Support Center > Search Results > SecureKnowledge Details
R80 Security and stability enhancements for Security Management server (Hotfix #1)
Solution

Table of Contents:

  • Introduction
  • Installation instructions
  • Uninstall instructions

Introduction

Effective April 25th, 2016, the R80 Gaia image has been replaced resolving the issues described below. By installing the new Gaia image, the R80 Security Management will automatically install this hotfix on top of the R80 installation.

This article provides a unified hotfix package for the following issues:

ID Symptoms
01996434,
01998604
When choosing "Show on Gateway_Name" in the Suspicious Activity Rules editor in SmartView Monitor, the following message appears: "Failed to monitor SAM rules".

New SAM (Suspicious activity Monitoring) rules cannot be added in SmartView Monitor. The following message appear after using the Add -> Enforce option to add a new SAM rule: "The block process failed".
01997794,
02006927
In rare scenarios login to SmartDashboard in Management HA environment fails after failover.
01999269,
02004412,
02015303 
Primary Multi-Domain Management server may crash with cpm core file. All FWM processes were in pending state and machine was out of memory.
01998131,
02005525,
02005566 
If the Threat Prevention profiles action is Ask, malicious sites can be reached with no redirection to the Anti-Virus ask page.
01998970,
02000508,
02004471,
01945475 
OPSEC Server Application object is missing after database import to R80.
02001921,
02016425 
RDP (UDP/port 259) is changed to RDP (UDP/port 3389) after upgrade to R80.
02004016,
02016247 
Pre-Upgrade Verifier crashes on export if the GUI client list ($FWDIR/conf/gui-clients) includes an empty line.
02020403,
02020470,
02020452 
"Services port conflict" warning when installing Security policy after upgrade to R80. 
Refer to sk111114.


Installation instructions

This Hotfix package is suitable for the following configurations on Gaia OS only:

  • Security Management server
  • Multi-Domain Management server
  • Instructions for Gaia OS using CPUSE (Check Point Update Service Engine)

    • Online installation

      1. Connect to the Gaia Portal on your Check Point machine and navigate to Upgrades (CPUSE) pane - click on Status and Actions.
      2. Select the hotfix package R80 Hotfix for sk111055 - click on Install Update button on the toolbar.
      3. Reboot is required.
    • Offline installation

      OS R80 Download
      Gaia - CPUSE

      1. Download the Gaia CPUSE Offline package.
      2. Connect to the Gaia Portal on your Check Point machine and navigate to Upgrades (CPUSE) pane - click on Status and Actions.
      3. On the toolbar, click on the More button - select Import Package - browse for the CPUSE Offline package (TGZ file) - click on Upload.
      4. Select the hotfix package R80 Hotfix for sk111055 - click on Install Update button on the toolbar.
      5. Reboot is required.

    Notes:



  • Instructions for Gaia OS (manual installation in Command Line)

    OS R80 Download
    Gaia - CLI

    Procedure:

    1. Download the relevant hotfix package, transfer the hotfix package to the machine and unpack it:
      [Expert@HostName]# tar -zxvf Check_Point_Hotfix_R80_Gaia_sk111055.tgz
    2. Install the hotfix:
      [Expert@HostName]# ./fw1_wrapper_HOTFIX_R80_015_991015010_1
      Note: The script will stop all of Check Point services ('cpstop') - read the output on the screen.
    3. Reboot is required.

    Notes:

    • Make sure to take a snapshot of your Check Point machine before installing this hotfix.
    • In Management HA environment, this procedure must be performed on both Management Servers.

 

Uninstall instructions

  • Using CPUSE (Check Point Update Service Engine)

    1. Connect to the Gaia Portal on your Check Point machine and navigate to Upgrades (CPUSE) pane - click on Status and Actions.
    2. Select Installed in the menu near the Help icon.
    3. Select the hotfix package R80 Hotfix for sk111055 - click on More button on the toolbar - click on Uninstall.

      Example:
    4. Reboot is required.

    Notes:



  • Manual uninstall in Command Line

    1. Download and unpack the hotfix package (refer to the "Installation instructions" (manual installation in Command Line) above).
    2. Run the installation script with "-u" flag:
      # ./UnixInstallScript -u
    3. Reboot is required.

    Note:

    • In Management HA environment, this procedure must be performed on both Management Servers.


Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment