoint Security (SmartEndpoint)                                                                                                                                                                                                                                                               |||
> | PMTR-62510 | When you create a new Active Director Scanner in the Endpoint Server Web Management Portal, you cannot scan user certificates from the Active Directory.                                                                                                          | R81              |
> | PMTR-11057 | "*An internal server fault has occured* " server error is shown when logging in to the SmartEndpoint GUI client with a custom administrator created in SmartConsole with the name "*endpoint* ". * **To resolve**: Create an administrator with a different name. | R80.20.M1        |

*** ** * ** ***

<br />

Check Point Appliances Small Office Appliances / Maestro and Scalable Chassis
> {#Small Office Appliances}{#Small Office Appliances}
>
> |-----------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                    | Description                                                                                                                                                                                                                                                                                                                                                                                        | Found in version |
> | Small Office Appliances                                                                                                                                                                                                                                                                                                                                                                                                                     |||
> | PMTR-47300, SMB-11103 | When trying to configure a 1400 appliance with firmware for a 1500 appliance and vice versa, a policy installation error message appears.                                                                                                                                                                                                                                                          | R80.40           |
> | PMTR-3327             | After upgrade, you must install Access Policy before installing Threat Prevention Policy. Otherwise, the Threat Prevention Policy installation may fail.                                                                                                                                                                                                                                           | R80.20.M1        |
> | PMTR-47765            | In Small Office appliance policy installation, services that are manually configured with INSPECT code including the definition "*CALL_XLATE_FOLD_FUNC (...* " will cause a policy installation failure. * **To resolve**: Remove the "*_FUNC* " from the definition and use "*CALL_XLATE_FOLD (...*"                                                                                              | R80.10           |
> | PMTR-47518            | "*Commit function failed* " error on policy installation failure on 1100 series appliance. Refer to [sk105217](http://supportcontent.checkpoint.com/solutions?id=sk105217).                                                                                                                                                                                                                        | R7x              |
> | PMTR-47520            | "*SIC error*" status might occur when the gateway object is defined in a "Management first" scenario before it is deployed, but the device's IP address is already accessible. The Security Management tries to create SIC with the gateway's IP address. Instead of the policy ending in a "waiting for first connection" status, an error message states the SIC status must be rectified first. | R7x              |
> | Maestro and Scalable Chassis                                                                                                                                                                                                                                                                                                                                                                                                                |||
> | For the list of limitations and unsupported features, refer to [sk148074](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk148074).                                                                                                                                                                                                                                              |||

*** ** * ** ***

CloudGuard Controller Server / Enforcement / Monitoring / Nuage Networks / VMware NSX and vCenter / Cisco APIC / Cisco ISE / Public Cloud
>
> Enter the string to filter the below table:
>
> {#CloudGuard Controller}
>
> |------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | Found in version |
> | CloudGuard Controller                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | CloudGuard Controller - General Limitations                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
> | PMTR-60092 | SmartConsole \> "Menu" \> "Verify Access Control Policy" fails when there are Data Center objects in rules. The Verify Policy window shows: `Status: Verification of policy '<Name of Policy>' completed with errors` `Details: Error: Invalid network object <Name of Object> in Rule X` **Note:** Policy installation succeeds, only policy verification fails.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81              |
> | PMTR-69263 | Policy Verification fails in this specific scenario: 1. There are two specific rules in the policy - one below the other (not necessarily adjacent) 2. The lower rule of the two: Contains one or more Data Center objects in the Source or Destination column 3. The upper rule of the two: 1. Contains the "Negate" condition in the same column where the Data Center objects are used in the lower rule 2. Contains the same objects in the "Services \& Applications" column as the lower rule                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.40           |
> | PRJ-8570   | The Management API *add-data-center-server* for vCenter Data Center uses an optional parameter "*unsafe-auto-accept* " to allow usage of unsafe certificates. Its default value is set to *false* for not allowing unsafe certificates. **To avoid unexpected behavior** , explicitly use "*unsafe-auto-accept=false*" when using the Management API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | VSECC-589  | Changes in connection properties (such as credentials or URL) of existing Data Center Servers will take effect (e.g., importing objects, updating objects updates, etc.) only after policy is installed on all the Security Gateways that have Data Center Objects from this Data Center Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20           |
> | VSECC-1059 | Cluster objects (ClusterXL and 3rd party Cluster with the exception of CloudGuard for NSX) must be configured with reachable VIP as the main Cluster IP address to receive updates on Data Center imported objects.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.20           |
> | PMTR-3442  | Connections to/from Data Center Objects that appear for the first time in a policy package pushed to the Security gateway will not be re-matched even if the rematch connection option was chosen enabled in the Security Gateway policy. Connections involving the Data Center Objects that were included in previous policy installations on the Security Gateway are re-matched.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.20           |
> | CloudGuard Controller - Security Policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | VSECC-875  | * Data Center Objects in a Network Group are only supported in Access Control policy. * A policy that contains a Network Group with Data Center Objects can be installed only on Security Gateways R80.10 and above.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.40           |
> | VSECC-1066 | Policy Verification for overlapping, hiding or contradicting rules that include Data Center Objects is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.20           |
> | VSECC-1063 | CloudGuard Objects (Data Center Servers and Data Center Objects) are not supported in Global Domain.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.20           |
> | VSECC-1062 | Data Center Objects are not supported in Threat Prevention Exceptions that are installed on R77.20 and R77.30 Security Gateways (R80.x SmartConsole -\> SECURITY POLICIES App -\> Threat Prevention section -\> Exceptions).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.20           |
> | CloudGuard Controller - CloudGuard Objects Naming                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | VSECC-1064 | * Non-ASCII characters (non-English languages) in 'Data Center Server' properties (i.e., user, password and shared secret fields) are not supported. (If an object name contains one of the above characters, enforcement will not work.) * If Data Center Object's name includes Non-ASCII characters (non-English languages), enforcement will work, but its name might not be displayed properly in Security Logs and Events.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20           |
> | VSECC-1065 | If Data Center Object name contains the following characters in its name: * "{" - opening curly bracket * "}" - closing curly bracket * "\[" - opening square bracket * "\]" - closing square bracket * "\<" - less than * "\>" - greater than Then, the Data Center Object name will appear in SmartLog with "_", instead of of each of the above characters. For example: *{Name1}* will appear as *_Name1_*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.20           |
> | CloudGuard Controller Server                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | VSECC-1067 | A policy that contains Data Center Objects is not enforced immediately after the policy installation. It takes time for the CloudGuard Controller to update the Security Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.20           |
> | VSECC-1068 | In a Multi-Domain Security Management Server environment, VSX Gateway / VSX Cluster and all Virtual Systems that enforce a policy with Data Center Objects, must reside on the same Domain Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20           |
> | VSECC-1069 | For MDS HA managing a VSX gateway, a domain server must be deployed on all MDS servers that manage the VSX gateway installed with imported Data Center Objects. Note: This instruction applies to the VSX object. This is not mandatory for the virtual systems.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20           |
> | VSECC-1070 | VS Cluster first policy installation should not include Data Center Objects. **Note:** If this cannot be achieved, a full-sync must be run on the cluster by running the following on the standby member: 1. *fw ctl setsync off* 2. *fw ctl setsync start*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.20           |
> | CloudGuard Controller Enforcement                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | VSECC-1071 | If a Security Gateway works with CloudGuard Controller and other Identity Sources, there must not be IP addresses belonging to Data Center Objects also associated with Machines in other Identity Sources. Such overlapping can result in disassociation of the IP addresses from either the Data Center Object, or Access Roles with such Machines, and improper Security Policy enforcement.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.20           |
> | CloudGuard Controller Monitoring                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | VSECC-422  | After executing these commands, reboot, *cprestart* , and *cloudguard off* , Data Centers that have no imported objects, will not automatically show in the Data Center table. To see the Data Centers in the table, open each Data Center individually in SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.20           |
> | VSECC-1072 | Data Centers that have no imported objects, will not appear in the Data Center table, after the *cloudguard off* command is run.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20           |
> | VSECC-346  | Problems in Data Center will not always change the status of the Security Management server in SmartConsole. * **To resolve**: Open the Device \& License information window to see the real status and update the status in SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80.20           |
> | CloudGuard Controller - Nuage Networks                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | VSECC-1073 | Virtual IPs and Floating IPs are currently not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.20           |
> | CloudGuard Controller - VMware NSX and vCenter                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
> | VSECC-1075 | VMware NSX Object - IP Set Objects with ranges or CIDR block notations are not supported. IP Set Objects representing one, or more, individual IP address/es are supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.20           |
> | VSECC-1076 | Official VMware Tools must be installed on a VM in order for CloudGuard Controller to successfully pool IP addresses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.20           |
> | CloudGuard Controller - Cisco APIC                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
> | VSECC-1085 | Cisco APIC versions lower than 2.1: The Cisco ACI fabric does not age out individual endpoint IP address mappings, as long as one of the IP addresses responds to keep-alive ARP Requests from the fabric. As a result, these stale IP addresses will also be learned by the CloudGuard Controller.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.20           |
> | VSECC-1086 | Supported fabric size: The total amount of all the following objects must not exceed 100,000: * Tenants * Application Profiles * EPGs * IP addresses                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.20           |
> | VSECC-1087 | APIC HTTP URLs, which redirect to HTTPS, are not supported. Use either HTTPS URLs directly, or HTTP without redirection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.20           |
> | VSECC-1089 | When multiple APIC URLs are specified, the connectivity test will succeed, as long as one of the URLs connects. There is no requirement for initial verification for all the URLs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20           |
> | VSECC-1090 | On failure to connect to all the given APIC URLs, the returned error message is for the first unsuccessful URL.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.20           |
> | VSECC-1091 | Changes to privileges of the APIC user that was used to create the Data Center Object, are not reflected during an active login session. For example, if a new security domain is added to the user, which allows him to see a new tenant, this will not be visible to the APIC scanner. * **To resolve**: Run the *vsec_controller_stop* command on the CloudGuard Controller to restart the CloudGuard Controller services and force a new login.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.20           |
> | VSECC-1092 | If an object imported from Cisco APIC is deleted on the APIC, and then created again, the object must be re-imported into Check Point Policy. Enforcement will work properly once the object has been recreated in APIC, however the re-import is required to maintain updates for the object in the Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20           |
> | VSECC-1093 | Only the following TLS cipher suites are supported for APIC HTTPS connectivity: |--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | * TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA * TLS_DHE_DSS_WITH_AES_128_CBC_SHA * TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 * TLS_DHE_DSS_WITH_AES_256_CBC_SHA * TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 * TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA * TLS_DHE_RSA_WITH_AES_128_CBC_SHA * TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 * TLS_DHE_RSA_WITH_AES_256_CBC_SHA * TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 * TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA * TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA * TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 * TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA * TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 * TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA * TLS_ECDH_RSA_WITH_AES_128_CBC_SHA * TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 | * TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 * TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA * TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 * TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA * TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA * TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 * TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA * TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 * TLS_EMPTY_RENEGOTIATION_INFO_SCSV * TLS_RSA_WITH_3DES_EDE_CBC_SHA * TLS_RSA_WITH_AES_128_CBC_SHA * TLS_RSA_WITH_AES_128_CBC_SHA256 * TLS_RSA_WITH_AES_256_CBC_SHA * TLS_RSA_WITH_AES_256_CBC_SHA256 * TLS_ECDH_RSA_WITH_AES_256_CBC_SHA * TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 * TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA * TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA | | R80.20           |
> | CloudGuard Controller - Cisco ISE                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | VSECC-1095 | Filtering IP-to-SGT mappings by SG name uses a wildcard ('\*SG_NAME\*') search, so incorrect IPs may be returned, in case two SGs have overlapping names (one is contained in the other).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.20           |
> | CloudGuard Controller - Public Cloud: Amazon Web Services, Microsoft Azure and Google Cloud Platform                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
> | VSECC-1096 | Logs for rules with Subnets, AWS Security Groups, Microsoft Azure Network Security Groups or VMware NSX Security Groups will contain only the IP address, and will not contain the instance name.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.20           |
> | VSECC-1097 | IPv6 information is not imported for Data Center Objects in Public Cloud. CloudGuard Gateways in Public Cloud **do not** support IPv6.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.20           |
> | VSECC-1098 | Data Center Tags: * Tags keys and values longer than 100 characters will be truncated to the first 100 characters and "..." will be padded to the end of the tag. * In Microsoft Azure, Tag keys are case-insensitive, whereas Tag values are case-sensitive. **In CloudGuard Controller, both Tag key and Tag value will be treated as case-sensitive.** Meaning, the same key/value in different cases will be shown on 2 separate lines in SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.20           |

> {#CloudGuardTable}

*** ** * ** ***

<br />

<br />

<br />

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
