CheckPoint R80.10 ReleaseNotes
CheckPoint R80.10 ReleaseNotes
CheckPoint R80.10 ReleaseNotes
R80.10
Release Notes
Classification: [Protected]
© 2018 Check Point Software Technologies Ltd.
All rights reserved. This product and related documentation are protected by copyright and
distributed under licensing restricting their use, copying, distribution, and decompilation. No part
of this product or related documentation may be reproduced in any form or by any means without
prior written authorization of Check Point. While every precaution has been taken in the
preparation of this book, Check Point assumes no responsibility for errors or omissions. This
publication and features described herein are subject to change without notice.
RESTRICTED RIGHTS LEGEND:
Use, duplication, or disclosure by the government is subject to restrictions as set forth in
subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS
252.227-7013 and FAR 52.227-19.
TRADEMARKS:
Refer to the Copyright page http://www.checkpoint.com/copyright.html for a list of our
trademarks.
Refer to the Third Party copyright notices http://www.checkpoint.com/3rd_party_copyright.html
for a list of relevant copyrights and third-party licenses.
Important Information
Latest Software
We recommend that you install the most recent software release to stay up-to-date
with the latest functional improvements, stability fixes, security enhancements and
protection against new and evolving attacks.
Feedback
Check Point is engaged in a continuous effort to improve its documentation.
Please help us by sending your comments
mailto:cp_techpub_feedback@checkpoint.com?subject=Feedback on R80.10 Release
Notes.
Revision History
Date Description
29 March 2018 Updated support for vSEC IaaS in Supported Platforms (on page 17)
19 July 2017 Added support for UTM-1 Edge N in Backward Compatibility Gateways
("Supported Backward Compatibility Gateways" on page 18)
02 July 2017 Added Hyper-V support in Supported Platforms (on page 17)
Added Smart-1 405 and 410 support in Check Point Appliances (on page
15)
Date Description
01 June 2017 Updated requirements for Security Management Server / Standalone in
Open Server Hardware Requirements ("Open Server Hardware
Recommendations" on page 16)
Introduction
Thank you for installing Check Point R80.10 - The cyber security platform of the future. This
release integrates R80 management features with new Security Gateway features and
enhancements.
Important Notes
Effective 18 January 2018:
The R80.10 image for installation and upgrade has been replaced.
The new R80.10 image includes:
• Reduced running time for the First Time Configuration Wizard during Security Management
Server installation.
• Replacement of Kaspersky Anti-Virus components in accordance with security orders from the
United States Department of Homeland Security, refer to www.checkpoint.com/kaspersky
www.checkpoint.com/kaspersky and sk118539
http://supportcontent.checkpoint.com/solutions?id=sk118539
• Integrated support for Smart-1 405 and 410 appliances, refer to sk117578
http://supportcontent.checkpoint.com/solutions?id=sk117578
• Upgrade stability enhancements:
• Upgrade of secondary R80 Security Management Server
• Upgrade of Multi-Domain Server
• Upgrade of R77.x Multi-Domain Log Server using NGX license
• Import of R80.10 Multi-Domain Server using mds_import
• Upgrade option from R77.30 with vSEC Controller to R80.10 is available via CPUSE
• Resolved vSEC controller for AWS connectivity issues due to CA change, refer to sk121885
http://supportcontent.checkpoint.com/solutions?id=sk121885
• Gaia Fast Deployment Tool, refer to sk120193
http://supportcontent.checkpoint.com/solutions?id=sk120193
• Integrated R80.10 Jumbo Hotfix Accumulator Take 42, refer to sk116380
http://supportcontent.checkpoint.com/solutions?id=sk116380
Important Links
For more about R80.10, and to download the software, see the R80.10 Home Page: sk111841
http://supportcontent.checkpoint.com/solutions?id=sk111841
• R80.10 image replacement, for more information see sk120981
http://supportcontent.checkpoint.com/solutions?id=sk120981
• Before you upgrade, see the latest upgrade tools on the Home Page
• Read the Known Limitations: sk110519
http://supportcontent.checkpoint.com/solutions?id=sk110519
• See issues resolved in this release: sk110518
http://supportcontent.checkpoint.com/solutions?id=sk110518
Visit the Check Point CheckMates Community https://community.checkpoint.com/
• Start discussions
• Get answers from experts
• Join the API community to get code samples and share yours
Visit http://www.checkpoint.com/architecture/infinity/ to learn more about Infinity R80.10.
What's New
R80.10 creates a breakthrough in Check Point Security Gateway, matching the R80 security
management innovations.
R80.10 is part of Check Point Infinity, a consolidated cyber security architecture that spans
networks, cloud, and mobile. It provides the highest level of threat prevention against both known
and unknown targeted attacks to keep you protected now and in the future.
• NAT Enhancements
• Improved scalability of hide NAT on high-end multicore gateways, allowing maximum
usage of available hide ports by dynamically assigning available ports to the cores. See
sk103656 http://supportcontent.checkpoint.com/solutions?id=sk103656.
• IP Pool NAT performance enhancement - CoreXL multicore scalability for IP Pool NAT
connections.
• Gaia Enhancements
• Netflow support for IPFIX (with NAT and IPv6 flow records).
• IPv6 DHCP relay with ClusterXL (Security Gateway and VSX modes).
• Dynamic Routing Enhancements
• RIPng with VRRPv2.
• SNMP enhancements for routing.
• BGP 4-Byte AS and Local AS.
• VSX Enhancements
• 64-bit support for VSX Gateways, increasing concurrent connections capacity.
• Content Awareness for VSX Gateways.
• ClusterXL Enhancements
• The MAC Magic value is acquired automatically and is backward compatible with gateways
that were configured manually in earlier versions.
• For VSX Clusters in load sharing environments (VSLS), Backup members can communicate
with external networks and receive updates, in addition to Active and Standby members.
• Connectivity Upgrades now support synchronization of Dynamic Routing.
Management Enhancements
These enhancements were first introduced in R80.
• Multi-Domain Security Management
• Unified architecture and management console for Security Management and Multi Domain
Security Management.
• New and improved views for Domain management and Global Assignment.
• Role-based & Concurrent Administration - Several administrators can work in parallel on the
same security policy, with granular and flexible privilege delegation to each administrator.
• A new advanced locking mechanism ensures administrators do not overwrite each other's
work.
• Rich administrator profiles for exact privileges each administrator will have, including
managing specific policies or network segments, viewing specific logs, and conducting
security operations, such as installing policy.
• Secured Automation and Orchestration - CLI and API for security management enables full
integration with 3rd party systems and automation of daily operations. Automation and
SmartConsole management operations are allowed based on the same privilege profile.
• Faster Day to Day Operations
• Integrated logging to see all logs related to a rule in the same screen.
• Detailed rule information of who created the rule and when, hit counts, and user-defined
data, such as ticket numbers.
• Enhanced search capabilities to quickly find any rule or object in the system.
• Enhanced Management High Availability synchronizes only changes between servers,
significantly improving efficiency.
• Next Generation Logs, Events and Reports
• Analyze hundreds of millions of logs per day with graphical views and reports, customized
to address specific requirements.
• Logging, monitoring, and report aspects also available in the Web-based interface.
• Free-text search of logs and events with auto-suggest and favorites, with results in
seconds.
• New and Enhanced Revision Management Capabilities
• Built-in automatic policy revision.
• Install a specific version of policies.
• Change to a specific version of IPS package.
• Cloud Demo - Experience R80.10 management scenarios on any computer. sk103431
http://supportcontent.checkpoint.com/solutions?id=sk103431
• vSEC Controller - Natively integrates with the leading private and public cloud platforms:
VMware vCenter & NSX, CISCO ACI, Amazon Web Services (AWS), Microsoft Azure, and
OpenStack.
vSEC Controller provides dynamic security policy and visibility, which automatically adapts to
changes in the cloud environments. This provides simple automated security across physical,
virtual, and cloud environments, from a single unified management solution.
Behavior Changes
• Management
• Management API commands and the SmartView Web-based interface replace the
Management Portal. Use the API commands to install a policy and show a list of Gateways
and Servers. Use SmartView to see logs.
• The new tags for objects replace the renaming of object colors. You can name a tag
according to a color. The tags make it easier to manage objects in SmartConsole.
• New and improved management abilities replace the Database Revision function. To learn
about the enhanced Revisions Management in R80 and higher, see sk113615
http://supportcontent.checkpoint.com/solutions?id=sk113615.
• The mdsstop and mdsstart commands on the Multi-Domain Server are the only way to
start and stop Domain Management Servers function. Most Domain Management Server
components are handled in one process. This reduces memory consumption and CPU
usage.
• Improved verification process of the Rule Base when installing a policy. Therefore, Security
Policies, which passed the verification process before the upgrade, may fail after the
upgrade. If you get a verification error message after the upgrade, fix the rules manually.
Note - You can do an upgrade simulation using the R80.10 Upgrade Verification and
Environment Simulation Service
http://supportcontent.checkpoint.com/solutions?id=sk110267. The service notifies you
about possible policy verification failure.
Licensing
Contact Account Services mailto:accountservices@checkpoint.com?subject=Licensing Issues for
all license issues.
From R75.40, R75.45, R75.46, R75.47, R75.40VS, R76, R77, R77.10, R77.20, R77.30 to
R80.10:
Component Supported Methods
Security Management Server • CPUSE Upgrade
• CPUSE Clean Install
Multi-Domain Server
• Advanced Database Migration
Security Gateway • CPUSE Upgrade
• CPUSE Clean Install
VSX CPUSE Upgrade (from R77 only)
Earlier versions: Use instructions in sk101518
http://supportcontent.checkpoint.com/solutions
?id=sk101518
To upgrade from R77.20 or R77.30 with the Add-on: It is not necessary to uninstall the Add-on.
Remove these unsupported features: Modbus support with the Application Control Software
Blade, "SAML" Cloud Connector for web based single sign on.
Note: User Defined reports will be migrated during the upgrade to the SmartConsole reports.
Report Scheduling and email server definitions will not be migrated and need to be defined.
If you do not have enough disk space, you can use the Logical Volume Manager (lvm) to increase
the disk space of logical volumes on Gaia. This space is taken from the unallocated disk space,
which is usually used for snapshots and upgrades. See sk95566
http://supportcontent.checkpoint.com/solutions?id=sk95566.
Management Servers
Component Smart-1 Smart-1
25b, 205, 210, 225, 405, 410 50, 150, 3050, 3150
Security Management
Log Server
SmartEvent Server
Multi-Domain Security
Management
Multi-Domain Log Server
* Smart-1 25b, 205, and 210 appliances with default memory can run Security Management OR
Log Server OR SmartEvent.
** We recommend that you upgrade the memory of Smart-1 205 to 16GB as part of the upgrade to
R80.10.
*** Smart-1 210 with memory extension to 16GB can run Security Management AND/OR Log
Server AND/OR SmartEvent.
3000
4000 *
5000
12000 12600*
13000
15000
21000
23000
Supported Platforms
Build Numbers
Software Blade / Product Build Number Verifying Build Number
Gaia 462 show version all
R80.10 Management Servers can manage appliance Security Gateways of these versions:
Note - This table applies to Check Point Appliances and to Open Servers.
Open Servers:
Hardware Sensors: Use the Gaia Portal or SNMP to monitor fan speed, motherboard voltages,
power supply health, and temperatures. Some open servers are supported with an IPMI interface
card that requires an IPMI card.
Note - IPMI is an open standard. We cannot guarantee the Hardware Health Monitoring
performance on all systems and configurations.
Logging Requirements
Logs Storing
Logs can be stored on:
• A Security Management Server that collects logs from the Security Gateways. This is the
default.
• A Log Server on a dedicated machine. This is recommended for organizations that generate
many logs.
A dedicated Log Server has greater capacity and performance than a Security Management Server
with an activated logging service. On dedicated Log Servers, the Log Server must be the same
version as the Management Server.
SmartEvent Requirements
You can install a SmartEvent Server on a Security Management Server or on a different, dedicated
server. SmartEvent R80.10 can connect to a different version of Log Server - R77.xx or earlier.
Usually SmartEvent and a Correlation Unit are installed on the same server. You can also install
them on separate servers, for example, to balance the load in large logging environments. The
Correlation unit must be the same version as SmartEvent.
To deploy SmartEvent and to generate reports, a valid license or contract is required.
SmartConsole Requirements
Hardware Requirements
This table shows the minimum hardware requirements for SmartConsole applications:
Memory 4 GB
Software Requirements
SmartConsole is supported on:
• Windows 10 (all editions), Windows 8.1 (Pro), and Windows 7 (SP1, Ultimate, Professional, and
Enterprise).
• Windows Server 2016, 2012, 2008 (SP2), and 2008 R2 (SP1).
8 and higher
Microsoft Internet Explorer (If you use Internet Explorer 8, file uploads through the Gaia
Portal are limited to 2 GB.)
Compliance Scanner
Secure Workspace
Clientless Citrix
Web mail
Browser Compatibility
Endpoint Browser Microsoft Google Mozilla Apple Opera
Compatibility Internet Chrome Firefox Safari for
Explorer Windows
Mobile Access Portal
Compliance Scanner *
Secure Workspace *
Clientless Citrix
Web mail
* Google Chrome support for Mobile Access Portal on-demand clients, such as SSL Network
Extender, Secure Workspace, and Endpoint Security on Demand, requires Java JRE 32-bit
installed on the end-user's computer.
UserCheck Client
SecureClient
(32-bit only)
Note - Identity Agent for Terminal Servers is also supported on Citrix version 6.
Check Point Product XP Home (SP3) XP Pro (SP3) Vista (SP2) Vista (SP1)
32-bit 32-bit 32-bit 64-bit
Remote Access clients
E75.x
UserCheck Client
SecureClient
Check Point Product Server 2003 Server 2008 Server Server Server
(SP2) (SP1 / SP2) 2008 R2 2012 2012 R2
32-bit 32 / 64 bit (+SP1) 64-bit
UserCheck Client
Note: DLP Exchange Agent supports Microsoft Exchange Server 2007 and 2010 on Windows
Servers 64-bit. A 32-bit version is available for demonstration or educational purposes. DLP
Exchange Agent supports Microsoft Exchange Server 2013 on Windows Server 2012 64-bit.
Endpoint Security VPN E75 or higher 32-bit / 64-bit 32-bit / 64-bit 64-bit
Endpoint Security Client E80.40 or higher 32-bit / 64-bit 32-bit / 64-bit 64-bit
For earlier server versions, use the R77.30 DLP Exchange Agent.