Support Center > Search Results > SecureKnowledge Details
R77.20.75 for Small and Medium Business Appliances
Solution

This article is suitable for Check Point 600 / 700 / 1100 / 1200R / 1400 Small and Medium Business (SMB) Appliances

Table of Contents

  • What's New in Check Point R77.20.75 for SMB Appliances
  • Resolved Issues
  • Downloads
  • Known Limitations
  • Documentation

For more information, see the Check Point 600, Check Point 700, Check Point 1100, Check Point 1200R and Check Point 1400 Appliance Product Pages.
Visit Check Point CheckMates Community and the SMB Forum to ask questions or start a discussion and get our experts assistance.

 

What's New in Check Point R77.20.75 for SMB Appliances

  • New hardware model available for 730/750 and 1430/1450 appliances with a built in ADSL2+/VDSL2 modem

    • VDSL: G.993.1 (VDSL), G.993.2 (VDSL2), G.993.5 (VDSL2 Vectoring), G.998.4 (G.INP)
    • VDSL2 profiles: 8a, 8b, 8c, 8d, 12a, 12b, and 17a
    • ADSL: Annex A (POTS), Annex B (ISDN), G.992.1 (ADSL), G.992.3 (ADSL2), G.992.5 (ADSL2+), Annex M (ADSL2/2+), Annex L Reach-extended (ADSL2)
    • DSL Forum TR-067, TR-100, TR-114 conformity
    • IPoE or PPPoE Internet connection
    • Multiple connections over DSL
    • Static or dynamic IP
    • VDSL over PTM (EFM) with optional VLAN tagging
  • VPN Enhancements

    • Route all traffic via VPN Site-to-Site to an SMB gateway
  • SandBlast Threat Emulation Enhancements

    • E-mails received over POP3 protocol will now be scanned using SandBlast Threat Emulation
  • Support administrator roles via RADIUS server authentication


R77.20.75 for SMB Appliances Resolved Issues

The below table lists R77.20.75 resolved issues:

ID Symptoms
General
SMB-3593,
SMB-3589

An increasing number of "Zombie" processes are presented in the output of ps command.
Zombies are created with a parent process ID which is the process ID of the 'sfwd' daemon. Usually there is 1 "Zombie" process every 24 hours.

WebUI
SMB-3424,
SMB-3048
When the Windows AD has more than 1000 groups, not all the groups can be seen on the SMB appliance outgoing rule/attach the appliance to the AD server. When the Windows AD has more than 500 groups, only 500 groups can be seen on the SMB appliance.
Refer to sk121442.
SMB-3632 In the DHCP settings tab (or DHCP/SLAAC settings in IPv6 mode), when adding any custom DHCP option and save, if you try to edit this local network object again, an "Invalid Input - Unknown Field" error message appears. 
Logging and Monitoring
SMB-3594 In locally managed appliances, when logs are forwarded to an R80.x Log Server / SmartLog, the origin column in the SmartLog / R80.x Log Server shows "myown_obj" instead of the gateway name
Anti-Virus
SMB-3909 Video on demand (VOD) service in YES satellite TV fails to play content when Anti-Virus is configured in Hold mode. 
IPS / User Awareness
SMB-3135 With IPS enabled, in some scenarios a kernel panic or freeze occurred.
This fix prevents that from happening. Specifically the "Adobe Acrobat Reader PDF catalog handling" protection, if enabled, would trigger the issue under certain traffic.
SMB-3946

If User Awareness blade is disabled but Browser-Based authentication is enabled, hosts behind the appliance are unable to reach web sites.

SMP
SMB-3917,
SMB-3916
The "Test Cloud Services Ports" test tool shows "Unreachable" for some of the ports even when all Cloud services are reachable.
VPN
SMB-3542
The external IP address of the gateway is also part of its local VPN encryption domain by default. This may cause conflicts with IP addresses of peers when the gateway is behind NAT or uses a dynamic Internet Connection IP address.
  • To exclude the external IP of the gateway from the encryption domain, use this Аdvanced setting: "VPN Site to Site global settings - Do not encrypt connections originating from the local gateway".
    For the Permanent VPN Tunnels feature to work properly in this mode, use the Аdvanced setting: "VPN Site to Site global settings - Perform Tunnel Tests using an internal IP address".
01498635 In a locally managed appliance, you can define a remote VPN site and route all traffic through that site. The option to define a remote VPN site that routes all traffic to the gateway itself is not support. 
01571378 In centrally managed appliances, when the appliance takes part in site-to-site VPN with route all traffic, access to SSH and WebUI fails. 

 

R77.20.75 for SMB Appliances Downloads

Important: check the MD5 string before installing the downloaded file.

Download Package 700 Appliance 1400 Appliance 600 Appliance 1100 Appliance 1200R Appliance
R77.20.75 Image (IMG) (IMG) (IMG) (IMG) (IMG)
R77.20.75 package for SmartUpdate - For R77.30 SmartUpdate and SmartProvisioing
(TGZ)
- (TGZ) (TGZ)
For R80.10 SmartUpdate
(TGZ)

Note: To download these packages you will need to have a Software Subscription or Active Support plan.


R77.20.75 for SMB Appliances Known Limitations

The below table lists R77.20.75 known limitations:

ID Symptoms
WebUI
SMB-3644 When finish running the First Time Configuration Wizard, the time that is displayed in the System Information page of the WebUI is 2 hours earlier than the actual time.
SMB-4115 In a centrally managed gateway, when the VPN certificate is pushed from SmartDashboard and used by the SSL Network Extender, the WebUI displays the internal VPN certificate even though it is not in use. 
DSL
SMB-3546 In non-DSL appliances, the 'show diag' CLISH command provides information about DSL-related fields, such as DSL MAC address, DSL firmware version and DSL Annex.
SMB-3545 In a non-DSL appliance, when running the 'add internet-connection interface' CLISH command, the list of suggested interfaces includes DSL even though this interface does not exist.
SMB-3407

In 730/750/1430/1450 VDSL appliances, 'ADSL' is included in the options for the CLISH command 'add internet-connection interface' even though this is not supported in these appliances.

  • Use the DSL option to configure either ADSL or VDSL Internet Connection in this models. 
SMB-3286 In 730/750/1430/1450 appliances, the DSL modes EoA and PPPoA are included in the options for the CLISH command 'set internet connection internet1 type' even though these are not supported. 
SMB-4134 QoS is not supported for DSL interfaces. In centrally managed appliances, it is possible to configure QoS settings in SmartDashboard, but the settings will not be applied. 
QoS
SMB-4149
No logs are generated for QoS rules enforcement.

 

R77.20.75 for SMB Appliances Documentation

Release Notes
Check Point R77.20.75 SMB Appliances Release Notes
Administration Guides
Check Point R77.20.75 600/700 Administration Guide
Check Point R77.20.75 1100/1200R/1400 Locally Managed Administration Guide
Check Point R77.20.75 1100/1200R/1400 Centrally Managed Administration Guide
Check Point R77.20.75 600/700/1100/1200R/1400 Appliance CLI Reference Guide
Related Solutions
sk97766 - Check Point 600 / 1100 / 1200R /700 / 1400 Appliances Releases
sk105380 - Check Point R77.20 for 600 / 700 /1100 / 1200R / 1400 Appliance Known Limitations

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment