> Source: [sk183419](https://support.checkpoint.com/results/sk/sk183419)

# sk183419 - Spark Firewall R82.00.X - Resolved Issues and Enhancements

| Property | Value |
|----------|-------|
| Solution ID | sk183419 |
| Date Created | 2025-05-04 |
| Last Modified | 2026-09-16 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed), Spark Firewall (Centrally Managed) |
| Versions | R82.00.X, R82.00.X |
| Platform | 1900, 2000, 1600, 1800, 2500, 15x5 |

## Solution

This article lists all Resolved Issues and Enhancements for R82.00.X releases.

![](https://sc1.checkpoint.com/sc/images/sk_images/Important_Note.png) **Important Notes**:

* There are no new Resolved Issues for R82.00.00.
* For R81.10.17 Resolved Issues, see [sk181134](https://support.checkpoint.com/results/sk/sk181134).
* For a comprehensive list of R82.00.X Known Limitations and Unsupported Features, see [sk183400](https://support.checkpoint.com/results/sk/sk183400).
* For more information about a specific release, see its Home Page ([R82.00.11](https://support.checkpoint.com/results/sk/sk183419) / [R82.00.10](https://support.checkpoint.com/results/sk/sk184357) / [R82.00.00](https://support.checkpoint.com/results/sk/sk183407) / [R82.00.05](https://support.checkpoint.com/results/sk/sk184063)).
* Visit the [CheckMates Community](https://community.checkpoint.com) to ask questions, start a discussion, and get our experts' assistance.

Show the Entire Article

R82.00.11 Resolved Issues and Enhancements
------------------------------------------

Show / Hide this section  
> Enter the string to filter this table:
>
> |--------------|--------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | **ID**       | **Category** | **Description**                                                                                                                                                                                                                                                                                                                     |
> | **Build 998002754**                                                                                                                                                                                                                                                                                                                                             |||
> | SMBGWY-21107 | General      | If you do a clean install of version R82.00.11 on your device, you can no longer configure to allow admin access from any IP address. However, if you set the Advanced Settings Attribute "Allow any IP" for administrator access for your device and upgraded from R82.00.10 to R82.00.11, the configuration survives the upgrade. |

> {#Unique_ID_1Table}

<br />

R82.00.10 Resolved Issues and Enhancements
------------------------------------------

Show / Hide this section  
> Enter the string to filter this table:
>
> |-----------------------------------------|-----------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | **ID**                                  | **Category**          | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | **Build 996002325**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | SMBGWY-22590                            | General               | The DHCP lease end time displayed on the WebUI Assets page is not the appliance local time but is shifted by the time zone offset of the administrator's browser.                                                                                                                                                                                                                                                                                                                                                    |
> | SMBGWY-22371                            | Certificates          | After a new third-party CA-signed certificate is imported, Gaia Portal presents the default self-signed certificate instead of the selected imported certificate.                                                                                                                                                                                                                                                                                                                                                    |
> | SMBGWY-22397                            | Access Policy         | Custom application URLs or non-regex patterns containing special characters may prevent policy management module generation, blocking policy installation with WebUI error 00351                                                                                                                                                                                                                                                                                                                                     |
> | SMBGWY-22017                            | VPN                   | In a locally managed Spark Firewall appliance, IKEv2 negotiation for Site to Site VPN with DAIP peer fails with "`INVALID_MAJOR_VERSION`."                                                                                                                                                                                                                                                                                                                                                                           |
> | SMBGWY-21785                            | NAT                   | NAT entries are not refreshed after a PPPoE IP address change.                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
> | SMBGWY-21771                            | Access Policy         | In Access Policy, entering an IP address value containing a hyphen may cause a domain entry to be treated as an IP range.                                                                                                                                                                                                                                                                                                                                                                                            |
> | SMBGWY-21745                            | Access Policy         | Users with Access Policy Admin permissions can not add access policies.                                                                                                                                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-21991                            | Internet Connectivity | On a Spark Firewall running version R82.00, the default gateway cannot be change after expanding the Bridge Network subnet.                                                                                                                                                                                                                                                                                                                                                                                          |
> | SMBGWY-21620                            | VPN                   | Refreshing the Remote Access VPN users view may show different connected-user counts and session visibility despite there being no change in the active users.                                                                                                                                                                                                                                                                                                                                                       |
> | SMBGWY-22016                            | IPv6                  | IPv6 connection monitoring shows "example.com" instead of "dns.google.com.                                                                                                                                                                                                                                                                                                                                                                                                                                           |
> | SMBGWY-21857                            | General               | Software Blades fail after upgrading from R82.00.10 Build 2216 to R82.00.10 Build 2242.                                                                                                                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-21738                            | VPN                   | SD-WAN VPN overlay: IKE traffic fails to egress through a non-default ISP link on Spark Kernel 5.15 when `skbuff_packet_update_route` sets `rt_gw4` without setting `rt_gw_family`.                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-20332                            | IOC                   | Obsolete IOC feeds are not removed from the system after a successful load.                                                                                                                                                                                                                                                                                                                                                                                                                                          |
> | SMBGWY-22047                            | Internet Connectivity | The "Route traffic through this connection by default" checkbox is not displayed when adding or editing an IPv6 Internet connection in the WebUI.                                                                                                                                                                                                                                                                                                                                                                    |
> | SMBGWY-22048                            | Internet Connectivity | IPv4 over IPv6: Adding a second IPv6 connection on a different interface causes the Linked Connection field of an IPv4 over IPv6 connection to reset to "Please choose", with no valid entries available in the list.                                                                                                                                                                                                                                                                                                |
> | SMBGWY-21810                            | General               | Because Domain objects on Locally Managed appliances ignore the FQDN setting, a rule allowing a domain also allows its sub-domains.                                                                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-22060                            | Access Policy         | In Access Policy, entering an IP address value containing a hyphen is an invalid input.                                                                                                                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-21910                            | Cellular              | SIM data usage may be counted twice after a file download is completed.                                                                                                                                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-22112                            | NAT                   | L2TP fails to connect when the client is behind NAT                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-22216                            | Routing               | Recognition rank is sent to normalization above threshold                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
> | SMBGWY-22342                            | SD-WAN                | SD-WAN policy installation fails when one of the SD-WAN interfaces is down.                                                                                                                                                                                                                                                                                                                                                                                                                                          |
> | SMBGWY-22398                            | Interface             | Converting an interface with a static next-hop route to an Internet Connection can cause permanent loss of the default gateway route.                                                                                                                                                                                                                                                                                                                                                                                |
> | SMBGWY-22363                            | Gateway               | The system view continues showing an IP address after the address was changed.                                                                                                                                                                                                                                                                                                                                                                                                                                       |
> | PMTR-131442                             | VPN                   | Update: Resolved [CVE-2026-85102](https://www.cve.org/CVERecord?id=CVE-2026-85102) - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN. Refer to [sk1000117](https://support.checkpoint.com/results/sk/sk1000117).                                                                                                                                                                                                                                                               |
> | PMTR-131527                             | VPN                   | Update: Resolved [CVE-2026-85103](https://www.cve.org/CVERecord?id=CVE-2026-85103) - ASN.1 decoding heap overflow leading to a remote code execution. Refer to [sk1000118](https://support.checkpoint.com/results/sk/sk1000118).                                                                                                                                                                                                                                                                                     |
> | **ID**                                  | **Category**          | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | **Build 998002279**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | SMBGWY-21700                            | Access Policy         | When adding multiple objects in the Firewall Access Policy, the new network object or domain from Source or Destination may retain values from the previous entry.                                                                                                                                                                                                                                                                                                                                                   |
> | SMBGWY-21510                            | Logs                  | In Locally Managed R82.00.10 environments, long values in Log Details fields, such as User, may appear on a single line instead of wrapping. This can reduce readability.                                                                                                                                                                                                                                                                                                                                            |
> | SMBGWY-21711                            | Access Policy         | In the WebUI, under **Access Policy** \> **Firewall** \> **Firewall Access Policy (Outgoing and Internet traffic)** , searches in **Applications and Services** can return results that match description text in addition to the application name. As a result, users may need to review multiple pages to find the intended application.                                                                                                                                                                           |
> | SMBGWY-21769                            | Threat Prevention     | In the WebUI, when adding a Source or Destination to a Threat Prevention Exception, entering a value (single IP address, network/CIDR, IP range, or domain name) to the field and pressing Enter does not add the object.                                                                                                                                                                                                                                                                                            |
> | SMBGWY-21813                            | NAT                   | In JPIX v6plus MAP-E deployments, NAT behavior may be incorrect, leading to connectivity anomalies for translated traffic flows.                                                                                                                                                                                                                                                                                                                                                                                     |
> | SMBGWY-21629                            | VPN                   | Remote Access VPN user objects cannot be removed if they are referenced in Access Policy rules.                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | SMBGWY-21642                            | Cloud Services        | If a cloud managed 2530/2550 appliance reboots within 5 minutes after the upgrade completes, it automatically reverts to the previous build.                                                                                                                                                                                                                                                                                                                                                                         |
> | SMBGWY-21688                            | Cellular              | In Spark Firewall 2570W Security Gateways with 5G cellular modems, certain network settings may cause the gateway to use the wrong carrier profile and results in reduced 5G performance, unstable connections while roaming internationally, and connection drops on some networks.                                                                                                                                                                                                                                 |
> | SMBGWY-21698                            | VPN                   | VLAN-based internet connectivity may cause the loss of other internet-connections' IP addresses during initialization, which can result in the loss of default-routes.                                                                                                                                                                                                                                                                                                                                               |
> | SMBGWY-21647                            | Spark Management      | When sfwd restarts while connectivity to Spark Management servers is temporarily unavailable, the scheduled Spark Management upgrade plan may not execute even after connectivity is restored.                                                                                                                                                                                                                                                                                                                       |
> | SMBGWY-21709                            | VoIP                  | In the VoIP wizard, administrators can select services services that are not valid SIP services for the relevant policy flow. This may result in incorrect VoIP configuration behavior.                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-21650                            | Cloud Services        | The time shown on the device interface may differ from cloud-synchronized time values during monitoring and event review workflows.                                                                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-21630                            | Internet Connectivity | Increasing the MTU of a bond interface (for example, when using Jumbo-frames) when one or more of the bond's interfaces are on the LAN switch fails and some packets may be silently dropped by the switch physical interface.                                                                                                                                                                                                                                                                                       |
> | SMBGWY-21858                            | Internet Connectivity | When Jumbo frames support is activated in the Advanced Settings, the setting is not applied properly on the LAN switch of the 1595R appliance. As a result, the LAN switch silently drops packets larger than the default MTU of 1500.                                                                                                                                                                                                                                                                               |
> | PRJ-70032. PMTR-129280                  | VPN                   | Improved certificate validation during IKEv2 VPN negotiations to ensure VPN connections are established only after successful certificate-based authentication.                                                                                                                                                                                                                                                                                                                                                      |
> | **Build 998002242**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | SMBGWY-20729                            | Anti-Spam             | Anti-Spam exception rules may not be applied correctly to messages with unusually long headers.                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | SMBGWY-21605                            | WiFi                  | When attempting to assign the Wi-Fi interface to the LAN Switch from the Local Network and Wireless pages, the operation fails with an error message.                                                                                                                                                                                                                                                                                                                                                                |
> | SMBGWY-21478                            | 2FA                   | The email for setting up Two-Factor Authentication is not sent after enabling Two-Factor Authentication through the WebUI through an RMD link via Spark Management.                                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-21463                            | Anti-Virus            | In some email clients, such as Outlook, emails with attachments cannot be received over IMAP when the Anti-Virus blade is enabled."                                                                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-21451                            | General               | RAM usage on the appliance gradually increases to full capacity, resulting in being unable to access the WebUI and SSH.                                                                                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-21488                            | VPN                   | After a failover from the primary to the backup internet connection, Site to Site VPN tunnels did not switch over to the backup link due to a link selection probing issue on the Locally Managed Spark Firewall.                                                                                                                                                                                                                                                                                                    |
> | SMBGWY-21461                            | WebUI                 | WebUI loads slowly when the gateway is connected over VPN for 2500 Spark Firewall models.                                                                                                                                                                                                                                                                                                                                                                                                                            |
> | SMBGWY-21209                            | General               | Accumulating defunct processes gradually consume memory, leading to no memory available.                                                                                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-21380                            | VPN                   | After upgrading a Locally Managed Spark Firewall to R82.00.10 Build 996002133, the VPN clients do not show the full list of authentication methods.                                                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-21331                            | Logs                  | On a Spark Firewall appliance, only logs from the past day can load. On Spark Management, all the logs are displayed but it is not possible to filter for the desired time frame.                                                                                                                                                                                                                                                                                                                                    |
> | SMBWY-21056                             | Threat Prevention     | After upgrading to R82.00.10, cannot select specific IPS protections in Threat Prevention Policy Exceptions via the WebUI. Only category-level options, such as "Any IPS", are available.                                                                                                                                                                                                                                                                                                                            |
> | SMBGWY-21214                            | Cluster               | On Spark Firewall 15X5 appliances running R82.00.10 Build 996002133, High Availability cluster trust establishment between members failed repeatedly without a clear error message, preventing the cluster from forming correctly during initialization.                                                                                                                                                                                                                                                             |
> | PRJ-69655, PMTR-128753                  | VPN                   | **UPDATE** : * Resolved [CVE-2026-50751](https://www.cve.org/CVERecord?id=CVE-2026-50751) - User Authentication bypass on VPN Remote Access and Mobile Access in deprecated IKEv1 key exchange. Refer to [sk185033](https://support.checkpoint.com/results/sk/sk185033). * Resolved [CVE-2026-50752](https://www.cve.org/CVERecord?id=CVE-2026-50752) - VPN site-to-site certificate bypass vulnerability in deprecated IKEv1 key exchange. Refer to [sk185035](https://support.checkpoint.com/results/sk/sk185035). |
> | SMBGWY-20762                            | VPN                   | VPN traffic is inspected by PSL and dropped, even though the "Bypass PSL inspection for VPN traffic" advanced setting is enabled.                                                                                                                                                                                                                                                                                                                                                                                    |
> | SMBGWY-20611                            | VPN                   | In environments configured with MAP-E, Remote Access (RA) VPN connections may fail when clients use Visitor Mode.                                                                                                                                                                                                                                                                                                                                                                                                    |
> | **Build 998002203**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PRJ-67985, PMTR-126652                  | Security Gateway      | **UPDATE** : Resolved CVE-2026-48131 - VPND IKE Fragment Reassembly - Heap Out-of-Bounds Write via Sequence Number Zero. Refer to [sk184981](https://support.checkpoint.com/results/sk/sk184981).                                                                                                                                                                                                                                                                                                                    |
> | PRJ-67840, PMTR-126457                  | Security Gateway      | **UPDATE** : Resolved CVE-2026-48132 - VPN process may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP. Refer to [sk184982](https://support.checkpoint.com/results/sk/sk184982).                                                                                                                                                                                                                                                                                                                |
> | PRJ-67875, PMTR-126538                  | Security Gateway      | **UPDATE** : Resolved CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion. Refer to [sk184993](https://support.checkpoint.com/results/sk/sk184993).                                                                                                                                                                                                                                                                                                                            |
> | PRJ-68010, PMTR-126694                  | Security Gateway      | **UPDATE** : Resolved CVE-2026-48135 - HTTP service can incorrectly process malformed HTTP requests. Refer to [sk184991](https://support.checkpoint.com/results/sk/sk184991).                                                                                                                                                                                                                                                                                                                                        |
> | SMBGWY-20788                            | General               | Stream Control Transmission Protocol (SCTP) connections remain in the connection table after receiving SHUTDOWN_COMPLETE or ABORT messages, preventing new connections with the same source/destination tuple and suppressing new firewall logs.                                                                                                                                                                                                                                                                     |
> | SMBGWY-19878                            | General               | The Cloud Services last synchronization time is displayed incorrectly.                                                                                                                                                                                                                                                                                                                                                                                                                                               |
> | SMBGWY-20514                            | General               | In Centrally Managed environments, policy installation may fail on Spark Gateways with error code `0?1?2000187`.                                                                                                                                                                                                                                                                                                                                                                                                     |
> | SMBGWY-20239                            | General               | An invalid host `0.0.0.0` appears in the infected hosts list.                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
> | SMBGWY-19528                            | General               | IoC feed enablement fails on first use after a clean install due to an invalid default refresh interval.                                                                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-20725                            | General               | A periodic backup configured from Spark Management does not work on newly provisioned gateways.                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | SMBGWY-20592                            | General               | Removing a LAN interface from a LAN switch triggers an incorrect validation error indicating an incorrect format or minimum value.                                                                                                                                                                                                                                                                                                                                                                                   |
> | SMBGWY-20354                            | Firewall              | When configuring a cluster, the cluster wizard displays the error `The IP address is in the subnet of an existing network (LAN2.102).`                                                                                                                                                                                                                                                                                                                                                                               |
> | SMBGWY-20660                            | Firewall              | License expiration notifications are incorrectly sent to Pay-As-You-Go (PAYG) accounts.                                                                                                                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-21055                            | Firewall              | Policy installation fails with `Error code: 0-2-2000245`, potentially causing a cluster member to start after reboot without a policy or cluster membership.                                                                                                                                                                                                                                                                                                                                                         |
> | SMBGWY-20202                            | GUI                   | When selecting "JPIX" as the MAP?E provider, the profile name is incorrectly displayed as "OCN Virtual Connect Dynamic IP" instead of "v6plus".                                                                                                                                                                                                                                                                                                                                                                      |
> | SMBGWY-20200                            | GUI                   | The VPN debug tool in the WebUI does not work correctly.                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-20158                            | GUI                   | The `show sfp-diag` command does not work correctly with LAN ports                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
> | SMBGWY-20829                            | GUI                   | Offline IPS signature updates uploaded via the WebUI are not applied.                                                                                                                                                                                                                                                                                                                                                                                                                                                |
> | SMBGWY-20218, SMBGWY-20973              | GUI                   | The subnet mask (IPv4) or prefix length (IPv6) is not displayed in the IP address field under **Device** \> **Network** \> **Internet**.                                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-19791                            | GUI                   | In a Quantum Spark HA setup, when performing a manual switch-over (via **Change member to Secondary** in the WebUI), LAN5 is removed from the sync bond and appears as a standalone interface instead of remaining part of the HA synchronization bond. This fix adds support for a second LAN interface as part of the sync bond in cluster configurations.                                                                                                                                                         |
> | SMBGWY-20805                            | VPN                   | Remote Access VPN Two-Factor Authentication settings (SMS, email, and authenticator) are reset to disabled after a firmware upgrade.                                                                                                                                                                                                                                                                                                                                                                                 |
> | **Build 998002133**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | SMBGWY-19992                            | General               | The Quantum Spark appliance generates false `infected device` notifications, such as `inx invalid type (0) is infected with malware...`.                                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-19348                            | General               | Proxy ARP does not work on Locally Managed Spark appliances after a cluster failover.                                                                                                                                                                                                                                                                                                                                                                                                                                |
> | SMBGWY-20164                            | General               | A cluster of Quantum Spark appliances running R82.00.10 may experience slow detection when a member becomes inaccessible during reboot or power off. For example, when rebooting the Active member, the Standby member remains Standby for several minutes and does not take the Active role. This may lead to an outage during that period.                                                                                                                                                                         |
> | SMBGWY-19702                            | General               | Unable to modify IPIP (IPv4 over IPv6) Internet connection settings.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
> | SMBGWY-19109                            | General               | Creating a New Service directly within an Access Policy rule ("on the fly") incorrectly opens the Service Group creation dialog, regardless of whether "Service" or "Service Group" is selected.                                                                                                                                                                                                                                                                                                                     |
> | SMBGWY-19465                            | General               | The **Connected Remote Users** page may not display all connected users.                                                                                                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-20195                            | General               | Backup and restore from R81.10.17 to R82.00.XX can trigger a startup loop, causing excessive memory consumption.                                                                                                                                                                                                                                                                                                                                                                                                     |
> | SMBGWY-19473                            | General               | SmartConsole reports and the output of the `cpstat` command do not display scanned files. The scanned file counter remains at `0` even after Threat Emulation scans files.                                                                                                                                                                                                                                                                                                                                           |
> | SMBGWY-19361                            | General               | GRE cannot be configured on an external interface that uses an automatic Internet connection (for example, DHCP).                                                                                                                                                                                                                                                                                                                                                                                                    |
> | SMBGWY-19620                            | GUI                   | The bond MAC address displayed in the WebUI does not match the actual MAC address.                                                                                                                                                                                                                                                                                                                                                                                                                                   |
> | SMBGWY-19127                            | GUI                   | When using IPv6 Bridge mode, the **Device** \> **Network** \> **Internet** page displays only IPv6 information, even though both IPv4 and IPv6 are configured in Bridge mode.                                                                                                                                                                                                                                                                                                                                        |
> | SMBGWY-19641                            | GUI                   | Certain application categories cannot be added to the "Other Undesired Applications" group under URL Filtering/Application Control. Attempts to add these categories via the WebUI do not complete successfully.                                                                                                                                                                                                                                                                                                     |
> | SMBGWY-18994                            | GUI                   | The system does not correctly enforce expiration dates for local "Temporary user" accounts, and VPN Remote Access permissions for users do not expire as expected.                                                                                                                                                                                                                                                                                                                                                   |
> | SMBGWY-19301                            | GUI                   | Automatically generated application groups are not created properly.                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
> | SMBGWY-18993                            | GUI                   | On V1 and V0 machines, it is not possible to save the first SSID during the First Time Wizard.                                                                                                                                                                                                                                                                                                                                                                                                                       |
> | SMBGWY-19334                            | CPOS                  | Flow control frames (XOFF/XON) used to pause GoP (MAC) are delivered to the CPU, causing unnecessary CPU load.                                                                                                                                                                                                                                                                                                                                                                                                       |
> | SMBGWY-19320                            | VPN                   | When Two-Factor Authentication (2FA) is enabled per group (using Authenticator) but global 2FA is disabled, newly added AD users do not receive the QR code email required for enrollment.                                                                                                                                                                                                                                                                                                                           |
> | SMBGWY-18012                            | VPN                   | PCI compliance scan fails with these error messages (see [sk184658](https://support.checkpoint.com/results/sk/sk184658) ): * `Weak Diffie-Hellman groups on UDP/500.` * `3DES encryption on UDP/500.`                                                                                                                                                                                                                                                                                                                |
> | SMBGWY-19381                            | VPN                   | **New**: Support for Perfect Forward Secrecy (PFS) mode on VPN sites of type "Only remote site initiates VPN" and "Hostname" in Locally Managed mode.                                                                                                                                                                                                                                                                                                                                                                |
> | SMBGWY-19565                            | VPN                   | SNMPwalk queries for VPN-related OIDs hang on a Centrally Managed cluster's standby member, though they work correctly on the active member.                                                                                                                                                                                                                                                                                                                                                                         |
> | SMBGWY-19097                            | VPN                   | On Quantum Spark appliances (Locally Managed and Centrally Managed) the IKE daemon and VPN port listeners (UDP ports 500, 4500, 30500, and 34500) run continuously, regardless of whether the VPN feature is enabled or disabled.                                                                                                                                                                                                                                                                                    |
> | SMBGWY-19193, SMBGWY-18624              | VPN                   | Unable to configure All-Day or Multi-Day schedule via Remote Access VPN WebUI.                                                                                                                                                                                                                                                                                                                                                                                                                                       |
> | SMBGWY-19018                            | Anti-Virus            | When the "Enable deep inspection scanning setting" option is enabled in SmartConsole, Anti-Virus scanning fails with the error message `failed to process the file`.                                                                                                                                                                                                                                                                                                                                                 |
> | SMBGWY-19850, SMBGWY-13144, SMBGWY-9723 | Anti-Virus            | Anti-Virus inspection of emails over the POP3 protocol is not supported in this scenario: 1. Locally Managed R81.10.X Quantum Spark Gateway. 2. A Bridge interface is configured. 3. VLAN interfaces are configured on the Bridge interface. 4. An internal email client is connected to one of these VLAN interfaces.                                                                                                                                                                                               |
> | SMBGWY-19497                            | Identity Awareness    | On a Centrally Managed Quantum Spark appliance, when Identity Awareness is set to "Get identities from other gateways" (Identity Sharing) without any local identity source, the Identity Awareness Blade fails to initialize after policy installation. This prevents PDP/PEP processes from starting, See [sk184730](https://support.checkpoint.com/results/sk/sk184730).                                                                                                                                          |
> | SMBGWY-19093                            | Identity Awareness    | Even after disabling "User Awareness" in the WebUI, the Identity Awareness blade remains listed as enabled in `enabled_blades` and `active_blades.txt.`                                                                                                                                                                                                                                                                                                                                                              |
> | SMBGWY-19633                            | SD-WAN                | In rare scenarios, SD-WAN objects (such as Peer VPN Domain, My VPN Domain, or SD-WAN Internet) populate incompletely, causing SD-WAN rules to match traffic incorrectly.                                                                                                                                                                                                                                                                                                                                             |
> | **Build 998002110 and Build 998002112**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |||
> | SMBGWY-19811                            | General               | Newly created certificates and newly generated Certificate Revocation Lists (CRLs) may fail validation. In addition, reverting to factory default may fail. See [sk184766](https://support.checkpoint.com/results/sk/sk184766) for more information.                                                                                                                                                                                                                                                                 |
> | SMBGWY-19692                            | General               | Periodic backups fail when configured from Quantum Spark Management. The failure occurs only when the backup topic has been modified in the Quantum Spark Management configuration after upgrading to R82.00.05, R82.00.10 (up to Build 998001645), or R81.10.17 (between Builds 996004668 and 996004846).                                                                                                                                                                                                           |
> | SMBGWY-19331                            | General               | Frequent system freezes and reboots may occur after upgrading to R82.00.xx during periods of heavy workload.                                                                                                                                                                                                                                                                                                                                                                                                         |
> | SMBGWY-19567                            | CPOS                  | On 1900/2000 appliances previously upgraded to R82, the primary bootloader may fail to boot, resulting in boot failover.                                                                                                                                                                                                                                                                                                                                                                                             |
> | **Build 998001562**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | SMBGWY-19002                            | GUI                   | No logs appear in the Quantum Spark Management application in the Infinity Portal for 1600/1800/1900/2000 Gateways.                                                                                                                                                                                                                                                                                                                                                                                                  |
> | SMBGWY-19076                            | General               | After upgrading to R82.00.10, environments with Internet connections configured on LANX interfaces may experience unexpected LANX interface reassignment, resulting in changes to Internet interface mappings.                                                                                                                                                                                                                                                                                                       |
> | SMBGWY-19213                            | General               | The Rule-based Policy could become corrupted when upgrading from R81.10.08 or R81.10.10. This issue does not affect R81.10.15 and later versions.                                                                                                                                                                                                                                                                                                                                                                    |
> | **Build 998001559**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | SMBGWY-16521                            | Anti-Virus            | Starting in R82.00.10, the Anti-Virus engine does not scan FTP traffic by default. To restore old behavior, select the FTP protocol in the **Threat Prevention** \> **Engine Settings** page.                                                                                                                                                                                                                                                                                                                        |
> | SMBGWY-18508                            | General               | **Enhancement**: added support for specifying a static unnumbered IPv4 address for the MAP-E connection instead of using the IPv4 address assigned by the service provider.                                                                                                                                                                                                                                                                                                                                          |
> | SMBGWY-17521                            | General               | Hosts behind a bridge interface cannot access an internal server through the appliance's external IP address on the server's port, even when destination NAT is configured to forward the traffic.                                                                                                                                                                                                                                                                                                                   |
> | SMBGWY-17401                            | General               | When the Local NTP Server is enabled, it is accessible from the WAN, allowing external clients to receive NTP responses, instead of being restricted to local/internal networks.                                                                                                                                                                                                                                                                                                                                     |
> | SMBGWY-18716                            | General               | Updating the IP address or subnet of a Local Network object may not always take effect, causing firewall rules that reference the object to continue using the old IP address or subnet.                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-17627                            | General               | Some 1600/1800 appliances do not establish a link on SFP ports.                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
> | SMBGWY-17978                            | General               | On a Centrally Managed Gateway running R80.20.15 or higher with Identity Awareness (IDA) enabled and using Active Directory (AD) for authentication, the Gateway may send NTLMv1 authentication requests to AD. This occurs even when AD is configured to require NTLMv2. As a result, AD rejects the NTLMv1 requests, which can lead to user account lockouts.                                                                                                                                                      |
> | SMBGWY-17852                            | General               | IPv6 Prefix Delegation cannot be enabled on LAN, DMZ, or WLAN interfaces, even though these interfaces support IPv6 Prefix Delegation. A validation mechanism incorrectly prevents activation of Prefix Delegation on these interface types.                                                                                                                                                                                                                                                                         |
> | SMBGWY-18836                            | General               | System logs are not written to the SD card after a boot.                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-18227                            | General               | When the Gateway is in IPv6 Bridge mode (dual-stack IPv4/IPv6), a firmware upgrade initiated from Quantum Spark Management in the Infinity Portal does not start, although manual upgrades via the local WebUI function correctly.                                                                                                                                                                                                                                                                                   |
> | SMBGWY-17613                            | VPN                   | When "Route Internet traffic from connected clients through this Security Gateway" is disabled (Split Tunnel mode) and the Local Encryption Domain is set to Automatic (default), the L2TP client does not receive the automatic encryption domain subnet route in its routing table.                                                                                                                                                                                                                                |
> | SMBGWY-17494                            | VPN                   | When a client establishes an L2TP connection with "Route Internet traffic from connected clients through this Security Gateway" enabled, the client receives an IP address but does not receive DNS server information. As a result, external IP connectivity works, but hostname resolution fails.                                                                                                                                                                                                                  |
> | SMBGWY-18011                            | GUI                   | * Deleting the static Office Mode IP from the WebUI triggers a `system error `and does not remove the entry from the `ipassignment.conf` file. * Modifying the static Office Mode IP for usernames containing special characters creates duplicate entries in the `ipassignment.conf` file. * Multiple users can be assigned the same Office Mode IP address.                                                                                                                                                        |
> | SMBGWY-18302                            | GUI                   | In the Quantum Spark Management Portal, on the **Internet Monitoring** page, the connection status for PPPoE connections and flexports (LAN ports used as external Internet connections) is displayed as `Connected (No Probing)`.                                                                                                                                                                                                                                                                                   |
> | SMBGWY-18788                            | GUI                   | When operating in strict mode with the "APPI policy -- Bypass Check Point products" advanced setting enabled, an AppiBypass rule is automatically generated.                                                                                                                                                                                                                                                                                                                                                         |
> | SMBGWY-18009                            | GUI                   | Route Redistribution entries cannot be deleted when the configured AS number is greater than 65535; attempting to remove them results in an error popup.                                                                                                                                                                                                                                                                                                                                                             |
> | SMBGWY-18622                            | GUI                   | The system does not display injected routes in the output of the "`show route`" command, although it displays them in the output of the "`route -n"` command.                                                                                                                                                                                                                                                                                                                                                        |

> {#Unique_ID_2Table}

<br />

R82.00.05 Resolved Issues and Enhancements
------------------------------------------

Show / Hide this section  
> Enter the string to filter this table:
>
> |--------------|--------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
> | **ID**       | **Category** | **Description**                                                                                                                                                                                                                                                                                                                                 |
> | **Build 998000913**                                                                                                                                                                                                                                                                                                                                                         |||
> | SMBGWY-17136 | General      | **UPDATE** : Updated CRL and OCSP validation in Remote Access VPN, Site-to-Site VPN, and HTTPS Inspection to use HTTP/1.1 instead of HTTP/1.0. This ensures continued compatibility with DigiCert's updated requirements and prevents certificate validation failures. Refer to [sk183884](https://support.checkpoint.com/results/sk/sk183884). |
> | SMBGWY-16636 | General      | LAN interface MAC address could be incorrectly assigned to a LANX interface during configuration.                                                                                                                                                                                                                                               |
> | SMBGWY-16936 | General      | Policies created in R77.20.xx and restored to R80.20.xx change behavior after upgrading to R81.10.17. A rule containing both a URL and services is treated as `AND`. However, after the unification into a single field `appsAndServies`, the rule effectively became `OR`.                                                                     |
> | SMBGWY-16697 | General      | LANX cannot be used for a bridged internet connection on 1900/2000 appliances.                                                                                                                                                                                                                                                                  |
> | SMBGWY-17468 | General      | `Invalid CRL Retrieved` error in Security Logs when the Gateway downloads CRLs during HTTPS Inspection.                                                                                                                                                                                                                                         |
> | SMBGWY-16831 | VPN          | When the pfrm2.0 partition becomes exhausted due to SAML Portal logs, VPN connections fail. The VPN attempts to authenticate with the Identity Provider (for example, Microsoft Entra ID) but eventually times out.                                                                                                                             |
> | SMBGWY-16941 | VPN          | In a rare scenario, the Gateway fails to find a valid certificate for a Remote Access (RA) VPN connection.                                                                                                                                                                                                                                      |
> | SMBGWY-17072 | VPN          | Previously, it was not possible to configure the parameter `internet-traffic-through-this-gw` for VPN Site-to-Site in Clish. It is now configurable with these Clish commands: * `set vpn site <SITE_NAME> internet-traffic-through-this-gw true` * `set vpn site <SITE_NAME> internet-traffic-through-this-gw false`                           |
> | SMBGWY-17055 | Networking   | After receiving DHCPv6 prefix via prefix delegation, the internal interface(example: LAN1) is assigned an IPv6 address/prefix, but SLAAC remains disabled. Workaround: Change IPv6 Auto Assignment to "SLAAC" manually.                                                                                                                         |
> | SMBGWY-17282 | VLAN         | Deleting VLANs from a disabled port incorrectly enables the port while still displaying the port as disabled in the WebUI.                                                                                                                                                                                                                      |

> {#Unique_ID_3Table}

<br />

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
