> Source: [sk178604](https://support.checkpoint.com/results/sk/sk178604)

# sk178604 - Check Point R81.10.X for 1500, 1600, 1800, 1900, and 2000 appliance Known Limitations 

| Property | Value |
|----------|-------|
| Solution ID | sk178604 |
| Date Created | 2022-03-31 |
| Last Modified | 2026-07-08 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1575R, 1500, 1900, 2000, 1600, 1800, 1595R |

## Solution

This article provides a list of Supported Features, Unsupported Features, and Known Limitations, for Check Point R81.10.x versions on Spark Firewall Appliances. For R81.10.X Resolved Issues, see [sk181134](https://support.checkpoint.com/results/sk/sk181134).  

For the complete list of R82.00.X Known Limitations, refer to[sk183400](For%20the%20complete%20list%20of%20R82.00.X%20Known%20Limitations,%20refer%20to%20sk183400.).

![](https://sc1.checkpoint.com/uc/images/Information_icon1.gif)This is a live document that may be updated without special notice. We recommend that you register for our weekly updates in order to stay up to date. To register, go to **[UserCenter](https://usercenter.checkpoint.com/)** \> **ASSETS** / **INFO** \> **My Subscriptions**.

This article contains two sections:

* Supported and Unsupported Features
* Known Limitations

**Important Notes**:

* Embedded Gaia software inherits its code base from the R81.10 GA version of enterprise appliances. Therefore, although not specifically mentioned, the R81.10 Spark Firewall inherits all maintrain limitations (see [sk170418)](https://support.checkpoint.com/results/sk/sk170418).
* All Known Limitations with ID 010XXXX (not SMB-XXX) originate in R77.20 versions.
* For the complete list of R80.20.X Known Limitations, refer to [sk159772](https://support.checkpoint.com/results/sk/sk159772).

Supported and Unsupported Features {#SupportedFeatures}
-------------------------------------------------------

**Note** - All features available on a Locally Managed appliance are also available in the Spark Management App on the Infinity Portal (replacement for the old SMP portal).

Enter the string to filter this table:

{#PRODUCT_2}{#PRODUCT_2}{#PRODUCT_2}

|-----------------------------------------------------------------------------------------------------|----------------------------------------------|----------------------------|------------------------------------------------------------------------------------------------------------------------------|
| Blade / Feature                                                                                     | Locally Managed                              | Centrally Managed          | Comments                                                                                                                     |
| Unified Access                                                                                                                                                                                                                                                                                              ||||
| Access Rules                                                                                        | Yes                                          | Yes                        |                                                                                                                              |
| Application Control Blade                                                                           | Yes                                          | Yes                        |                                                                                                                              |
| URL Filtering Blade                                                                                 | Yes                                          | Yes                        |                                                                                                                              |
| Content Awareness                                                                                   | No                                           | No                         |                                                                                                                              |
| QoS                                                                                                 | Yes                                          | Yes                        |                                                                                                                              |
| Data Loss Prevention (DLP) Blade                                                                    | No                                           | No                         |                                                                                                                              |
| Geo Protection                                                                                      | Yes                                          | Yes                        |                                                                                                                              |
| Network Address Translation (NAT)                                                                   | Yes                                          | Yes                        |                                                                                                                              |
| HTTP/HTTPS proxy                                                                                    | No                                           | No                         |                                                                                                                              |
| UserCheck                                                                                           | Yes                                          | Yes                        | UserCheck client on endpoint computers is not supported                                                                      |
| Hotspot portal                                                                                      | Yes                                          | Yes                        |                                                                                                                              |
| Rule Hit Count                                                                                      | Yes                                          | Yes                        |                                                                                                                              |
| Domain Object                                                                                       | Yes                                          | Yes                        |                                                                                                                              |
| Time Objects                                                                                        | Yes                                          | Yes                        |                                                                                                                              |
| Updatable Objects                                                                                   | Yes                                          | Yes                        |                                                                                                                              |
| Suspicious Activity Monitoring (SAM) Rules                                                          | No                                           | No                         |                                                                                                                              |
| Rule Base Layers                                                                                    | No                                           | Yes                        |                                                                                                                              |
| Security Zones                                                                                      | No                                           | Yes                        |                                                                                                                              |
| Data Center objects                                                                                 | No                                           | Yes                        |                                                                                                                              |
| SmartAccess                                                                                         | Yes                                          | No                         |                                                                                                                              |
| SSL Inspection                                                                                                                                                                                                                                                                                              ||||
| Inbound HTTPS Inspection                                                                            | No                                           | Yes                        |                                                                                                                              |
| Probing                                                                                             | Yes                                          | Yes                        |                                                                                                                              |
| Categorization enabled with full SSL inspection                                                     | Yes                                          | Yes                        |                                                                                                                              |
| HTTPS layers                                                                                        | No                                           | Yes                        |                                                                                                                              |
| HTTP/2                                                                                              | Yes                                          | Yes                        |                                                                                                                              |
| SSL bypass by FQDN / Updatable Object                                                               | Yes                                          | Yes                        |                                                                                                                              |
| TLS 1.3                                                                                             | No                                           | No                         |                                                                                                                              |
| Identity Awareness                                                                                                                                                                                                                                                                                          ||||
| AD Query                                                                                            | Yes                                          | Yes                        |                                                                                                                              |
| Azure AD                                                                                            | Yes                                          | Yes                        |                                                                                                                              |
| RADIUS Accounting                                                                                   | No                                           | No                         |                                                                                                                              |
| Identity Collector                                                                                  | Yes                                          | Yes                        |                                                                                                                              |
| Identity Broker                                                                                     | No                                           | No                         |                                                                                                                              |
| IoT and SD-WAN                                                                                                                                                                                                                                                                                              ||||
|                                                                                                     | Locally Managed (WebUI and Spark Management) | Centrally Managed (Smart1) |                                                                                                                              |
| IoT Protect for Enterprise                                                                          | Not Applicable                               | Yes                        | Available from R81.10.05                                                                                                     |
| IoT Protect for SMBs                                                                                | Yes                                          | No                         | Available from R81.10.10 Not supported in Ruggedized appliances 1570R, 1575R, 1595R.                                         |
| SD-WAN for Enterprise                                                                               | Not Applicable                               | Yes                        |                                                                                                                              |
| SD-WAN for SMBs                                                                                     | Yes                                          | No                         | Available from R81.10.10 Supports application-based steering. No support for VPN overlay.                                    |
| VPN and Remote Access                                                                                                                                                                                                                                                                                       ||||
| Central VPN Gateway in Star VPN communities                                                         | Yes                                          | No                         | * In Locally Managed Mode, limited to serve 100 Satellite Gateways (starting from R81.10.10).                                |
| Satellite VPN Gateway in Star VPN communities                                                       | Yes                                          | Yes                        |                                                                                                                              |
| IPSec VPN Blade                                                                                     | Yes                                          | Yes                        |                                                                                                                              |
| Mobile Access Blade                                                                                 | Partial                                      | Partial                    | * Remote Access VPN clients are supported (Endpoint, SNX). * Mobile Access Web Portal is not supported.                      |
| VTI                                                                                                 | Yes                                          | Yes                        |                                                                                                                              |
| Traditional VPN Mode                                                                                | No                                           | No                         |                                                                                                                              |
| Secure Configuration Verification (SCV) and Desktop policy                                          | No                                           | No                         |                                                                                                                              |
| Multiple Entry Points (MEP)                                                                         | No                                           | Yes                        |                                                                                                                              |
| Multiple Entry Points (MEP) using Dead Peer Detection (DPD) with 3rd-party VPN peers                | No                                           | Yes                        |                                                                                                                              |
| VPN Link Selection                                                                                  | Yes                                          | Yes                        |                                                                                                                              |
| VPN Service-based link selection                                                                    | No                                           | Yes                        |                                                                                                                              |
| Remote Access VPN client multifactor authentication                                                 | Yes                                          | Yes                        | Email, SMS, and Google/MS Authenticator as second factor authentication                                                      |
| NAT-T support for Site-to-Site VPN                                                                  | Yes                                          | Yes                        |                                                                                                                              |
| VPN multicore performance with CoreXL                                                               | Yes                                          | Yes                        |                                                                                                                              |
| Different VPN encryption domains on a Security Gateway that is a member of multiple VPN communities | No                                           | Yes                        |                                                                                                                              |
| Machine certificate authentication                                                                  | No                                           | No                         |                                                                                                                              |
| Data Center objects                                                                                 | No                                           | Yes                        |                                                                                                                              |
| Multiple ciphers for external Gateways in a single VPN community                                    | No                                           | Yes                        |                                                                                                                              |
| Support for SHA-512                                                                                 | Yes                                          | Yes                        |                                                                                                                              |
| SAML for Remote Access VPN                                                                          | Yes                                          | Yes                        | Available starting in R81.10.15                                                                                              |
| Threat Prevention                                                                                                                                                                                                                                                                                           ||||
| Autonomous Threat Prevention                                                                        | Not Applicable                               | No                         |                                                                                                                              |
| IPS Blade                                                                                           | Yes                                          | Yes                        |                                                                                                                              |
| Anti-Bot Blade                                                                                      | Yes                                          | Yes                        |                                                                                                                              |
| Anti-Virus Blade                                                                                    | Yes                                          | Yes                        |                                                                                                                              |
| Traditional Anti-Virus Blade                                                                        | Yes                                          | Yes                        |                                                                                                                              |
| Threat Emulation Blade                                                                              | Yes                                          | Yes                        |                                                                                                                              |
| Threat Extraction Blade                                                                             | No                                           | No                         | Refer to [sk101553](https://support.checkpoint.com/results/sk/sk101553)                                                      |
| Anti-Spam and Email Security Blade                                                                  | Yes                                          | Yes                        |                                                                                                                              |
| Mail Transfer Agent (MTA) support for Threat Emulation                                              | No                                           | No                         |                                                                                                                              |
| IPS Packet Capture                                                                                  | No                                           | No                         |                                                                                                                              |
| Anti-Virus archive scanning                                                                         | No                                           | No                         |                                                                                                                              |
| Threat Emulation archive scanning                                                                   | No                                           | Yes                        | In Check Point Cloud only                                                                                                    |
| Threat Prevention Indicators of Compromise (IoC)                                                    | No                                           | Yes                        |                                                                                                                              |
| Anti-Virus for FTP traffic                                                                          | Yes                                          | Yes                        |                                                                                                                              |
| DNS tunneling protection                                                                            | Yes                                          | Yes                        |                                                                                                                              |
| IoC Feeds                                                                                           | Yes                                          | Yes                        | In Locally Managed, supported in CLI only.                                                                                   |
| Enhanced support for password-protected documents                                                   | No                                           | No                         |                                                                                                                              |
| New file types and protocols                                                                        | No                                           | No                         |                                                                                                                              |
| SSH inspection                                                                                      | No                                           | Yes                        |                                                                                                                              |
| Threat Prevention bypass by FQDN / Updatable Object                                                 | Yes                                          | Yes                        |                                                                                                                              |
| Management and Monitoring                                                                                                                                                                                                                                                                                   ||||
| Monitoring Blade                                                                                    | No                                           | No                         | Other monitoring solutions are available                                                                                     |
| Compliance Blade                                                                                    | No                                           | Yes                        | Supported for Management Server R82 and higher versions. See [sk181127](https://support.checkpoint.com/results/sk/sk181127). |
| SNMP                                                                                                | Yes                                          | Yes                        |                                                                                                                              |
| Central Deployment                                                                                  | No                                           | Yes                        | Supported in Management Server R81.20 and higher                                                                             |
| SmartUpdate                                                                                         | No                                           | Yes                        |                                                                                                                              |
| SmartProvisioning / SmartLSM                                                                        | No                                           | Yes                        |                                                                                                                              |
| CPView                                                                                              | Yes                                          | Yes                        |                                                                                                                              |
| Skyline ([sk178566](https://support.checkpoint.com/results/sk/sk178566))                            | No                                           | No                         | For Early Availability only                                                                                                  |
| Infrastructure                                                                                                                                                                                                                                                                                              ||||
| SecureXL                                                                                            | Yes                                          | Yes                        |                                                                                                                              |
| CoreXL                                                                                              | Yes                                          | Yes                        | Limitation - Security Gateway automatically changes the number of CoreXL Firewall instances based on current traffic         |
| Smart Accel                                                                                         | Yes                                          | No                         |                                                                                                                              |
| Span Port                                                                                           | Yes                                          | Yes                        |                                                                                                                              |
| Monitor Mode                                                                                        | Yes                                          | Yes                        | Refer to [sk112572](https://support.checkpoint.com/results/sk/sk112572)                                                      |
| Netflow                                                                                             | Yes                                          | Yes                        | Configured only in Gaia Clish                                                                                                |
| Cluster                                                                                                                                                                                                                                                                                                     ||||
| ClusterXL High Availability mode                                                                    | Yes                                          | Yes                        |                                                                                                                              |
| ClusterXL Load Sharing mode                                                                         | No                                           | No                         |                                                                                                                              |
| VRRP cluster                                                                                        | No                                           | No                         |                                                                                                                              |
| 3rd-party cluster mode                                                                              | No                                           | No                         |                                                                                                                              |
| Connectivity Upgrade                                                                                | No                                           | No                         |                                                                                                                              |
| Connectivity                                                                                                                                                                                                                                                                                                ||||
| ISP Redundancy                                                                                      | Yes                                          | Yes                        |                                                                                                                              |
| Dynamic Routing                                                                                     | Yes                                          | Yes                        |                                                                                                                              |
| Policy-Based Routing (PBR)                                                                          | Yes                                          | Yes                        |                                                                                                                              |
| IPv6                                                                                                | Yes                                          | Yes                        |                                                                                                                              |
| IP Helper                                                                                           | No                                           | No                         |                                                                                                                              |
| DHCP Client                                                                                         | Yes                                          | Yes                        | For external interfaces                                                                                                      |
| DHCP Relay                                                                                          | Yes                                          | Yes                        | For internal interfaces                                                                                                      |
| DHCP Server                                                                                         | Yes                                          | Yes                        | For internal interfaces                                                                                                      |
| Jumbo Frames                                                                                        | Yes                                          | Yes                        | Early Availability level                                                                                                     |
| Bond / Link aggregated interface                                                                    | Yes                                          | Yes                        |                                                                                                                              |
| Alias / Secondary IP address                                                                        | Yes                                          | Yes                        |                                                                                                                              |
| OS                                                                                                                                                                                                                                                                                                          ||||
| OS Web Management Portal (Gaia Portal)                                                              | Yes                                          | Yes                        |                                                                                                                              |
| NTP Client                                                                                          | Yes                                          | Yes                        |                                                                                                                              |
| NTP Server                                                                                          | Yes                                          | Yes                        |                                                                                                                              |
| General                                                                                                                                                                                                                                                                                                     ||||
| IPv6 packet inspection                                                                              | Yes                                          | Yes                        | Refer to [sk174348](https://support.checkpoint.com/results/sk/sk174348) for limitations                                      |
| "All-In-One" license                                                                                | Yes                                          | Yes                        |                                                                                                                              |
| Evaluation license                                                                                  | Yes                                          | Yes                        |                                                                                                                              |
| MAC filtering on WiFi                                                                               | Yes                                          | Yes                        |                                                                                                                              |
| MAC filtering on LAN                                                                                | Yes                                          | Yes                        |                                                                                                                              |
| Anti-ARP spoofing                                                                                   | No                                           | No                         |                                                                                                                              |
| 802.1x based authentication                                                                         | Yes                                          | Yes                        |                                                                                                                              |
| 802.1w RSTP (Rapid Spanning Tree Protocol)                                                          | No                                           | No                         |                                                                                                                              |

{#FeaturesTable}

<br />

Known Limitations {#KnownLimitations}
-------------------------------------

The following limitations are known in R81.10 for Spark Firewall Appliances.

**Important Notes**:

* All previous limitations are relevant to the following version unless stated as resolved.
* **For Resolved Issues in R81.10.05 and higher versions, see [sk181134 - Check Point R81.10.X for 1500, 1600, and 1800 appliance Resolved Issues](https://support.checkpoint.com/results/sk/sk181134). If an issue in this table was resolved in a version lower than R81.10.05, the corresponding entry for that issue includes the version in which it was resolved.**

Enter the string to filter the below table:

|---------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------|
| ID                        | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Found In                                          |
| General                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| SMBGWY-17712              | After upgrade from R81.10.10 to R81.10.17, the gateway reverts back to the previous version. See [sk184034](https://support.checkpoint.com/results/sk/sk184034).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.17                                         |
| SMBGWY-11897              | The Interactive front panel view (2D), which was introduced in version R81.10.15, is not available on Centrally Managed or Ruggedized appliances. For more information, refer to the "Viewing System Information" section in the [R81.10.X Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Viewing-System-Information.htm?tocpath=The%20Home%20Tab%7C_____1) (refer to the table entry for the "Interactive front panel view").                                                                                                                                                                                                                                                                                                                                                                                                                                                                |                                                   |
| SMBGWY-13190              | For 15XX appliances, you can create a maximum of 10 Internet connections. On 1600, 1800, 1900, and 2000 appliances the maximum number is 20. This includes alias IP connections.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |                                                   |
| SMBGWY-5463               | To upgrade from R80.20.35 (or lower), you must follow this two-step upgrade path: 1. Upgrade from R80.20.35 (or lower) to R80.20.60: See [sk181079](https://support.checkpoint.com/results/sk/sk181079) \> "Upgrade from R80.20 Versions" section. 2. Upgrade to version R81.10.08 (or higher).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |                                                   |
| Gaia Embedded                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
| SMB-12119                 | A USB storage device used for clean installation of a new image on the 1500 series must be formatted with FAT32 file-system.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SMB-10086                 | Certain CLISH commands allow configuration of a DMZ interface even though there is no DMZ port on the appliance (relevant to V0 only).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
| SMBGWY-12678              | Disabling Threat Emulation inspection for an FTP connection from a specific IP address is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.10                                         |
| SMB-12009                 | In a rare scenario, malicious emails detected by IMAP inspection are not deleted from the client. Note: The malicious content is NOT downloaded.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMB-13721                 | SNORT rules are not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMB-9988                  | The "Import IPS protections" option fails if done via the WebUI. Offline updates can be installed via CLI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| SMB-12965                 | Anti-Spam is supported only when SMTP is outside the branch. In case SMTP is inside the branch, then it should work with port forwarding.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMB-10433                 | In Centrally Managed Gateways, you can not fetch the IPS package from Management. Workaround: To install the package: 1. Enter expert mode. 2. Copy $FWDIR/state/local/AMW/local.sd_updates to /storage partition. 3. Run: online_update_cmd -b IPS -o offlineUpdate -f storage/local.sd_updates                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| First Time Wizard Configuration                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
| SMBGWY-1388               | Policy installation in SmartConsole might fail with the "Error code 1-2000232" after a firmware upgrade from R81.10.00 to R81.10.05. To avoid the error, in the "Install Policy" window, right-click the Spark Firewall object and select the option "Do not use Install Policy Acceleration for all targets". This is only needed one time after a firmware upgrade.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.05                                         |
| SMBGWY-2442               | When configuring the First Time Configuration Wizard from the WAN interface, you cannot set the SIC One-Time-Password immediately after the FTW. To set it you need to refresh your web browser first.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| Hardware - General                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
| SMBGWY-21652              | External USB cellular modem is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.08                                         |
| SMB-14272                 | SFP-DSL is supported in Automatic mode only.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SMB-19564                 | Use of the EXT port on 1800 Spark Firewall appliance is currently not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.20                                            |
| SMB-14263                 | To disable the "Connect to the appliance by name from the Internet (DDNS)" option, it is necessary to enter the DDNS password again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| SMB-13955                 | These statistics are not available from the SFP DSL modem: * RS Code Words * RS Corrected Errors * Configured G.Inp * Vectoring * HEC Errors                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SMB-13373                 | In 1800 appliances: When working in manual mode on the DMZ port, only 100Mbps and 10Mbps link speed are supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| SMB-12254                 | 1570R, 1600 and 1800 WAN and DMZ ports support copper RJ45 and fiber interfaces. Each port can only use one interface. If both the copper and fiber of the same port are plugged in, the port may experience stability issues.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| Hardware - Flash                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
| -                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | -                                                 |
| Hardware - CPU                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| -                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | -                                                 |
| Hardware - WiFi                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
| 02340182                  | When more than one VAP is added to a local network switch or bridge, it cannot be unassigned Workaround: delete it and then recreate it.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.00                                         |
| Hardware - LTE                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| -                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | -                                                 |
| Hardware - USB                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| SMBGWY-20004              | SD cards and USB devices formatted as exFAT are not supported in the Bootloader.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMB-12119                 | A USB storage device used for clean installation of a new image on the 1500 series must be formatted with FAT32 file-system.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SecureXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
| SMB-17073                 | Internal traffic for which the source and destination are both bridges is dropped when SXL is enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2444               | The SecureXL penalty box mechanism is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| ClusterXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
| SMBGWY-19178              | The High Availability table only shows interface details if the interface state is "High Availability" for a static connection. No information is given for monitor or non-High Availability interfaces or for different connection types.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| SMBGWY-19141              | In a cluster, you cannot define only the Active member but must also select a peer type. "NONE" peer type is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMBGWY-19140              | Different VLAN IDs in a cluster are not supported as the VLAN ID is determined on the Active member and is synced to the other member.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-16966              | Single Routable IP (Scope local) is not supported in Smart-1 Cloud appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMBGWY-14689              | When setting the 'Cloud Services' to 'Off' (this is the default state) and then immediately to 'On', the Active cluster member will connect to the Cloud, while the Standby cluster member will remain disconnected. This may also lead to one of the cluster members changing its cluster state to 'DOWN' (because the Critical Device 'FSYNC' reports its state as 'problem'). Workaround: 1. On each Spark Firewall - disconnect it from Cloud Services: WebUI \> Home view \> Overview section \> Cloud Services page \> at the top, click Off \> at the bottom, click Save. 2. Wait for 2-3 minutes. 3. On the Active cluster member - connect it to Cloud Services: WebUI \> Home view \> Overview section \> Cloud Services page \> at the top, click On \> follow the wizard.                                                                                                                                                                                                | R81.10.15                                         |
| PRHF-30411                | In R80.20, it is not possible to set up two or more Spark Firewall clusters in the same VLAN when the clusters are managed by SmartSLM. The Cluster MAC Magic functionality is not supported for Spark Firewall clusters managed by SmartLSM. In R81.1.0X, Spark Firewall cluster members use unicast CCP by default so there is no need for Magic MAC. In addition, the parameter `fwha_mac_magic` can be set in R81.10.X if necessary. Resolved In: R81.10.X                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20.X                                          |
| SMBGWY-11710              | In a new Spark Firewall cluster, the Secondary cluster member does not become a full cluster member. See [sk182658](https://support.checkpoint.com/results/sk/sk182658). Resolved In: R81.10.15 Build 996003935                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.15                                         |
| SMBGWY-2804               | Cluster cannot be used with GRE.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.07                                         |
| SMBGWY-2468               | When configuring a cluster and setting DHCP on one of the cluster interfaces, a DHCP server might include the other cluster member's IP address in its available IP addresses range. Therefore, the DHCP server might serve this IP to another computer in the same network, which will cause connectivity issues. Workaround: Manually exclude the other cluster member's IP address from the range. Resolved In: R80.20                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMBGWY-2469               | Before configuring a local cluster, make sure that the sync interface is unassigned by checking the Device \> Local Network page in the WebUI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMBGWY-2470               | Cluster mode configuration of the gateway is supported from the WebUI only.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMBGWY-2471               | When configuring a cluster, you can only use a LAN interface as the Sync interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| SMBGWY-2472               | Configuring a Cluster Virtual IP address in a PPP interface is not supported, but the interface can still be monitored by ClusterXL.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| SMBGWY-2633               | When defining a local cluster with the "Strict" Firewall mode enabled, a manual internal rule must be defined in the WebUI to allow connectivity between the cluster members on the sync interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| SMBGWY-2474               | In Locally Managed small office appliances, initiate reboot after cluster reset.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| -                         | A cluster cannot be created when a switch is configured on network interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| -                         | If a bridge is configured on network interfaces, a cluster can only be created when the Spark Firewall appliance is Centrally Managed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| PMTR-23835                | When you create an SMB cluster using the Wizard mode, SmartConsole automatically assigns an incorrect IP "0.0.0.X" as the cluster main IP address. To resolve: The admin must first publish the new cluster object, then configure the correct IP address before enabling any blade. If the cluster is created via 'Classic' mode, there is no issue.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.10                                            |
| Networking - General                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |||
| SMBGWY-19112              | MAPe / IPv6 tunnels are not supported in a cluster, only on a single gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.00.00                                         |
| SMB-1674                  | In Locally Managed appliances, to change an existing cluster in pure IPv4 mode to dual stack mode, you should break and rebuild the cluster, as this is a major change in network configuration. Both members should be configured in IPv6 mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMB-19490                 | When configuring multiple internet connections in 'High Availability' mode, unable to access NATed services behind the standby internet connection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| SMB-17652                 | BFD monitoring is not supported for static routes on Spark Firewall appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-15419                 | Configuring a LAN port as internet connection is not supported with IPv6 internet connection types.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| VPNS2S-2220               | When you use the "Connection Monitoring" feature, you must specify a reachable server or the system will disconnect. If no reachable DNS server exists within the network, disable the "Connection Monitoring" feature.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| Networking - Bond                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
| SMB-14226                 | If an interface is a Bond slave, the Clish commands set interface \<Name of Interface\> state off and set interface \<Name of Interface\> down fail and this error message appears: "Could not set interface: Internal Error."                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMB-13639                 | Monitor mode can only be configured for LAN1, LAN2, LAN5, LAN6, and LAN7.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| Networking - Bridge                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-2477               | When the WAN Internet connection is configured as PPPoE, an Anti-Spoofing warning appears in SmartView Tracker. You can safely ignore the warning.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| SMBGWY-2478               | Bridge interfaces cannot be disabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| SMB-6597, SMB-6663        | When multiple Internet connections are configured on one physical interface in High Availability mode, and primary connection failover occurs without the main connection going down/restarting, traffic will continue to be routed for the previous primary connection for more than the routing cache lifetime (20 seconds) if the QoS blade is configured.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.00                                         |
| SMB-12567                 | Asymmetric-routing is not supported for SNMP traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| SMB-10543                 | Embedded Gaia appliances conform to the Maintrain bridge (L2) limitations listed in [sk101371](https://support.checkpoint.com/results/sk/sk101371)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| DNS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-2441               | We recommend that you configure DNS to resolve both internal and external domains. DNS that does not resolve external domains may impact gateway operations.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| Networking - Dynamic Routing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
| SMBGNG-19621              | Dynamic Routing for IPv6 is not supported in a locally managed cluster, only on single gateways. Dynamic Routing for IPv6 is supported for a centrally managed cluster.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| SMBGWY-13144, SMBGWY-9723 | Anti-Virus inspection of emails over the POP3 protocol is not supported in this scenario: 1. Locally Managed R81.10.X Spark Firewall. 2. A Bridge interface is configured. 3. VLAN interfaces are configured on the Bridge interface. 4. An internal email client is connected to one of these VLAN interfaces. <br /> Workaround (supported only for a single VLAN interface on the bridge interface) - The IP address of the Bridge interface and the IP address of the VLAN interface (where the email client connects) must be in the same subnet. See [sk182991](https://support.checkpoint.com/results/sk/sk182991).                                                                                                                                                                                                                                                                                                                                                           | R81.10.00 (Resolved in R82.00.10 Build 998002133) |
| SMBGWY-12240              | If you configure a routemap with the name X (example: "`bgpIn`") and a different routemap with X as its prefix followed by an "`-`" and some suffix (example: "`bgpIn-backup`"), the routemap with the name X multiplies. You will see this when you run the "`show routemaps`" and "`show router-configurations routemaps`" commands. The issue is cosmetic and does not affect performance or connectivity.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.15                                         |
| SMBGWY-7878               | OSPF is not supported on a GRE interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.08 JHF                                     |
| SMBGWY-1355               | In WebUI, the "Device" view \> section "Advanced Routing" \> page "OSPF" \> section "Interfaces" does not show VLAN interfaces. Workaround: To configure OSPF on VLAN interfaces, use Gaia Clish commands.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.05                                         |
| SMB-14228                 | The 1600/1800 appliances support up to 1000 routes of all types.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMBGWY-2481               | Policy-based routing rules are not enforced on POP3 traffic when the Anti-Virus or Anti-Spam blades are active and set to inspect POP3 traffic. Policy-based routing rules are also not enforced on SMTP traffic when inspecting outgoing SMTP traffic is configured.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| CLI                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-17555              | RADIUS users logged in to SSH receive "Role is not defined" error when attempting to access Clish commands after the initial session. Workaround: Disconnect from SSH and establish a new connection to restore proper Clish functionality.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.17 JHF                                     |
| SMBGWY-11353              | If in the Expert mode you use the command "`clish -c add administrator`" (to add a new administrator user) or use the command "`clish -c set administrator`" (to change an existing administrator user), and you specify the password using its hash, then in the password hash string you must escape each "`$`" character with two backward slash characters. Example: `[Expert@Hostname:0]# clish -c "add administrator permission remote-access username test3 password-hash \\$abc\\$def\\$ghi1234567890"`                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.15                                         |
| SMBGWY-10967              | On a Firefox browser, when you click the CLI shell button in the WebUI, a certificate warning appears.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.15                                         |
| SMBGWY-11889              | The CLI from the WebUI works only over SSH on the default port 22.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.15                                         |
| SMB-12375                 | Attempting to assign the pivot port of a switch to a bridge using the CLI fails, but does not display an error.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMBGWY-2482               | File related configuration (certificates, customized logo for portals) is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.00                                         |
| CPView                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
| SMB-16256                 | CPView is supported in Gaia Embedded appliances, but the History feature is not supported on the 1500 series.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.00                                         |
| HTTPS Inspection                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
| -                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| IPS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMB-9988, SMB-10104       | "Import IPS protections" option is not supported on the WebUI. Offline updates can be installed via CLI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.00                                         |
| SMBGWY-2484               | The IPS protection "Non compliant HTTP" drops a valid HTTP reply containing an empty zip file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMBGWY-2486               | Using autocomplete in CLISH after the parameter protection-name in IPS configuration takes several minutes to show all options.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-12874                 | On a Locally Managed Spark Firewall appliance, you can configure exceptions for the IPS protections listed below, even though they do not support Threat Prevention exceptions. Note - The protections are still enforced. * Ping of Death * SYN Attack * Sequence Verifier * Teardrop                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| Application Control                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-2487               | The Signature Tool for Custom Application Control and URL Filtering Applications is not supported for Locally Managed Small Office appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMBGWY-2488               | Using autocomplete in CLISH after the parameter application name in Application Control configuration takes several minutes to show all options.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMBGWY-2490               | In Locally Managed devices, it is not possible to configure Applications in policy base for incoming / VPN traffic. They can be configured using LAN as internet connections.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.00                                         |
| SMB-2558                  | Adding a CLI category name for Application Awareness/URL filtering or SSL inspection configuration results in "Failed to find the requested category-name" error when the name is more than one word. Use the category ID instead of the application name.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| Security                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
| SMBGWY-1291               | Smart Accel does not support IPv6                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.05                                         |
| Access Policy                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
| SMBGWY-9011               | The maximum number of Firewall Access Policy manual rules is 100.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.15                                         |
| SMB-19492                 | It is not supported to use these predefined objects in the Access Policy \> Firewall \> Policy: * Trusted Wireless Networks * Untrusted Wireless Networks                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.20 GA                                         |
| SMB-17498                 | A device object cannot be used in a network object group. Resolved in: R81.10.10 Build 996002906 (see [sk181134](https://support.checkpoint.com/results/sk/sk181134))                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| SMB-10398                 | FQDN objects are only supported in the destination column (not in the source). Resolved In: R80.20                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| SMBGWY-2491               | When creating a Firewall or NAT rule in CLI, the source/destination value must be a network object and not just an IP address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| NAT                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| -                         | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | -                                                 |
| User Check                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| SMBGWY-2492               | User Check client is not supported in either Centrally or Locally managed mode of appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.00                                         |
| SMBGWY-2493               | To search the security logs on the local web portal for a specific User Check incident ID, use this filter string "User Check Incident UID:" followed by the ID.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMBGWY-2494               | In Centrally Managed Small Office appliances, the User Check portal does not appear if the configuration for the main URL of the User Check portal under gateway settings is set to use the gateway's external IP address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| User / Identity Awareness                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
| -                         | If the same username is defined on AD and Radius, the Security Gateway tries to authenticate only with the AD Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| SMB-12189                 | Traffic is blocked if the User Awareness blade is turned off and Browser-Based Authentication is turned on. Resolved In: R80.20                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-16255                 | Identity Awareness Gateway as an Active Directory Proxy feature is not supported on 1500, 1600, and 1800 Spark Firewall Appliances. Resolved In: R81.10.00 for R81.20 management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMB-12516                 | LDAP connection is only supported on port 389.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMB-14519                 | * Identity Awareness supports authentication of AD users, user groups, organization units. In addition, you can define LDAP groups with more advanced filtering. * Identity Awareness does not support authentication of Primary Groups of user and computer accounts. By default, the Primary Groups are 'Domain Users' and 'Domain Computers.'                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMBGWY-2635               | Identity Agent is not supported on 1500, 1600, and 1800 Spark Firewall Appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| SMBGWY-2495               | On Locally Managed appliances, only a single DC is supported per AD server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| -                         | On a Locally Managed appliances, there is no Identity Awareness option to add Active Directory (AD) users/ Organization Units inside the source column in policy rules. There is an Identity Awareness option to add Active Directory (AD) groups, but not to add specific users. The Users tab on the left contains only internal users, which are not from Active Directory. See [sk105977](https://support.checkpoint.com/results/sk/sk105977).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |                                                   |
| SMBGWY-2486               | An AD Domain Controller used for authenticating users that is located in the external zone of a device using Hide-NAT is not supported. Workaround: Install another Domain Controller in the internal zone of the device.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMBGWY-2496               | In Centrally Managed appliances, these user identifications methods are not supported (even though they appear in SmartConsole): * RADIUS Accounting * Terminal Servers                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
|                           | Identity awareness AD query functionality is supported when the domain controller server is part of one of the internal networks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.00                                         |
| Administrators                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| SMBGWY-19502              | CPInfo and Dr. Spark logs are not supported by default for Read-only users, but may be turned on in the Advanced Settings.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.17                                         |
| VPN - General                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
| SMBGWY-8828               | When changing the configuration from the Locally Managed mode to the Centrally Managed mode and enabling the IPSec VPN Software Blade for the first time, it is necessary to: 1. In SmartConsole, install the Access Control policy. 2. Run the "`sfwd_restart`" command in the Expert mode or reboot the Spark Firewall.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.10                                         |
| SMB-9711                  | Locally Managed appliances do not support subordinate certificates. Resolved in R77.20.80 for \*.P12 files only. For .crt files, refer to [sk157413](https://support.checkpoint.com/results/sk/sk157413).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMB-13552                 | Tunnel test is supported only against fixed IP address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| SMB-10127                 | In the Logs \& Monitoring tab, the "Decrypt" action does not appear on some configurations (for example, PPPoE) but the functionality still works. Resolved In: R80.20                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2498               | Configuring VPN site to site or VPN RA with certificate-based authentication on a Locally Managed cluster is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMBGWY-2501               | In Locally Managed appliances, the parameter "vpn_force_nat_t" does not force NAT-T if the remote site is configured using a hostname.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2510               | In Centrally Managed appliances, the VPN overview page in SmartDashboard does not show tunnels from small office appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| VPN - Remote Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-21481              | Remote Access connections using Check Point Capsule client are supported using user name and password only. Connecting using a Personal Client Authentication Certificate is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMBGWY-21409              | VPN Remote Access with IKEv2 is only supported using the StrongSwan client.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.00.00                                         |
| SMBGWY-12831              | If you override VPN Remote Access 2FA settings for specific users, these changes take effect only if the global VPN Remote Access 2FA setting is enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.15                                         |
| SMBGWY-12300              | In Azure AD, authentication with SAML fails when you change the default port for Remote Access VPN. Workaround: Use the default port 443.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.15                                         |
| SMB-12802, SMBGWY-6940    | L2TP does not work when two-factor authentication is enabled. Note - In R81.10.00 and higher, the L2TP connection can work when 2FA is enabled, even though L2TP still does not support 2FA. To enable this, run in Gaia Clish: `set vpn remote-access advanced allow-older-clients true`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMB-12802, SMBGWY-6940    | VPN SNX client is not supported when Two-Factor Authentication is enabled. Note - In R81.10.00 and higher, the VPN SNX connection can work when 2FA is enabled, even though VPN SNX still does not support 2FA. To enable this, run in Gaia Clish: `set vpn remote-access advanced allow-older-clients true`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SMBGWY-2088               | DynamicID, a multi-factor authentication for VPN clients, is not supported in Centrally Managed mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.05                                         |
| SMB-14970                 | When office mode is disabled on Locally Managed 1500 appliances, you can configure a manual rule with VPN Remote Access, but the rule is not enforced.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMB-10431                 | During a cluster failover, connected Remote Access users may be disconnected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.00                                         |
| SMB-15262                 | Layer 2 Tunneling Protocol (L2TP) clients are disconnected after two hours when a non-Windows client is used. Workaround: Increase the renegotiation-interval time for Phase 2.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMBGWY-2506               | Remote Access SecurID authentication is not supported in Locally Managed mode of appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SMBGWY-2517               | When you connect to the appliance with Remote Access VPN, the appliance only uses the default internal certificate.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| 02115796                  | The "Route all traffic through gateway" option is not supported for SSL Network Extender clients.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.00                                         |
| -                         | Two-Factor Authentication using mobile access is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-11978                 | The Remote Access feature "Location Aware Connectivity" is not supported on Locally Managed Spark Firewall appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMB-9710                  | MEP is not supported in Remote Access VPN.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| SMB-12591                 | You cannot create a firewall rule where the source/destination is "VPN Remote Access."                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2502               | The WebUI Home \> Security Dashboard page shows the VPN Remote Access blade as turned "ON" only if the Gateway object in SmartDashboard is set with IPSec VPN and the gateway is part of the Remote Access community. When the object is defined but not part of the Remote Access community, the WebUI Home \> Security Dashboard page shows the VPN Remote Access blade as turned "OFF".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| VTI                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMB-10109                 | When changing the configuration of an existing VPN Tunnel interface (VTI) from numbered to unnumbered or vice versa, routes which contain the VTI interface as a destination must be redefined.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-12842                 | Route-based VPN (VTI) is not supported with policy based routing.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.00                                         |
| SMB-2668                  | When a VPN tunnel goes down, routes that use the associated VTI as a target (next hop) remain active. Therefore, you cannot use metric-based failover between routes to different VTIs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| SMBGWY-2500               | When using numbered VTI, the traffic on Rx and Tx in vpnt interfaces is shown as z.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| SMBGWY-2499               | Unnumbered VTIs can only be associated with external interfaces through the Internet connection definition. Other interface types are not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| VPN Site to Site                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
| SMBGWY-5109               | Cannot use Identity Collector over Site-to-Site VPN on Locally Managed Spark Firewall appliance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.05                                         |
| SMBGWY-3286               | VPN S2S with 5G does not work with CGNAT.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.07                                         |
| SMB-10115                 | In Locally Managed mode: When configuring a VPN tunnel with PSK/certificate authentication methods in IKEv2 mode, and a peer in the community is configured with dynamic IP, the tunnel fails to establish. Workaround: 1. Go to the VPN tab \> Site \> Encryption settings. 2. Select a specific encryption method instead of the default suites.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| -                         | Site-to-Site VPN is not supported with layer 2 (bridge) connection types.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMB-12173                 | VPN (Site-to-Site and Remote Access) is not supported when an Alias IP is assigned to one of the Gateway interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| SMBGWY-2503               | In Locally Managed appliances, VPN sites configured with the IKEv2 encryption method and "Default (Most compatible)" encryption settings only support peer sites configured with Diffie-Helman group 2. Workaround: Configure an encryption suite that matches the peer's configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.00                                         |
| SMBGWY-2504               | In Locally Managed appliances with a defined proxy, if a 3rd party external Trusted CA is used in a certificate, CRL validation does not work. Disable CRL validation for the CA or disable the proxy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2507               | In Locally Managed mode, when submitting a certificate signing request that contains alternative subject names, the resulting certificate contains only the DN as the subject and not the alternative names.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SMBGWY-2509               | When a VPN community includes dynamic IP addresses for remote sites (behind NAT or connection via hostname), only Diffie-Helman group 2 is supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00 **Resolved in R81.10.17**               |
| 01664759                  | When configuring the aggressive mode peer ID field for VPN remote sites in Locally Managed appliances, you can only enter alphanumeric characters and these special characters: _ - . @ \~ ! # % $                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| SMBGWY-2513               | When configuring DHCP relay on Centrally Managed appliances, if the DHCP server is in a VPN peer's encryption domain, the implied rule "Accept Dynamic Address modules' outgoing Internet connections" must be disabled in SmartDashboard for the DHCP requests to be sent encrypted. Workaround: Create manual rules that allow DHCP.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2514               | When using aggressive mode with user peer_id, the remote VPN peer has to be a mobile peer for authentication to succeed. Resolved In: R80.20.X                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMBGWY-2515               | In Locally Managed appliances, when defining a remote site using a custom encryption suite and IKEv2 is selected, multiple selection of Diffie-Helman groups may cause issues. Workaround: Choose the specific Diffie-Helman group that the remote site uses.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.00                                         |
| SMBGWY-2516               | When using Aggressive mode with peer ID in VPN site to site in Locally Managed appliances, the VPN Remote Access blade must be turned on (even if no users are defined with remote access privileges).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2518               | RIM configuration is not supported in this firmware. RIM functionality is usually needed in the center Gateways of a VPN star community. This image is primarily used in satellite Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| 01260760                  | In Locally Managed small office appliances, when a cluster failover happens, VPN Remote Access clients need to re-establish the connection. Also, a different certificate is seen when re-connecting.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| SMB-12201                 | Site to site directional VPN is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SMB-2689                  | The "New Certificate Request" feature that allows an external CA to sign the device's certificate does not include the defined Alternative Names in the request.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMB-1895                  | Locally Managed appliances cannot establish a VPN connection to a remote site that consists of multiple centrally managed hub VPN gateways in a MEP configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10.00                                         |
| 01663225                  | When configuring a remote site using a certificate and aggressive mode in VPN site to site in Locally Managed appliances, a peer ID string in aggressive mode must be configured. Resolved In: R80.20.X                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| VoIP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |||
| SMB-10136                 | In Locally Managed appliances, H.323 is not supported in the hide NAT configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| SMBGWY-12380              | External to internal calls do not work correctly in the SIP configuration, which involves external phones connecting to the internal PBX located behind the Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |                                                   |
| Anti-Bot                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
| SMBGWY-2519               | The Suspicious email outbreak engine in the Anti-Bot Software Blade is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| Anti-Virus                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| SMBGWY-9712               | In Centrally and Locally Managed appliances, when attempting to download from an internal FTP server (behind the gateway) with Anti-Virus (AV) enabled, the process may work inconsistently in active mode. Workaround: Switch to passive mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-19073                 | When an EICAR virus test-file (handled as a special case of AV detection) is downloaded, a push notification is not published with the "block" security log.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.05                                         |
| Anti-Spam                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
| -                         | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | -                                                 |
| IoC                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-4845               | Spark Firewall does not support IOC feeds parsing from custom CSV formats (refer to the format list in [sk132193](https://support.checkpoint.com/results/sk/sk132193)). If you attempt to use a custom CSV format, policy installation failure will occur.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| SMB-18691                 | R81.10.XX does not support MD5 indicators for local management.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SmartConsole / SmartDashboard                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
| SMBGWY-17942              | Spark Firewalls in SmartConsole show "NA" for SKU, Account ID, and other related licensing fields. This data can be fetched from the User Center but not through the Management to the gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-19675                 | In the Centrally Managed mode, when in SmartConsole "Manage \& Settings" view \> "Blades" page \> "Threat Prevention" section \> "Advanced Settings" \> "General" page \> "Check Point Online Web Service" section \> you configure the "Resource classification mode" to "Hold", by design the managed Spark Firewall appliances download 99% of a file over FTP and hold only the last packet before providing a verdict.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMB-18388                 | In Centrally Managed appliances, SmartConsole sometimes shows inaccurate license information for Software Blades such as "No License" or "About to Expire."                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMBGWY-2520               | The VPN Advanced option to perform an organized shutdown of tunnels upon gateway restart is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| SMBGWY-2521               | Install policy fails on Centrally Managed appliances when a rule contains an action set to User authentication.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMBGWY-2522               | The "Monitoring" blade (Real Time Monitoring) is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMB-3241                  | When a DMZ interface is used as a Local Network interface, the "Get Topology" action shows the DMZ interface as network type "Internal" instead of "DMZ." Workaround: Manually change the network type to "DMZ."                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SmartProvisioning                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
| SMB-1383                  | In Small Office appliances, Identity Sharing is not supported when managed through the SmartProvisioning LSM profile.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| SmartView Monitor                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
| SMBGWY-2525               | The SmartConsole "Device \& License Information" window shows incorrect information for the Centrally Managed Spark Firewall in these scenarios: * The Centrally Managed Spark Firewall is configured with a Dynamically Assigned IP Address (DAIP) * There is a NAT device between the Check Point Management Server and the Centrally Managed Spark Firewall To get to this window: 1. In SmartConsole, from the left navigation panel, click the "Gateways \& Servers" view. 2. Select the Spark Firewall object. 3. In the bottom pane, click the "Summary" tab. 4. At the bottom, click the link "Device \& License Information".                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SSL Inspection                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| SMBGWY-4897               | SSL inspection exception rules are not supported for pop3s traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20.60                                         |
| Logging and Monitoring                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
| SMBGWY-19104              | Traffic to the gateway IP address is dropped on the 1570R appliance. The logs show an invalid checksum, but there is no security impact.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.17                                         |
| SMB-13355                 | In Locally Managed appliances: Logs might be seen in the first few minutes after a policy change for the default outgoing rule even though the rule is configured not to generate logs. Workaround: Turn on the connection persistence flag in Advanced Settings (this keeps established connections when installing a new policy).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| SMBGWY-2673               | External Security Log Server cannot be configured when High Availability is turned on (not supported) on Locally Managed appliances                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10.00                                         |
| SMBGWY-2674               | Gaia Embedded appliances cannot send logs to more than one Security Management Server or Customer Log Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10.00                                         |
| SMB-1764                  | An external syslog server cannot be configured with an IPv6 address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.20                                            |
| SSL Network Extender                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |||
| 01634523                  | The SNX command line for Linux (script that can be download from the SNX portal using the "Download command line SNX for Linux") fails on Small Office appliances. Resolved In: R80.20                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| Compliance                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| -                         |                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | -                                                 |
| Online Updates                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| SMB-883                   | If the Time Zone is set after the command that turns off the First Time Wizard in a preset or auto conf script, the initial service updates might not start automatically in the first 12 hours after installation. The service updates can still be initiated manually. Best practice: The command that turns off the First Time Wizard should be the last command in a preset or auto conf script.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| SMB-2914                  | If a firmware upgrade procedure is interrupted, intentionally or due to error, online updates might fail. Workaround: reboot the device.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.00                                         |
| Wi-Fi                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| SMB-13533                 | Changing the VAP configuration (enable, disable, create, clone) causes all networks on the same wireless radio (2.4GHz or 5GHz) to stop working for a short period of time.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMB-2286                  | In Centrally Managed appliances, the standby member does not bring down the wireless networks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| IoT                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-5825               | Ruggedized Spark models (1570R, 1575R, 1595R) do not support IoT.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.05                                         |
| SMBGWY-7679               | IoT for LMM is not supported on 1570R, 1575R and 1595R.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.10                                         |
| Hotspot Portal                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| SMB-3188                  | Hotspot portal redirection does not work when you browse to HTTPS sites. First, browse to an HTTP site, and you will be redirected to a Hotspot portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| QoS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
| SMBGWY-2529               | In Centrally Managed appliances configured with QoS in Express mode, internal interfaces should not be configured for QoS as it may cause loss of connectivity. Starting from R77.20.20, QoS works by default in accelerated mode. This decreases the chance of an interruption to internal traffic. Still, the common use-case for QoS is to be activated on the external interfaces. Resolved In: R81.10.00                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.20                                            |
| SMBGWY-2530               | In connected Centrally Managed small office appliances, when a push policy of QoS and Firewall is attempted on a Gateway that has been cleanly installed, the policy installation might show a failure icon on the QoS blade without additional error messages even though the push policy succeeded. If a Firewall policy push was attempted before the QoS policy installation it will also succeed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMBGWY-2531               | * Delay Sensitivity feature and Differential Services marking feature can be used on Centrally Managed SMB appliance only under Express QoS mode. * Configuration is done in the "Advanced (UTM-1 Edge \& SG80 Gateways)" section of the QoS action properties window. * Under Traditional QoS mode only Best Effort QoS class is supported. Using any other Diffserv/Latency classes will disable QoS policy. * For Delay Sensitivity feature on Centrally Managed SMB appliance, the "Bulk" option is not supported (behaves as "Normal") * On specific QoS rule, when Delay Sensitivity is set with "Interactive" value on Centrally Managed SMB appliance, or "Low Latency" is set on Locally Managed SMB appliance, limit and guarantee values for the same rule are ignored. * All rules that are configured with Delay Sensitivity = Interactive/Low Latency will share a joint limit. This limit is by default 20 percent of the interfaces bandwidth and can be configured. | R81.10.00                                         |
| -                         | Centrally Managed SMB appliance can be configured to use Delay Sensitivity and Differential Services marking features only under Express QoS mode. Configuration is done in the "Advanced" section of the QoS action configuration window which is unique for Edge/SG80 appliances. Under Traditional QoS mode only Best Effort QoS class is supported, using other classes will disable QoS policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| SMB-10458                 | QoS does not support matching packets based on DiffServ tagging. QoS only supports marking the traffic with Differential Services (DiffServ) tags and preserving existing DiffServ tags.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.00                                         |
| Unified Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
| SMB-15218                 | The use of object names that contain spaces is not supported in clish commands. Use the object ID instead of the object name when possible.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10.00                                         |
| SMB-8464                  | When a QoS rule is configured to be applied to a specific time/day/date, it is not limited to those specifications. Resolved In: R80.20                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| SMB-7992                  | In Locally Managed appliances, H.323 is not supported in the hide NAT configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| -                         | Identity awareness AD query functionality is supported when the domain controller server is part of one of the internal networks.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.00                                         |
| WatchTower                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| -                         | -                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | -                                                 |
| WebUI                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| SMBGWY-5931               | In WebUI \> Home view \> Troubleshooting section \> Support page \> the Firmware releases link opens [sk165734 - Spark Firewall - Release R80.20.X](https://support.checkpoint.com/results/sk/sk165734) instead of [sk179615 - Spark Firewall Appliances - Releases R81.10.X](https://support.checkpoint.com/results/sk/sk179615). Workaround: Manually open [sk179615](https://support.checkpoint.com/results/sk/sk179615).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81.10.00                                         |
| SMB-14832                 | This pop-up error message may appear in the WebUI when CPU usage is temporarily high: "Connectivity with the appliance was temporarily lost during the last operation" Workaround: Refresh the browser                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMB-12761                 | In 1590 appliances: In Firewall Access rules of the type "Incoming, Internal and VPN traffic", you cannot select "internet" as a source or destination in the WebUI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.00                                         |
| 01261065                  | These characters cannot be used in WebUI textual fields: * single quote - ' * double quote - " * backslash - \\                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10.00                                         |
| SMBGWY-2532               | Toggling between Central and Local Management modes of the appliance is not supported when a cluster is configured. To change to Central Management mode, an administrator must first disable the local cluster.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| 01469798                  | Configuration of the serial port through Advanced Settings is not supported when an Internet connection is configured to an analog modem through the serial port.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81.10.00                                         |
| SMBGWY-2534               | When defining server objects, the "Force translated traffic to return to the gateway" is important for traffic originating from internal sources. However, currently, sources of all traffic to the server will be translated and hidden behind the gateway's IP address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMBGWY-2537               | Host objects can be defined with up to 32 characters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10.00                                         |
| SMBGWY-2538               | When a log in a Locally Managed appliance shows the "myown_obj" object, it in fact means "this appliance".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10.00                                         |
| SMBGWY-2539               | In Locally Managed appliances, in the Threat Prevention Exception page \> Malware Exceptions section, if the "Scope" field is not configured to "Any" it may result in the exception not being matched.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.10.00                                         |
| SMBGWY-2540               | The Identity Awareness portal sometimes does not show correctly in a Chrome browser. Workaround: refer to [sk106125](https://support.checkpoint.com/results/sk/sk106125).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMBGWY-2443               | When more than one VAP is added to a local network switch or bridge, it cannot be unassigned. Workaround: delete it and then recreate it.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.10.00                                         |
| SMB-4869                  | After replacing the web portal certificate, login to the administration web portal fails with a "Connectivity error. Refresh page and retry" message due to the browser's certificate caching mechanism. Workaround: refresh the page.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.10.00                                         |
| SMB-4792                  | Attempting to configure the same specific feature through WebUI and CLI interfaces at the same time may cause settings to be overridden or subject to submission timing.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.10.00                                         |
| Zero Touch                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
| SMB-14915                 | When Zero Touch is used, the appliance is always set to the Locally Managed mode before the clish script (defined by the user in the Zero Touch server) runs, as the command "`set security-management mode locally-managed`" is injected by default from the Zero Touch servers before the user-defined script.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10.00                                         |
| SMB-13704                 | Zero Touch works with WAN and LTE interfaces but not with DMZ.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10.00                                         |
| SD-WAN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
| SMBGWY-6086               | In R81.10.10 Centrally Managed mode, the SD-WAN Nexthop probing is disabled. As a result: * The appliance does not send pings to the nexthop of an SD-WAN interface * The "Nexthop Probing Results" section is empty in: * CPview \> Advanced \> SDWAN \> Probing-IPv4 * CPview \> Advanced \> SDWAN \> Probing-IPv6                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10.10                                         |

{#LimitationsTable}

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
