CP R80.20 GA ReleaseNotes
CP R80.20 GA ReleaseNotes
R80.20
Release Notes
[Protected]
Classification:
CHAPTER 1
Important Information
Latest Software
We recommend that you install the most recent software release to stay up-to-date
with the latest functional improvements, stability fixes, security enhancements and
protection against new and evolving attacks.
Certifications
For third party independent certification of Check Point products, see the Check Point
Certifications page
https://www.checkpoint.com/products -solutions/certified -check-point-solutions/ .
CheckPoint R80.20
For more about this release, see the R80.20 home page
http://supportcontent.ch eckpoint.com/solutions?id=sk122485.
More Information
Visit the Check Point Support Center https://supportcenter.checkpoint.com .
Feedback
Check Point is engaged in a continuous effort to improve its documentation.
Please help us by sending your comments
mailto:cp_techpub_feedback@checkpoint.com?subject=Feedbackon R80.20 Release
Notes.
RevisionHistory
Date Description
15-January-2019 R80.20 becomes the default version (on page 8)
18 November 2018 Updated: R80.10 Security Management Server can manage R80.20
Security Gateway (on page 16)
17 October 2018 Updated: Advanced Threat Prevention (on page 10) - added "Threat
Emulation is fully supported."
Date Description
08 October 2018 Updated: Supported Upgrade Paths (on page 16) - Added a note "New
Early Availability program with our new Linux kernel version 3.10 based
on R80.20 is now available for Security Gateway (see sk137854
http://supportcontent.checkpoint.com/solutions?id=sk137854 )"
04 October 2018 Improved formatting and document layout for the HTML guide
26 September 2018 First release of this document
Important Links
For more about R80.20 and to download the software, see the R80.20 Home Page: sk122485
http://supportcontent.checkpoint.com/solutions?id=sk122485 .
Read the Known Limitations: sk122486
http://supp ortcontent.checkpoint.com/solutions?id=sk122486 .
See issues resolved in this release: sk122488
http://supportcontent.checkpoint.com/solutions?id=sk122488 .
Visit the Check Point Checkmates Community https://community.checkpoint.com/ :
Start discussions
Get answers from experts
Join the API community to get code samples and share yours
Visit http://www.checkpoint.com/architecture/infinity/ to learn more about R80.20.
Introduction
R80.20, part of the Check Point Infinity architecture, delivers the most innovative and effective
security that keeps our customers protected against large scale, fifth generation cyber threats.
The release contains innovations and significant improvements in:
Gateway performance
Advanced Threat Prevention
Cloud Security
Access policy
Consolidated network and endpoint management capabilities
And much more
R80.20 was released on September 26, 2018. Starting January 15th 2019, R80.20 take 101 with
Jumbo Hotfix Accumulator take_17 (see sk137592) is considered as Check Point's default version
(widely recommended for all deployments)
What's New
R80.20 creates a breakthrough in Check Point Security Gateway,matching the R80 security
management innovations.
R80.20 is part of CheckPoint Infinity, a consolidated cyber security architecture that spans
networks, cloud, and mobile. It provides the highest level of Threat Prevention against both known
and unknown targeted attacks to keep you protected now and in the future.
Performance Enhancements
Performance Enhancements
HTTPSInspection performance improvements
Session rate improvements on high- end appliances (13000,15000, 21000 & 23000 Security
Gateway models).
Acceleration remains active during policy installation, no impact on Security Gateway
performance.
VSX Gateways
Significant boost to Virtual Systems performance, utilizing up to 32 CoreXL FW instances for
each Virtual System.
Dynamic Dispatcher - Packets are processed by different FW worker (FWK) instances based on
the current instance load.
Changes in the number of FW worker instances (FWK) in a VSLSsetup do not require
downtime.
SecureXL Penalty Box supports the contexts of each Virtual System, see sk74520
http://supportcontent.checkpoint.com/solutions?id=sk74520 .
Access Policy
Updatable Objects – a new type of network objects that represent an external service such as
Office 365, Amazon Web Services, Azure GEOlocations and more, and can be used in the
Source and Destination columns of an Access Control policy. These objects are dynamically
updated and kept up-to-date by the Security Gateway without the need to install a policy.
Wildcard network object in Access Control that represents a series of IP addresses that are
not sequential.
Only for Multi -Domain Server: Support for scheduled policy installation with cross-Domain
installation targets (Security Gateways or Policy Packages).
Rule Base performance improvements, for enhanced Rule Base navigation and scrolling.
Global VPN Communities (previously supported in R77.30).
Support for using NAT64 and NAT46 objects in Access Control policy.
Identity Awareness
Identity Tags support the use of tags defined by an external source to enforce users, groups or
machines in Access Roles matching.
Improved SSOTransparent Kerberos Authentication for Identity Agent, LDAP groups are
extracted from the Kerberos ticket.
Two Factor Authentication for Browser- Based Authentication (support for RADIUS
challenge/respons e in Captive Portal and RSA SecurID next Token/Next PIN mode).
Identity Collector
Support for Syslog Messages - ability to extract identities from syslog notifications.
Support for NetIQ eDirectory LDAP Servers.
Additional filter options - "Filter per Security Gateway" and "Filter by domain".
Improvements and stability fixes related to Identity Collector and Web API.
New configuration container for Terminal Servers Identity Agents.
Active Directory cross-forest trust support for Terminal Servers Agent.
Identity Agent automatic reconnection to prioritized PDP gateways.
Security Management Server can securely connect to Active Directory through a Security
Gateway,if the Security Management Server has no connectivity to the Active Directory
environment and the Security Gateway does.
HTTPSInspection
Hardware Security Module (HSM) support – outbound HTTPSInspection stores the SSL keys
and certificates on a third party dedicated appliance.
Additional ciphers support for HTTPSInspection (for more information see sk104562
http://supportcontent.checkpoint.com/solutions?id=sk104562 ).
Clustering
New CCP Unicast mode - a new mode in which a cluster member sends the CCP packets to the
unicast address of a peer member.
New Automatic CCP mode - CCP mode is adaptive to network changes, Unicast, Multicast or
Broadcast modes are automatically applied according to network state.
Enhanced cluster monitoring capabilities.
Enhanced cluster statistics and debugging capabilities.
Enhanced Active/Backup Bond.
Support for more topologies for Synchronization Network over Bond interfaces.
Improved cluster synchronization and policy installation mechanism.
New grace mechanism for cluster failover for improved stability.
New cluster commands in Gaia Clish.
Improved clustering infrastructure for RouteD (Dynamic Routing) communication.
Gaia OS
Upgraded Linux kernel (3.10) - applies to Security Management Server only.
New file system (xfs)
More than 2TB support per a single storage device.
Enlarged systems storage (up to 48TB).
I/O-related performance improvements.
Support of new system tools for debugging, monitoring and configuring the system
iotop (provides I/O runtime statistics).
lsusb (provides information about all devices connected to USB).
lshw (provides detailed information about all hardware).
lsscsi (provides information about storage).
ps (new version, more counters).
top (new version, more counters).
R80.20 Release Notes | 12
What's New
Advanced Routing
Allow AS-in-count.
IPv6 MD5 for BGP.
IPv4 and IPv6 OSPFmultiple instances.
Bidirectional Forwarding Detection (BFD) for gateways and VSX,including IP Reachability
detection and BFD Multihop.
OSPFv2HMAC-SHA authentication (in addition to OSPFv2MD5 authentication).
ICAP Client
Integrated ICAP Client functionality.
SmartProvisioning
Integration with SmartProvisioning (previously supported in R77.30).
Support for the 1400 series appliances.
Administrators can now use SmartProvisioning in parallel with SmartConsole.
Mobile Access
Support for reCAPTCHA,keep abusive automated software activities from interfering with
regular portal operations.
Support for One Time Password (OTP)without any hardware tokens.
Compliance
User can create custom best practices based on scripts.
Support for 35 regulations including General Data Protection Regulation (GDPR).
Licensing
For all licenses issues contact Account Services
mailto:accountservices@checkpoint.com?subject=Licensing Issues.
To enable this:
Install R80.10 Jumbo Hotfix Accumulator Take 167 and higher (Refer to sk116380
http://supportcontent.checkpoint.com/solutions?id=sk116380 ).
Install R80.10 SmartConsole build 89 and higher (Refer to sk119612
http://supportcontent.checkpoin t.com/solutions?id=s119612).
Note that if you choose to not upgrade to R80.20 Security Management Server or Multi -Domain
Server, the new features will not be supported.
ManagementServers
Check Point Product Smart-1 Smart-1
25b, 205, 210, 225, 405, 410, 525 50, 150, 3050, 3150, 5050, 5150
Security Management * *
Log Server * *
SmartEvent Server * *
Multi-Domain Security
*
Management
Multi-Domain Log Server *
* Smart -1 25B, 205, and 210 appliances with default memory can run Security Management OR
Log Server OR SmartEvent.
** We recommend that you upgrade the memory of Smart-1 205 to 16GB as part of the upgrade to
R80.20.
*** Smart -1 210 with memory extension to 16GB can run Security Management AND/OR Log
Server AND/OR SmartEvent.
3000 * *
4000 * *, **
5000 * *
12000 * **
13000 * *
15000 * *
21000 * *
23000 * *
Supported Platforms
Check Point Product Red Hat Enterprise VMware ESXi Microsoft
Linux Hyper-V**
Windows 2012 R2,
Security Management Server 7.3 or higher 5.x, 6.x
2016 (64-bit only)*
Multi -Domain Security Windows 2012 R2,
7.3 or higher 5.x, 6.x
Management Server 2016 (64-bit only)*
Windows 2016 (64
Security Gateway Not Supported 5.x, 6.x
bit only)
* For the most up-to-date information about Microsoft Hyper-V, see the Virtual Machines section
of the Hardware Compatibility List https://www.checkpoint.com/support -services/hcl/ .
R80.20 Release Notes | 20
Build Numbers
Build Numbers
Software Blade / Product Build Number Verifying Build Number
Gaia OS build 101 show version all
R80.20 Management Servers can manage appliance Security Gateways that run these versions:
Note - This table applies to Check Point Appliances and Open Servers.
Logging Requirements
Storing Logs
Logs can be stored on:
A Security Management Server that collects logs from the Security Gateways.This is the
default.
A Log Server on a dedicated machine. This is recommended for organizations that generate
many logs.
A dedicated Log Server has greater capacity and performance than a Security Management Server
with an activated logging service. On dedicated Log Servers, the Log Server must be the same
version as the Management Server.
SmartEvent Requirements
You can enable the SmartEvent Blade on a Security Management Server, or install a dedicated
SmartEvent Server. SmartEvent R80.20 can connect to a different version of Log Server - R77.xx
or lower.
SmartEvent and a SmartEvent Correlation Unit are usually installed on the same server. You can
also install them on separate servers, for example, to balance the load in large logging
environments. The SmartEvent Correlation Unit must be the same version as SmartEvent Server.
To deploy SmartEvent and to generate reports, a valid license or contract is required.
SmartConsole Requirements
Hardware Requirements
This table shows the minimum hardware requirements for SmartConsole applications:
Software Requirements
SmartConsole is supported on:
Windows 10 (all editions), Windows 8.1 (Pro), and Windows 7 (SP1, Ultimate, Professional, and
Enterprise)
Windows Server 2016, 2012, 2008 (SP2),and 2008 R2 (SP1)
8 and higher
Microsoft Internet Explorer (If you use Internet Explorer 8, file uploads through the Gaia
Portal are limited to 2 GB)
Secure Workspace *
Browser Compatibility
Endpoint Microsoft Microsoft Google Mozilla Apple Opera
Browser Internet Edge Chrome(1) Firefox Safari for
Compatibility Explorer Windows
1. Google Chrome support for Mobile Access Portal on-demand clients, such as SSL Network
Extender Network Mode, SSL Network Extender Application Mode, Secure Workspace, and
Endpoint Security on Demand, requires Java JRE 32-bit installed on the end-user's computer.
2. Running Compliance Scanner on Windows platforms requires Java Runtime Environment (JRE
or JDK) 32-bit installed on the end-user's computer.
3. Secure Workspace and SSL Network Extender Application Mode are available for Windows
platforms only.
Post-Upgrade Requirement:
If you upgraded the Endpoint Security Management Server to R80.20, then to keep visibility of
Endpoint client events in the SmartConsole, you must perform these steps:
1. Connect with SmartConsole to the Security Management Server.
2. In the top left corner, click Menu > Install database.
3. Select all objects.
4. Click Install.
5. Click OK.
For more information, see the R80.20 Endpoint Security Management Server Administration Guide
https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_EndpointSe
curity_AdminGuide/html_frameset.htm .
UserCheck Client * * *
* Supported Windows 10 versions: 1703, 1709, 1803 for more information see the Detailed Client
Releases Information section in sk117536
http://supportcontent.checkpoint.com/solutions?id=sk117536
Microsoft WindowsServer
Identity Agent * * *
SSL Network Extender * * *
* *
Endpoint Security VPN E80.x or higher (E80.62 (E80.64 *
and higher) and higher)
For earlier server versions, use the R77.30 DLP Exchange Agent.