Support Center > Search Results > SecureKnowledge Details
R80.10 CloudGuard Controller / vSEC Controller Hotfix v1
Solution

Table of Contents

  • What's New
  • Resolved Issues
  • Installation Instructions
  • Documentation
  • Revision History

 

This hotfix has been integrated. It is included in:

Note: CloudGuard Controller is already included in R80.10 GA and above. To review existing features, go to the R80.10 CloudGuard Controller Administration Guide

We recommend installing this hotfix, only if:

  • You need one of the issues listed in the "What's New" section below.
  • You cannot upgrade to R80.20.

 

For more information on R80.10 vSEC Controller Hotfix v1, refer to:
You can also visit our Cloud (vSEC) forum, or any other CHECKMATES forum to ask questions and get answers from technical peers and Support experts.

 

What's New

  • Integration with Google Cloud Platform
  • Integration with Cisco ISE
  • Integration with Nuage Networks VSP
  • Automatic license management with the vSEC Central Licensing utility
  • Starting with Jumbo Hotfix Accumulator Take 20, support for R76SP.50 60000/40000 Security Platforms
  • Integration of monitoring capabilities into SmartView

Resolved Issues

Note: For Known Limitations, refer to sk121129 - R80.10 vSEC Controller Hotfix v1 Known Limitations and sk110519 - Check Point R80.10 Known Limitations.

ID Symptoms
vSEC Controller

vSEC Controller does not support VSX Virtual System Load Sharing (VSLS).
vSEC Controller Server
02413226 'Data Center Object' names should not contain the following characters in their name:
  • "{" - opening curly bracket 
  • "}" - closing curly bracket 
  • "[" - opening square bracket 
  • "]" - closing square bracket 
  • "<" - less than 
  • ">" - greater than
 (If an object name contains one of the above characters, enforcement will not work.)
Public Cloud

Imported Data Center Tag Object ("Key" or "Value") that is not associated with any instance will be marked as "Object is inaccessible / deleted on Data Center Server" in the SmartConsole. The object will remain in this state until re-imported into the policy. Policy enforcement will resume once instances are associated with the Tag.

 

Installation Instructions

  1. Install R80.10 vSEC Controller Hotfix v1:

    1. Using JHF take 70:
      1. Install Take_421 of Check Point R80.10 and then Take_70 of R80.10 Jumbo Hotfix Accumulator, or install Take_462 of Check Point R80.10 and then Take_70 of R80.10 Jumbo Hotfix Accumulator.

      2. Install R80.10 vSEC Controller Hotfix v1 on R80.10 Security Management Server / Multi-Domain Security Management Server:

        Package CPUSE
        Online Identifier (a)
        CPUSE
        Offline (b,c)
        vSEC Controller Hotfix for R80.10 Security Management Server and Multi-Domain Security Management Server
        Check_Point_R80_10_JHF_T70_vSEC_Controller_V1_HOTFIX_sk120464_FULL.tgz
        (TGZ)

        Show / Hide the Notes

        1. For CPUSE Online installation instructions, refer to sk92449 - sections (4-A-a) / (4-A-b) and (4-B-a).
        2. Before installing this package using CPUSE on an offline machine, it is required to manually install the latest build of CPUSE Agent from sk92499.
        3. For CPUSE Offline installation instructions, refer to sk92449 - sections (4-A-c) / (4-A-d) and (4-B-a).
        4. Legacy CLI installation is not supported.
      3. Install R80.10 SmartConsole for R80.10 vSEC Controller hotfix v1:

        Package Link
        R80.10 SmartConsole for R80.10 vSEC Controller Hotfix v1 (for JHF_T70) (EXE)

    2. Using JHF take 154:
      1. Install Take_421 of Check Point R80.10 and then Take_154 of R80.10 Jumbo Hotfix Accumulator, or install Take_462 of Check Point R80.10 and then Take_154 of R80.10 Jumbo Hotfix Accumulator, or install Take_479 of Check Point R80.10 and then Take_154 of R80.10 Jumbo Hotfix Accumulator 

      2. Then, install R80.10 vSEC Controller Hotfix v1 on R80.10 Security Management Server / Multi-Domain Security Management Server:

        Package CPUSE
        Online Identifier (a)
        CPUSE
        Offline (b,c)
        vSEC Controller Hotfix for R80.10 Security Management Server and Multi-Domain Security Management Server
        Check_Point_R80_10_JHF_T154_vSEC_Controller_V1_HOTFIX_sk120464_FULL.tgz
        (TGZ)

        Show / Hide the Notes

        1. For CPUSE Online installation instructions, refer to sk92449 - sections (4-A-a) / (4-A-b) and (4-B-a).
        2. Before installing this package using CPUSE on an offline machine, it is required to manually install the latest build of CPUSE Agent from sk92499.
        3. For CPUSE Offline installation instructions, refer to sk92449 - sections (4-A-c) / (4-A-d) and (4-B-a).
        4. Legacy CLI installation is not supported.
      3. Install R80.10 SmartConsole for R80.10 vSEC Controller hotfix v1:

        Package Link
        R80.10 SmartConsole for R80.10 vSEC Controller Hotfix v1 (for JHF_T154) (EXE)
  2. Install Security Gateway and R80.10 vSEC Controller v1 Enforcer Hotfix:

    1. On an R80.10 Security Gateway, there is no need to install the Enforcer Hotfix. 

    2. Install R80.10 vSEC Controller v1 Enforcer Hotfix on Security Gateway R77.20 / R77.30:

      • On R77.30 Security Gateway with R77.30 Jumbo Hotfix Accumulator Take_309 and above, there is no need to install the Enforcer Hotfix.

      Package CPUSE
      Online Identifier
      CPUSE
      Offline
      Legacy
      CLI
      R80.10 vSEC Controller v1 Enforcer hotfix for Security Gateway R77.30 (a) Check_Point_R77.30_vSEC_Controller_Enforcer_Hotfix_FULL.tgz (c) (TGZ) (d,e) (TGZ) (f)
      R80.10 vSEC Controller v1 Enforcer hotfix for Security Gateway R77.20 (b) N / A (g) N / A (g) (TGZ) (f)

      Show / Hide the Notes

      1. This package of R80.10 vSEC Controller v1 Enforcer Hotfix for Security Gateway R77.30 can be installed:
        • either on top of R77.30 GA,
        • or on top of Take_185 (and above) of R77.30 Jumbo Hotfix Accumulator
        (otherwise, the installation of the R80.10 vSEC Controller v1 Enforcer Hotfix will fail)
      2. This package of R80.10 vSEC Controller v1 Enforcer Hotfix for Security Gateway R77.20 can be installed:
        • on top of R77.20 GA,
        • or on top of Take_99 (and above) of R77.20 Jumbo Hotfix Accumulator
        (otherwise, the installation of the R80.10 vSEC Controller v1 Enforcer Hotfix will fail)
      3. For CPUSE Online installation instructions, refer to sk92449 - sections (4-A-a) / (4-A-b) and (4-B-a).
      4. Before installing this package using CPUSE on an offline machine, it is required to manually install the latest build of CPUSE Agent from sk92499.
      5. For CPUSE Offline installation instructions, refer to sk92449 - sections (4-A-c) / (4-A-d) and (4-B-a).
      6. Legacy CLI installation instructions:
        1. Transfer the hotfix package to the machine (into some directory, e.g., /some_path_to_fix/).
        2. Unpack and install the hotfix package:
          [Expert@HostName:0]# cd /some_path_to_fix/
          [Expert@HostName:0]# tar -zxvf Check_Point_<Version>_vSEC_Controller_Enforcer_Hotfix_Gaia_ sk115772.tgz
          [Expert@HostName:0]# ./fw1_wrapper_<HOTFIX_NAME>
          Note: The script will stop all of Check Point services (cpstop) - read the output on the screen.
        3. Reboot the machine.
      7. On Security Gateway R77.20, only Legacy CLI installation is supported.

 

Documentation

Product Link
R80.10 vSEC Controller v1
vSEC for NSX
vSEC for Amazon Web Services
vSEC for Microsoft Azure

 

Revision History

Show / Hide the revision history

Date Description
11 Mar 2018 First release of this article

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment