> Source: [sk183507](https://support.checkpoint.com/results/sk/sk183507)

# sk183507 - Check Point Quantum R82.10 Release Known Limitations

| Property | Value |
|----------|-------|
| Solution ID | sk183507 |
| Date Created | 2025-05-28 |
| Last Modified | 2026-08-18 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82.10 |

## Solution

### This article lists all Quantum R82.10 Release specific known limitations and unsupported features, including limitations from the previous versions.

For more information about R82.10, see the [R82.10 Release Notes](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_RN/Default.htm), [R82.10 Home Page](https://support.checkpoint.com/results/sk/sk183506) and [R82.10 Resolved Issues](https://support.checkpoint.com/results/sk/sk183508).  
Visit [Check Point CheckMates Community](https://community.checkpoint.com) to ask questions or start a discussion and get our experts assistance.

**Important notes:**

* To see if an issue has been fixed in other releases or Jumbo Hotfixes, search for the issue ID in Support Center.

* To get a fix for an issue listed below, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) with the issue ID.

Click Here to Show the Entire Article

<br />

<br />

Unsupported Features **Show this section**
> **Table of Contents**
>
> |----------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------|
> | * Installation and Upgrade * Licensing * Gaia OS * Multi-Domain Management * SmartConsole / Management Console * Logging * SmartProvisioning | * Security Gateway * SD-WAN * ClusterXL * ICAP * VSNext * Threat Prevention | * Identity Awareness * Mobile Access * VPN * Zero Phishing * CloudGuard Network * ElasticXL and Maestro |
>
> <br />
>
> Enter the string to filter the below table:
>
> <br />
>
> {#Unsupported-Installation and Upgrade}{#Unsupported-Licensing}{#Unsupported-Gaia OS}{#Unsupported-MDS}{#Unsupported-SmartConsole}{#Unsupported-Logging / SmartLog}{#Unsupported-SmartProvisioning}{#Unsupported-SecurityGateway}{#Unsupported-SD-WAN}{#Unsupported-ClusterXL}{#Unsupported-ICAP}{#Unsupported-VSNext}{#Unsupported-Threat Prevention}{#Unsupported-Identity Awareness}{#Unsupported-Mobile Access}{#Unsupported-VPN}{#Unsupported-Zero Phishing}{#Unsupported-CloudGuard Network}
>
> |-----------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                    | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Found in version |
> | Unsupported Features - Installation and Upgrade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-110069           | The R82.10 release is not supported on the Threat Emulation Appliances.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R82              |
> | PMTR-59345            | Central Deployment in SmartConsole does not support: * Connection from SmartConsole to the Management Server through a proxy Server. In this case, use the applicable API command * ClusterXL in Load Sharing mode * VRRP Cluster * Installation of a package on a VSX VSLS Cluster that contains more than 3 members * On Multi-Domain Servers: Global Domain, or the MDS context * Standby Security Management Server or Multi-Domain Security Management * Quantum Maestro                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81              |
> | Unsupported Features - Licensing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-47087            | These products do not support the new licensing visibility features: * Network Security: Advanced Networking and Clustering, Capsule Cloud and Capsule Workspace. * Security Management: Endpoint Policy Management, SmartPortal, User Directory (LDAP). * Multi-Domain Management: Security Domain * Remote Access \& Endpoint                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80              |
> | Unsupported Features - Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-48258            | The Gaia "Cloning Group" feature (all its modes) is not supported in a Multi-Version Cluster (while cluster members run different release versions).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.40           |
> | Unsupported Features - Multi-Domain Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-17365            | The "Install Policy" action from a Multi-Domain Management Server (also through "Install Policy Presets") does not support QoS and Desktop policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.20.M1        |
> | Unsupported Features - SmartConsole / Management Console                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-101120           | Login into SmartConsole with an IPv6 address using SAML is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.20           |
> | PMTR-104470           | SmartConsole does not support (or has a limited support) the High Contrast Theme in these sections and windows: * "Gateways \& Servers" view \> select a Security Gateway / Cluster object \> at the top, click the Actions menu \> click Install Hotfix, or Version Upgrade * "Gateways \& Servers" view \> select a Security Gateway / Cluster object \> in the lower pane, click the Licenses tab * "Gateways \& Servers" view \> at the top, click Changes * "Security Policies" view \> Autonomous Threat Prevention \> click Policy, or File Protections * "Security Policies" view \> Access Control policy or Threat Prevention policy \> at the top, click Changes * "Manage \& Settings" view \> Sessions \> View Sessions \> at the top, click Changes * "Manage \& Settings" view \> Sessions \> Revisions \> at the top, click Changes * "Manage \& Settings" view \> Sessions \> Revisions \> select a revision \> at the top, click the Actions menu \> Revert to this Revision * "Manage \& Settings" view \> Package Repository                                                                 | R81.10           |
> | PMTR-58838            | Changes (Diff) report does not support: * A Standalone Server * Changes made in the Legacy SmartDashboard                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PROV-2200             | The "Get Interfaces" operation on the "Network Management" page of a Security Gateway (or Cluster) object only supports up to 500 interfaces of all types. * **To resolve:**If the Security Gateway (or Cluster) has 500 or more interfaces of all types, use the API `get-interfaces` on the Management Server to pull this information. Examples: 1)`get-interfaces target-name <Name of Security Gateway> with-top?logy false` 2) `get-interfaces target-name <Name of Cluster Object> with-top?logy true`For more information refer to [Management API](https://sc1.checkpoint.com/documents/latest/APIs/index.html#introduction~v1.6%20).                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81              |
> | PMTR-57122            | Search for section titles is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80              |
> | -                     | Changes to the Traditional Anti-Virus file types policy are not supported. Use the Anti-Virus blade to change the out-of-the-box Check Point policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80              |
> | Unsupported Features - Logging                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |||
> | PMTR-40514            | In the SmartConsole \> Logs \& Monitor view \> \[ + \] New Tab \> Views, sorting of the Favorites and Shared columns is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.40           |
> | PMTR-47703            | Purge, log switch and fetch log file tasks are not supported from SmartConsole. * Fetch log files from a remote Server is available from the command line only. Run: `fw fetchlogs <Gateway-Name/IP>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.10           |
> | Unsupported Features - SmartProvisioning                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-109023           | SmartProvisioning / SmartLSM is not supported in VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R82              |
> | PMTR-56758            | It is not supported to remove an IP address from one interface and assign the same IP address to another interface in the device object in the same edit action. "*Error field: ipAddr, Desc: IP address is in the subnet of an existing network*" is displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81              |
> | PMTR-54979            | When managing devices with the SmartProvisioning Software Blade, on the devices you must configure the connection with the Security Management Server using the IPv4 address in the `connect security-management mgmt-addr <IPv4 address of Security Management Server>` command (it is not supported to use the FQDN of the Security Management Server in this command).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.40           |
> | Unsupported Features - Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-60143            | The `perf` command is not supported on Threat Emulation appliances and on all other Check Point appliances that have only one or two CPU cores. * On these appliances, use the `top` and `turbostat` commands to monitor the performance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.10           |
> | PMTR-58361            | Intra-Tunnel Inspection of GTP-U user traffic is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81              |
> | PMTR-58366            | The "Produce extended logs on unmatched PDUs" option is not supported in the Security Gateway (Cluster) object \> Carrier Security \> Track. As a result, it is not possible to generate informative logs for unmatched GTP-C control packets (except for a plain clean up rule logging).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | Unsupported Features - SD-WAN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | PMTR-109701           | SD-WAN Overlay does not support having multiple center gateways in a star community with no satellites, when "Mesh center gateways" checkbox is selected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | PMTR-108481           | Anti-Spam, Threat Emulation and Threat Extraction Blades do not support Security Gateways with Dynamically Assigned IP (DAIP).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-108485           | SD-WAN Overlay does not support VPN Tunnel between gateways while both sides behind CGNAT / Dynamic NAT.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-108281           | SD-WAN does not support matching a "Local Breakout" rule to traffic in this scenario: 1. Traffic matches a Policy-Based Routing (PBR) rule that applies to traffic from a local network to "Default", and the next hop in this rule is set to a VPN Tunnel Interface (VTI). 2. The priority of this PBR rule is lower than 100.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-106136           | SD-WAN does not support Cluster configuration when Cluster Members are DAIP Security Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-107839           | SD-WAN Overlay does not support the "Exclude gateway's external IP addresses from the VPN Domain" configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R82              |
> | PMTR-106717           | In a Spoke-Hub-Spoke configuration, an encrypted connection from a Satellite SD-WAN DAIP Security Gateway to another Satellite Security Gateway VPN Domain is not supported when both conditions are met: * The source IP is from a Dynamic IP interface * The connection is routed through the central Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-106135           | SD-WAN does not support Security Gateways running Gaia OS that have more than one DAIP interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R82              |
> | PMTR-108004           | SD-WAN does not support "Overlay - VPN" over Route Based VPN configured with unnumbered VPN Tunnel Interfaces (VTI).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R82              |
> | PMTR-108010           | For inbound connections from the Internet to the Security Gateway itself, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received if there are multiple ISPs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-105725           | In a cluster, SD-WAN does not support interfaces in which the "Network Type" is set to "Private" (Non-Monitored Interface).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R82              |
> | PMTR-105210           | SD-WAN Local Breakout does not apply to connections that originate on the Security Gateway itself (for example, when an administrator connects from the Security Gateway to an FTP server).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R82              |
> | PMTR-105208           | SD-WAN Overlay VPN does not support Route Based VPN.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R82              |
> | PMTR-105207           | SD-WAN Overlay VPN does not support VPN peer Security Gateways connected over a Layer 2 line (SD-WAN Overlay VPN requires Layer 3 connectivity between VPN peers). The external interfaces of SD-WAN Security Gateways cannot be in the same subnet, if they are configured for a VPN overlay.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-105213           | SD-WAN Overlay VPN is only supported between Check Point Security Gateways that are connected to the same infinity tenant.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82              |
> | PMTR-105370           | SD-WAN Overlay VPN does not support the configuration of the probing IP address. By default, SD-WAN Overlay VPN probing sends ICMP requests only to the IP addresses of the VPN Peers.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82              |
> | PMTR-105209           | SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Security Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82              |
> | PMTR-108031           | SD-WAN Overlay VPN is supported only between Check Point Security Gateways managed by the same Domain Management Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-108901           | SD-WAN does not support using DAIP Security Gateway objects in Access Control rules (neither in the Source column, nor in the Destination column).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.20           |
> | PMTR-104984           | SD-WAN does not support VPN Route Injection Mechanism (RIM) configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.20           |
> | PMTR-104985           | SD-WAN does not support VPN Explicit Multiple Entry Point (MEP) configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.20           |
> | PMTR-105215           | SD-WAN does not support VPN Overlay with third-party VPN Peers (Check Point Security Gateway continues to use the existing Link Selection).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.20           |
> | PMTR-104986           | For inbound connections from the internet, SD-WAN does not support the symmetric return of packets through the same interface on which the connection was originally received, in case of multiple ISPs. The return will be determined based on the OS routes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R81.20           |
> | PMTR-104981           | SD-WAN does not support IPv6 traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-104980           | Maestro Security Groups do not support SD-WAN configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.20           |
> | PMTR-105894           | SD-WAN does not support ClusterXL in the Load Sharing Multicast mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-105895           | SD-WAN does not support ClusterXL in the Active-Active mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.20           |
> | PMTR-105533           | SD-WAN does not support Security Gateways that are managed with SmartProvisioning / LSM Profiles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.20           |
> | PMTR-104576           | SD-WAN does not support VPN Permanent Tunnels (SmartConsole \> VPN Community object \> Tunnel Management). SD-WAN tunnels are kept up automatically by the probing.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.20           |
> | PMTR-105543           | SD-WAN does not support Geo Cluster in Microsoft Azure.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.20           |
> | PMTR-105542           | SD-WAN does not support Geo Cluster in Amazon Web Services (AWS).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81.20           |
> | PMTR-105544           | SD-WAN does not support Geo Cluster in Google Cloud Platform (GCP).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.20           |
> | PMTR-104977           | VSX Gateways and VSX Clusters do not support SD-WAN configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81.20           |
> | Unsupported Features - ClusterXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-59404            | Geo Cluster does not support IPv6 traffic. Therefore, it is not supported to configure an IPv6 address on the Cluster and Sync interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
> | PMTR-48477            | ICAP Client and ICAP Server are not supported with ClusterXL Load Sharing modes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.10           |
> | Unsupported Features - ICAP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |||
> | PMTR-28828            | ICAP is not supported when Anti-Virus Deep Scan, Threat Extraction over HTTP or Threat Emulation hold mode is set.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.30           |
> | Unsupported Features - VSNext                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | PMTR-109340           | Virtual Gateway / Virtual System in Monitor Mode is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R82              |
> | PMTR-118023           | ElasticXL in the VSNext configuration does not supports the Load Sharing mode (more than one Cluster Member per Site). * **Resolved** in [R82.10 Jumbo Hotfix Accumulator Take 19](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |                  |
> | PMTR-109011           | The "Mirror and Decrypt" feature is not supported in VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R82              |
> | PMTR-119289, HEC-2236 | In the VSNext mode, after you create a Numbered VTI and attach it to a Virtual Gateway, you must reboot the Security Group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R82              |
> | PMTR-109016           | Enhanced Link Selection is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | PMTR-109024           | Anti-Virus archive scanning is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R82              |
> | PMTR-109025           | Threat Emulation archive scanning is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R82              |
> | PMTR-109026           | Mail Transfer Agent (MTA) for Threat Emulation is not supported in VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-109028           | Alias / Secondary IP address is not supported in VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R82              |
> | PMTR-109029           | ECMP (Equal Cost Path Splitting - Static Routs) is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R82              |
> | PMTR-109032           | Web SmartConsole is not supported when working in VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-109033           | Object Sharing from on-premises Management Server to Infinity Portal is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82              |
> | PMTR-109034           | Log Sharing from on-premises Management Server to Infinity Portal is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R82              |
> | PMTR-109035           | Infinity Playblocks is not supported in VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R82              |
> | PMTR-108070           | ISP Redundancy is not supported in VSNext mode.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-109023           | SmartProvisioning / SmartLSM is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-111386           | Maestro in VSNext mode do not support DHCP Server configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R82              |
> | Unsupported Features - Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-59492            | In a Multi-Domain Server environment, Infinity Threat Prevention does not support the Global Domain. Other Domains are supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-42537            | Threat Prevention Software blades do not support files with the HTTP 206 partial format with multiple ranges in the same HTTP connection (multipart).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.40           |
> | PMTR-59837            | SSH Deep Packet Inspection limitations: * SSH DPI is only supported for Security Gateways R80.40 and above, managed by Management Servers R80.40 and above. * Inspection of IPv6 connections is not supported. * Bridge Mode is not supported. * Cluster members do not synchronize the data about the inspected SSH traffic. * Cluster members do not synchronize the SSH DPI configuration. * Inspection of SSH traffic generated by clients, which do not support the "Diffie-Hellman group exchange" algorithm, is not supported. * These SSH clients are not supported: * PuTTY versions 0.64 and lower. * OpenSSH versions 2.5.2 and lower. * WinSCP versions 5.7.4 and lower. * SecureCRT versions 5.2 and lower.                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | Unsupported Features - Identity Awareness                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | PMTR-64495            | Identity Awareness does not support the authentication of Primary Groups of user and computer accounts. By default, the Primary Groups are "Domain Users" and "Domain Computers". Access roles defined with User groups do not work for users who are members of those user groups and have them as their primary group. * To use the entire Accounting Unit in an Access Role, use an LDAP group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R7x              |
> | Unsupported Features - Mobile Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | PMTR-60331            | These limitations apply to the Guacamole feature: 1. A dedicated Apache Guacamole Server version 1.1.0 or higher is required. 2. The following Guacamole features are not supported: * The VNC protocol * RDP file transfer * The SFTP protocol * Session recording 3. RDP/SSH is not supported from Capsule Workspace. 4. RDP/SSH is supported only by web browsers with HTML5 support. 5. RDP and SSH applications can be configured only by using their corresponding service objects in SmartConsole: * "Remote_Desktop_Protocol" * "SSH" * "SSH_version_2" 6. The Clipboard function in RDP sessions is supported with these limitations: * Text only * Supported browsers: Chrome and Explorer 7. This Single Sign-On option is not supported for Guacamole applications: "This application reuses the portal credentials. If authentication fails, Mobile Access prompts users and stores their credentials" 8. In a VSX environment where the "custom user directory attribute" feature is used, adding a new Virtual System requires manually adding the *customUserRecordAttribute.conf* file as well. | R81              |
> | PMTR-58003            | Mobile Access rules in the Unified Access Policy do not support Native Applications that authorize non-TCP or non-UDP services (for example, "*icmp-proto*").                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R81              |
> | PMTR-47745            | The Mobile Access Portal does not support Web-Form SSO for Citrix StoreFront Web interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.10           |
> | PMTR-47591            | Mobile Access does not support viewing or editing files with "*Office Online apps"*, Microsoft's browser-based Office applications. Outlook Web Access is supported, however you cannot open or edit Office Online app files from emails.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R7x              |
> | Unsupported Features - VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
> | AAD-2302              | IKEv2 VPN tunnels and Remote Access VPN connections may fail to establish when fragmented packets are encountered during IKEv2 negotiation, because IKEv2 Fragmentation is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.20           |
> | PMTR-60396            | Large Scale VPN (LSV) does not support: * IPv6 * Route Based VPN (VTI) * Two VPN peers behind the same NAT device * Suite-B-GCM-128 * Suite-B-GCM-256 with IKEv1-only (it is necessary to change the global properties of Phase 1 for Remote Access VPN) * Multiple Hubs * Route Injection Mechanism (RIM) * IKE Aggressive Mode * Permanent Tunnel * Multiple Entry Point (MEP) VPN * Dead Peer Detection (DPD) * Global VPN Community (GVC) * Tunnel Per Security Gateway pair (Universal Tunnel)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.40           |
> | PMTR-47783            | NAT-T initiator is not supported on VSX Gateways.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R80.10           |
> | PMTR-47235            | Converting Traditional VPN Policy to Simplified VPN Policy is not supported.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80              |
> | Unsupported Features - Zero Phishing                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |||
> | PMTR-81859            | Browser Zero Phishing is not supported in CloudGuard Network Security Auto Scale solution.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81              |
> | Unsupported Features - CloudGuard Network                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | PMTR-117752           | Microsoft Azure Gateway Load Balancer solution is not supported in R82.10.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82.10           |
>
> {#limitationTable}
>
> <br />
>
> ElasticXL and Quantum Maestro Unsupported Features {#Unsupported-SP}
> --------------------------------------------------------------------
>
> <br />
>
> Enter the string to filter the below table:
>
> <br />
>
> {#NSF_General}{#NSF_GaiaOS}{#NSF_Hardware}{#NSF_Licensing}{#NSF_Cluster}{#NSF_VSX}{#NSF_VSX}{#NSF_Networking}{#NSF_Firewall}{#NSF_VPN}{#NSF_IA}{#NSF_DLP}{#KL_TP}{#KL_SBMA}
>
> |------------------------|-----------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                     | Product   | Description                                                                                                                                                                                                                                                                                                                                                                         | Found in version |
> | ElasticXL and Quantum Maestro Unsupported Features - General                                                                                                                                                                                                                                                                                                                                                                             ||||
> | PMTR-108783            | ElasticXL | DHCP Server is not supported on ElasticXL.                                                                                                                                                                                                                                                                                                                                          | R82              |
> | PMTR-107886            | ElasticXL | Interface Active Check (IAC) is not supported on ElasticXL.                                                                                                                                                                                                                                                                                                                         | R82              |
> | PMTR-84368             | Maestro   | Configuring Auto Scaling Settings is not supported if a Maestro Security Group contains different appliance models.                                                                                                                                                                                                                                                                 | R81.20           |
> | PMTR-111387, MBS-10252 | Maestro   | Maestro does not support Zero Touch.                                                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-111384, MBS-12257 | Maestro   | Maestro does not support the detection of IP address conflict in Gaia OS.                                                                                                                                                                                                                                                                                                           | R81              |
> | PMTR-111368, MBS-9128  | All       | The Unique IP address per Chassis (UIPC) feature is not supported for IPv6 addresses.                                                                                                                                                                                                                                                                                               | R80.20SP         |
> | PMTR-111382, MBS-3001  | All       | The `fw fetchlog` command on the Management Server is not supported. * Use SmartConsole to fetch logs from Security Members.                                                                                                                                                                                                                                                        | R80.20SP         |
> | PMTR-111386, MBS-3246  | Maestro   | Maestro in VSNext mode does not support DHCP Server configuration                                                                                                                                                                                                                                                                                                                   | R80.20SP         |
> | PMTR-108605            | All       | OPSEC SDK is not supported.                                                                                                                                                                                                                                                                                                                                                         | R76SP            |
> | PMTR-108606            | All       | Hide NAT for traffic initiated from the Management interface of a Security Group is not supported.                                                                                                                                                                                                                                                                                  | R76SP            |
> | ElasticXL and Quantum Maestro Unsupported Features - Gaia OS                                                                                                                                                                                                                                                                                                                                                                             ||||
> | PMTR-101680            | ElasticXL | ElasticXL supports IP Broadcast Helper (iphelper) in Gaia OS only when two ElasticXL Sites are configured.                                                                                                                                                                                                                                                                          | R82              |
> | PMTR-108178            | ElasticXL | In the Gaia First Time Configuration Wizard, when configuring the first ElasticXL Cluster Member, it is possible to configure an IP address only on the "Mgmt" (Management) interface. This is done on the "Management Connection" page of the wizard. Configuring an IP address on any other interface, such as on the "Internet Connection" page of the wizard, is not supported. | R82              |
> | PMTR-71560, MBS-7145   | Maestro   | Maestro does not support the Dynamic CLI. Refer to [sk144112](https://support.checkpoint.com/results/sk/sk144112).                                                                                                                                                                                                                                                                  | R80.30SP         |
> | PMTR-111362, MBS-13308 | All       | The `set iphelper` (IP Broadcast Helper) commands are not supported in Gaia gClish.                                                                                                                                                                                                                                                                                                 | R80.20SP         |
> | PMTR-90800             | Maestro   | It is not supported to use the `set web ssl-port` command to change the MHO's WebUI SSL port from the default port 443 (for example: `set web ssl-port 4434`). Changing it causes communication issues between Maestro devices.                                                                                                                                                     | R80.20SP         |
> | ElasticXL and Quantum Maestro Unsupported Features - Hardware                                                                                                                                                                                                                                                                                                                                                                            ||||
> | PMTR-106636, MBS-1244  | All       | The Check Point Performance Sizing Utility *cpsizeme* (see [sk88160](https://support.checkpoint.com/results/sk/sk88160)) is not supported.                                                                                                                                                                                                                                          | R80.20SP         |
> | PMTR-111375, MBS-4754  | All       | Central Management of Gaia Device Settings is not supported: 1. In SmartConsole, click "Gateways \& Servers" on the navigation panel. 2. Right-click the Gateway object or the Maestro Security Appliance Gateway object. 3. The "Scripts" menu and "Actions" menu are not supported.                                                                                               | R80.20SP         |
> | PMTR-111360, MBS-5227  | Maestro   | It is not supported to install both of the following expansion cards in the same Security Appliance connected to a Maestro Hyperscale Orchestrator: * 10 GbE and 40 GbE * 10 GbE and 100 GbE                                                                                                                                                                                        | R80.20SP         |
> | ElasticXL and Quantum Maestro Unsupported Features - Licensing                                                                                                                                                                                                                                                                                                                                                                           ||||
> | PMTR-111374, MBS-7929  | Maestro   | Central License is not supported on Quantum Maestro.                                                                                                                                                                                                                                                                                                                                | R80.20SP         |
> | ElasticXL and Quantum Maestro Unsupported Features - Cluster                                                                                                                                                                                                                                                                                                                                                                             ||||
> | PMTR-99761             | ElasticXL | Bridge is not supported on ElasticXL in Load Sharing mode.                                                                                                                                                                                                                                                                                                                          | R82              |
> | PMTR-111390, MBS-12227 | Maestro   | Active-Active cluster does not support Maestro.                                                                                                                                                                                                                                                                                                                                     | R81              |
> | PMTR-111364, MBS-7913  | Maestro   | Cluster Control Protocol (CCP) encryption is not supported.                                                                                                                                                                                                                                                                                                                         | R80. 30SP        |
> | PMTR-106619            | All       | BGP confederations are not supported.                                                                                                                                                                                                                                                                                                                                               | R76SP            |
> | ElasticXL and Quantum Maestro Unsupported Features - SecureXL                                                                                                                                                                                                                                                                                                                                                                            ||||
> | PMTR-122236            | ElasticXL | Policy-Based Routing (PBR) with ElasticXL requires configuring the incoming interface and any PBR rules.                                                                                                                                                                                                                                                                            | R82              |
> | PMTR-111379, MBS-5415  | All       | Configuring the IPS protection "SYN Attack" in SmartConsole is not supported. You must only use the `fwaccel synatk` and `fwaccel6 synatk` CLI commands.                                                                                                                                                                                                                            | R80.20SP         |
> | ElasticXL and Quantum Maestro Unsupported Features - VSX                                                                                                                                                                                                                                                                                                                                                                                 ||||
> | PMTR-60874, ACCHA-736  | Maestro   | VxLAN interfaces are not supported on Quantum Maestro.                                                                                                                                                                                                                                                                                                                              | R80.20SP         |
> | PMTR-111371, MBS-16945 | All       | NAT46 is not supported in VSX.                                                                                                                                                                                                                                                                                                                                                      | R80.20SP         |
> | ElasticXL and Quantum Maestro Unsupported Features - Networking                                                                                                                                                                                                                                                                                                                                                                          ||||
> | PMTR-111442, MBS-14222 | Maestro   | Maestro does not support Dynamic Routing protocols over GRE tunnels.                                                                                                                                                                                                                                                                                                                | R81              |
> | PMTR-111441, MBS-14223 | Maestro   | Maestro does not support BGP over VXLAN tunnels.                                                                                                                                                                                                                                                                                                                                    | R81              |
> | PMTR-104455, MBS-3946  | Maestro   | Maestro does not support Carrier Security (LTE).                                                                                                                                                                                                                                                                                                                                    | R80.20SP         |
> | PMTR-111367, MBS-12823 | All       | "*6in4 tunnel*" interface is not supported.                                                                                                                                                                                                                                                                                                                                         | R80.20SP         |
> | PMTR-111445, MBS-14200 | Maestro   | Maestro does not support RIPng (IPv6).                                                                                                                                                                                                                                                                                                                                              | R76SP            |
> | ElasticXL and Quantum Maestro Unsupported Features - Firewall                                                                                                                                                                                                                                                                                                                                                                            ||||
> | PMTR-111383, MBS-14173 | All       | ConnectControl is not supported.                                                                                                                                                                                                                                                                                                                                                    | R76SP.50         |
> | ElasticXL and Quantum Maestro Unsupported Features - VPN                                                                                                                                                                                                                                                                                                                                                                                 ||||
> | PMTR-111847, MBS-12310 | Maestro   | Maestro does not support Large Scale VPN (LSV).                                                                                                                                                                                                                                                                                                                                     | R81              |
> | PMTR-111366, MBS-14408 | All       | Simultaneous Login Prevention (SLP) is not supported.                                                                                                                                                                                                                                                                                                                               | R80.20SP         |
> | PMTR-111444, MBS-4097  | All       | * Site-to-Site VPN with IPv6 peers is not supported. * Remote Access VPN from IPv6 clients is not supported.                                                                                                                                                                                                                                                                        | R80.20SP         |
> | AAD-1653, MBS-8316     | All       | IPv6 VPN is not supported.                                                                                                                                                                                                                                                                                                                                                          | R80.20SP         |
> | ElasticXL and Quantum Maestro Unsupported Features - Identity Awareness                                                                                                                                                                                                                                                                                                                                                                  ||||
> | PMTR-111378, MBS-14460 | Maestro   | Maestro Security Group does not support the Identity Awareness Captive Portal if the L4 distribution is enabled.                                                                                                                                                                                                                                                                    | R80.20SP         |
> | ElasticXL and Quantum Maestro Unsupported Features - DLP                                                                                                                                                                                                                                                                                                                                                                                 ||||
> | PMTR-111370, MBS-13243 | All       | The Data Loss Prevention Software Blade does not support rules with the Action "Ask".                                                                                                                                                                                                                                                                                               | R80.20SP         |
> | PMTR-108607            | All       | DLP Fingerprint is not supported.                                                                                                                                                                                                                                                                                                                                                   | R76SP            |
> | ElasticXL and Quantum Maestro Unsupported Features - Threat Prevention                                                                                                                                                                                                                                                                                                                                                                   ||||
> | PMTR-111385, MBS-12329 | All       | Inspection of SMBv3 multi-channel with Anti-Virus and Threat Emulation Software Blades is not supported.                                                                                                                                                                                                                                                                            | R81              |
> | ElasticXL and Quantum Maestro Unsupported Features - Mobile Access                                                                                                                                                                                                                                                                                                                                                                       ||||
> | PMTR-111377, MBS-14368 | All       | The Mobile Access Portal Agent is not supported.                                                                                                                                                                                                                                                                                                                                    | R80.20SP         |

> {#SPTable}

*** ** * ** ***

<br />

<br />

<br />

Known Limitations

**Installation and Upgrade**
>
> Enter the string to filter the below table:
>
> {#Installation and Upgrade}
>
> |-------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID          | Description                                                                                                                                                                        | Found in version |
> | Installation and Upgrade                                                                                                                                                                                          |||
> | PMTR-108824 | The "*Timeout waiting for response from database server* " message may be shown when performing "*set snapshot revert*" and the member goes to reboot. The issue is cosmetic only. | R82              |
> | PMTR-61069  | SmartEvent upgrade is allowed only after all Multi-Domain Management Servers with Active Domain Management Servers are upgraded.                                                   | R81              |

> {#UpgradeTable}

*** ** * ** ***

> <br />
>
**Quantum Security Gateway** / Identity Awareness / Gaia OS / VSX (Traditional) \& VSNext / VPN / QoS / ClusterXL / SecureXL
> <br />
>
> Identity Awareness
>
> Quantum Security Gateway \| Identity Awareness \| Gaia OS \| VSX (Traditional) / VSNext \| VPN \| QoS \| ClusterXL \| SecureXL
>
> <br />
>
> Enter the string to filter the below table:
>
> . {#Security Gateway}{#Identity Awareness}{#Gaia OS}{#VSX}{#VPN}{#QoS}{#ClusterXL}{#SecureXL}
>
> |-------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                                  | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | Found in version |
> | Quantum Security Gateway                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-92527                          | The `enabled_blades` command shows these errors instead of the expected output when running this command multiple times in parallel: `cat: /tmp/bladesStatus/blades_list: No such file or directory` `sed: can't read /tmp/bladesStatus/local_obj: No such file or directory`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R82              |
> | PMTR-117260                         | Security Gateway drops FTP "Extended Passive Mode" traffic on a Clean Up rule, although an explicit Access Control rule is configured. See [sk183853](https://support.checkpoint.com/results/sk/sk183853). * **Resolved** in [R82.10 Jumbo Hotfix Accumulator Take 36](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm)                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10           |
> | PMTR-59152                          | Traffic on a single GRE tunnel cannot be distributed to multiple CoreXL Firewall instances. Therefore, the maximum throughput of a single GRE tunnel is limited by the throughput of a single CoreXL Firewall instance.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81              |
> | PMTR-38747                          | Output of the `fw ctl zdebug + drop` command shows messages about connection drops, in addition to Firewall drops. These are internal debug messages that do not reflect real Firewall drops. To avoid them, use one of these: 1. The `fw ctl zdebug drop` command without the "`+`" character in the syntax 2. The full debug procedure                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.20           |
> | PMTR-42525                          | When Using a rule with legacy object, in or below a rule with one of the new features that are integrated in the unified policy, install policy on a Security Gateway fails with a verification message. * **To resolve**: change the order of the rules so that rules with legacy objects are above rules with new features. Refer to [sk115961](https://support.checkpoint.com/results/sk/sk115961).                                                                                                                                                                                                                                                                                                                                                                                                             | R80.10           |
> | PMTR-109230, PMTR-47316, PMTR-17546 | Logging session does not switch to the backup logging Server after connectivity loss. Refer to [sk118697](https://support.checkpoint.com/results/sk/sk118697).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R7x              |
> | Identity Awareness                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |||
> | PMTR-117380                         | When working in parallel with the Management API and SmartConsole, sometimes you cannot navigate to/from the Sharing Identity page. * **To resolve:** close and reopen the SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82.10           |
> | Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-122146                         | If there are multiple snapshots stored on the Gateway server, new snapshot creation fails with the error `"Cannot create snapshot, insufficient space in /boot"`, although there is enough unpartitioned space. * **To resolve:** delete or export some of the locally stored snapshots.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82.10           |
> | PMTR-120025                         | The Ansible Playbook role "`check_point.gaia.cp_gaia_role`" may fail on every several attempts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R82              |
> | PMTR-116563                         | The 3600 and 3800 appliances continue to send the SNMP Trap "`powerSupplyFailure`" even after disabling the alarm LED activation as described in [sk166000](https://support.checkpoint.com/results/sk/sk166000).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82              |
> | PMTR-51440                          | While the 4x10G Fiber NIC (CPAC-4-10F-B) is installed in the appliance, the HW Diagnostics "Network Test" fails with these messages: `Network Test: Failed` `General Error`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81              |
> | PMTR-81308, GAIA-3345               | Changing the MTU on the directly connected switches may cause drops of fragmented traffic due to a MTU mismatch.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.30           |
> | PMTR-47577                          | If the backup schedule is changed to an invalid date or time, all backup schedules are lost and "*Backup schedule failed. The backup will not be scheduled*" error message is displayed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R80.10           |
> | VSX (Traditional) / VSNext                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
> | PMTR-120495                         | It is not recommended to run the `fw unloadolcal` command on a VSX/VSNext, as this may break packet forwarding on all virtual switches.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R82              |
> | PMTR-60160                          | In VSX, you can use the `vsx_util downgrade` command only if you did not make any configuration changes after you used the `vsx_util upgrade` command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81              |
> | VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
> | PMTR-104094                         | If Perfect Forward Secrecy is enabled, Remote Access VPN client may disconnect from the Security Gateway in one hour.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R82              |
> | PMTR-101631                         | "IPSec VPN" page in the Security Gateway object still shows a selected VPN Community, although the configuration changes were discarded. Refer to [sk182068](https://support.checkpoint.com/results/sk/sk182068).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-68228                          | If the Diffie-Hellman (DH) group configuration is changed (SmartConsole \> Global Properties \> Remote Access \> VPN - Authentication and Encryption \> Encryption algorithms \> Edit \> Phase 1 \> Use Diffie-Hellman group) while an Endpoint VPN client is connected, the client disconnects during the next Phase 2 negotiation.                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R81              |
> | PMTR-55445                          | Site to Site VPN with a Large Scale VPN profile can drop traffic after decryption with the log "*According to policy traffic shouldn't have been decrypted* ". **To prevent this traffic drop**: 1. Edit the Large Scale VPN profile object: 1. On the VPN Domain page, in the section "IP addresses allowed in the VPN Domain" select "Restrict to these groups or networks" 2. Select the applicable "Host", "Network", and "Group" objects. 2. Edit the LSV peer object: 1. In the VPN Domain (Encryption Domain), select the "Address Range" objects, whose IP addresses contain the IP addresses of the "Host", "Network", and "Group" objects you selected in the Large Scale VPN profile object. 3. Install the Security Policy.                                                                            | R81              |
> | PMTR-33694, PMTR-44902              | After running the `cpstop ; cpstart` commands, the "*FW-1: fwconn_chain_get_opaque: invalid id -1*" message appears repeatedly on the screen and in the dmesg. This is a cosmetic issue only.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.20           |
> | PMTR-58668                          | If a Security Gateway with PIM configured is part of a VPN community, PIM service must be added to the Excluded Services in the VPN community object. This only applies in one of these scenarios: * Security Gateway is directly connected to a multicast sender * Security Gateway is configured as a PIM Rendezvous Point                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.10           |
> | PMTR-47752                          | The VPN client shows as "*Not Compliant* " when it is not compliant according to the local.scv file, even if SCV is disabled. * **To resolve**: Configure the VPN site again on the client.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.10           |
> | PMTR-47501                          | When using a VPN client, activity logs are not generated for ICMP traffic.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R7x              |
> | PMTR-50210                          | RADIUS authentication fails for LDAP users as the Security Gateway uses *sAMAccountName* and not UPN when UPN is needed. Refer to [sk122477](https://support.checkpoint.com/results/sk/sk122477).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R7x              |
> | QoS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |||
> | PMTR-47566                          | No warning is displayed if an empty network group object appears in the source or destination column.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R7x              |
> | ClusterXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | ACCHA-3403                          | Traffic outage may occur in a ClusterXL / VSX Virtual System configured in the Active/Standby Bridge Mode after a cluster failover that was caused by the disconnection of the direct bridge link.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.10           |
> | SecureXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |||
> | PMTR-120253                         | In VSX mode, when running performance tests at higher CPS (Connections per second) across different sources and destinations, the Security Gateway will experience drops because that source-based routing is enabled in VSX mode by default. * **To resolve:** Disable source-based routing to reduce the number of cache entries created and deleted during CPS test and improves the performance. Run: `fw ctl set -f int cphwd_enable_ecmp 0 -a`                                                                                                                                                                                                                                                                                                                                                               | R82.10           |
> | PMTR-121309, PMTR-121673            | If appliance includes one of the following line cards (CPAC-2-40F-B, CPAC-2-40F-C, CPAC-2-100/25F-B), then use this upgrade procedure to R82.10: 1. Install R82 2. Upgrade to R82.10 Ensure the correct firmware version is installed on card: 1. Connect to the command line on the appliance. 2. Log in. 3. If the default shell is Gaia Clish, go to the Expert mode: `expert` 4. Get the current firmware version: `ethtool -i <Name of Line Card Interface>` Example output: `[Expert@MyGW:0]# ethtool -i eth1-01` `driver: mlx5_pci` `version: DPDK 20.11.7.4.0 (14 Nov 24)` `firmware-version: 12.26.6402` Check that the firmware-version is either 12.26.6402 or 12.28.2700 * **Resolved** in [R82.10 Jumbo Hotfix Accumulator Take 6](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) | R82.10           |

> {#GatewayTable}

*** ** * ** ***

**Quantum Security Management** / Multi-Domain Security Management / Compliance / Logging / SmartEvent / SmartProvisioning
> <br />
>
> Quantum Security Management \| Multi-Domain Security Management \| Compliance \| Logging \| SmartEvent \| SmartProvisioning
>
> <br />
>
> Enter the string to filter the below table:
>
> {#Quantum Security Management}{#MDS}{#Compliance}{#Logging}{#SmartEvent}{#SmartProvisioning}
>
> |------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID                     | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | Found in version |
> | Quantum Security Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |||
> | PMTR-116108            | Wildcard objects do not appear in the search results when searching by IP address.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R82              |
> | PMTR-74025             | In API commands like `show-software-packages-per-targets` and in the SmartConsole, the "installed" field remains empty. As a result, The Security Management is not aware of the specific image installed on SMB appliances, but only of the version.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-85908             | When configuring the SD-WAN interface of the Security Gateway with the `set_sdwan` command and then perform "Get Interfaces" in SmartConsole while the interface has already been listed on the Network Management page (as internal), the interface may not turn to external as expected. * **To resolve:** Remove this interface from the Network Management page and perform "Get Interfaces" again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10           |
> | PMTR-51456             | The value configured in SmartConsole \> Global properties \> Advanced \> Configure \> Central Device Management \> "*device_settings_max_script_length_in_KB* " field is not applied. The upper limit is always 8 kilobytes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10           |
> | PMTR-56141             | When fetching a VPN Tunnel Interface (VTI) from Cluster Members using the `get-interfaces` Management API command, you must configure the Cluster VIP address using the `set simple-cluster` API before publishing the session. Examples: 1. `mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "private"` 2. `mgmt_cli -s sid.txt set-simple-cluster name cluster1 interfaces.update.name vpnt1 interfaces.update.interface-type "cluster" interfaces.update.ip-address 1.2.3.4 interfaces.update.ipv4-mask-length 24`                                                                                                                                                                                                                                                                                                                                         | R81              |
> | PMTR-60100             | When creating a rule with the "Detailed Log" track without "Accounting" disabled, the "Accounting" still appears after you close and open SmartConsole. * **To resolve**: Modify the rule to remove the "Accounting" setting.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.40           |
> | PMTR-50315             | "*Certificate with the same Distinguished Name already installed for another CA* " message in SmartConsole in the following scenario: 1. A user started to create a new Trusted CA object with a certificate 2. A user discarded the session 3. A user tried to create a new Trusted CA object with the same certificate                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | PMTR-81309, PRHF-14607 | Running a one time script on a Security Gateway (that reads files or outputs of commands) using a "One Time Script" feature in SmartConsole or with API may fail after 5 minutes with the "Operation timed out" error. The limit for reading files is 9,730 lines or 730 KB (whichever is reached first).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R80.10           |
> | PMTR-54350             | The API `show access-rule` with the specified values `from-date` or `to-date` in the `hits-setting `parameter, returns accurate data only when these timestamps cover more than the last 24 hours. For example, on May 27th at 14:00, the query must not cover any part of the last 24 hours (between May 26th at 14:00 and May 27th at 14:00).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.10           |
> | PMTR-41764             | The "URL" field shows "*\*\*\* Confidential \*\*\**" in HTTPS Inspection logs on 3rd party LEA OPSEC client.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R7x              |
> | Multi-Domain Security Management                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |||
> | PMTR-62123             | In Multi-Domain Servers, you cannot create an install policy preset with a policy package that has an OSE device as the target, due to an internal error when trying to get target information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10           |
> | PMTR-60856             | To correlate logs from the Domain Management Server in a NAT environment, in which a Domain Management Server is hidden behind a NATed address, and a Domain Dedicated SmartEvent Server has an external IP address, an administrator must follow these steps: 1. Connect with SmartConsole to the Domain Management Server 2. Create a dummy Check Point Host object with the external IP address of the Domain Management Server 3. Enable the "Logging" Software Blade in this Check Point Host object 4. Install database on the Domain Management Server 5. Open the SmartEvent GUI and connect to the Dedicated SmartEvent Server 6. In the list of the log servers, from which the Correlation Unit reads the data: remove the Domain Management Server object with the real IP address and add the dummy Check Point Host object (with the external IP address) 7. Install the Event Policy and close the SmartEvent GUI | R81              |
> | Compliance                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | PMTR-47756             | In a Multi-Domain Management environment, in the local Domain policy, some Compliance best practices, which validate the status of rules in the policy, incorrectly identify the section header, "Parent section for domain rules," as a rule, and report it as not valid. * **To resolve**: Manually exclude this result from the Best Practices view. To do so, in the Best Practices view, select the practice. In the bottom pane \> Relevant Object section \> double-click the desired rulebase object and disable the rule/section from the list.                                                                                                                                                                                                                                                                                                                                                                         | R80.10           |
> | PMTR-47761             | In a Multi-Domain environment, policy changes in the Global Compliance Policy do not trigger a partial Compliance scan.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80.10           |
> | Logging                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    |||
> | PMTR-120903            | In some scenarios when trying to export logs, operation fails and the `log_indexer` process crashes. * **Resolved** in [R82.10 Jumbo Hotfix Accumulator Take 6](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) (PRHF-42386)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-92829             | The output of the commands `cpstat mg -f log_server` or `cpstat ls -f logging` on a Security Management Server or Log Server that receives logs from a Maestro Security Group displays Log Receive Rate only for the individual Security Group Member (SMO), and not the combined log receive rate for all Security Group Members in the group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10           |
> | SmartEvent                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |||
> | PMTR-50435             | On a dedicated SmartEvent Server, the user who was configured in the First Time Configuration wizard cannot share items and view shared items in the SmartView application.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81              |
> | PMTR-66532             | SmartConsole \> "Logs \& Events" \> "Logs" tab may show duplicate log records with partial data for connection logs if log entries are spread over several log files due to a log switch. Log switch operation occurs in these scenarios on a Management Server / Log Server: * At midnight * When the size of the active log file reaches 2 GB * Based on user configuration (explicitly)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20           |
> | PMTR-47559             | On a dedicated SmartEvent Server which assigned to MDS, when you enable or disable a blade, the license information is not immediately updated. An automatic updates takes place at midnight. * **To resolve** and update immediately, ?n Server's command line, run: `$CPDIR/bin/esc_db_complete_linux_50 activation_data entitlement_data`If you manually change a license or contract, the changes take effect immediately.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80              |
> | SmartProvisioning                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-56630             | When you configure an LSM profile topology, do not reopen interface properties after you make a change. Instead, close the Topology grid and click OK to close the editor. When you reopen it, you will see the correct interface topology settings.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81              |
> | PMTR-49235             | A new object called "NewObject" is left in SmartConsole when an administrator creates a new object with same name as an object that exists in SmartProvisioning. * **To resolve**: Either click "No" when SmartConsole shows "Do you want to keep changes anyway?" or manually delete the new object called "NewObject".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R81              |
> | PMTR-45475             | The status of an SMB device in SmartProvisioning may show "*not responding*" for a short time, even though the status is OK.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.40           |
> | PMTR-1568              | When working with LSM managed Security Gateways in a Management High Availability environment, creating and working with LSM Gateways must be consistent, they can only be used in the Security Management Server they are created in. Using the secondary Security Management Server might lead to inconsistent actions/status related to LSM objects.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R80.20.M1        |
> | PMTR-70744             | The "Enable Provisioning" checkbox is greyed out in SmartProvisioning \> SmartLSM Security Gateway object properties \> "General" tab \> "Provisioning" section, if the user who logged into SmartConsole has a profile with assigned permissions other than "Read/Write All".                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.10           |
> | PMTR-8209              | After a major upgrade to a Security Management Server, LSM profiles lose their installed policy and new devices attached to them are not able to fetch a policy. * **To resolve**: Install policy on the LSM profiles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R7x              |

> {#ManagementTable}

*** ** * ** ***

**SmartConsole** / Management Console / SmartLog / SmartView
> <br />
>
> <br />
>
> Enter the string to filter the below table:
>
> {#Management_Console}{#SmartLo}
>
> |-------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID          | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Found in version |
> | SmartConsole / Management Console                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |||
> | PMTR-120528 | When upgrading from SmartConsole, the upgrade of the second cluster member may fail during the automatic policy installation with `"Installation failed. Reason: TCP connectivity failure ( port = 18191 )( IP = <IP address> )[ error no. 10 ]"` error. * **To resolve:** upgrade of the second member manually using the local CPUSE web page.                                                                                                                                                                                                                                                                                                                                               | R82.10           |
> | PMTR-120942 | The Management API commands "`add/set data-type-weighted-keywords`" and "`add data-type-file-attributes`" do not save the "description" field in the object.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R82.10           |
> | PMTR-121727 | When object is updated in the cloud environment (Smart-1 Cloud), the update may not be shown in the SmartConsole. Registration of Data Center assets with a numeric, non-UID unique identifier may fail, potentially causing performance impact on the Security Management Server. * **Resolved** in [R82.10 Jumbo Hotfix Accumulator Take 19](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) (PRJ-65014)                                                                                                                                                                                                                                                                  | R82.10           |
> | PMTR-121600 | Sync interfaces may not be fetched in the Maestro Security Group Member.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R82              |
> | PMTR-98504  | There may be a latency in connecting to SmartConsole with an administrator configured on an AD (LDAP) server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-121999 | When executing a SmartTask that is configured to send an email notification, it pulls the Submitter Email from the Contact Details instead of the Email field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.20           |
> | PMTR-121954 | In some scenarios, the wrong interface window opens in SmartConsole after you want to edit an interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.20           |
> | PMTR-122000 | When updating the time object for an Access Control rule, the summary tab does not update.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.20           |
> | PMTR-121843 | Best Practices might be missing or show incorrect results in the Security Best Practices view of Compliance blade.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R81.20           |
> | PMTR-86567  | When using the Updatable objects picker, the search may retrieve previously selected item's additional information.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-62190  | When creating a test user via the Mobile Access configuration page, the user's password is limited to 8 characters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-81166  | In a Multi-Domain Environment, when log in with SSO to a Domain behind NAT, the Security Gateway object will load but not open. * **To resolve:** Connect to the Domain directly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R81.20           |
> | PMTR-71266  | In SmartConsole, the "Get Interfaces" operation in a cluster object does not fetch interfaces with IP addresses from the subnet 1.1.1.0. * **To resolve:** Use the `get-interfaces` Management API.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R81.20           |
> | PMTR-119587 | On Multi-Domain Security Management Servers, custom Compliance Blade Best Practices may differ between the Multi-Domain Security Management level and the Domain level. * **Resolved** in [R82.10 Jumbo Hotfix Accumulator Take 6](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) (PRHF-41803)                                                                                                                                                                                                                                                                                                                                                                             | R81.10           |
> | PMTR-70829  | Central Deployment Package Repository is local to the Multi-Domain Server. In a Multi-Domain High Availability environment, make sure to initiate Central Deployment operations on the Server to which the package was added.                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R81.10           |
> | PMTR-58448  | When the screen resolution is low, changes in Log View widgets are not exported in PDF files: 1. In SmartConsole, from the left navigation panel click Logs \& Monitoring. 2. Click + to open a new tab. 3. From the left, click Views, and open any view. 4. Click Options \> Edit. 5. Make some layout changes - move, resize, delete, or add widgets, and click Done. 6. Click Options \> Export \> Export to PDF. 7. Download the PDF and open it. 8. The PDF file has the default layout.                                                                                                                                                                                                 | R81.10           |
> | PMTR-68527  | When you enter a search query that starts with "\*" in various search fields (for example, \*168.20), SmartConsole shows only objects that contain this partial string in their "Name", "Comment", or "IP Address" field.                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R81.10           |
> | PMTR-58272  | In the "Gateways \& Servers" view, the "Task" tab in the bottom pane does not show messages about a successful license attachment (shows messages only about a failed license attachment).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10           |
> | PMTR-60830  | A link named "*#.name* " appears in a policy (above the Shared Policies section) in this scenario: 1. From the left navigation panel, click the Security Policies view 2. Open a policy with the HTTPS Inspection 3. Click Access Control \> HTTPS Inspection 4. In the Certificate column, right-click a certificate and select Where Used 5. In the Where Used window, click the Policies tab 6. Double-click a policy that does not contain the Access Control (contains only Threat Prevention or QoS) 7. The policy opens, but instead of HTTPS Inspection section, a link named "*#.name*" appears * **To resolve**: 1. Close the Where Used window 2. Manually open the affected policy | R81.10           |
> | PMTR-78482  | If you delete an existing object of a Centrally Managed Quantum Spark appliance with the model 1800 or lower and some name (for example, "XXX"), then you cannot create another object of a Centrally Managed Quantum Spark appliance: 1. With the same name "XXX" - SmartConsole shows "*Name already used!*" 2. With the name of that contains the previous name (for example, "XXXnew") - SmartConsole shows "*There is another network object \[XXX\] with the same IPv4 address*"                                                                                                                                                                                                         | R81              |
> | PMTR-58838  | Changes (Diff) report: * does not track rule numbers or rule positions in the policy (If a sub-rule is changed, the report only shows the number of the sub-rule and not the number of the parent rule). * does not show changes made in: Inspection Settings, Software Blade Engine settings, Multi-Domain Management Server settings, and administrator settings (including permission profiles and all other options in Manage \& Settings \> Permissions \& Administrators). * In the Changes (Diff) report, there is inconsistency between the number of changes that appear in the session toolbar and the Revisions view.                                                               | R81              |
> | PMTR-42956  | In HTTPS Inspection policy rules, when selecting the same action that already appears in the "Action" column, the Management Server counts it as part of the session changes.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.40           |
> | PMTR-38804  | The "Import Node" action (accessible from the SmartConsole Network Object tree \> Nodes \> Import) can fail with "*Internal Error*" message.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.40           |
> | PMTR-31345  | In languages other than English, the blades in the summary tab are not arranged correctly.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.30           |
> | PMTR-27705  | When installing a policy, "*The policy included Blades that have an expired contract or a contract that is about to expire*" warnings are displayed only for Application Control and URL Filtering and not for all Service Blades.                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.30           |
> | PMTR-31193  | Search for disabled or expired rules in Access Control policy does not work.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | R80.30           |
> | PMTR-25063  | The "Groups" page / tab is not shown if you edit a predefined service.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.20.M2        |
> | PMTR-39387  | Hitcount of Shared Inline Layer rules shows the sum of all rules it is used in as it is shared between all of them.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R80.20           |
> | PMTR-50263  | No warning is displayed, if an empty Network Group object appears in the "Source", "Destination", or "Protected Scope" column of a Threat Prevention policy rule.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R80.10           |
> | PMTR-40848  | When an inline layer appears more than once in an ordered layer, in logs that are generated from rules in that layer, the "Go to rule" link does not always navigate to the correct occurrence of the rule in the policy. * To find the other occurrences of the rule, use the packet mode search with the rule's information. For more information about packet mode search, refer to [sk118592](https://support.checkpoint.com/results/sk/sk118592).                                                                                                                                                                                                                                         | R80.10           |
> | PMTR-82170  | After upgrading the Security Management Server from to R80.x, users cannot add suggestions to add objects to group - the options are grayed out. Refer to [sk118276](https://support.checkpoint.com/results/sk/sk118276).                                                                                                                                                                                                                                                                                                                                                                                                                                                                      | R80.10           |
> | PMTR-36940  | When selecting a source or destination for a user object, cluster objects are not available for selection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.10           |
> | SmartLog / SmartView                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |||
> | PMTR-111298 | Query for the "drop_reason" field in SmartConsole / SmartView \> Logs \& Events view \> Logs tab does not return data because this log field is not indexed in Security Gateway traffic logs.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R82              |
> | PMTR-118511 | When searching the logs by source or destination and using URL Filtering, the screen go blank when certain logs are supposed to appear.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R81.20           |
> | PMTR-55182  | In the Logs view, the sessions timeline widget is missing when connecting to the SmartView web interface of a Dedicated Log Server or a Domain Log Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R81.10           |
> | PMTR-42730  | When viewing logs in the SmartView Web portal, the description fields are empty.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-44559  | When querying logs in the SmartView web Logs tab, the numbers shown in the timeline section do not correlate to the log list if the indexing retention policy in SmartEvent and the Log Server are not the same.                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.40           |
> | PMTR-45323  | Updatable objects are not resolved in SmartLog/SmartEvent queries: 1. You cannot create a filter or SmartView query which contains an Updatable object name. 2. When viewing logs/events, the IP address of an Updatable object is not resolved to a name.                                                                                                                                                                                                                                                                                                                                                                                                                                     | R80.20.M2        |
> | PMTR-47699  | In a global SmartEvent configured in Multi-Domain environment, SAM rules are not created by events auto-reactions. * **To resolve**: refer to [sk86941](https://support.checkpoint.com/results/sk/sk86941).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R80.10           |
> | PMTR-47589  | Users connected with SmartConsole to specific Domain, will not be able to see Global objects assigned to this Domain in SmartLog logs results, and cannot search by Global objects (but can search by IP address).                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R7x              |

> {#ConsoleTable}

*** ** * ** ***

**Access Control** Mobile Access / DLP
> <br />
>
> Mobile Access \| DLP
>
> <br />
>
> Enter the string to filter the below table:
>
> {#Mobile Access}{#DLP}
>
> |------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Found in version |
> | Mobile Access                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-41608 | Error: "*Failed to generate RADIUS auth request*" when a Mobile Access user browses to a resource that requires authentication.                                                                                                                                                                                                                                                                                                                                                                                                                                         | R80.40           |
> | PMTR-70    | If you use Outlook Anywhere application with Mobile Access Reverse Proxy, and then want to disable Outlook Anywhere or Reverse Proxy, perform: 1. Delete Outlook Anywhere rule from reverse proxy. 2. Run `cvpnrestart --with-pinger` to close all Outlook Anywhere open connections. If you do not perform step 2, open connections of Outlook Anywhere will not be closed and users can still work with it.                                                                                                                                                           | R80.10           |
> | PMTR-47782 | After upgrading a Standalone (Management and Gateway) or VSX deployment with Mobile Access blade enabled, the "*Allow Dynamic ID for mobile devices* " option might be enabled by default, even if Dynamic ID was not configured prior to the upgrade. * If you do not want Dynamic ID authentication for Capsule Workspace users, disable it in: Gateway Properties \> Mobile Access \> Authentication \> Compatibility with Older clients \> Settings \> Capsule Workspace section \> clear Enable DynamicID. For VSX, this configuration is done per Virtual System. | R80.10           |
> | PMTR-47499 | When Mobile Access is included in the Unified Access Policy, in Mobile Access Authorization logs \> Log Details \> Matched Rules, the Mobile Access Application name and Category do not show.                                                                                                                                                                                                                                                                                                                                                                          | R7x              |
> | DLP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |||
> | PMTR-47691 | DLP can apply visible or hidden Watermark (for forensic tracking) to Office Open XML formats (DOCX, PPTX and XLSX) as a rule action in a DLP rule base. Refer to [sk117413](https://support.checkpoint.com/results/sk/sk117413) if DLP Watermark is used.                                                                                                                                                                                                                                                                                                               | R80.10           |

> {#AccessTable}

*** ** * ** ***

**Threat Prevention**
>
> Enter the string to filter the below table:
>
> {#Anti-Malware}
>
> |-------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID          | Description                                                                                                                                                                                                                                                                                                                                                                                                                            | Found in version |
> | Threat Prevention                                                                                                                                                                                                                                                                                                                                                                                                                                                     |||
> | PMTR-107710 | The "DNS Mismatched replies" IPS protection does not work after upgrade.                                                                                                                                                                                                                                                                                                                                                               | R82              |
> | PMTR-107493 | DNS NAT does not work on R82 Security Gateways.                                                                                                                                                                                                                                                                                                                                                                                        | R82              |
> | PMTR-107712 | In some scenarios, DNS Trap may fail to replace DNS replies with bogus IP addresses on certain connections, resulting in dropped connections. This prevents affected hosts from receiving the intended IP address but also limits the visibility into which host IPs are impacted.                                                                                                                                                     | R82              |
> | PMTR-85353  | When you activate Threat Emulation with the "Hold" mode, Threat Extraction, Zero Phishing, or Anti-Virus Deep Inspection, the Security Gateway downgrades the relevant connections from HTTP/2 to HTTP 1.1. To force HTTP/2, run this command on the Security Gateway / Security Group / each Cluster Member: `fw ctl set -f int disable_http2_with_strict_hold 0` Limitation: Zero Phishing will keep downgrading HTTP/2 to HTTP 1.1. | R81.20           |
> | PMTR-80495  | An exception in an Anti-Virus or Anti-Bot protection added manually to the rule base does not work. * To add an exception in an Anti-Virus or Anti-Bot protection, open the corresponding Security Gateway log in SmartConsole and click the link "Add Exception".                                                                                                                                                                     | R81.20           |
> | PMTR-76710  | When Security Gateways use an Autonomous Threat Prevention policy: * Compliance Best Practices do not support the checks for the Threat Prevention Software Blade. * The Compliance Software Blade may show an incorrect status for the Threat Prevention checks.                                                                                                                                                                      | R81.20           |
> | PMTR-19839  | CRL validation is not supported in pure IPv6 environments (when IPv4 addresses are not configured on the Security Gateway's interfaces).                                                                                                                                                                                                                                                                                               | R80.20           |

> {#ThreatTable}

*** ** * ** ***

**Endpoint Security**
> {#Endpoint Security}
>
> |------------|----------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                  | Found in version |
> | Endpoint Security / SmartEndpoint                                                                                          |||
> | PMTR-68226 | The Perfect Forward Secrecy (PFS) feature supports only Diffie-Hellman (DH) groups 2 and 14. | R81.10           |

*** ** * ** ***

<br />

**Quantum Spark Gateways**
> {#Small Office Appliances}
>
> |------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------|
> | ID         | Description                                                                                                                                                                                                                                                                                                                                                                                      | Found in version |
> | Quantum Spark Gateways                                                                                                                                                                                                                                                                                                                                                                                                         |||
> | PMTR-47520 | "*SIC error*" status may occur when the Gateway object is defined in a "Management first" scenario before it is deployed, but the device's IP address is already accessible. The Security Management tries to create SIC with the Gateway's IP address. Instead of the policy ending in a "waiting for first connection" status, an error message states the SIC status must be rectified first. | R7x              |

*** ** * ** ***

<br />

**ElasticXL and Quantum Maestro**
> General Limitations \| Gaia OS \| VSX \| CoreXL \| Networking \| VPN
>
> <br />
>
> Enter the string to filter the below table:
>
> {#KL_General}{#KL_GaiaOS}{#KL_VSX}{#KL_CoreXL}{#KL_Networking_Features}{#KL_SBVPN}
>
> |-------------|-----------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|----------|
> | ID          | Product   | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   | Found in |
> | ElasticXL and Quantum Maestro - General Limitations                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             ||||
> | PMTR-122558 | Maestro   | SIC fails on SMO with `"Failed to connect to the Security Gateway"` error after SIC reset on Maestro with MDPS enabled. * **To resolve:** An SMO reboot is required after an SIC reset on Maestro with MDPS enabled. After SIC reset from `cpconfig`, wait for all non-SMO members to reboot. After the reboot is complete, reboot SMO and wait for it to complete boot. Then re-establish SIC from SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R82.10   |
> | PMTR-107075 | ElasticXL | ElasticXL Cluster supports only physical Check Point appliances (Virtual Machines or Open Servers are not supported).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82      |
> | PMTR-107076 | ElasticXL | ElasticXL Cluster supports only Check Point appliances of the same model.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R82      |
> | PMTR-107077 | ElasticXL | ElasticXL Cluster requires each appliance to be after a Clean Install or restored to factory defaults.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R82      |
> | PMTR-109641 | Maestro   | In rare scenarios, after installing R82 on Maestro Orchestrator, the LLDP daemon (lldpd) is running but paused, and therefore does not transmit or process LLDP PDUs. As a result, MHO cannot communicate with the gateways. * **To resolve:**From the Expert mode, run on MHO: `lldpcli resume`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R82      |
> | PMTR-121616 | Maestro   | When a Maestro Security Group runs SecureXL in the UPPAK mode, the `asg perf` command fails with this error: `"can't read "stats(system_total,traffic,bps)": no such element in array"`. * **To resolve:**Use the [CPView utility](https://support.checkpoint.com/results/sk/sk101878).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10   |
> | PMTR-113582 | All       | On non-SMO members, QoS is enabled after policy installation despite being disabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R81.10   |
> | PMTR-93476  | All       | Management Aggregation (MAGG) bond mode is available only through the gClish of the Security Group (and not via the Gaia portal).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.20SP |
> | PMTR-111361 | All       | * The Active-Backup bond is supported only when a Primary slave is configured (for example: `set bonding group 1 primary eth1-05`). * The Active-Backup bond supports a maximum of 2 slaves.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20SP |
> | PMTR-111372 | Maestro   | Maestro Orchestrators and Security Group CIN interfaces are configured in the subnet of 198.51.10\<SG_ID\>.0. You cannot use this subnet for data and management interfaces.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20SP |
> | ElasticXL and Quantum Maestro - Gaia OS                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         ||||
> | PMTR-119680 | All       | On a Scalable Platform Security Group, the Gaia gClish command "`add user username uid <ID> homedir <PATH>`" does not stop if a home directory with the specified path already exists.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        | R82.10   |
> | PMTR-107433 | ElasticXL | Adding an unassigned interface to or from Sync bond leads to the flags reset and, as a result, it disrupts the ElasticXL detection and ElasticXL drops the packets.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | R82      |
> | PMTR-109292 | All       | Configuring a Unique IP per Site over the management interface is not possible if Management Data Plane Separation (MDPS) is enabled.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R82      |
> | PMTR-71458  | Maestro   | Collecting Gaia Backup and restoring Gaia Backup in Global Clish (gclish) is not supported on a Security Group that contains appliances of different models. * To collect Gaia Backup and restore Gaia Backup, you must use Gaia Clish (clish) on each appliance in the Security Group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R81.10   |
> | PMTR-111365 | Maestro   | On a Maestro Security Group, the Security Gateway does not show the correct speed of data and management interfaces. Run commands on the Orchestrator (the `orch_stat -p` command and Clish commands) to see the interface speed.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R80.30SP |
> | PMTR-111389 | All       | A Security Group cannot be configured as an NTP Server.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20SP |
> | PMTR-111373 | All       | To prevent the Gaia configuration mismatch between Security Group Members, it is not supported to change the user's password on a Security Group in these ways: * In Gaia Portal \> User Management \> Change My Password * In Gaia gClish with the command `set selfpasswd` To change the user's password on a Security Group, run one of these commands in Gaia gClish: * `set user <UserName> password` * `set user <UserName>password-hash <Password Hash>`                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R80.20SP |
> | PMTR-111388 | Maestro   | In Dual Site deployment, no warning is displayed when changing the "type" of the QSFP port in Gaia Clish on Maestro Hyperscale Orchestrators on the local site, while the Maestro Hyperscale Orchestrators on the remote site are down.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20SP |
> | PMTR-109474 | All       | When you run multiple Gaia gClish `set <...>` commands, one after another, some of these commands can stop running. When this happens, the message `"Processing Transaction"` shows in the output.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | R76SP    |
> | PMTR-108599 | All       | The `asg` commands are an extension of native Gaia gClish commands. The `asg` commands have different syntax and there is no auto-completion.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R76SP    |
> | PMTR-108600 | All       | A CLI command that uses a range for the parameter can only operate if all the relevant SGMs are defined in the security group.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R76SP    |
> | PMTR-108601 | All       | The arguments of the global commands are processed before the local (native) arguments, and this can cause the local arguments to be ignored. For example, the `g_ls -l /tmp/` command is processed as `ls /tmp/` on the local SGM instead of as `ls -l /tmp/` on all SGMs. Relocating the local arguments within the command (where applicable) can resolve the problem. For example, run the `g_ls /tmp/ -l` command instead of the `g_ls -l /tmp/` command.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | R76SP    |
> | PMTR-108602 | All       | Running the `asg_hard_shutdown` command on an SGM two times, one after the other, causes a reboot and not a shutdown. It takes one minute for the SGM to shut down after running the `asg_hard_shutdown` command. During this interval, do not run the `asg_hard_shutdown` command again.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R76SP    |
> | ElasticXL and Quantum Maestro - VSX                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             ||||
> | PMTR-106379 | ElasticXL | In ElasticXL in the VSNext mode (with 2 or more Security Appliances on one ElasticXL Site), VoIP UDP traffic is not supported between networks in this topology: Network 1 - Virtual System 1 - Virtual Switch - Virtual System 2 - Network 2                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R82      |
> | PMTR-108547 | ElasticXL | No information is shown on both servers when attempting to see the LLDP (lldpneighbors) between Security Management and a Virtual Gateway.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | R82      |
> | PMTR-111446 | Maestro   | A change in the number of CoreXL Firewall instances (in a VSX Virtual System object in SmartConsole) in Dual Chassis VSLS setup requires a downtime, because the Virtual System must be restarted. During this restart, traffic cannot pass through the Virtual System.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       | R80.20SP |
> | PMTR-109478 | All       | After running the `vsx_util reconfigure` command on the Management Server, the VLAN interface on a Security Group in VSX mode may come up without an IP address if the VLAN's MTU was set to a value larger than 1500. Refer to [sk111513](https://support.checkpoint.com/results/sk/sk111513).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | R76SP.40 |
> | PMTR-109469 | All       | No local configuration should be performed on a Security Group or on a Security Group Members while the `vsx_util reconfigure` command is running on the Management Server. It is necessary to wait until all Security Group Members and Virtual Systems are up and running (otherwise, the local configuration will not be applied).                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         | R76SP.30 |
> | PMTR-109468 | All       | You cannot configure Bond interfaces on chassis Management ports after you create the VSX object in SmartConsole.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | R76SP.20 |
> | PMTR-109476 | All       | The Alerts configuration wizard does not allow setting of performance thresholds per Virtual System. * **To resolve:** You can manually configure thresholds for Virtual Systems using the `dbset` command from the Expert mode: `g_all dbset chassis:vs:0:alert_threshold: <alert_name> <value>` Where `<value>` is the percentage of the default threshold per Security Group Member. Example: `[Expert@Host]# g_all dbset chassis:vs:0:alert_threshold:packet_rate_threshold_high 30` In this example, an alert is triggered when any Virtual System packet rate is higher than 30% x 1.8MB (1.8MB is the default packet rate threshold per SGM). Note: One ratio applies to all Virtual Systems.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | R76SP    |
> | PMTR-109465 | All       | If you lower the Connections Table limit of a Virtual System, and one of the SGMs has more or the same number of connections than the limit, the new value is rejected for that SGM. The new Connections Table limit may be accepted by other SGMs. Notes: * To see the current number of entries in the Connections Table, run the `fw tab -t connections -s` command in the Expert mode. * To configure the Connections Table limit of a Virtual System: In SmartConsole, open the Virtual System object \> Go to the "Capacity Optimization" pane \> Set the value in the "Limit the maximum concurrent connections" field \> click OK \> Install the policy.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              | R76SP    |
> | PMTR-109466 | All       | You cannot enable IPv6 before you create and configure a new VSX Gateway. You must first create the new VSX Gateway and then enable and configure IPv6 using Gaia gClish.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | R76SP    |
> | ElasticXL and Quantum Maestro Known Limitations - CoreXL                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        ||||
> | PMTR-74532  | All       | To make sure there is connectivity after changing the number of instances in the CoreXL configuration, follow these steps: 1. Reboot all Security Group Members one by one, **except the SMO**. **IMPORTANT: Traffic capacity is greatly reduced after you reboot all Security Group Members except the SMO, because only the SMO handles traffic until it is rebooted.** **Examples**: In a Dual Site deployment with four Security Group Members (two on each Site), where the SMO is "1_1", reboot the Security Group Members in this order: 1. Reboot the Security Group Member 2_2 on Site 2 and wait for it to finish the reboot. 2. Reboot the Security Group Member 2_1 on Site 2 and wait for it to finish the reboot. 3. Reboot the Security Group Member 1_2 on Site 1 and wait for it to finish the reboot. In a Single Site deployment with four Security Group Members, where the SMO is "1_1", reboot the Security Group Members in this order: 1. Reboot the Security Group Member 1_4 and wait for it to finish the reboot. 2. Reboot the Security Group Member 1_3 and wait for it to finish the reboot. 3. Reboot the Security Group Member 1_2 and wait for it to finish the reboot. 2. When a Security Group Member finishes the reboot, it enters the "DOWN" state because of a mismatch in the number of CoreXL Firewall instances with other Security Group Members. All other Security Group Members that were not rebooted yet, including the SMO, are in the "ACTIVE!" state (Active Attention) and handle traffic. 3. When all Security Group Members except the SMO have finished the reboot, you must reboot the SMO Security Group Member. A failover occurs immediately, and one of the other Security Group Members becomes the SMO. All other Security Group Members become "ACTIVE" and start to handle traffic. 4. When the last Security Group Member, which was the SMO, finishes the reboot, all Security Group Members become "ACTIVE" and full capacity is restored. | R80.20SP |
> | ElasticXL and Quantum Maestro Known Limitations - Networking                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    ||||
> | PMTR-111381 | All       | After a failover of the FTP control connection, it is not possible to open an asymmetric FTP data connection.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R80.20SP |
> | ElasticXL and Quantum Maestro Known Limitations - VPN                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           ||||
> | PMTR-108430 | All       | Performing Hide NAT on Remote Access VPN connection (on the decrypt connection) with L4 distribution enabled may lead to NAT port collisions.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | R81.10   |
> | PMTR-111380 | All       | VPN traffic on a VSX Virtual System that is connected to a VSX Virtual Switch is supported only when the distribution mode configured for the WRP interface is the same as the distribution mode configured for the physical interface on the VSX Virtual Switch. Example of a VSX topology: (Virtual System) == wrp100 == (Virtual Switch) == (eth1-01) The same distribution mode must be configured for the interface wrp100 as was configured for the interface eth1-01.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | R80.20SP |

> {#ScalableTable}

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
