Support Center > Search Results > SecureKnowledge Details
R77.20.80 for Small and Medium Business Appliances Technical Level

This article is suitable for Check Point 600 / 700 / 1100 / 1200R / 1400 Small and Medium Business (SMB) Appliances

Table of Contents

  • What's New in Check Point R77.20.80 for SMB Appliances
  • Enhancements
  • Resolved Issues
  • Downloads
  • Known Limitations
  • Documentation

For more information, see the Check Point 600, Check Point 700, Check Point 1100, Check Point 1200R and Check Point 1400 Appliance Product Pages.
Visit Check Point CheckMates Community and the SMB Forum to ask questions or start a discussion and get our experts assistance.

Important Note: This may not be the latest firmware release. To see the latest firmware release, refer to sk97766.

What's New in Check Point R77.20.80 for SMB Appliances

  • Support additional deployments with ZeroTouch

    • Option to configure Internet connection before ZeroTouch deployment
    • Dynamic change of the default LAN subnet in case of a conflict with WAN IP address (provided by DHCP server), to allow connection to ZeroTouch server
  • Intermediate CA

    • Option to replace the gateway WebUI certificate and VPN certificate with a certificate signed by an intermediate CA
  • Logs management

    • Added an option to configure the gateway to log only outgoing blocked traffic
  • SMP connection

    • Retry mechanism in case of a failure in connection to the cloud services (SMP)
  • Performance and stability fixes


R77.20.80 for SMB Appliances Enhancements

ID Symptoms
SMB-4431 Added support for RFC 3021: you can use 31-Bit Prefixes for IPv4 point-to-point Internet links. 
SMB-4067  Removed unsafe ciphers/HMACs from SSH server supported ciphers/HMACs: hmac-sha1-96, hmac-md5
SMB-3929 The user can change the number of years for which the internal VPN certificate and the internal CA certificates are valid. 


R77.20.80 for SMB Appliances Resolved Issues

The below table lists R77.20.80 resolved issues:

ID Symptoms

POP3 session disconnects and the next attempt to fetch emails fails when:

  • POP3 AV/TE is enabled in locally-managed mode
  • Email was detected as malicious after more than 400Kb of data have passed to the POP3 client
SMB-4342 TCP traffic dropped by the gateway is logged under IPS "TCP Segment Limit Enforcement" log.
SMB-4417 Cluster configuration fails when using VLAN-associated interfaces. 
SMB-5310 Some Gateway name combinations in a cluster result in both members of the High Availability cluster becoming Active members and not being able to see that the other member exists. 

In the Chrome browser, the Welcome page in the the First Time Configuration Wizard does not display properly and the Next button is disabled.

  • Workaround: Use a different Internet browser for when deploying for the first time. 
SMB-5414 After upgrade to R77.20.75, the admin Radius Authorization mode changes to the new mode which requires you to either define the Radius role on the Radius server, or to change the radius authorization mode to legacy mode (go to Administrators -> Edit permissions -> select "Use default role...").
If you upgrade directly from R77.20.70 to R77.20.80, you do not need to define the Radius role. 
 SMB-6450 For 600/1100 appliances, the NAS-IP-ADDRESS attribute is missing from the RADIUS authentication packet sent from the SMB to the RADIUS server. 
SMB-4688 When creating a custom URL, it appears in the list of custom applications but is not saved. 
SMB-2534 The Infected / possibly infected hosts page (or relevant sections in the periodic report) might show IP addresses that are not in the appliance's internal networks.
Refer to sk126374
SMB-4604 VPN Site-to-Site connection cannot be established between a centrally managed SMB gateway and an Azure cloud VPN gateway.
SMB-3968 Added option to turn off the logging of the IKE key exchange in Advanced Settings -> VPN Site-to-Site global settings -> Successful key exchange tracking. 
SMB-4664 In locally-managed mode, Remote Access users are not able to connect when using a certificate trusted by a CA installed on the gateway. (Degradation from previous versions). 
On SMB gateways with Dynamic IP, it takes a long time to establish a VPN permanent tunnel (DPD) after reboot. 
When configuring client to site VPN (Remote Access ) using Endpoint Security VPN toward a 700 Security Gateway installed with R77.20.75, and the interface that accepts the connection is checked as VLAN, passing traffic to the LAN, may cause the appliance to crash. 
Application Control / URL Filtering
Application Control drops HTTP response traffic when the HTTP response contains two different host headers. This prevents access to some websites.
The UserCheck Block page might not be displayed for a website that is blocked by both the Anti-Virus and Application Control / URL Filtering blades.
Refer to sk64162.
Dynamic Routing
SMB-5151 In an SMB cluster, in some scenarios, the BGP & OSPF stop working after the first failover.
Refer to sk129792.


R77.20.80 for SMB Appliances Downloads

Important: check the MD5 string before installing the downloaded file.

Download Package 700 Appliance 1400 Appliance 600 Appliance 1100 Appliance 1200R Appliance
R77.20.80 Image (IMG) (IMG) (IMG) (IMG) (IMG)
R77.20.80 package for SmartUpdate - For R77.30 SmartUpdate and SmartProvisioing
- (TGZ) (TGZ)
For R80.10 SmartUpdate

Note: To download these packages you will need to have a Software Subscription or Active Support plan.

R77.20.80 for SMB Appliances Known Limitations

The below table lists R77.20.80 known limitations:

ID Symptoms

When fetching settings from Zero Touch on the Welcome page of the First Time Configuration Wizard, if the internet configuration causes an IP conflict (if the WAN address received is in the subnet, the IP address of the LAN network is automatically changed to, the Zero Touch feature fails and the First Time Configuration Wizard becomes stuck.

  • Workaround: Restart the appliance, connect to the First Time Configuration Wizard with IP address, and click the "Fetch settings from Zero Touch" link on the Welcome page.
SMB-4475 The One Touch feature is not supported on 600/1100 appliances.
SMB-4493 When you use a certificate signed by an intermediate CA to create a VPN tunnel with a gateway, the intermediate CA must be installed on the gateway as a trusted CA.
SMB-4506 When the VPN remote site certificate is limited to a specific CA, and the certificate is signed by an intermediate CA that is installed as trusted on the gateway, then the intermediate CA must be the specific CA to match and not the root CA.

The IP address or subnet assigned to the gateway using the DHCP server running on the modem may overlap with the user-configured LAN/Internet connection, causing an IP conflict. This may cause one or more of those interfaces to be unable to work as expected.

  • Change the conflicting LAN address manually.

The Vodaphone K3765 modem works in PPP mode by default instead of Ethernet. As a result, the modem cannot get an IP address and connect to the internet.

  • Workaround: Unplug the modem and run this Clish command before you reconnect the modem: "add usb-modem-advanced vendor-id 12d1 product-id 1465 field-name include_plugins_list field-value ppp is-any-device false"


R77.20.80 for SMB Appliances Documentation

Release Notes
Check Point R77.20.80 SMB Appliances Release Notes
Administration Guides
Check Point R77.20.80 600/700 Administration Guide
Check Point R77.20.80 1100/1200R/1400 Locally Managed Administration Guide
Check Point R77.20.80 1100/1200R/1400 Centrally Managed Administration Guide
Check Point R77.20.80 600/700/1100/1200R/1400 Appliance CLI Reference Guide
Related Solutions
sk97766 - Check Point 600 / 1100 / 1200R /700 / 1400 Appliances Releases
sk105380 - Check Point R77.20 for 600 / 700 /1100 / 1200R / 1400 Appliance Known Limitations

Give us Feedback
Please rate this document