<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.10 Bug? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123440#M17724</link>
    <description>&lt;P&gt;Well, no language barrier there lol. Before last option does exactly what it says...which literally means that whatever is listed as you said, it would be accepted before clean up rule. Anyway, keep us posted, this is quite interesting.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jul 2021 15:35:41 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-07-09T15:35:41Z</dc:date>
    <item>
      <title>R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123417#M17708</link>
      <description>&lt;P&gt;Today I was Billy Big Balls and upgraded a customer from R80.20 to R81.10.&amp;nbsp; All went well, except site-to-site VPN tunnels didn't come back up.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"zdebug" showed outbound IKE dropping on the cleanup rule.&lt;/P&gt;&lt;P&gt;Previously this worked via the Global "Accept outgoing traffic from the gateway" tick box.&lt;/P&gt;&lt;P&gt;This box is still ticked, but doesn't seem to be working...&amp;nbsp; hence maybe this is a bug?&lt;/P&gt;&lt;P&gt;I've added a security rule to allow outbound IKE and the tunnels all came back.&lt;/P&gt;&lt;P&gt;So - one to be aware of if you go to R81.10 and your tunnels stay down.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 13:11:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123417#M17708</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-07-09T13:11:16Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123421#M17709</link>
      <description>&lt;P&gt;Thanks for sharing your experience with us.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 13:30:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123421#M17709</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2021-07-09T13:30:48Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123422#M17710</link>
      <description>&lt;P&gt;I've also informed TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 13:32:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123422#M17710</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-07-09T13:32:17Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123423#M17711</link>
      <description>&lt;P&gt;Just out of curiosity, can you send us a screenshot of the rule you had to change/add?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 13:35:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123423#M17711</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-09T13:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123429#M17715</link>
      <description>&lt;P&gt;Did you install the policy after upgrade to R81.10 without doing any modifications with the policy? Simple policy push after cluster has been upgraded.&lt;/P&gt;
&lt;P&gt;But anyway, here we go, freshly released/tested version and first issue within the day(s) ...&lt;/P&gt;
&lt;P&gt;I am wondering if there will be any version without bugs...&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 14:09:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123429#M17715</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2021-07-09T14:09:10Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123430#M17716</link>
      <description>&lt;P&gt;Yep - policy was installed.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The gateway had "Initial Policy" after the upgrade, so it needed a policy install...&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 14:13:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123430#M17716</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-07-09T14:13:12Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123432#M17717</link>
      <description>&lt;P&gt;Hmm, that would give the customer away&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The rule was literally&amp;nbsp;&lt;/P&gt;&lt;P&gt;SRC:&amp;nbsp; My cluster object&lt;BR /&gt;DST:&amp;nbsp; Azure object&lt;BR /&gt;Service:&amp;nbsp; IKE (UDP/500)&lt;BR /&gt;Action:&amp;nbsp; Accept&lt;/P&gt;&lt;P&gt;The tunnel came straight back up then.&amp;nbsp; For 3 years prior, that rule hasn't been needed.&amp;nbsp; So I'm assuming at this point that the "accept outgoing traffic from gateway" tick box is no longer doing what it says on the tin in R81.10?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 14:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123432#M17717</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-07-09T14:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123433#M17718</link>
      <description>&lt;P&gt;Thats fair : ). I have a feeling this could be a bug if you never needed that sort of rule before. Personally, I cannot recall anyone having to do so going back to even before R54.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 14:47:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123433#M17718</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-09T14:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123434#M17719</link>
      <description>&lt;P&gt;Just to be 100% sure, you are referring to the option I circled in the attached screenshot, correct?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 14:56:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123434#M17719</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-09T14:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123435#M17720</link>
      <description>&lt;P&gt;In you screenshot, this option is set to "Before Last".&lt;BR /&gt;Have you changed that from default?&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/26803"&gt;@biskit&lt;/a&gt; : Do you also have "Before Last" there?&lt;/P&gt;
&lt;P&gt;If I remember correctly, default in new databases for this option is "First" for many years. Maybe this is the problem why R&amp;amp;D did not found this problem in yet?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 15:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123435#M17720</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2021-07-09T15:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123436#M17721</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1408"&gt;@Tobias_Moritz&lt;/a&gt;&amp;nbsp;...I am pretty sure by default it has always been "before last", even in older releases. I had a quick look for R77.30 and it also shows "before last". Also checked production R80.;40 and R81 and it shows the same.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 15:08:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123436#M17721</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-09T15:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123439#M17723</link>
      <description>&lt;P&gt;Yes - that's the right tick box.&amp;nbsp; Mine is also set to "before last", which technically should still allow IKE out before hitting the cleanup rule.&amp;nbsp; Maybe there's something TAC can do to troubleshoot why it isn't working.&amp;nbsp; They did reply saying "there is no bug with VPN" so I replied back agreeing, and saying the problem is the tick box not doing what it did prior to the upgrade.&amp;nbsp; I'll see where the SR takes me...&amp;nbsp; Maybe some language barriers to overcome first&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_tears_of_joy:"&gt;😂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 15:29:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123439#M17723</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-07-09T15:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123440#M17724</link>
      <description>&lt;P&gt;Well, no language barrier there lol. Before last option does exactly what it says...which literally means that whatever is listed as you said, it would be accepted before clean up rule. Anyway, keep us posted, this is quite interesting.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 15:35:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123440#M17724</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-07-09T15:35:41Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123443#M17727</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have’nt seen this error before.&lt;/P&gt;&lt;P&gt;what take of R81.10 do you run?&lt;/P&gt;&lt;P&gt;Have been running R81.10 take 335 in EA in production with almost 200 site2site tunnels and didnt see this issue.&lt;/P&gt;&lt;P&gt;I find this release very stable and but again maybe a combo of different setups can trigger different bugs that haven’t seen before.&lt;/P&gt;&lt;P&gt;BTW were you able to download the GA version from supportcenter? I have only been able to find the scalable version to download not the main train version.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 15:57:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123443#M17727</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2021-07-09T15:57:57Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123445#M17729</link>
      <description>&lt;P&gt;I'm on the same version - R81.10 Take 335, which I downloaded straight from CPUSE in the WebUI yesterday.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jul 2021 16:20:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123445#M17729</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-07-09T16:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123464#M17737</link>
      <description>&lt;P&gt;Do you see hits on this manually created IKE rule ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do you have implied rules logging ?&lt;/P&gt;</description>
      <pubDate>Sat, 10 Jul 2021 10:13:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123464#M17737</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2021-07-10T10:13:05Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123710#M17801</link>
      <description>&lt;P&gt;Yes, I see hits on the new IKE rule.&lt;/P&gt;&lt;P&gt;I didn't have implied rule logging on.&amp;nbsp;&lt;/P&gt;&lt;P&gt;As this is a production environment I'll struggle to go back and test stuff now without a maintenance window.&amp;nbsp; I've got a case with TAC though (who still think I'm reporting a VPN problem rather than the global properties tick box problem) so I'll see where that leads me...&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jul 2021 09:34:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/123710#M17801</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2021-07-13T09:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: R81.10 Bug?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/124124#M17869</link>
      <description>&lt;P&gt;I have no such issues on R81.10 myself. IKE traffic is hitting rule 0 / implied rule as per usual. Implied_rules.def lives on the management server. Did you do an in-place upgrade of the management server? Or did you go with an advanced upgrade?&lt;BR /&gt;&lt;BR /&gt;Would be interesting to see your $FWDIR/lib/implied_rules.def file. There have been changes to the implied_rules.def in newer versions. Might the upgrade somehow have kept the old version instead of going with the newer one? This tends to be a possible issue when installing Jumbo Hotfixes that makes changes to implied_rules.def. If the JHF installation notices that you are not running a default implied_rules.def it will create a copy like&amp;nbsp;implied_rules_HFA_R81_JUMBO_HF_take34.def and not overwrite the one you have which might cause issues.&lt;BR /&gt;&lt;BR /&gt;Have you verified global properties on the R81.10 management to make sure "Accept Remote Access control connections" are still activated after the upgrade?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jul 2021 18:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-10-Bug/m-p/124124#M17869</guid>
      <dc:creator>RamGuy239</dc:creator>
      <dc:date>2021-07-15T18:27:02Z</dc:date>
    </item>
  </channel>
</rss>

