> Source: [sk181128](https://support.checkpoint.com/results/sk/sk181128)

# sk181128 - Check Point Quantum R82 Release Known Limitations

| Property | Value |
|----------|-------|
| Solution ID | sk181128 |
| Date Created | 2023-06-14 |
| Last Modified | 2026-09-02 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82, R82 |
| OS | Gaia |

## Solution

### This article lists all Quantum R82 Release specific known limitations and unsupported features, including limitations from the previous versions.


For more information about R82, see the [R82 Release Notes](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Default.htm), [R82 Home Page](https://support.checkpoint.com/results/sk/sk181127) and [R82 Resolved Issues](https://support.checkpoint.com/results/sk/sk181129).  
Visit [Check Point CheckMates Community](https://community.checkpoint.com) to ask questions or start a discussion and get our experts assistance.

**Important notes:**

* To see if an issue has been fixed in other releases or Jumbo Hotfixes, search for the issue ID in Support Center.

* To get a fix for an issue listed below, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) with the issue ID.

Click Here to Show the Entire Article

<br />

<br />

Unsupported Features **Show this section** **Table of Contents**
>
> |----------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
> | * Installation and Upgrade * Licensing * Gaia OS * Multi-Domain Management * SmartConsole / Management Console * Logging * SmartProvisioning | * Security Gateway * SD-WAN * ClusterXL * SecureXL * Routing * ICAP * Threat Prevention | * Identity Awareness * HTTPS Inspection * Mobile Access * VPN * Zero Phishing * ElasticXL, Maestro, and Scalable Chassis |
>
> <br />
>
> Enter the string to filter the below table:
>
> <br />
>
> {#Unsupported-Installation and Upgrade}{#Unsupported-Licensing}{#Unsupported-Gaia OS}{#Unsupported-MDS}{#Unsupported-SmartConsole}{#Unsupported-Logging / SmartLog}{#Unsupported-SmartProvisioning}{#Unsupported-SecurityGateway}{#Unsupported-SD-WAN}{#Unsupported-ClusterXL}{#Unsupported-SecureXL}{#Unsupported-Routing}{#Unsupported-ICAP}{#Unsupported-Threat Prevention}{#Unsupported-Identity Awareness}{#Unsupported-HTTPS Inspection}{#Unsupported-Mobile Access}{#Unsupported-VPN}{#Unsupported-Zero Phishing}
>
> |---------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Found in version |
> | Unsupported Features - Installation and Upgrade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-59345                            | Central Deployment in SmartConsole does not support: * Connection from SmartConsole to the Management Server through a proxy Server. In this case, use the applicable API command * ClusterXL in Load Sharing mode * VRRP Cluster * Installation of a package on a VSX VSLS Cluster that contains more than 3 members * On Multi-Domain Servers: Global Domain, or the MDS context * Standby Security Management Server or Multi-Domain Security Management * Security Group in Maestro * Security Group on Scalable Chassis 40000 / 60000 * ElasticXL Cluster                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81              |
> | Unsupported Features - Licensing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-47087                            | These products do not support the new licensing visibility features: * Network Security: Advanced Networking and Clustering, Capsule Cloud and Capsule Workspace. * Security Management: Endpoint Policy Management, SmartPortal, User Directory (LDAP). * Multi-Domain Management: Security Domain * Remote Access \& Endpoint                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80              |
> | Unsupported Features - Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-48258                            | The Gaia "Cloning Group" feature (all its modes) is not supported in a Multi-Version Cluster (while cluster members run different release versions).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.40           |
> | Unsupported Features - Multi-Domain Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-17365                            | The "Install Policy" action from a Multi-Domain Management Server (also through "Install Policy Presets") does not support QoS and Desktop policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.20.M1        |
> | Unsupported Features - SmartConsole / Management Console                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-101120                           | Login into SmartConsole with an IPv6 address using SAML is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.20           |
> | PMTR-104470                           | SmartConsole does not support (or has a limited support) the High Contrast Theme in these sections and windows: * "Gateways \& Servers" view \> select a Security Gateway / Cluster object \> at the top, click the Actions menu \> click Install Hotfix, or Version Upgrade * "Gateways \& Servers" view \> select a Security Gateway / Cluster object \> in the lower pane, click the Licenses tab * "Gateways \& Servers" view \> at the top, click Changes * "Security Policies" view \> Autonomous Threat Prevention \> click Policy, or File Protections * "Security Policies" view \> Access Control policy or Threat Prevention policy \> at the top, click Changes * "Manage \& Settings" view \> Sessions \> View Sessions \> at the top, click Changes * "Manage \& Settings" view \> Sessions \> Revisions \> at the top, click Changes * "Manage \& Settings" view \> Sessions \> Revisions \> select a revision \> at the top, click the Actions menu \> Revert to this Revision * "Manage \& Settings" view \> Package Repository                                                                 | R81.10           |
> | PMTR-58838                            | Changes (Diff) report does not support: * A Standalone Server * Changes made in the Legacy SmartDashboard                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PROV-2200                             | The "Get Interfaces" operation on the "Network Management" page of a Security Gateway (or Cluster) object only supports up to 500 interfaces of all types. * **To resolve:**If the Security Gateway (or Cluster) has 500 or more interfaces of all types, use the API `get-interfaces` on the Management Server to pull this information. Examples: 1)`get-interfaces target-name <Name of Security Gateway> with-top?logy false` 2) `get-interfaces target-name <Name of Cluster Object> with-top?logy true`For more information refer to [Management API](https://sc1.checkpoint.com/documents/latest/APIs/index.html#introduction~v1.6%20).                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81              |
> | PMTR-57122                            | Search for section titles is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80              |
> | -                                     | Changes to the Traditional Anti-Virus file types policy are not supported. Use the Anti-Virus blade to change the out-of-the-box Check Point policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80              |
> | Unsupported Features - Logging                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-40514                            | In the SmartConsole \> Logs \& Monitor view \> \[ + \] New Tab \> Views, sorting of the Favorites and Shared columns is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.40           |
> | PMTR-47703                            | Purge, log switch and fetch log file tasks are not supported from SmartConsole. * Fetch log files from a remote Server is available from the command line only. Run: `fw fetchlogs <Gateway-Name/IP>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.10           |
> | Unsupported Features - SmartProvisioning                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-109023                           | SmartProvisioning / SmartLSM is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R82              |
> | PMTR-56758                            | It is not supported to remove an IP address from one interface and assign the same IP address to another interface in the device object in the same edit action. "*Error field: ipAddr, Desc: IP address is in the subnet of an existing network*" is displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81              |
> | PMTR-54979                            | When managing devices with the SmartProvisioning Software Blade, on the devices you must configure the connection with the Security Management Server using the IPv4 address in the `connect security-management mgmt-addr <IPv4 address of Security Management Server>` command (it is not supported to use the FQDN of the Security Management Server in this command).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.40           |
> | Unsupported Features - Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-60143                            | The `perf` command is not supported on Threat Emulation appliances and on all other Check Point appliances that have only one or two CPU cores. * On these appliances, use the `top` and `turbostat` commands to monitor the performance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10           |
> | PMTR-58361                            | Intra-Tunnel Inspection of GTP-U user traffic is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81              |
> | PMTR-58366                            | The "Produce extended logs on unmatched PDUs" option is not supported in the Security Gateway (Cluster) object \> Carrier Security \> Track. As a result, it is not possible to generate informative logs for unmatched GTP-C control packets (except for a plain clean up rule logging).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | Unsupported Features - SD-WAN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | PMTR-109701                           | SD-WAN Overlay does not support having multiple center gateways in a star community with no satellites, when "Mesh center gateways" checkbox is selected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | PMTR-108481                           | Anti-Spam, Threat Emulation and Threat Extraction Blades do not support Security Gateways with Dynamically Assigned IP (DAIP).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-108485                           | SD-WAN Overlay does not support VPN Tunnel between gateways while both sides behind CGNAT / Dynamic NAT.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-108281                           | SD-WAN does not support matching a "Local Breakout" rule to traffic in this scenario: 1. Traffic matches a Policy-Based Routing (PBR) rule that applies to traffic from a local network to "Default", and the next hop in this rule is set to a VPN Tunnel Interface (VTI). 2. The priority of this PBR rule is lower than 100.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-106136                           | SD-WAN does not support Cluster configuration when Cluster Members are DAIP Security Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-107839                           | SD-WAN Overlay does not support the "Exclude gateway's external IP addresses from the VPN Domain" configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R82              |
> | PMTR-106717                           | In a Spoke-Hub-Spoke configuration, an encrypted connection from a Satellite SD-WAN DAIP Security Gateway to another Satellite Security Gateway VPN Domain is not supported when both conditions are met: * The source IP is from a Dynamic IP interface * The connection is routed through the central Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-106135                           | SD-WAN does not support Security Gateways running Gaia OS that have more than one DAIP interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R82              |
> | PMTR-108004                           | SD-WAN does not support "Overlay - VPN" over Route Based VPN configured with unnumbered VPN Tunnel Interfaces (VTI).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R82              |
> | PMTR-108010                           | For inbound connections from the Internet to the Security Gateway itself, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received if there are multiple ISPs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-105725                           | In a cluster, SD-WAN does not support interfaces in which the "Network Type" is set to "Private" (Non-Monitored Interface).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R82              |
> | PMTR-105211                           | SD-WAN Local Breakout is not supported for outbound connections configured with fixed Hide/Static NAT IP address, and which should be steered using more than one ISP. The only option is "Hide behind gateway". * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 14](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_14.htm) (PRJ-56616)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R82              |
> | PMTR-105210                           | SD-WAN Local Breakout does not apply to connections that originate on the Security Gateway itself (for example, when an administrator connects from the Security Gateway to an FTP server).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R82              |
> | PMTR-105208                           | SD-WAN Overlay VPN does not support Route Based VPN.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R82              |
> | PMTR-105207                           | SD-WAN Overlay VPN does not support VPN peer Security Gateways connected over a Layer 2 line (SD-WAN Overlay VPN requires Layer 3 connectivity between VPN peers). The external interfaces of SD-WAN Security Gateways cannot be in the same subnet, if they are configured for a VPN overlay.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-105213                           | SD-WAN Overlay VPN is only supported between Check Point Security Gateways that are connected to the same infinity tenant.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82              |
> | PMTR-105370                           | SD-WAN Overlay VPN does not support the configuration of the probing IP address. By default, SD-WAN Overlay VPN probing sends ICMP requests only to the IP addresses of the VPN Peers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82              |
> | PMTR-105209                           | SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82              |
> | PMTR-108031                           | SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Domain Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-108901                           | SD-WAN does not support using DAIP Security Gateway objects in Access Control rules (neither in the Source column, nor in the Destination column).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.20           |
> | PMTR-104984                           | SD-WAN does not support VPN Route Injection Mechanism (RIM) configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.20           |
> | PMTR-104985                           | SD-WAN does not support VPN Explicit Multiple Entry Point (MEP) configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.20           |
> | PMTR-105215                           | SD-WAN does not support VPN Overlay with third-party VPN Peers (Check Point Security Gateway continues to use the existing Link Selection).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.20           |
> | PMTR-104986                           | For inbound connections from the internet, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received, in case of multiple ISPs. The return will be determined based on the OS routes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.20           |
> | PMTR-104981                           | SD-WAN does not support IPv6 traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-104980                           | Scalable Platform Security Groups (Maestro and Chassis) do not support SD-WAN configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.20           |
> | PMTR-105894                           | SD-WAN does not support ClusterXL in the Load Sharing Multicast mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-105895                           | SD-WAN does not support ClusterXL in the Active-Active mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.20           |
> | PMTR-105533                           | SD-WAN does not support Security Gateways that are managed with SmartProvisioning / LSM Profiles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.20           |
> | PMTR-104576                           | SD-WAN does not support VPN Permanent Tunnels (SmartConsole \> VPN Community object \> Tunnel Management). SD-WAN tunnels are kept up automatically by the probing.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.20           |
> | PMTR-105543                           | SD-WAN does not support Geo Cluster in Microsoft Azure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.20           |
> | PMTR-105542                           | SD-WAN does not support Geo Cluster in Amazon Web Services (AWS).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.20           |
> | PMTR-105544                           | SD-WAN does not support Geo Cluster in Google Cloud Platform (GCP).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.20           |
> | PMTR-104977                           | VSX Gateways and VSX Clusters do not support SD-WAN configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.20           |
> | PMTR-104982                           | SD-WAN is not supported if a Security Gateway / Cluster runs SecureXL in the User Mode (UPPAK) on supported appliances (Quantum LightSpeed and Quantum Force - see [sk179432](https://support.checkpoint.com/results/sk/sk179432)). Note - Using [SecureXL in the Kernel Mode (KPPAK)](https://sc1.checkpoint.com/documents/Appliances/100G_Ports_AdminGuide/Content/Topics-100G-Card-AG/SecureXL-Configuration.htm) is supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.20           |
> | Unsupported Features - ClusterXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-59404                            | Geo Cluster does not support IPv6 traffic. Therefore, it is not supported to configure an IPv6 address on the Cluster and Sync interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
> | PMTR-48477                            | ICAP Client and ICAP Server are not supported with ClusterXL Load Sharing modes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.10           |
> | Unsupported Features - SecureXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-87460                            | SecureXL Rate Limiting rules for DoS Mitigation do not support these parameters: * `cc:<COUNTRY_CODE>` * `asn:<AUTONOMOUS_SYSTEM_NUMBER>` Refer to [sk182350](https://support.checkpoint.com/results/sk/sk182350). * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 44](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_44.htm) (PRJ-60142)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.10           |
> | Unsupported Features - Routing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-100077, PMTR-100198, PMTR-100206 | PIM routing for IPv6 is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82              |
> | Unsupported Features - ICAP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |||
> | PMTR-28828                            | ICAP Client cannot forward traffic to an ICAP Server when the Security Gateway is configured to apply the Threat Prevention "Strict Hold" mode. See [sk183785](https://support.checkpoint.com/results/sk/sk183785).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.30           |
> | Unsupported Features - Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-59492                            | In a Multi-Domain Server environment, Infinity Threat Prevention does not support the Global Domain. Other Domains are supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-42537                            | Threat Prevention Software blades do not support files with the HTTP 206 partial format with multiple ranges in the same HTTP connection (multipart).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.40           |
> | PMTR-59837                            | SSH Deep Packet Inspection limitations: * SSH DPI is only supported for Security Gateways R80.40 and above, managed by Management Servers R80.40 and above. * Inspection of IPv6 connections is not supported. * Bridge Mode is not supported. * Cluster members do not synchronize the data about the inspected SSH traffic. * Cluster members do not synchronize the SSH DPI configuration. * Inspection of SSH traffic generated by clients, which do not support the "Diffie-Hellman group exchange" algorithm, is not supported. * These SSH clients are not supported: * PuTTY versions 0.64 and lower. * OpenSSH versions 2.5.2 and lower. * WinSCP versions 5.7.4 and lower. * SecureCRT versions 5.2 and lower.                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | Unsupported Features - Identity Awareness                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | PMTR-64495                            | Identity Awareness does not support authentication of Primary Groups of user and computer accounts. By default, the Primary Groups are "Domain Users" and "Domain Computers". Access roles that are defined with User groups do not work for users with which those user groups are their primary group. * To use the entire Accounting Unit in an Access Role, use an LDAP group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R7x              |
> | Unsupported Features - HTTPS Inspections                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-103024, CRYPTOIS-2197            | HTTPS Inspection does not support Hardware Security Modules (HSM) when inspection of TLS 1.3 traffic is enabled. With HTTPS Inspection, you can enable only one of these features - TLS 1.3 or HSM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81              |
> | Unsupported Features - Mobile Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | PMTR-60331                            | These limitations apply to the Guacamole feature: 1. A dedicated Apache Guacamole Server version 1.1.0 or higher is required. 2. The following Guacamole features are not supported: * The VNC protocol * RDP file transfer * The SFTP protocol * Session recording 3. RDP/SSH is not supported from Capsule Workspace. 4. RDP/SSH is supported only by web browsers with HTML5 support. 5. RDP and SSH applications can be configured only by using their corresponding service objects in SmartConsole: * "Remote_Desktop_Protocol" * "SSH" * "SSH_version_2" 6. The Clipboard function in RDP sessions is supported with these limitations: * Text only * Supported browsers: Chrome and Explorer 7. This Single Sign-On option is not supported for Guacamole applications: "This application reuses the portal credentials. If authentication fails, Mobile Access prompts users and stores their credentials" 8. In a VSX environment where the "custom user directory attribute" feature is used, adding a new Virtual System requires manually adding the *customUserRecordAttribute.conf* file as well. | R81              |
> | PMTR-58003                            | Mobile Access rules in the Unified Access Policy do not support Native Applications that authorize non-TCP or non-UDP services (for example, "*icmp-proto*").                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81              |
> | PMTR-47745                            | The Mobile Access Portal does not support Web-Form SSO for Citrix StoreFront Web interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.10           |
> | PMTR-47591                            | Mobile Access does not support viewing or editing files with "*Office Online apps"*, Microsoft's browser-based Office applications. Outlook Web Access is supported, however you cannot open or edit Office Online app files from emails.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R7x              |
> | Unsupported Features - VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
> | AAD-2302                              | IKEv2 VPN tunnels and Remote Access VPN connections may fail to establish when fragmented packets are encountered during IKEv2 negotiation, because IKEv2 Fragmentation is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.20           |
> | PMTR-60396                            | Large Scale VPN (LSV) does not support: * IPv6 * Route Based VPN (VTI) * Two VPN peers behind the same NAT device * Suite-B-GCM-128 * Suite-B-GCM-256 with IKEv1-only (it is necessary to change the global properties of Phase 1 for Remote Access VPN) * Multiple Hubs * Route Injection Mechanism (RIM) * IKE Aggressive Mode * Permanent Tunnel * Multiple Entry Point (MEP) VPN * Dead Peer Detection (DPD) * Global VPN Community (GVC) * Tunnel Per Security Gateway pair (Universal Tunnel)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.40           |
> | PMTR-47783                            | NAT-T initiator is not supported on VSX Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.10           |
> | PMTR-47235                            | Converting Traditional VPN Policy to Simplified VPN Policy is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80              |
> | Unsupported Features - Zero Phishing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | PMTR-81859                            | Browser Zero Phishing is not supported in CloudGuard Network Security Auto Scale solution.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
>
> {#limitationTable}
>
> ElasticXL, Maestro, and Scalable Chassis Unsupported Features {#Unsupported-SP}
> -------------------------------------------------------------------------------
>
> <br />
>
> Enter the string to filter the below table:
>
> <br />
>
> {#NSF_General}{#NSF_GaiaOS}{#NSF_Hardware}{#NSF_Licensing}{#NSF_Cluster}{#NSF_VSX}{#NSF_VSX}{#NSF_Networking}{#NSF_Firewall}{#NSF_VPN}{#NSF_IA}{#NSF_DLP}{#KL_TP}{#KL_SBMA}
>
> |---------------------------------|------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------|
> | ID                              | Product          | Description                                                                                                                                                                                                                                                                                                                                                                         | Found in  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - General                                                                                                                                                                                                                                                                                                                                                                           ||||
> | PMTR-108783                     | ElasticXL        | DHCP Server is not supported on ElasticXL.                                                                                                                                                                                                                                                                                                                                          | R82       |
> | PMTR-107886                     | ElasticXL        | Interface Active Check (IAC) is not supported on ElasticXL.                                                                                                                                                                                                                                                                                                                         | R82       |
> | PMTR-101283                     | Maestro, Chassis | Maestro and Scalable Chassis Security Groups do not support SD-WAN configuration.                                                                                                                                                                                                                                                                                                   | R81.20    |
> | PMTR-84368                      | Maestro          | Configuring Auto Scaling Settings is not supported if a Maestro Security Group contains different appliance models.                                                                                                                                                                                                                                                                 | R81.20    |
> | PMTR-111387, MBS-10252          | All              | Zero Touch is not supported.                                                                                                                                                                                                                                                                                                                                                        | R81       |
> | PMTR-111384, MBS-12257          | All              | Detection of IP address conflict in Gaia OS is not supported..                                                                                                                                                                                                                                                                                                                      | R81       |
> | PMTR-111368, MBS-9128           | All              | The Unique IP address per Chassis (UIPC) feature is not supported for IPv6 addresses.                                                                                                                                                                                                                                                                                               | R80.20SP  |
> | PMTR-111382, MBS-3001           | All              | The `fw fetchlog` command on the Management Server is not supported. * Use SmartConsole to fetch logs from Security Members.                                                                                                                                                                                                                                                        | R80.20SP  |
> | PMTR-111386, MBS-3246           | All              | DHCP Server configuration in the VSNext mode is not supported.                                                                                                                                                                                                                                                                                                                      | R80.20SP  |
> | PMTR-108605, 00824847           | All              | OPSEC SDK is not supported.                                                                                                                                                                                                                                                                                                                                                         | R76SP     |
> | PMTR-108606, 01800842           | All              | Hide NAT for traffic initiated from the Management interface of a Security Group is not supported.                                                                                                                                                                                                                                                                                  | R76SP     |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Gaia OS                                                                                                                                                                                                                                                                                                                                                                           ||||
> | PMTR-101680                     | ElasticXL        | ElasticXL supports IP Broadcast Helper (iphelper) in Gaia OS only when two ElasticXL Sites are configured.                                                                                                                                                                                                                                                                          | R82       |
> | PMTR-108178                     | ElasticXL        | In the Gaia First Time Configuration Wizard, when configuring the first ElasticXL Cluster Member, it is possible to configure an IP address only on the "Mgmt" (Management) interface. This is done on the "Management Connection" page of the wizard. Configuring an IP address on any other interface, such as on the "Internet Connection" page of the wizard, is not supported. | R82       |
> | PMTR-109486                     | ElasticXL        | In ElasticXL, it is not supported to collect Gaia OS backup and restore it. * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 14](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_14.htm)                                                                                                                                                                         | R82       |
> | PMTR-81746                      | All              | When Management Data Plane Separation (MDPS) is enabled (see [sk138672](https://support.checkpoint.com/results/sk/sk138672)), Gaia Portal is not supported on a Security Group.                                                                                                                                                                                                     | R81.20    |
> | PMTR-71560, MBS-7145            | Maestro          | Maestro does not support the Dynamic CLI. Refer to [sk144112](https://support.checkpoint.com/results/sk/sk144112).                                                                                                                                                                                                                                                                  | R80.30SP  |
> | PMTR-111362, MBS-13308          | All              | The `set iphelper` (IP Broadcast Helper) commands are not supported in Gaia gClish.                                                                                                                                                                                                                                                                                                 | R80.20SP  |
> | PMTR-90800                      | Maestro          | It is not supported to use the `set web ssl-port` command to change the MHO's WebUI SSL port from the default port 443 (for example: `set web ssl-port 4434`). Changing it causes communication issues between Maestro devices.                                                                                                                                                     | R80.20SP  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Hardware                                                                                                                                                                                                                                                                                                                                                                          ||||
> | PMTR-106636, MBS-1244           | All              | The Check Point Performance Sizing Utility *cpsizeme* (see [sk88160](https://support.checkpoint.com/results/sk/sk88160)) is not supported.                                                                                                                                                                                                                                          | R80.20SP  |
> | PMTR-111375, MBS-4754           | All              | Central Management of Gaia Device Settings is not supported: 1. In SmartConsole, click "Gateways \& Servers" on the navigation panel. 2. Right-click the Maestro and Scalable Chassis Gateway object or the Maestro Security Appliance Gateway object. 3. The "Scripts" menu and "Actions" menu are not supported.                                                                  | R80.20SP  |
> | PMTR-111360, MBS-5227           | Maestro          | It is not supported to install both of the following expansion cards in the same Security Appliance connected to a Maestro Hyperscale Orchestrator: * 10 GbE and 40 GbE * 10 GbE and 100 GbE                                                                                                                                                                                        | R80.20SP  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Licensing                                                                                                                                                                                                                                                                                                                                                                         ||||
> | PMTR-111374, MBS-7929           | Maestro          | Central License is not supported on Quantum Maestro.                                                                                                                                                                                                                                                                                                                                | R80.20SP  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Cluster                                                                                                                                                                                                                                                                                                                                                                           ||||
> | PMTR-106210                     | ElasticXL        | Multicast traffic routing over VTI Interface is not supported with ElasticXL in Load Sharing Mode.                                                                                                                                                                                                                                                                                  | R82       |
> | PMTR-99761                      | ElasticXL        | Bridge is not supported on ElasticXL in Load Sharing mode (more than one Cluster Member per Site).                                                                                                                                                                                                                                                                                  | R82       |
> | PMTR-111390, MBS-12227          | All              | Active-Active cluster is not supported.                                                                                                                                                                                                                                                                                                                                             | R81       |
> | PMTR-111364, MBS-7913           | Maestro          | Cluster Control Protocol (CCP) Encryption is not supported.                                                                                                                                                                                                                                                                                                                         | R80. 30SP |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - SecureXL                                                                                                                                                                                                                                                                                                                                                                          ||||
> | PMTR-106079                     | Maestro          | Maestro Security Groups do not support the SecureXL User Space (UPPAK) mode.                                                                                                                                                                                                                                                                                                        | R81.20    |
> | PMTR-111379, MBS-5415           | All              | Configuring the IPS protection "SYN Attack" in SmartConsole is not supported. You must only use the "`fwaccel synatk`" and "`fwaccel6 synatk`" CLI commands.                                                                                                                                                                                                                        | R80.20SP  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - VSNext / VSX                                                                                                                                                                                                                                                                                                                                                                      ||||
> | PMTR-118023                     | ElasticXL        | ElasticXL in the VSNext configuration does not support the Load Sharing mode (more than one Cluster Member per Site). * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 103](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_103.htm)                                                                                                                             | R82       |
> | PMTR-108696, PMTR-110224        | ElasticXL        | VSLS (Virtual System Load Sharing) is not supported in the VSNext mode on ElasticXL. * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 14](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_14.htm)                                                                                                                                                                | R82       |
> | PMTR-111371, MBS-16945          | All              | NAT46 is not supported in the VSNext / Traditional VSX modes.                                                                                                                                                                                                                                                                                                                       | R80.20SP  |
> | PMTR-109340                     | All              | Virtual Gateway in Monitor Mode is not supported.                                                                                                                                                                                                                                                                                                                                   | R82       |
> | PMTR-109011                     | All              | The "Mirror and Decrypt" feature is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                               | R82       |
> | PMTR-109016                     | All              | VPN Enhanced Link Selection is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                                    | R82       |
> | PMTR-119289, HEC-2236           | All              | In the VSNext mode, after you create a Numbered VTI and attach it to a Virtual Gateway, you must reboot the Security Group. * Resolved in [R82 Jumbo Hotfix Accumulator Take 103](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_103.htm) (PRJ-65727)                                                                                                               | R82       |
> | PMTR-109024                     | All              | Anti-Virus archive scanning is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                                    | R82       |
> | PMTR-109025                     | All              | Threat Emulation archive scanning is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                              | R82       |
> | PMTR-109026                     | All              | Mail Transfer Agent (MTA) support for Threat Emulation is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                         | R82       |
> | PMTR-109028                     | All              | Alias / Secondary IP address is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                                   | R82       |
> | PMTR-109029                     | All              | ECMP (Equal Cost Path Splitting - Static Routs) is not supported in the VSNext mode..                                                                                                                                                                                                                                                                                               | R82       |
> | PMTR-109032                     | All              | Web SmartConsole does not support Security Groups in the VSNext mode.                                                                                                                                                                                                                                                                                                               | R82       |
> | PMTR-109033                     | All              | Object Sharing from on-premises Management Server to Infinity Portal is not supported.                                                                                                                                                                                                                                                                                              | R82       |
> | PMTR-109034                     | All              | Log Sharing from on-premises Management Server to Infinity Portal does not support Security Groups in the VSNext mode.                                                                                                                                                                                                                                                              | R82       |
> | PMTR-109035                     | All              | Infinity Playblocks does not support Security Groups in the VSNext mode.                                                                                                                                                                                                                                                                                                            | R82       |
> | PMTR-108070                     | All              | ISP Redundancy is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                                                 | R82       |
> | PMTR-109023                     | All              | SmartProvisioning / SmartLSM is not supported in the VSNext mode.                                                                                                                                                                                                                                                                                                                   | R82       |
> | PMTR-111386, MBS-3246           | All              | Maestro in the VSNext mode does not support DHCP Server configuration.                                                                                                                                                                                                                                                                                                              | R82       |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Networking                                                                                                                                                                                                                                                                                                                                                                        ||||
> | PMTR-107585                     | ElasticXL        | ElasticXL does not support IPv6 in the Load Sharing mode (more than one Cluster Member per Site).                                                                                                                                                                                                                                                                                   | R82       |
> | PMTR-60874, ACCHA-736           | Maestro          | VxLAN interfaces are not supported on Quantum Maestro.                                                                                                                                                                                                                                                                                                                              | R80.20SP  |
> | PMTR-111442, MBS-14222          | All              | Dynamic Routing protocols over GRE tunnels is not supported.                                                                                                                                                                                                                                                                                                                        | R81       |
> | PMTR-106619                     | All              | BGP confederations are not supported.                                                                                                                                                                                                                                                                                                                                               | R76SP     |
> | PMTR-111441, MBS-14223          | All              | BGP over VxLAN tunnels is not supported.                                                                                                                                                                                                                                                                                                                                            | R81       |
> | PMTR-111369, MBS-3944           | Chassis          | Asymmetric traffic between two chassis in Dual Chassis deployment is not supported.                                                                                                                                                                                                                                                                                                 | R80.20SP  |
> | PMTR-104455, MBS-3946           | All              | Carrier Security (LTE) is not supported.                                                                                                                                                                                                                                                                                                                                            | R80.20SP  |
> | PMTR-111367, MBS-12823          | All              | "*6in4 tunnel*" interface is not supported.                                                                                                                                                                                                                                                                                                                                         | R80.20SP  |
> | PMTR-104437                     | Chassis          | TFTP connections do not survive failover when using SSM440 and the distribution matrix size of 16K.                                                                                                                                                                                                                                                                                 | R80.20SP  |
> | MBS-8326, PMTR-104452           | All              | [Central Deployment Tool](https://support.checkpoint.com/results/sk/sk111158) is not supported.                                                                                                                                                                                                                                                                                     | R80.20SP  |
> | PMTR-111363, MBS-11398          | Chassis          | Correction is not supported for IPv6 local connections initiated from the Standby chassis.                                                                                                                                                                                                                                                                                          | R80.20SP  |
> | PMTR-111445, MBS-14200          | All              | RIPng (IPv6) is not supported.                                                                                                                                                                                                                                                                                                                                                      | R76SP     |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Firewall                                                                                                                                                                                                                                                                                                                                                                          ||||
> | PMTR-111383, MBS-14173          | All              | ConnectControl is not supported.                                                                                                                                                                                                                                                                                                                                                    | R76SP.50  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - VPN                                                                                                                                                                                                                                                                                                                                                                               ||||
> | PMTR-111847, MBS-12310          | All              | Large Scale VPN (LSV) is not supported.                                                                                                                                                                                                                                                                                                                                             | R81       |
> | PMTR-111366, MBS-14408          | All              | Simultaneous Login Prevention (SLP) is not supported.                                                                                                                                                                                                                                                                                                                               | R80.20SP  |
> | PMTR-111444. MBS-4097           | All              | * Site-to-Site VPN with IPv6 peers is not supported. * Remote Access VPN from IPv6 clients is not supported.                                                                                                                                                                                                                                                                        | R80.20SP  |
> | AAD-1653, MBS-8316              | All              | IPv6 VPN is not supported.                                                                                                                                                                                                                                                                                                                                                          | R80.20SP  |
> | PMTR-111443, MBS-7914           | Maestro          | Multiple Entry Points (MEP) configuration using Dead Peer Detection (DPD) is not supported.                                                                                                                                                                                                                                                                                         | R80.30SP  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Identity Awareness                                                                                                                                                                                                                                                                                                                                                                ||||
> | PMTR-111378, MBS-14460          | Maestro          | Maestro Security Group does not support the Identity Awareness Captive Portal if the L4 distribution is enabled.                                                                                                                                                                                                                                                                    | R80.20SP  |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - DLP                                                                                                                                                                                                                                                                                                                                                                               ||||
> | PMTR-111370, MBS-13243          | All              | The Data Loss Prevention Software Blade does not support rules with the Action "Ask".                                                                                                                                                                                                                                                                                               | R80.20SP  |
> | PMTR-108607, 01157859, 01349731 | All              | DLP Fingerprint is not supported.                                                                                                                                                                                                                                                                                                                                                   | R76SP     |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Threat Prevention                                                                                                                                                                                                                                                                                                                                                                 ||||
> | PMTR-111385, MBS-12329          | All              | Inspection of SMBv3 multi-channel with Anti-Virus and Threat Emulation Software Blades is not supported.                                                                                                                                                                                                                                                                            | R81       |
> | ElasticXL, Maestro, and Scalable Chassis Unsupported Features - Mobile Access                                                                                                                                                                                                                                                                                                                                                                     ||||
> | PMTR-111377, MBS-14368          | All              | The Mobile Access Portal Agent is not supported.                                                                                                                                                                                                                                                                                                                                    | R80.20SP  |

> {#SPTable}

*** ** * ** ***

<br />

<br />

<br />

Known Limitations

**Installation and Upgrade**
>
> Enter the string to filter the below table:
>
> {#Installation and Upgrade}
>
> |-------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID          | Description                                                                                                                                                                             | Found in version |
> | Installation and Upgrade                                                                                                                                                                                               |||
> | PMTR-109123 | Because of postgres limitation, upgrades fail when policy contains groups with more than 32000 members. * A verification that prevents the upgrade if oversized groups exist was added. | R82              |
> | PMTR-108824 | The "*Timeout waiting for response from database server* " message may be shown when performing "*set snapshot revert*" and the member goes to reboot. The issue is cosmetic only.      | R82              |
> | PMTR-61069  | SmartEvent upgrade is allowed only after all Multi-Domain Management Servers with Active Domain Management Servers are upgraded.                                                        | R81              |

> {#UpgradeTable}

*** ** * ** ***

**Licensing**
>
> Enter the string to filter the below table:
>
> {#Licensing}
>
> |------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Found in version |
> | Licensing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
> | PMTR-47532 | When loaded for the first time, web components such as the licensing or monitoring view can take up to thirty seconds to show.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80              |
> | PMTR-47101 | In the License Status View, the Additional Info column, quota information and quota statuses are not available for pre-R80 Gateways and Servers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80              |
> | PMTR-47103 | Automatic license activation on Check Point appliances is not available on pre-R80 appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80              |
> | PMTR-47308 | The proxy that synchronizes license information with the User Center, must be at least R80 Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R7x              |
> | PMTR-47531 | On SmartEvent NGSE dedicated machine, license information is not automatically updated when Installing Database. When you enable or disable a blade, one of the following will update the license information with the change: * If you force a license update, changes occur immediately. To force a license update: On the R81 Security Management Server, run the following command in Expert mode: `[Expert@HostName]# $CPDIR/bin/esc_db_complete_linux_50 bc_refresh <Name of Target Object>` * Automatic update at midnight * If you manually change a license or contract on a dedicated machine, changes take effect within 20 minutes | R7x              |

> {#LicensingTable}

*** ** * ** ***

**Quantum Security Gateway** / Gaia OS / VSX (Traditional)/ VPN / QoS / ClusterXL
> Quantum Security Gateway \| Gaia OS \| VSX (Traditional) \| VPN \| QoS \| ClusterXL
>
> <br />
>
> Enter the string to filter the below table:
>
> .

<br />

{#Security Gateway}{#Gaia OS}{#VSX}{#VPN}{#QoS}{#ClusterXL}

|-------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
| ID                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Found in version |
| Quantum Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
| PMTR-107789                         | Upon reopening an IDP object, the previously entered data may not be visible.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.20           |
| PMTR-59152                          | Traffic on a single GRE tunnel cannot be distributed to multiple CoreXL Firewall instances. Therefore, the maximum throughput of a single GRE tunnel is limited by the throughput of a single CoreXL Firewall instance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81              |
| PMTR-38747                          | Output of the `fw ctl zdebug + drop` command shows messages about connection drops, in addition to Firewall drops. These are internal debug messages that do not reflect real Firewall drops. To avoid them, use one of these: 1. The `fw ctl zdebug drop` command without the "`+`" character in the syntax 2. The full debug procedure                                                                                                                                                                                                                                                                                                                                                                                                | R80.20           |
| PMTR-42525                          | When Using a rule with legacy object, in or below a rule with one of the new features that are integrated in the unified policy, install policy on a Security Gateway fails with a verification message. * **To resolve**: change the order of the rules so that rules with legacy objects are above rules with new features. Refer to [sk115961](https://support.checkpoint.com/results/sk/sk115961).                                                                                                                                                                                                                                                                                                                                  | R80.10           |
| PMTR-109230, PMTR-47316, PMTR-17546 | The logging session does not switch to the backup logging Server after a connectivity loss. Refer to [sk118697](https://support.checkpoint.com/results/sk/sk118697).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R7x              |
| Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |||
| PMTR-131798                         | In R82 Take 779: * Zero Touch provisioning is not available. * When running config_system, this message may be displayed: *"/bin/config_system: line 149: /opt/CPzetc/bin/zetc_setlaunch: No such file or directory"* This issue is cosmetic and does not affect the proper operation of config_system.                                                                                                                                                                                                                                                                                                                                                                                                                                 | R82              |
| PMTR-51440                          | While the 4x10G Fiber NIC (CPAC-4-10F-B) is installed in the appliance, the HW Diagnostics "Network Test" fails with these messages: *Network Test: Failed* *General Error*                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81              |
| PMTR-81308, GAIA-3345               | Changing the MTU on the directly connected switches may cause drops of fragmented traffic due to a MTU mismatch.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.30           |
| PMTR-47577                          | If the backup schedule is changed to an invalid date or time, all backup schedules are lost and "*Backup schedule failed. The backup will not be scheduled*" error message is displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.10           |
| VSX (Traditional)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
| PMTR-60160                          | You can use the `vsx_util downgrade` command only if you did not make any configuration changes after you used the `vsx_util upgrade` command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81              |
| VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| PMTR-101631                         | "IPSec VPN" page in the Security Gateway object still shows a selected VPN Community, although the configuration changes were discarded. Refer to [sk182068](https://support.checkpoint.com/results/sk/sk182068).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82              |
| PMTR-68228                          | If the Diffie-Hellman (DH) group configuration is changed (SmartConsole \> Global Properties \> Remote Access \> VPN - Authentication and Encryption \> Encryption algorithms \> Edit \> Phase 1 \> Use Diffie-Hellman group) while an Endpoint VPN client is connected, the client disconnects during the next Phase 2 negotiation.                                                                                                                                                                                                                                                                                                                                                                                                    | R81              |
| PMTR-55445                          | Site to Site VPN with a Large Scale VPN profile can drop traffic after decryption with the log "*According to policy traffic shouldn't have been decrypted* ". **To prevent this traffic drop**: 1. Edit the Large Scale VPN profile object: 1. On the VPN Domain page, in the section "IP addresses allowed in the VPN Domain" select "Restrict to these groups or networks" 2. Select the applicable "Host", "Network", and "Group" objects. 2. Edit the LSV peer object: 1. In the VPN Domain (Encryption Domain), select the "Address Range" objects, whose IP addresses contain the IP addresses of the "Host", "Network", and "Group" objects you selected in the Large Scale VPN profile object. 3. Install the Security Policy. | R81              |
| PMTR-25046, PMTR-33694, PMTR-44902  | After running the `cpstop ; cpstart` commands, the "*FW-1: fwconn_chain_get_opaque: invalid id -1*" message appears repeatedly on the screen and in the dmesg. This is a cosmetic issue only.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.20           |
| PMTR-58668                          | If a Security Gateway with PIM configured is part of a VPN community, PIM service must be added to the Excluded Services in the VPN community object. This only applies in one of these scenarios: * Security Gateway is directly connected to a multicast sender * Security Gateway is configured as a PIM Rendezvous Point                                                                                                                                                                                                                                                                                                                                                                                                            | R80.10           |
| PMTR-47752                          | The VPN client shows as "*Not Compliant* " when it is not compliant according to the local.scv file, even if SCV is disabled. * **To resolve**: Configure the VPN site again on the client.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.10           |
| PMTR-47501                          | When using a VPN client, activity logs are not generated for ICMP traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R7x              |
| PMTR-32305                          | RADIUS authentication fails for LDAP users as the Security Gateway uses *sAMAccountName* and not UPN when UPN is needed. Refer to [sk122477](https://support.checkpoint.com/results/sk/sk122477).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R7x              |
| PMTR-104094                         | If Perfect Forward Secrecy is enabled, Remote Access VPN client may disconnect from the Security Gateway in one hour.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
| QoS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
| PMTR-47566                          | No warning is displayed if an empty network group object appears in the source or destination column.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R7x              |
| ClusterXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
| ACCHA-3403                          | Traffic outage may occur in a ClusterXL / VSX Virtual System configured in the Active/Standby Bridge Mode after a cluster failover that was caused by the disconnection of the direct bridge link.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.10           |

{#GatewayTable}


*** ** * ** ***

**Quantum Security Management** / Multi-Domain Security Management / Compliance / Logging / SmartEvent / SmartProvisioning
> Quantum Security Management \| Multi-Domain Security Management \| Compliance \| Logging \| SmartEvent \| SmartProvisioning
>
> <br />
>
> Enter the string to filter the below table:
>
> {#Quantum Security Management}{#MDS}{#Compliance}{#Logging}{#SmartEvent}{#SmartProvisioning}
>
> |--------------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                             | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Found in version |
> | Quantum Security Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |||
> | PMTR-116108                    | Wildcard objects do not appear in the search results when searching by IP address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R82              |
> | PMTR-74025                     | In API commands like `show-software-packages-per-targets` and in the SmartConsole, the "installed" field remains empty. As a result, The Security Management is not aware of the specific image installed on SMB appliances, but only of the version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-85908                     | When configuring the SD-WAN interface of the Security Gateway with the `set_sdwan` command and then perform "Get Interfaces" in SmartConsole while the interface has already been listed on the Network Management page (as internal), the interface may not turn to external as expected. * **To resolve:** Remove this interface from the Network Management page and perform "Get Interfaces" again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10           |
> | PMTR-51456                     | The value configured in SmartConsole \> Global properties \> Advanced \> Configure \> Central Device Management \> "*device_settings_max_script_length_in_KB* " field is not applied. The upper limit is always 8 kilobytes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10           |
> | PMTR-56141                     | When fetching a VPN Tunnel Interface (VTI) from Cluster Members using the `get-interfaces` Management API command, you must configure the Cluster VIP address using the `set simple-cluster` API before publishing the session. Examples: 1. `mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "private"` 2. `mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "cluster" interfaces.update.ip-address 1.2.3.4 interfaces.update.ipv4-mask-length 24`                                                                                                                                                                                                                                                                                                                                         | R81              |
> | PMTR-60100                     | When creating a rule with the "Detailed Log" track without "Accounting" disabled, the "Accounting" still appears after you close and open SmartConsole. * **To resolve**: Modify the rule to remove the "Accounting" setting.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.40           |
> | PMTR-50315                     | "*Certificate with the same Distinguished Name already installed for another CA* " message in SmartConsole in the following scenario: 1. A user started to create a new Trusted CA object with a certificate 2. A user discarded the session 3. A user tried to create a new Trusted CA object with the same certificate                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | PMTR-81309, PRHF-14607         | Running a one time script on a Security Gateway (that reads files or outputs of commands) using a "One Time Script" feature in SmartConsole or with API may fail after 5 minutes with the "Operation timed out" error. The limit for reading files is 9,730 lines or 730 KB (whichever is reached first).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.10           |
> | PMTR-54350                     | The API `show access-rule` with the specified values `from-date` or `to-date` in the `hits-setting `parameter, returns accurate data only when these timestamps cover more than the last 24 hours. For example, on May 27th at 14:00, the query must not cover any part of the last 24 hours (between May 26th at 14:00 and May 27th at 14:00).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.10           |
> | PMTR-47133                     | Internal user names must contain only English characters. Names in other languages (unicode) will show as question marks in the Users and Administrators window.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80              |
> | PMTR-41764                     | The "URL" field shows "*\*\*\* Confidential \*\*\**" in HTTPS Inspection logs on 3rd party LEA OPSEC client.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R7x              |
> | Multi-Domain Security Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-62123                     | In Multi-Domain Servers, you cannot create an install policy preset with a policy package that has an OSE device as the target, due to an internal error when trying to get target information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10           |
> | PMTR-60856                     | To correlate logs from the Domain Management Server in a NAT environment, in which a Domain Management Server is hidden behind a NATed address, and a Domain Dedicated SmartEvent Server has an external IP address, an administrator must follow these steps: 1. Connect with SmartConsole to the Domain Management Server 2. Create a dummy Check Point Host object with the external IP address of the Domain Management Server 3. Enable the "Logging" Software Blade in this Check Point Host object 4. Install database on the Domain Management Server 5. Open the SmartEvent GUI and connect to the Dedicated SmartEvent Server 6. In the list of the log servers, from which the Correlation Unit reads the data: remove the Domain Management Server object with the real IP address and add the dummy Check Point Host object (with the external IP address) 7. Install the Event Policy and close the SmartEvent GUI | R81              |
> | Compliance                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-47756                     | In a Multi-Domain Management environment, in the local Domain policy, some Compliance best practices, which validate the status of rules in the policy, incorrectly identify the section header, "Parent section for domain rules," as a rule, and report it as not valid. * **To resolve**: Manually exclude this result from the Best Practices view. To do so, in the Best Practices view, select the practice. In the bottom pane \> Relevant Object section \> double-click the desired rulebase object and disable the rule/section from the list.                                                                                                                                                                                                                                                                                                                                                                         | R80.10           |
> | 02449324, 02478559, PMTR-47761 | In a Multi-Domain environment, policy changes in the Global Compliance Policy do not trigger a partial Compliance scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80.10           |
> | PMTR-47237                     | Compliance Blade does not contain Compliance Overview Report. * **To resolve**and have the Compliance Overview Report, deploy a SmartEvent Server and enable SmartEvent. Then find it at Logs \& Monitoring \> new tab \> Reports \> Compliance Blade.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80              |
> | Logging                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-106428                    | When disconnecting the Security Management Server from the Infinity Portal and connecting to a different region, log sharing from Log Servers does not work until the Log Server restarts. * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 25](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_25.htm)(PRJ-60574)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R82              |
> | PMTR-103823                    | if no log-sharing exporter is created on the MLM Server before the upgrade, the log-sharing exporter is not created after the upgrade. * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 25](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_25.htm) (PRJ-60574)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R82              |
> | PMTR-92829                     | The output of the commands `cpstat mg -f log_server` or `cpstat ls -f logging` on a Security Management Server or Log Server that receives logs from a Maestro Security Group displays Log Receive Rate only for the individual Security Group Member (SMO), and not the combined log receive rate for all Security Group Members in the group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10           |
> | SmartEvent                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-50435                     | On a dedicated SmartEvent Server, the user that was configured in the First Time Configuration wizard cannot share items and view shared items In the SmartView application.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81              |
> | PMTR-66532                     | SmartConsole \> "Logs \& Monitor" view \> "Logs" tab may show duplicate log records with partial data, if log entries are spread over several log files due to a log switch. Log switch operation occurs in these scenarios on a Management Server / Log Server: * At midnight * When the size of the active log file reaches 2 GB * Based on user configuration (explicitly)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.20           |
> | PMTR-47559                     | On a R80.x dedicated SmartEvent Server which assigned to MDS, when you enable or disable a blade, the license information is not immediately updated. An automatic updates takes place at midnight. * **To resolve** and update immediately, ?n Server's command line, run: `$CPDIR/bin/esc_db_complete_linux_50 activation_data entitlement_data`If you manually change a license or contract, the changes take effect immediately.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80              |
> | SmartProvisioning                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-56630                     | When you configure an LSM profile topology, do not reopen interface properties after you make a change. Instead, close the Topology grid and click OK to close the editor. When you reopen it, you will see the correct interface topology settings.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81              |
> | PMTR-49235                     | A new object called "NewObject" is left in SmartConsole when an administrator creates a new object with same name as an object that exists in SmartProvisioning. * **To resolve**: Either click "No" when SmartConsole shows "Do you want to keep changes anyway?" or manually delete the new object called "NewObject".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81              |
> | PMTR-45475                     | The status of an SMB device in SmartProvisioning may show "*not responding*" for a short time, even though the status is OK.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.40           |
> | PMTR-1568                      | When working with LSM managed Security Gateways in a Management High Availability environment, creating and working with LSM Gateways must be consistent, they can only be used in the Security Management Server they are created in. Using the secondary Security Management Server might lead to inconsistent actions/status related to LSM objects.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80.20.M1        |
> | PMTR-70744                     | The "Enable Provisioning" checkbox is greyed out in SmartProvisioning \> SmartLSM Security Gateway object properties \> "General" tab \> "Provisioning" section, if the user who logged into SmartConsole has a profile with assigned permissions other than "Read/Write All".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.10           |
> | PMTR-8209                      | After a major upgrade to a Security Management Server, LSM profiles lose their installed policy and new devices attached to them are not able to fetch a policy. * **To resolve**: Install policy on the LSM profiles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R7x              |

> {#ManagementTable}

*** ** * ** ***

**SmartConsole** / Management Console / SmartLog / SmartView
>
> Enter the string to filter the below table:
>
> {#Management_Console}{#SmartLo}
>
> |-------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Found in version |
> | SmartConsole / Management Console                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | PMTR-109351 | Changing language with Ctrl+F2 may cause SmartConsole to terminate unexpectedly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R82              |
> | PMTR-98504  | There may be a latency in connecting to SmartConsole with an administrator configured on an AD (LDAP) server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-116746 | The Policy Insight dialog may have inconsistent behavior if the screen DPI settings are not set to 100%. * **Resolved** in [R82 SmartConsole Build 1065](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82_SC/R82.00/Build_1065.htm)                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.20           |
> | PMTR-86567  | When using the Updatable objects picker, the search may retrieve previously selected item's additional information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-62190  | When creating a test user via the Mobile Access configuration page, the user's password is limited to 8 characters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-81166  | In a Multi-Domain Environment, when log in with SSO to a Domain behind NAT, the Security Gateway object will load but not open. * **To resolve:** Connect to the Domain directly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.20           |
> | PMTR-71266  | In SmartConsole, the "Get Interfaces" operation in a cluster object does not fetch interfaces with IP addresses from the subnet 1.1.1.0. * **To resolve:** Use the `get-interfaces` Management API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-108389 | "*SmartDashboard not able to connect to XXXX*" error message when there is no connectivity or there are no users to fetch from the LDAP Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.10           |
> | PMTR-70168  | Open connections may not survive VSLS upgrade using SmartConsole Central Deployment.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R81.10           |
> | PMTR-70829  | Central Deployment Package Repository is local to the Multi-Domain Server. In a Multi-Domain High Availability environment, make sure to initiate Central Deployment operations on the Server to which the package was added.                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10           |
> | PMTR-58448  | When the screen resolution is low, changes in Log View widgets are not exported in PDF files: 1. In SmartConsole, from the left navigation panel click Logs \& Monitoring. 2. Click + to open a new tab. 3. From the left, click Views, and open any view. 4. Click Options \> Edit. 5. Make some layout changes - move, resize, delete, or add widgets, and click Done. 6. Click Options \> Export \> Export to PDF. 7. Download the PDF and open it. 8. The PDF file has the default layout.                                                                                                                                                                                                 | R81.10           |
> | PMTR-68527  | When you enter a search query that starts with "\*" in various search fields (for example, \*168.20), SmartConsole shows only objects that contain this partial string in their "Name", "Comment", or "IP Address" field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10           |
> | PMTR-58272  | In the "Gateways \& Servers" view, the "Task" tab in the bottom pane does not show messages about a successful license attachment (shows messages only about a failed license attachment).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10           |
> | PMTR-60830  | A link named "*#.name* " appears in a policy (above the Shared Policies section) in this scenario: 1. From the left navigation panel, click the Security Policies view 2. Open a policy with the HTTPS Inspection 3. Click Access Control \> HTTPS Inspection 4. In the Certificate column, right-click a certificate and select Where Used 5. In the Where Used window, click the Policies tab 6. Double-click a policy that does not contain the Access Control (contains only Threat Prevention or QoS) 7. The policy opens, but instead of HTTPS Inspection section, a link named "*#.name*" appears * **To resolve**: 1. Close the Where Used window 2. Manually open the affected policy | R81.10           |
> | PMTR-78482  | If you delete an existing object of a Centrally Managed Quantum Spark appliance with the model 1800 or lower and some name (for example, "XXX"), then you cannot create another object of a Centrally Managed Quantum Spark appliance: 1. With the same name "XXX" - SmartConsole shows "*Name already used!*" 2. With the name of that contains the previous name (for example, "XXXnew") - SmartConsole shows "*There is another network object \[XXX\] with the same IPv4 address*"                                                                                                                                                                                                         | R81              |
> | PMTR-58838  | Changes (Diff) report: * does not track rule numbers or rule positions in the policy (If a sub-rule is changed, the report only shows the number of the sub-rule and not the number of the parent rule). * does not show changes made in: Inspection Settings, Software Blade Engine settings, Multi-Domain Management Server settings, and administrator settings (including permission profiles and all other options in Manage \& Settings \> Permissions \& Administrators). * In the Changes (Diff) report, there is inconsistency between the number of changes that appear in the session toolbar and the Revisions view.                                                               | R81              |
> | PMTR-42956  | In HTTPS Inspection policy rules, when selecting the same action that already appears in the "Action" column, the Management Server counts it as part of the session changes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.40           |
> | PMTR-38804  | The "Import Node" action (accessible from the SmartConsole Network Object tree \> Nodes \> Import) can fail with "*Internal Error*" message.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.40           |
> | PMTR-31345  | In languages other than English, the blades in the summary tab are not arranged correctly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.30           |
> | PMTR-27705  | When installing a policy, "*The policy included Blades that have an expired contract or a contract that is about to expire*" warnings are displayed only for Application Control and URL Filtering and not for all Service Blades.                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.30           |
> | PMTR-31193  | Search for disabled or expired rules in Access Control policy does not work.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.30           |
> | PMTR-25063  | The "Groups" page / tab is not shown if you edit a predefined service.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.20.M2        |
> | PMTR-39387  | Hitcount of Shared Inline Layer rules shows the sum of all rules it is used in as it is shared between all of them.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.20           |
> | PMTR-50263  | No warning is displayed, if an empty Network Group object appears in the "Source", "Destination", or "Protected Scope" column of a Threat Prevention policy rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.10           |
> | PMTR-40848  | When an inline layer appears more than once in an ordered layer, in logs that are generated from rules in that layer, the "Go to rule" link does not always navigate to the correct occurrence of the rule in the policy. * To find the other occurrences of the rule, use the packet mode search with the rule's information. For more information about packet mode search, refer to [sk118592](https://support.checkpoint.com/results/sk/sk118592).                                                                                                                                                                                                                                         | R80.10           |
> | PMTR-82170  | After upgrading the Security Management Server from to R80.x, users cannot add suggestions to add objects to group - the options are grayed out. Refer to [sk118276](https://support.checkpoint.com/results/sk/sk118276).                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.10           |
> | PMTR-36940  | When selecting a source or destination for a user object, cluster objects are not available for selection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.10           |
> | SmartLog / SmartView                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-55182  | In the Logs view, the sessions timeline widget is missing when connecting to the SmartView web interface of a Dedicated Log Server or a Domain Log Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10           |
> | PMTR-42730  | When viewing logs in the SmartView Web portal, the description fields are empty.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-44559  | When querying logs in the SmartView web Logs tab, the numbers shown in the timeline section do not correlate to the log list if the indexing retention policy in SmartEvent and the Log Server are not the same.                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-45323  | Updatable objects are not resolved in SmartLog/SmartEvent queries: 1. You cannot create a filter or SmartView query which contains an Updatable object name. 2. When viewing logs/events, the IP address of an Updatable object is not resolved to a name.                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.20.M2        |
> | PMTR-47699  | In a global SmartEvent configured in Multi-Domain environment, SAM rules are not created by events auto-reactions. * **To resolve**: refer to [sk86941](https://support.checkpoint.com/results/sk/sk86941).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.10           |
> | PMTR-47589  | Users connected with SmartConsole to specific Domain, will not be able to see Global objects assigned to this Domain in SmartLog logs results, and cannot search by Global objects (but can search by IP address).                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R7x              |

> {#ConsoleTable}

*** ** * ** ***

**Access Control** Mobile Access / DLP
> Mobile Access \| DLP
>
> <br />
>
> Enter the string to filter the below table:
>
> {#Mobile Access}{#DLP}
>
> |------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Found in version |
> | Mobile Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-41608 | Error: "*Failed to generate RADIUS auth request*" when a Mobile Access user browses to a resource that requires authentication.                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | PMTR-70    | If you use Outlook Anywhere application with Mobile Access Reverse Proxy, and then want to disable Outlook Anywhere or Reverse Proxy, perform: 1. Delete Outlook Anywhere rule from reverse proxy. 2. Run `cvpnrestart --with-pinger` to close all Outlook Anywhere open connections. If you do not perform step 2, open connections of Outlook Anywhere will not be closed and users can still work with it.                                                                                                                                                           | R80.10           |
> | PMTR-47782 | After upgrading a Standalone (Management and Gateway) or VSX deployment with Mobile Access blade enabled, the "*Allow Dynamic ID for mobile devices* " option might be enabled by default, even if Dynamic ID was not configured prior to the upgrade. * If you do not want Dynamic ID authentication for Capsule Workspace users, disable it in: Gateway Properties \> Mobile Access \> Authentication \> Compatibility with Older clients \> Settings \> Capsule Workspace section \> clear Enable DynamicID. For VSX, this configuration is done per Virtual System. | R80.10           |
> | PMTR-47499 | When Mobile Access is included in the Unified Access Policy, in Mobile Access Authorization logs \> Log Details \> Matched Rules, the Mobile Access Application name and Category do not show.                                                                                                                                                                                                                                                                                                                                                                          | R7x              |
> | DLP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-47691 | DLP can apply visible or hidden Watermark (for forensic tracking) to Office Open XML formats (DOCX, PPTX and XLSX) as a rule action in a DLP rule base. Refer to [sk117413](https://support.checkpoint.com/results/sk/sk117413) if DLP Watermark is used.                                                                                                                                                                                                                                                                                                               | R80.10           |

> {#AccessTable}

*** ** * ** ***

**Threat Prevention**
>
> Enter the string to filter the below table:
>
> {#Anti-Malware}
>
> |-------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID          | Description                                                                                                                                                                                                                                                                                                                                                                                                                            | Found in version |
> | Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
> | PMTR-107710 | The "DNS Mismatched replies" IPS protection does not work after upgrade to R82.                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | PMTR-107493 | DNS NAT does not work on R82 Security Gateways.                                                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | PMTR-107712 | In some scenarios, DNS Trap may fail to replace DNS replies with bogus IP addresses on certain connections, resulting in dropped connections. This prevents affected hosts from receiving the intended IP address but also limits the visibility into which host IPs are impacted.                                                                                                                                                     | R82              |
> | PMTR-85353  | When you activate Threat Emulation with the "Hold" mode, Threat Extraction, Zero Phishing, or Anti-Virus Deep Inspection, the Security Gateway downgrades the relevant connections from HTTP/2 to HTTP 1.1. To force HTTP/2, run this command on the Security Gateway / Security Group / each Cluster Member: `fw ctl set -f int disable_http2_with_strict_hold 0` Limitation: Zero Phishing will keep downgrading HTTP/2 to HTTP 1.1. | R81.20           |
> | PMTR-80495  | An exception in an Anti-Virus or Anti-Bot protection added manually to the rule base does not work. * To add an exception in an Anti-Virus or Anti-Bot protection, open the corresponding Security Gateway log in SmartConsole and click the link "Add Exception".                                                                                                                                                                     | R81.20           |
> | PMTR-76710  | When Security Gateways use an Autonomous Threat Prevention policy: * Compliance Best Practices do not support the checks for the Threat Prevention Software Blade. * The Compliance Software Blade may show an incorrect status for the Threat Prevention checks.                                                                                                                                                                      | R81.20           |
> | PMTR-19839  | CRL validation is not supported in pure IPv6 environments (when IPv4 addresses are not configured on the Security Gateway's interfaces).                                                                                                                                                                                                                                                                                               | R80.20           |

> {#ThreatTable}

*** ** * ** ***

**Endpoint Security**
> {#Endpoint Security}
>
> |------------|----------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                  | Found in version |
> | Endpoint Security / SmartEndpoint                                                                                          |||
> | PMTR-68226 | The Perfect Forward Secrecy (PFS) feature supports only Diffie-Hellman (DH) groups 2 and 14. | R81.10           |

*** ** * ** ***

**Quantum Spark Gateways**
> {#Small Office Appliances}
>
> |------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                                                                                      | Found in version |
> | Quantum Spark Gateways                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-47520 | "*SIC error*" status may occur when the Gateway object is defined in a "Management first" scenario before it is deployed, but the device's IP address is already accessible. The Security Management tries to create SIC with the Gateway's IP address. Instead of the policy ending in a "waiting for first connection" status, an error message states the SIC status must be rectified first. | R7x              |

*** ** * ** ***

**ElasticXL, Maestro, and Scalable Chassis**
> General Limitations \| Gaia OS \| VSX \| CoreXL \| Networking \| VPN
>
> <br />
>
> Enter the string to filter the below table:
>
> {#KL_General}{#KL_GaiaOS}{#KL_VSX}{#KL_CoreXL}{#KL_Networking_Features}{#KL_SBVPN}
>
> |--------------------------|--------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                       | Product            | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Found in version |
> | ElasticXL, Maestro, and Scalable Chassis - General Limitations                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||||
> | PMTR-107075              | ElasticXL          | ElasticXL Cluster supports only physical Check Point appliances (Virtual Machines or Open Servers are not supported).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-107076              | ElasticXL          | ElasticXL Cluster supports only Check Point appliances of the same model.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R82              |
> | PMTR-107077              | ElasticXL          | ElasticXL Cluster requires each appliance to be after a Clean Install or restored to factory defaults.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | PMTR-107078              | All                | ElasticXL Cluster requires the supported Check Point appliance to run SecureXL in the Kernel Mode (KPPAK). The Gaia First Time Configuration Wizard automatically changes the SecureXL mode from UPPAK to KPPAK on the supported appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-111692              | Maestro            | If a Maestro Security Group (in the VSNext mode or Traditional VSX mode) is configured with MAGG, then adding a new Mgmt interface to this Security Group in Gaia gClish or with API may fail because the Gaia database lock is continuously lost. During this issue, the `/var/log/messages` file repeatedly shows: `cmd by admin: Start executing : add bonding ...` `cmd by admin: Start executing : delete bonding ...` Refer to [sk183031](https://support.checkpoint.com/results/sk/sk183031).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R82              |
> | PMTR-109641              | Maestro            | In rare scenarios, after installing R82 on Maestro Orchestrator, the LLDP daemon (lldpd) is running but paused, and therefore does not transmit or process LLDP PDUs. As a result, MHO cannot communicate with the gateways. * **To resolve:**From the Expert mode, run on MHO: `lldpcli resume`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R82              |
> | PMTR-109620              | Maestro            | In rare scenarios, authentication between MHOs is not established. Trying to establish authentication manually fails with error: `"TrustEstablishmentError: Failed to set up communication user on host 1_1: invalid literal for int() with base 10"` * **To resolve:** * look for an available UID in the range 105-1000 using the command: `dbget -rv passwd | grep :uid | awk -F' ' '{{print $2}}' | uniq | sort -n` * using the chosen UID, run `dbset passwd:mho_comm:uid <some_available_uid>` * Run `dbset:save` * Perform authentication manually. * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 44](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_44.htm) (PRJ-58127)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | HCP-1082                 | Maestro            | HCP on MHO may fail because of timeout expiration since execution is on all MHOs in parallel                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-97177               | All                | The `set backup restore ftp` command performed via gClish is not applied on all the Security Group members but only on the SMO member. * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 118](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_118.htm)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R82              |
> | PMTR-104761              | Chassis            | On Scalable Chassis, after you move an SGM from one chassis to another, it is necessary to reboot the SGM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R82              |
> | PMTR-108738              | All                | During the upgrade of Scalable Platform Security Group Gateways, SSH keys are deleted. * **Resolved** in [R82 Jumbo Hotfix Accumulator Take 14](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_14.htm) (PRJ-58561)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-109848              | All                | Scalable Platform Site grade is not affected by the number of active subordinate interfaces in a LACP bond interface. Therefore, LACP bond failover is not triggered if all of the subordinate interfaces become inactive in the LACP bond interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81              |
> | PMTR-93476               | All                | Management Aggregation (MAGG) bond mode is available only through the gClish of the Security Group (and not via the Gaia portal).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.20SP         |
> | PMTR-111361, MBS-6188    | All                | * The Active-Backup bond is supported only when a Primary slave is configured (for example: `set bonding group 1 primary eth1-05`). * The Active-Backup bond supports a maximum of 2 slaves.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20SP         |
> | PMTR-111372, MBS-14811   | Maestro            | Maestro Orchestrators and Security Group CIN interfaces are configured in the subnet of 198.51.10\<SG_ID\>.0. You cannot use this subnet for data and management interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20SP         |
> | PMTR-109475, 02439227    | Chassis            | Scalable Chassis 44000 support PXE installation on Slot 6 (SGM 2_06 / SGM 1_06) by changing the kdevice to eth3.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R76SP.50         |
> | PMTR-109479, 00738754    | Chassis            | If SGMs lose connectivity to the CMM, the `asg stat` command displays the most recent status of the system. For example, a chassis module that was "UP" before the CMM lost connectivity, continues to have the status "UP". The state of the CMM is changed to "DOWN".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R76SP            |
> | PMTR-109467, 00894653    | Chassis            | Transceivers for the Scalable Chassis are not interchangeable with transceivers from other Check Point appliances. Only transceivers provided with the Scalable Chassis are certified for this system.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R76SP            |
> | ElasticXL, Maestro, and Scalable Chassis - Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ||||
> | PMTR-114355              | ElasticXL, Maestro | In the VSNext mode (on ElasticXL and Maestro Security Groups), the Gaia gClish / Gaia Clish command "`show interface`" in the context of Virtual Switches fails with *"CLINFR0699 Invalid command"*.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R82              |
> | PMTR-107433              | ElasticXL          | Adding an unassigned interface to or from Sync bond leads to the flags reset and, as a result, it disrupts the ElasticXL detection and ElasticXL drops the packets.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82              |
> | PMTR-109292              | All                | Configuring a Unique IP per Site over the management interface is not possible if Management Data Plane Separation (MDPS) is enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-71458               | Maestro            | Collecting Gaia Backup and restoring Gaia Backup in Global Clish (gclish) is not supported on a Security Group that contains appliances of different models. * To collect Gaia Backup and restore Gaia Backup, you must use Gaia Clish (clish) on each appliance in the Security Group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10           |
> | PMTR-111391, MBS-7069    | Maestro            | Remote authentication for the Expert mode using RADIUS / TACACS+ Servers with the Gaia gClish command "`set expert-authentication-method {shared-password | user-password}`" is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.30SP         |
> | PMTR-111365, MBS-7593    | Maestro            | On a Maestro Security Group, the Security Gateway does not show the correct speed of data and management interfaces. Run commands on the Orchestrator (the `orch_stat -p` command and Clish commands) to see the interface speed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.30SP         |
> | PMTR-111389, MBS-964     | All                | A Security Group cannot be configured as an NTP Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20SP         |
> | PMTR-111376, MBS-5177    | Maestro            | Maestro Security Groups do not support these Gaia Clish commands: * `set chassis id VALUE alert_threshold cpus_temperature_threshold_low VALUE` * `set chassis id VALUE alert_threshold fans_threshold_high VALUE` * `set chassis id VALUE alert_threshold fans_threshold_low VALUE` * `set chassis id VALUE alert_threshold power_consumption_threshold_perc_high VALUE` * `set chassis id VALUE alert_threshold power_consumption_threshold_perc_low VALUE` * `set chassis id VALUE modules_amount cmm VALUE` * `set chassis id VALUE modules_amount fans VALUE` * `set chassis id VALUE modules_amount power_units VALUE` * `show chassis high-availability factors sensor cmm` * `show chassis high-availability factors sensor fans` * `show chassis high-availability factors sensor power_supplies` * `show chassis id VALUE alert_threshold cpus_temperature_threshold_high` * `show chassis id VALUE alert_threshold cpus_temperature_threshold_low` * `show chassis id VALUE alert_threshold fans_threshold_high` * `show chassis id VALUE alert_threshold fans_threshold_low` * `show chassis id VALUE alert_threshold power_consumption_threshold_perc_high` * `show chassis id VALUE alert_threshold power_consumption_threshold_perc_low` * `show chassis id VALUE modules_amount cmm` * `show chassis id VALUE modules_amount fans` * `show chassis id VALUE modules_amount power_units`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20SP         |
> | PMTR-111373, MBS-14992   | All                | To prevent the Gaia configuration mismatch between Security Group Members, it is not supported to change the user's password on a Security Group in these ways: * In Gaia Portal \> User Management \> Change My Password * In Gaia gClish with the command `set selfpasswd` To change the user's password on a Security Group, run one of these commands in Gaia gClish: * `set user <UserName> password` * `set user <UserName>password-hash <Password Hash>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.20SP         |
> | PMTR-111388, MBS-6947    | Maestro            | In Dual Site deployment, no warning is displayed when changing the "type" of the QSFP port in Gaia Clish on Maestro Hyperscale Orchestrators on the local site, while the Maestro Hyperscale Orchestrators on the remote site are down.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20SP         |
> | PMTR-109472, 02434343    | Chassis            | On SSM440, the error `"Dot3Ah: Failed getting variable from bm"` may appear when running the `system reload` command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R76SP.50         |
> | PMTR-109473, 02169635    | Chassis            | On SSM440, the MTU is limited to a maximum of 9000 bytes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R76SP.50         |
> | PMTR-109474, 01237799    | All                | When you run multiple Gaia gClish `set <...>` commands, one after another, some of these commands can stop running. When this happens, the message `"Processing Transaction"` shows in the output.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R76SP            |
> | PMTR-108599, 00738300    | All                | The `asg` commands are an extension of native Gaia gClish commands. The `asg` commands have different syntax and there is no auto-completion.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R76SP            |
> | PMTR-109471, 01255170    | Chassis            | For monitoring Scalable Platforms over the SNMP, the only supported OIDs are under `iso.org.dod.internet.private.enterprise.checkpoint.products.asg (OID 1.3.6.1.4.1.2620.1.48)`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R76SP            |
> | PMTR-108600, 00642401    | All                | A CLI command that uses a range for the parameter can only operate if all the relevant SGMs are defined in the security group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R76SP            |
> | PMTR-108601, 00633262    | All                | The arguments of the global commands are processed before the local (native) arguments, and this can cause the local arguments to be ignored. For example, the `g_ls -l /tmp/` command is processed as `ls /tmp/` on the local SGM instead of as `ls -l /tmp/` on all SGMs. Relocating the local arguments within the command (where applicable) can resolve the problem. For example, run the `g_ls /tmp/ -l` command instead of the `g_ls -l /tmp/` command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R76SP            |
> | PMTR-108602, 01089206    | All                | Running the `asg_hard_shutdown` command on an SGM two times, one after the other, causes a reboot and not a shutdown. It takes one minute for the SGM to shut down after running the `asg_hard_shutdown` command. During this interval, do not run the `asg_hard_shutdown` command again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R76SP            |
> | ElasticXL, Maestro, and Scalable Chassis - VSX                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                ||||
> | PMTR-110224, PMTR-108696 | ElasticXL          | VSLS (Virtual System Load Sharing) is not supported in the VSNext mode. * **Resolved** in [R82 Jumbo Hotfix Take 14](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/Take_14.htm) (PRJ-58348)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82              |
> | PMTR-106379              | ElasticXL          | In ElasticXL in the VSNext mode (with 2 or more Security Appliances on one ElasticXL Site), VoIP UDP traffic is not supported between networks in this topology: Network 1 - Virtual System 1 - Virtual Switch - Virtual System 2 - Network 2                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R82              |
> | PMTR-108547              | ElasticXL          | No information is shown on both servers when attempting to see the LLDP (lldpneighbors) between Security Management and a Virtual Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R82              |
> | PMTR-113662              | All                | In a Dual Site VSX VSLS environment, when using MVC (Multi-Version Cluster), it is required to change a site priority of the Virtual System on both sites in order to change the active site for a given Virtual System.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.20           |
> | PMTR-111446, MBS-6572    | Maestro            | A change in the number of CoreXL Firewall instances (in a VSX Virtual System object in SmartConsole) in Dual Chassis VSLS setup requires a downtime, because the Virtual System must be restarted. During this restart, traffic cannot pass through the Virtual System.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20SP         |
> | PMTR-109478, 02024482    | All                | After running the `vsx_util reconfigure` command on the Management Server, the VLAN interface on a Security Group in VSX mode may come up without an IP address if the VLAN's MTU was set to a value larger than 1500. Refer to [sk111513](https://support.checkpoint.com/results/sk/sk111513).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R76SP.40         |
> | PMTR-109469, 01812597    | All                | No local configuration should be performed on a Security Group or on a Security Group Members while the `vsx_util reconfigure` command is running on the Management Server. It is necessary to wait until all Security Group Members and Virtual Systems are up and running (otherwise, the local configuration will not be applied).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R76SP.30         |
> | PMTR-109468, 01620389    | All                | You cannot configure Bond interfaces on chassis Management ports after you create the VSX object in SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R76SP.20         |
> | PMTR-109477, 01087321    | Chassis            | VSX Gateway creation in SmartConsole and the `vsx_util reconfigure` command are supported when only the left-most SGM is in the Security Group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R76SP            |
> | PMTR-108604, 01284809    | Chassis            | To use the Sync Lost mechanism, you must keep the Management interfaces for both chassis connected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R76SP            |
> | PMTR-109476, 00922958    | All                | The Alerts configuration wizard does not allow setting of performance thresholds per Virtual System. * **To resolve:** You can manually configure thresholds for Virtual Systems using the `dbset` command from the Expert mode: `g_all dbset chassis:vs:0:alert_threshold: <alert_name> <value>` Where `<value>` is the percentage of the default threshold per Security Group Member. Example: `[Expert@Host]# g_all dbset chassis:vs:0:alert_threshold:packet_rate_threshold_high 30` In this example, an alert is triggered when any Virtual System packet rate is higher than 30% x 1.8MB (1.8MB is the default packet rate threshold per SGM). Note: One ratio applies to all Virtual Systems.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R76SP            |
> | PMTR-109465, 01097957    | All                | If you lower the Connections Table limit of a Virtual System, and one of the SGMs has more or the same number of connections than the limit, the new value is rejected for that SGM. The new Connections Table limit may be accepted by other SGMs. Notes: * To see the current number of entries in the Connections Table, run the `fw tab -t connections -s` command in the Expert mode. * To configure the Connections Table limit of a Virtual System: In SmartConsole, open the Virtual System object \> Go to the "Capacity Optimization" pane \> Set the value in the "Limit the maximum concurrent connections" field \> click OK \> Install the policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R76SP            |
> | PMTR-109466, 01341918    | All                | You cannot enable IPv6 before you create and configure a new VSX Gateway. You must first create the new VSX Gateway and then enable and configure IPv6 using Gaia gClish.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R76SP            |
> | ElasticXL, Maestro, and Scalable Chassis Known Limitations - CoreXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           ||||
> | PMTR-74532               | All                | To make sure there is connectivity after changing the number of instances in the CoreXL configuration, follow these steps: 1. Reboot all Security Group Members one by one, **except the SMO**. **IMPORTANT: Traffic capacity is greatly reduced after you reboot all Security Group Members except the SMO, because only the SMO handles traffic until it is rebooted.** **Examples**: In a Dual Site deployment with four Security Group Members (two on each Site), where the SMO is "1_1", reboot the Security Group Members in this order: 1. Reboot the Security Group Member 2_2 on Site 2 and wait for it to finish the reboot. 2. Reboot the Security Group Member 2_1 on Site 2 and wait for it to finish the reboot. 3. Reboot the Security Group Member 1_2 on Site 1 and wait for it to finish the reboot. In a Single Site deployment with four Security Group Members, where the SMO is "1_1", reboot the Security Group Members in this order: 1. Reboot the Security Group Member 1_4 and wait for it to finish the reboot. 2. Reboot the Security Group Member 1_3 and wait for it to finish the reboot. 3. Reboot the Security Group Member 1_2 and wait for it to finish the reboot. 2. When a Security Group Member finishes the reboot, it enters the "DOWN" state because of a mismatch in the number of CoreXL Firewall instances with other Security Group Members. All other Security Group Members that were not rebooted yet, including the SMO, are in the "ACTIVE!" state (Active Attention) and handle traffic. 3. When all Security Group Members except the SMO have finished the reboot, you must reboot the SMO Security Group Member. A failover occurs immediately, and one of the other Security Group Members becomes the SMO. All other Security Group Members become "ACTIVE" and start to handle traffic. 4. When the last Security Group Member, which was the SMO, finishes the reboot, all Security Group Members become "ACTIVE" and full capacity is restored. | R80.20SP         |
> | ElasticXL, Maestro, and Scalable Chassis Known Limitations - Networking                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||||
> | PMTR-106002              | Maestro            | On Quantum Maestro, where Security Appliances are connected to two Maestro Orchestrators, rebooting one of these Orchestrators (or running the `orchd restart` command on one of these Orchestrators) causes a 10-second disruption in the sync traffic between Security Group Members. If a Security Group is configured in the VSX mode, this may affect the data traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10           |
> | PMTR-111381, MBS-2199    | All                | After a failover of the FTP control connection it is not possible to open an asymmetric FTP data connection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20SP         |
> | PMTR-109470, 02487403    | Chassis            | SSM Layer4 Distribution Mode is supported for IPv4 only. The IPv6 traffic will be distributed based on the Source/Destination IP addresses only. Note: a system can use SSM Layer4 Distribution Mode while IPv4 and IPv6 are inspected by the Security Gateway. Each IP version will use a different mechanism to distribute traffic, as described above.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R76SP.50         |
> | ElasticXL, Maestro, and Scalable Chassis Known Limitations - VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ||||
> | PMTR-108430              | All                | Performing Hide NAT on Remote Access VPN connection (on the decrypt connection) with L4 distribution enabled may lead to NAT port collisions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10           |
> | PMTR-111380, MBS-5242    | All                | VPN traffic on a VSX Virtual System that is connected to a VSX Virtual Switch is supported only when the distribution mode configured for the WRP interface is the same as the distribution mode configured for the physical interface on the VSX Virtual Switch. Example of a VSX topology: (Virtual System) == wrp100 == (Virtual Switch) == (eth1-01) The same distribution mode must be configured for the interface wrp100 as was configured for the interface eth1-01.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20SP         |

> {#ScalableTable}

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
