> Source: [sk181129](https://support.checkpoint.com/results/sk/sk181129)

# sk181129 - Check Point Quantum R82 Resolved Issues and Enhancements

| Property | Value |
|----------|-------|
| Solution ID | sk181129 |
| Date Created | 2023-06-14 |
| Last Modified | 2026-05-26 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82, R82 |
| OS | Gaia |

## Solution

### This article lists all new features and issues that have been resolved in Check Point Quantum R82 Release.

* The R82 Release accumulates all fixes from previous releases, including fixes from

  * [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm)**Take 89**(except fixes for PRJ-56237, PRJ-56616 and PRJ-57108)
  * [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm)**Take 170**
  * [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm)**Take 99**
* For more information about R82, see the [R82 Release Notes](https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RN/Default.htm), [R82 Home Page](https://support.checkpoint.com/results/sk/sk181127) and [R82 Known Limitations](https://support.checkpoint.com/results/sk/sk181128).

* Visit [Check Point CheckMates Community](https://community.checkpoint.com) to ask questions or start a discussion and get our experts assistance.

*** ** * ** ***

**Quantum Security Management \| Management High Availability \| SmartConsole \| Multi-Domain Security Management \| Logging \| Compliance
Quantum Security Gateway \| Identity Awareness \| Threat Prevention \| Mobile Access \| SSL Network Extender
Gaia OS \| Routing \| VPN \| VSX \| SecureXL \| CoreXL \| CloudGuard Controller \| Quantum Maestro and Scalable Chassis \| Endpoint Security**  

List of Resolved issues, New Features and Enhancements in Quantum R82 Release
-----------------------------------------------------------------------------

<br />

Enter the string to filter the below table:

{#Quantum Security Management}{#Management High Availability}{#SmartConsole}{#Multi-Domain Security Management}{#Logging}{#Compliance}{#Quantum Security Gateway}{#Identity Awareness}{#Threat Prevention}{#Mobile Access}{#SSL Network Extender}{#Gaia OS}{#Routing}{#VPN}{#VSX}{#SecureXL}{#CoreXL}{#CloudGuard Controller}{#Quantum Maestro and Scalable Chassis}{#Endpoint Security}

|------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| ID                                             | Symptoms                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| **Quantum Security Management**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||
| PMTR-47450                                     | **UPDATE:** Added support for `login`, `logout`, `discard` and `publish` commands in the SmartConsole's CLI.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| PMTR-89544                                     | **Enhancement** : The `import-management` command now includes a new `change-ip` parameter, which replaces the JSON *change-ip* configuration file, allowing administrators to inform all Servers in a Security Management environment about IP address changes when one or more Servers migrate to new IP addresses.                                                                                                                                                                                                                                                                                                                                              |
| PMTR-105561                                    | When passing a group parameter to the `set-host` command, and the host is already a part of this group, the host will no longer be removed and re-added to it. This prevents a redundant change from occurring.                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| PMTR-37712                                     | It is now possible to add updatable objects to network groups.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| PMTR-87634                                     | Connecting a Quantum Security Management Server to Infinity Portal is now supported in the Full High Availability Cluster (when each Cluster Member runs a Security Management Server and a Security Gateway).                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| PMTR-68625, PMTR-90912, PMTR-76791, PMTR-76792 | When installing the Access Control Policy on a Security Gateway with an enabled VPN blade, the policy installation succeeds but shows this message: "*dlopen: /opt/CPsuite-R8x.x/fw1/tmp/install_policy/\<UID\>/FW1/lib/libcpatlas.so: cannot open shared object file: No such file or directory*".                                                                                                                                                                                                                                                                                                                                                                |
| PMTR-59442                                     | SmartConsole may show the popup "*SmartDashboard component failed to connect to server \<IP Address\>*" if you upgraded a Management Server and you open a Security Gateway / Cluster object for the first time after the Server's upgrade.                                                                                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-95294                                     | SAML login in SmartConsole fails when Gaia Portal on the Management Server runs on a different port than 443. See [sk182032](https://support.checkpoint.com/results/sk/sk182032).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-47116                                     | After installation, the Device License Status shows N/A and the Device License View is not accessible until policy or database are installed. When blades are enabled or disabled, the changes are not visible in the Device License Views and Status until policy or database are installed.                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-47108                                     | Automatic license activation on a Multi-Domain Management Server machine works only on the MDS level and not on the Domain level.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-105923                                    | SmartConsole may get disconnected when installing a policy on more than five hundred targets.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| **Management High Availability**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   ||
| PMTR-47159                                     | When a secondary Management Server is added, the initial synchronization task starts automatically. Until it completes, the secondary peer status shows as "*Failed to communicate with peer*".                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **SmartConsole / Management Console**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ||
| PMTR-94041                                     | **Enhancement:** Added the CLI tool `$FWDIR/scripts/api_log_to_json.py` to get the API usage information (common calls, calls per unit time, and so on) from the API logs. See [sk181906](https://support.checkpoint.com/results/sk/sk181906).                                                                                                                                                                                                                                                                                                                                                                                                                     |
| PMTR-91293                                     | **Enhancement:** Added support of Smart-1 Cloud in the "Show Policy Package" tool. Use new flags: `--cloud-mgmt-id` and *-* `-api-key` to authenticate with the Smart-1 Cloud Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| PMTR-92425                                     | **Enhancement:** When a SmartConsole update is ready to be installed, the user can opt to have the version skipped by the automatic update process. It is still possible to install the update manually by selecting "Check for Update" from the main menu.                                                                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-89334, PMTR-90112                         | **Enhancement:**The "Change Report" feature in SmartConsole now supports all SmartConsole languages.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| PMTR-93105                                     | **Enhancement:** The Management Console is updated to .NET 4.8.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| PMTR-104160                                    | **Enhancement:**Improved the load time of a large number (above 4500 objects) of satellite and participant gateways view in the VPN Community tab.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| PMTR-82157                                     | **Update:**HTTP Inspection view was moved to SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| PMTR-87494                                     | **Update:**Added the "High Availability" section to the Security Gateway Editor \> ClusterXL \> Cluster Member Priority.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-101601                                    | When creating a Custom Report in SmartConsole, the "Malware Action" entry appears two times. Refer to [sk182049](https://support.checkpoint.com/results/sk/sk182049).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| PMTR-105768                                    | In some scenarios, when an authorized administrator loads the information about a submitted change, the change report may get stuck.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| PMTR-94546, PRHF-29733                         | When there are more than 100,000 network objects on a Security Management Server or within a Domain on a Multi-Domain Security Management Server, certain applications, such as Mobile Access SmartDashboard, SmartView Monitor, and the GUI Dbedit tool, may fail to load or may close shortly after starting.                                                                                                                                                                                                                                                                                                                                                    |
| PMTR-81158                                     | In Desktop SmartConsole, rule can expire even in the Expiration status is set to "Never".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-88932                                     | In the past, when a user cloned a network object in an Access Control rule, the cloned object was created but not shown in the rulebase. Now, the cloned object also appears in the Access Control rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-98514                                     | In the Threat Emulation first time activation flow, there is no option to ignore warnings. The "Next" button is disabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-57122                                     | Searching part of a phrase surrendered by asterisks now highlights only the relevant text.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| PMTR-97420                                     | Desktop SmartConsole may freeze when selecting a client in the "RADIUS Accounting Settings" window in a Security Gateway object with the Identity Awareness Software Blade enabled. See [sk181630](https://support.checkpoint.com/results/sk/sk181630).                                                                                                                                                                                                                                                                                                                                                                                                            |
| PMTR-42889                                     | The "*Could not locate an appropriate editor for the target object*" message appears in SmartConsole in the HTTPS Inspection Policy, when double-clicking a certificate object.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| PMTR-48072                                     | The "Restore all messages" button is disabled in Manage \& settings \> Preferences \> User Preferences \> "Restore all messages".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-44457                                     | Error: "*Error while trying to open certificate : The specified network password is not correct.*" when attempting to view a new HTTPS certificate that uses a password different from the previous one.                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-62419                                     | When you add an Updatable Object in a rule, you must wait for the object to load its data (see the sign for loading near the object). If you add an Updatable Object before it loads its data, all the sub-objects are added in the rule cell instead.                                                                                                                                                                                                                                                                                                                                                                                                             |
| PMTR-91258                                     | Added support for Management API calls to configure "Limit" objects (Object Explorer \> New \> Limit).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| PMTR-81196                                     | After renewing the outbound HTTPS Inspection certificate, the "View certificate" button in the Security Gateway object editor may show the "*Error while trying to open certificate: The specified network password is not correct*" error.                                                                                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-83632, PMTR-86822                         | Management API call `get-interfaces` (available in API v1.7.1 and above) now supports a Security Gateway object that represents a Security Group on Maestro or Scalable Chassis.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| PMTR-87666, PMTR-87667                         | If in a Network Feed object or IoC Feed object, you select the object of a Full High Availability cluster and click "Test Feed", the test fails with this error: *"Connection failed for \<Cluster Virtual IP address\>* *Make sure that the machine is up and running, and that SIC has been established"*                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-97179                                     | When configuring an LDAP Account Unit object in SmartConsole, clicking the "Fetch branches" button on the "Objects Management" tab does not populate the section "Branches in use" if the LDAP Server runs on Windows 10.                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-99014                                     | ?nabling/disabling rules in a rule base, followed by switching to another layer of the policy, incorrectly displays rules in the other layer as "enabled/disabled".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| PMTR-47540                                     | SCTP or Diameter objects cannot be the service of a manual NAT rule. Static NAT will still be applied for rules that match SCTP if the service is set to "Any". All NAT methods can be applied for Diameter over TCP traffic if the service is set to "Any".                                                                                                                                                                                                                                                                                                                                                                                                       |
| PMTR-98148                                     | Partial search without a wildcard character in SmartConsole Objects Explorer and Objects sidebar does not find objects. Refer to [sk182006](https://support.checkpoint.com/results/sk/sk182006).                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| **Multi-Domain Security Management**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               ||
| -                                              | **Enhancement:** Configuring an IPv6 address in addition to the configured IPv4 address is now supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-47622                                     | In some scenarios, re-assign or removal of global assignments succeeds, but changes that were not yet published at the Domain become conflicted. The SmartConsole for the Domain becomes unstable and can show: "*Could not load selected policy*".                                                                                                                                                                                                                                                                                                                                                                                                                |
| PMTR-47629                                     | When running Global Domain Assignment on one Multi-Domain Server for a Domain that is active on a different Multi-Domain Server, the task can stall at 5%. After a few minutes a message shows: "*timeout during task progress: Could not get information regarding task completion from MDS_1 'MDS_2"*.                                                                                                                                                                                                                                                                                                                                                           |
| **Logging**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| PMTR-93080                                     | **Enhancement:** Export to CSV limit in SmartView for Smart-1 Cloud and Harmony Endpoint has been raised from 1K to 10K logs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-79606                                     | **Update:** You can now add `tcp_state` and `tcp_flag` fields when editing column profiles in the Logging tab and see them in the Access Log Details view.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| PMTR-84784                                     | The Log tab in the Logs \& Monitor view repeatedly shows a "*Query failed* " message. To resolve this, log field values are replaced with "N/A" if the original value includes unsupported XML characters that cannot be parsed.                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| PMTR-92968                                     | SmartEvent does not send an automatic reaction email for Pre-Defined Generic IPS events.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-96010                                     | Log card in SmartConsole shows a port number in the "Service" field for the ICMP traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-83576                                     | In rare scenarios, SmartConsole unexpectedly closes when opening the Logs \& Monitor view.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| **Compliance**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     ||
| PMTR-103227                                    | **Enhancement:** Added [ISO/IEC 27001](https://www.iso.org/standard/27001) 2022 regulation to Compliance blade.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |
| **Quantum Security Gateway**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| PMTR-56389                                     | "*Authentication failure: check your username and password* " message on a Security Gateway when raising the "TACP" privileges of a TACACS user in the following scenario: 1. Configured the Management Data Plane Separation (MDPS) as described in [sk138672](https://support.checkpoint.com/results/sk/sk138672). 2. Configured Gaia OS roles with different privileges for TACACS users. 3. Configured a TACACS Server. 4. Logged in with a TACACS user. 5. Raised the "TACP" privileges in Gaia Portal (at the top of the "Overview" page, clicked "Enable") or in Gaia Clish (with the `tacacs_enable <Role>` command). 6. Entered the TACACS user password. |
| PMTR-56297                                     | In a rare scenario, the Security Gateway may crash and reboot if multiple slave interfaces are deleted at the same time from an 802.3AD bond interface (for example, with the `clish -f` command).                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| **Identity Awareness**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             ||
| PMTR-98732                                     | **Enhancement:** In the Identity Awareness PDP daemon, some CPU-intensive tasks were moved to a dedicated thread ("pdp update all", "pdp update specific", automatic group update).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **Threat Prevention**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ||
| PMTR-89387                                     | **Enhancement:** Improved performance for some connections in Threat Prevention.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| PMTR-87269                                     | Installation of Threat Prevention Policy fails with the error "*No profile defined on GW \<Name of Security Gateway Object\>* " in this scenario: 1. The "Install On" column of a Threat Prevention rule contains a Group object (Group #1) 2. This Group object (Group #1) contains another Group object (Group #2) 3. This nested Group object (Group #2) contains the Security Gateway object                                                                                                                                                                                                                                                                   |
| **Mobile Access**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  ||
| PMTR-87907                                     | Mobile Access ignores a Web application object's GuiDBedit attribute "*enable_floating_navigation_bar*", which controlls whether the Web application's pages render a Floating Navigation Bar (FNB).                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| PMTR-102830                                    | SmartView shows "*Error in disconnecting user* " message with the description "*SNX connection failed*" every time the user opens the main page of the Mobile Access portal.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **SSL Network Extender**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           ||
| PMTR-87429                                     | When trying to connect SSL Network Extender inside Secure Workspace, the portal page may stuck in the "Connecting" state, while outside Secure Workspace it works.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| PMTR-83342                                     | When HTTPS Inspection is enabled, the Security Gateway generates a log that includes the message "*Certificate Chain is not signed by a Trusted CA*" when an end-user connects to an HTTP site or a site with an untrusted SSL certificate. But, in some cases, the log does not include this text.                                                                                                                                                                                                                                                                                                                                                                |
| **Gaia OS**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| PMTR-78528                                     | When TACACS and RADIUS Servers are configured together, TACACS users fail.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| PMTR-89795                                     | In Gaia portal \> Network interfaces, when configuring an IPv4 interface without entering a Subnet mask, the OK button does not respond and the "*IPv4 address is empty*" error pops up.                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-87844                                     | Cpview history displays "N/A" value for the "Dynamic Balancing Status" field of the Configuration Information in SysInfo.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Routing**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||
| PMTR-71868                                     | OSPF route flags are now synchronized between cluster members.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| PMTR-100454                                    | The Gaia Clish command `set ospf instance default rfc1583-compatibility` is missing the `on` parameter.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| **VPN**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            ||
| PMTR-92197                                     | Endpoint Security VPN / Check Point Mobile / Remote Access clients fail to connect using Machine Certificate Authentication when the certificate has OCSP and CRL, but the Security Gateway is unable to resolve the OCSP or to get a proper answer from the OCSP Server.                                                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-91711                                     | It is now possible to configure SHA-384 and SHA-512 algorithms for IKE negotiation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **VSX (Traditional)**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ||
| PMTR-87534                                     | **Enhancement:** Added a column for IP/Mask length for Virtual System in Bridge mode to the table in `vsx_util view_vs_conf`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-104867                                    | **UPDATE:**Added Automatic Onboarding to Check Point Nano-Agent Installation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-106133                                    | When Hyperflow is enabled, after reboot, the outputs of `vsx stat -v` command shows that virtual systems loaded default filter. Refer to [sk182453](https://support.checkpoint.com/results/sk/sk182453).                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-88875                                     | In `vsx_util vsls` command, when setting priority and weight manually, VSs are chosen by typing the full name of the VS instead of choosing from a list.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-88874                                     | In `vsx_util` command, old interface cannot be removed when changes are applied to both Security Management and Security Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-87205                                     | When running `vsx_fetch` from a context that is not VS0, this confusing output is displayed: ... `Management rejected fetch for this module - sic name does not match.` `Couldn't fetch VSX configuration by IPs, trying to fetch by names`                                                                                                                                                                                                                                                                                                                                                                                                                        |
| **SecureXL**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       ||
| PMTR-107557                                    | IPX traffic over the bridge interface in UPPAK mode is now allowed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| **CoreXL**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||
| PMTR-58368                                     | CoreXL Dynamic Dispatcher is now supported with [CGNAT (Global NAT)](https://support.checkpoint.com/results/sk/sk165153).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **CloudGuard Controller**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          ||
| PMTR-100851                                    | **Enhancement:** Added ability to configure separately the timeout parameter of CloudGuard Controller's scanner for HTTP call and the timeout for `vsec.py` process in the `vsec.conf` file.                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| PMTR-85367, VSECC-1097                         | IPv6 information is now imported for Data Center Objects in the Public Cloud.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| VSECC-346                                      | Problems in Data Center will not always change the status of the Security Management Server in SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| **Quantum Maestro and Scalable Chassis**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           ||
| PMTR-105637                                    | **Enhancement:**In case MHO certificates are expired, a message indicating this will be displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| PMTR-95631                                     | **Enhancement:**QSFP ports can now be configured with 10G, 1G and 4x1G QSFP port modes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| MBS-4098, PMTR-60868                           | **Enhancement:**Added support for GRE tunnels.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| PMTR-91737                                     | **Enhancement:**When creating a Security Group, it is now possible to configure SGMs to save logs when they exit or change the Security Group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| PMTR-99920                                     | **Enhancement:** The output of the `orchd start` command on the Maestro Orchestrator shows more information if the *orchd* daemon is already running or stopping.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| PMTR-101544                                    | **Enhancement:** Improved the Gaia Clish command `show maestro port <ID> optic-info` on the Maestro Orchestrator to show information about the CPAC-TR-100SR-D and CPAC-TR-100CWDM4-D transceivers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| PMTR-71298                                     | **Enhancement:**You must disable the SMO Image Cloning in the Security Group before you assign an appliance of a model that is different from models of other appliances already assigned in this Security Group.                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| MBS-11278                                      | **Enhancement:**Unique IP address per Chassis (UIPC) feature is now supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| MBS-13635                                      | **Enhancement:** Gaia Message of the Day (MOTD) and banner messages now support the pound (#) character.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-102638                                    | In an environment where the Security Gateway is connected to the Maestro Orchestrator through two downlinks, disconnecting and connecting a downlink, physically or through the Orchestrator, causes an outage of 10 seconds between them.                                                                                                                                                                                                                                                                                                                                                                                                                         |
| PMTR-94043                                     | After upgrade: * Output of the `asg diag verify` command shows in the "System Components" section that the status of the "Software Provision" test is "Failed". * Output of the `asg diag print <ID of "Software Provision">` command shows a shell script code. * Output of the `asg_provision` command shows a shell script code.                                                                                                                                                                                                                                                                                                                                |
| PMTR-96243                                     | In Scalable Platforms, in a Dual Site configuration, ping fails from a Standby site to a host on the network connected to the Management interface of the Security Group. Refer to [sk182629](https://support.checkpoint.com/results/sk/sk182629).                                                                                                                                                                                                                                                                                                                                                                                                                 |
| PMTR-95470                                     | These errors appear in Gaia Clish on a Maestro Security Group during the installation of a Hotfix / Jumbo Hotfix Accumulator: `[ERROR] Failed to clear DB values.` `[ERROR] Failed to clear package_progress value from Gaia DB.` Note that this was a cosmetic issue.                                                                                                                                                                                                                                                                                                                                                                                             |
| PMTR-80541                                     | The "asgKernelVer" OID is now removed from the SNMP "ASG" tree because it is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| PMTR-58383                                     | Maestro and Scalable Chassis now support CGNAT (Global NAT) with the Layer 4 distribution.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| PMTR-98172                                     | The Gaia Clish command `set web daemon-enable off` on a Maestro Orchestrator now shows a warning and refers to [sk166692](https://support.checkpoint.com/results/sk/sk166692).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| PMTR-82182                                     | When configuring proxy NDP according to [sk91905](https://support.checkpoint.com/results/sk/sk91905) using interface name instead of MAC address, policy installation fails to add it to the *ndp_table*.                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| PMTR-89996                                     | With this release, when *orchd* process is down, the*/var/log/messages* file no longer contains the logs like "*The value of sensor could not be read*".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| PMTR-47869                                     | The `vsx stat -v` command does not work after reverting to Gaia Autosnapshot (a snapshot created automatically by the CPUSE Upgrade).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| PMTR-33894                                     | When configuring a Maestro Security Gateway object in SmartConsole, you must select only the R80.20SP version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| MBS-11339                                      | Maestro Orchestrator Clish command `set maestro port X/Y/Z admin-state <down/up>` does not survive reboot.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| MBS-2049                                       | After installation, a static route to 192.168.1.254 is automatically created due to the preconfigured subnet for the e*th1-Mgmt4* interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| MBS-9105                                       | Added ability to disable the "Drop out of state TCP packets" setting in SmartConsole \> Global properties \> Stateful Inspection when IPv6 traffic passes through Security Groups.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| MBS-9713                                       | "*Failed to set MTU 9000 on interface magg0. Maximum value allowed is 9710.* " error when running the Gaia gClish command `set interface magg0 mtu <Value>` for a Management Aggregation (MAGG) interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| MBS-7744                                       | In a Dual Site deployment, the external synchronization connection between the Orchestrators on different sites must be a direct Layer 2 link.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| MBS-5216                                       | When VLAN traffic needs to traverse the Security Group in Bridge mode, you must configure all relevant VLAN IDs on the Uplink ports assigned to the Security Group in the Gaia Portal on the Maestro Orchestrator.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| MBS-13867                                      | On Quantum Maestro, the `snmpwalk` and `snmpget` commands executed for the IP address of the Security Group on OIDs that have prefixes other than 1.3.6.1.4.1.2620.1.44 or 1.3.6.1.4.1.2620.1.48 return information only for the current SMO Security Group Member. To get the same information from non-SMO Security Group Members, connect to the command line of each non-SMO Security Group Member and run the `snmpwalk` or `snmpget` command for the "localhost".                                                                                                                                                                                            |
| MBS-11339                                      | The Maestro Orchestrator Clish command `set maestro port X/Y/Z admin-state <down/up>` does not survive reboot.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| MBS-11504                                      | Scalable Platforms now support the configuration of different VPN encryption domains on a Security Gateway that is a member of multiple VPN communities.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| MBS-2379                                       | The SMO Image Cloning feature only supports Security Group Members that run the same major version. When you add a new Security Group Member to the R80.20SP Security Group (with the `add smo security-group` command), it must have the same version as SMO.                                                                                                                                                                                                                                                                                                                                                                                                     |
| 01052419                                       | Connections may break when you change the System Distribution Mode using either the `set distribution configuration` command or the `set distribution interface` command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| 01255170                                       | For monitoring the 60000 / 40000 Scalable Chassis over the SNMP, the only supported OIDs are under `iso.org.dod.internet.private.enterprise.checkpoint.products.asg (OID 1.3.6.1.4.1.2620.1.48)`.                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| **Endpoint Security**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              ||
| PMTR-84345                                     | In Harmony Endpoint Web Management interface, when you enter the percent "%" character in Search fields, the backslash "\\" character is added repetitively in front of the percent "%" character.                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| PMTR-92866                                     | Installation of the Endpoint Security Client package "EPS.msi" signed with a custom certificate and exported from SmartEndpoint on Windows 11 is now possible                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| PMTR-62510                                     | It is now possible to scan user certificates from the Active Directory when you create a new Active Directory Scanner in the Endpoint Server Web Management Portal. "Scan user certificated from Active Directory" checkbox was added.                                                                                                                                                                                                                                                                                                                                                                                                                             |

{#resolvedTable}

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
