> Source: [sk174966](https://support.checkpoint.com/results/sk/sk174966)

# sk174966 - Check Point Quantum R81.20 (Titan) Resolved Issues and Enhancements

| Property | Value |
|----------|-------|
| Solution ID | sk174966 |
| Date Created | 2021-08-09 |
| Last Modified | 2025-03-09 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R81.20, R81.20, R81.20 |
| OS | Gaia |

## Solution

### This article lists all new features and issues that have been resolved in Check Point Quantum R81.20 (Titan) Release.

* The R81.20 Release accumulates all fixes from previous releases, including fixes from

  |----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
  | * [**Jumbo Hotfix Accumulator for R81.10**](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm)**Take 79** * [**Jumbo Hotfix Accumulator for R81**](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm)**Take 74** * [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm)**Take 173** | * **[Jumbo Hotfix Accumulator for R80.30](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm) Take 254** * **[Jumbo Hotfix Accumulator for R80.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.20/Default.htm) Take 211** * **[Jumbo Hotfix Accumulator for R80.10](https://support.checkpoint.com/results/sk/sk116380) Take 298** |

* For more information about R81.20, see the [R81.20 (Titan) Release Notes](https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RN/Default.htm), [R81.20 (Titan) Home Page](https://support.checkpoint.com/results/sk/sk173903) and [R81.20 (Titan) Known Limitations](https://support.checkpoint.com/results/sk/sk174965).

* Visit [Check Point CheckMates Community](https://community.checkpoint.com) to ask questions or start a discussion and get our experts assistance.

*** ** * ** ***

**Installation and Upgrade \| Gaia OS \| License \| Security Management \| SmartConsole \| SmartProvisioning \| Compliance \|
Security Gateway \| IPS \| Threat Prevention \| Identity Awareness \| Cluster \| Routing \| VPN \| VSX \| CloudGuard Controller \| Scalable Platforms**  

List of Resolved issues, New Features and Enhancements in Quantum R81.20 (Titan) Release
----------------------------------------------------------------------------------------

<br />

Enter the string to filter the below table:

{#Installation and Upgrade}{#Gaia}{#License}{#Security Management}{#SmartConsole}{#SmartProvisioning}{#Compliance}{#Security Gateway}{#IPS}{#Threat Prevention}{#Identity Awareness}{#Cluster}{#Routing}{#VPN}{#VSX}{#CloudGuard Controller}{#Scalable Platforms}

|-----------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID                                | Symptoms                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| Installation and Upgrade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               ||
| PMTR-86519                        | Added ability to upgrade from R81.10 on LightSpeed Appliances when LightSpeed acceleration (Userspace PPAK) is enabled.                                                                                                                                                                                                                                                                                                                                                                             |
| VSECPC-1341                       | Added ability to perform an in-place upgrade to Security Management Server or Multi-Domain Security Management Server that runs in CloudGuard for Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), or any other cloud providers.                                                                                                                                                                                                                                            |
| PRHF-7325, PMTR-27422, PMTR-47257 | Clean install from USB device fails on Open Server because the installation process (anaconda) includes the USB installation media as part of the installation target. Refer to [sk100566](https://support.checkpoint.com/results/sk/sk100566).                                                                                                                                                                                                                                                     |
| Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||
| PMTR-71544                        | **Enhancement** : Changed SNMP custom trap name restrictions: * name can contain only letters, numbers and underscore "_" * name length is a maximum of 128 characters.                                                                                                                                                                                                                                                                                                                             |
| PMTR-73867                        | **Enhancement:** * When adding a new SNMP custom trap in Clish, when choosing the operator "Changed", the threshold will suggest auto-complete to "change" * When changing in Clish the operator of a custom trap to "Changed", the threshold will automatically change to "change"                                                                                                                                                                                                                 |
| PMTR-71547                        | **UPDATE:** The "`delete snmp traps polling-frequency`" command is deprecated and changed to "`set snmp traps polling-frequency default`".                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-47866                        | **UPDATE:** It is now possible for Security Gateway interface names include spaces.                                                                                                                                                                                                                                                                                                                                                                                                                 |
| PMTR-74256                        | Scheduled snapshots and backups can now be scheduled hourly (every hour of the day or in specific hour/s) or at intervals (every x minutes).                                                                                                                                                                                                                                                                                                                                                        |
| License                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||
| PMTR-83038                        | When selecting an SMB appliance in the SmartConsole License tab, SmartConsole shows the error "*Security Gateway not found* " or "*This action is not supported for Quantum Spark appliances with Gaia Embedded OS*".                                                                                                                                                                                                                                                                               |
| Quantum Security Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ||
| PMTR-73021                        | **Enhancement**: R81.20 Security Management Server can manage R81.10 Gaia Embedded appliances.                                                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-85292                        | **Enhancement** : Improved the flow of migration from a Standalone environment to a distributed environment located in Smart-1 Cloud or on-premises. Refer to [sk179444](https://support.checkpoint.com/results/sk/sk179444).                                                                                                                                                                                                                                                                       |
| PMTR-86409                        | **Enhancement** : Added the ability for Internal CA on a Management Server to create certificates with 3072-bit RSA keys - the root ICA certificate and SIC certificates. Refer to [sk96591](https://support.checkpoint.com/results/sk/sk96591).                                                                                                                                                                                                                                                    |
| PMTR-68323                        | SmartConsole shows the error "*Publish failed due to session validation errors. Resolve the errors shown in the validation pane and publish again.* " when publishing a session after editing more than one interface in a cluster object and clicking OK. However, no errors or messages appear in the Validation Pane.                                                                                                                                                                            |
| SmartConsole / Management Console                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| PMTR-83170                        | **Enhancement**: Added the option to open SmartConsole with the parameter file that opens the Identity Provider to authenticate without indicating the IP address or the Authentication method.                                                                                                                                                                                                                                                                                                     |
| PMTR-78883                        | **Enhancement**: SmartConsole will show a warning about deleted Data Center objects in the "Validation" tab.                                                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-79733                        | **UPDATE**: The location of the operation progress bar on the final page of the VSX Gateway creation wizard was changed.                                                                                                                                                                                                                                                                                                                                                                            |
| PMTR-69996                        | **UPDATE**: The "Apply" button in custom traps is changed to be "disabled" before changes and after applying the relevant changes.                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-32595                        | "*Take over failed*" error appears when canceling an administrator session takeover.                                                                                                                                                                                                                                                                                                                                                                                                                |
| PMTR-58954                        | Policy installation fails with "*This operation cannot be done when unpublished changes are present* " and the Changes Report window shows "*Error: Failed to get changes*".                                                                                                                                                                                                                                                                                                                        |
| PMTR-65106                        | In SmartConsole, the sorting in table columns with numeric values is alphabetical and not numerical.                                                                                                                                                                                                                                                                                                                                                                                                |
| PMTR-82536                        | In some scenarios, editing the Threat Profile without any change creates a duplication of the profile.                                                                                                                                                                                                                                                                                                                                                                                              |
| SmartProvisioning                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| PMTR-69874, PMTR-71387            | **NEW** : Added support for: * QoS blade in R80.20 Quantum Spark Appliances (15xx/1600/1800) LSM Profile. * "Pending" policy installation state specific to Quantum Spark Appliances on QoS policy installation on R80.20 Security Gateways (15xx/1600/1800).                                                                                                                                                                                                                                       |
| PMTR-53925                        | After you upgrade a Security Gateway (or Cluster) managed with SmartProvisioning, you must enable the SmartProvisioning again.                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-66989                        | In SmartProvisioning, the Push Policy operation fails on SmartLSM objects R81.10 and lower, in which the selected SmartLSM Security Profile has any of the Threat Prevention Software Blades enabled.                                                                                                                                                                                                                                                                                               |
| Compliance                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             ||
| PMTR-73605                        | **Enhancement** : Best Practices were improved: * Added New Best Practice to check if URL Filtering \& Application Control are enabled in Access Policy * URL Filtering \& Application Control Best Practices show "*N/A"* when URL Filtering \& Application Control disabled in Access Policy * Some IPS Best Practices moved to FireWall Best Practice                                                                                                                                            |
| PMTR-81675                        | **Enhancement** : Added new regulations: * ISO 27001:2013 * SAMA Cybersecurity framework                                                                                                                                                                                                                                                                                                                                                                                                            |
| Quantum Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               ||
| PMTR-61444                        | **Enhancement**: Added support for IPv6 static routes via a logical interface. Users can specify a logical interface as the next hop gateway for an IPv6 static route, on which matching traffic will be forwarded.                                                                                                                                                                                                                                                                                 |
| PMTR-74261                        | **Enhancement:** Added destination filtering to the "`show route bgp`" command and its derivatives. Examples: `show route bgp aspath destination 2.2.2.2` `show route bgp communities destination 2.2.2.2` `show route bgp detailed destination 2.2.2.2 `                                                                                                                                                                                                                                           |
| PMTR-83158                        | **Enhancement:** Added Support for Remote Access VPN group policies. Note: login options (authentication methods) are shared between all group policies.                                                                                                                                                                                                                                                                                                                                            |
| PMTR-86820                        | **UPDATE**: Decreased the default value of core dump files, which are created when the Security Gateway crashes.                                                                                                                                                                                                                                                                                                                                                                                    |
| PMTR-76105                        | SIP early media traffic does not perform NAT when the SIP invite is sent from the external network to the internal.                                                                                                                                                                                                                                                                                                                                                                                 |
| PRHF-66, PMTR-71578               | SAM rules generate large amount of "*fwsam_v1_filter: matched rule is not found* " messages. Refer to [sk105347](https://support.checkpoint.com/results/sk/sk105347).                                                                                                                                                                                                                                                                                                                               |
| IPS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| PMTR-61444                        | **Enhancement** : Starting from R81.20, IPS Update packages are stored in the new location: the */var/log/IPS* directory. Refer to [sk176665](https://support.checkpoint.com/results/sk/sk176665).                                                                                                                                                                                                                                                                                                  |
| Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      ||
| PMTR-74908                        | **Enhancement** : You can block or allow sites that the Check Point Cloud Service is unable to classify as Phishing or Benign. To block unclassified sites, run this command on the Security Gateway CLI: `zph att set inbrowser_block_unclassified_sites 1` To allow unclassified sites (default), run this command on the Security Gateway CLI: `zph att set inbrowser_block_unclassified_sites 0`                                                                                                |
| PMTR-73043                        | "*Unauthorized: Access is denied due to invalid credentials (401)* " error in SmartConsole when clicking "Test Connectivity" in a custom IoC feed object. Note - The button "Test Connectivity" was renamed to "Test Feed".                                                                                                                                                                                                                                                                         |
| PMTR-78046                        | Custom intelligence feeds failure logs can show misleading information regarding the failure root cause.                                                                                                                                                                                                                                                                                                                                                                                            |
| DP-7857                           | Installing policy immediately after the gateway is upgraded might fail if the Threat Prevention Policy is applicable.                                                                                                                                                                                                                                                                                                                                                                               |
| Identity Awareness                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| PMTR-82848                        | When accessing the "Radius Accounting Settings" screen under Gateway Properties \> Identity Awareness, the loading time might increase significantly if there are many hosts objects defined in the policy.                                                                                                                                                                                                                                                                                         |
| Cluster                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||
| PMTR-60458, PROV-2306             | Changing the ClusterXL mode to Load Sharing Multicast with the Management REST API is not supported.                                                                                                                                                                                                                                                                                                                                                                                                |
| PMTR-57258, PMTR-74818            | Connections do not survive failover in a ClusterXL configured in the Active/Standby Bridge mode. As a result, a cluster failover may take longer than it should.                                                                                                                                                                                                                                                                                                                                    |
| Routing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||
| PMTR-52550                        | **Enhancement:** Added commands to view policy-based routing information per individual action tables: "`show pbr table TABLENAME`" and "`show pbr rule PRIORITY`".                                                                                                                                                                                                                                                                                                                                 |
| PMTR-55424                        | **Enhancement:** Added IPv4/IPv6 address filtering to "`show bgp peers adj-rib-in/out`" command using "`af`" flag.                                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-4925                         | When advertising IPv4 routes over an IPv6 BGP session, one of the following should to be true: * Routemap is used to set the nexthop of the IPv4 routes * The interface used for the BGP session needs to have an IPv4 address; When advertising IPv6 routes over an IPv4 BGP session, one of the following should to be true: * Routemap is used to set the nexthop of the IPv6 routes; * The interface used for the BGP session needs to have an IPv6 address                                     |
| VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| PMTR-78188                        | **Enhancement:** Added more detailed information for SSL clients in "`vpn tu tlist`" command.                                                                                                                                                                                                                                                                                                                                                                                                       |
| PMTR-17565, PMTR-17557            | Client Setting "*Calculate IP based on topology* " breaks when using host. Refer to [sk120121](https://support.checkpoint.com/results/sk/sk120121).                                                                                                                                                                                                                                                                                                                                                 |
| VSX                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| PMTR-84467                        | **Enhancement** : Anti-Spoofing for virtual devices can now be configured via *vsx_provisioning_tool*.                                                                                                                                                                                                                                                                                                                                                                                              |
| PMTR-71236                        | In a rare scenario, after running the "*vsx_util reconfigure*" command or upgrading the VSX Gateway / VSX Cluster, a Virtual System might load the "InitialPolicy" instead of its regular policy.                                                                                                                                                                                                                                                                                                   |
| CloudGuard Controller                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| PRHF-20096, PMTR-78173            | **NEW** : Added support for CloudGuard Controller on Active/Active cluster (Geo cluster) in AWS. Refer to [sk175904](https://support.checkpoint.com/results/sk/sk175904).                                                                                                                                                                                                                                                                                                                           |
| VSECC-1075                        | **NEW**: Added support for VMware NSX Object - IP Set Objects with ranges or CIDR block notations.                                                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-69263                        | Policy Verification fails in this specific scenario: 1. There are two specific rules in the policy - one below the other (not necessarily adjacent) 2. The lower rule of the two: Contains one or more Data Center objects in the Source or Destination column 3. The upper rule of the two: 1. Contains the "Negate" condition in the same column where the Data Center objects are used in the lower rule 2. Contains the same objects in the "Services \& Applications" column as the lower rule |
| Scalable Platforms                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| PMTR-82967, MBS-14962             | **Enhancement** : The Maestro Orchestrator will read the IP address range for CIN interfaces from the *smodb.json* database.                                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-67805                        | **Enhancement:** Added support for user authentication with SAML in Maestro Security Groups for: * Remote Access VPN * Mobile Access * Identity Awareness                                                                                                                                                                                                                                                                                                                                           |
| PMTR-83089, MBS-14167             | The BMAC address on Scalable Chassis is not updated after moving an SGM from one slot to a different slot. (The issue applies to Security Gateway only, not to VSX.)                                                                                                                                                                                                                                                                                                                                |
| PMTR-74253                        | The `asg if` command fails displaying "*missing close-brace*" error details.                                                                                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-81748                        | Added support for the ICMP outgoing connections from non-SMO Security Group Members through the Security Group's "Mgmt" interface.                                                                                                                                                                                                                                                                                                                                                                  |

{#resolvedTable}

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
