CP R80.10 ReleaseNotes
CP R80.10 ReleaseNotes
CP R80.10 ReleaseNotes
R80.10
Release Notes
Classification: [Protected]
© 2017 Check Point Software Technologies Ltd.
All rights reserved. This product and related documentation are protected by copyright and
distributed under licensing restricting their use, copying, distribution, and decompilation. No part
of this product or related documentation may be reproduced in any form or by any means without
prior written authorization of Check Point. While every precaution has been taken in the
preparation of this book, Check Point assumes no responsibility for errors or omissions. This
publication and features described herein are subject to change without notice.
RESTRICTED RIGHTS LEGEND:
Use, duplication, or disclosure by the government is subject to restrictions as set forth in
subparagraph (c)(1)(ii) of the Rights in Technical Data and Computer Software clause at DFARS
252.227-7013 and FAR 52.227-19.
TRADEMARKS:
Refer to the Copyright page http://www.checkpoint.com/copyright.html for a list of our
trademarks.
Refer to the Third Party copyright notices http://www.checkpoint.com/3rd_party_copyright.html
for a list of relevant copyrights and third-party licenses.
Important Information
Latest Software
We recommend that you install the most recent software release to stay up-to-date
with the latest functional improvements, stability fixes, security enhancements and
protection against new and evolving attacks.
Feedback
Check Point is engaged in a continuous effort to improve its documentation.
Please help us by sending your comments
mailto:[email protected]?subject=Feedback on R80.10 Release
Notes.
Revision History
Date Description
19 July 2017 Added support for UTM-1 Edge N in Backward Compatibility Gateways
(on page 14)
02 July 2017 Added Hyper-V support in Supported Platforms (on page 14).
Added Smart-1 405 and 410 support in Check Point Appliances (on page
12).
Introduction
Thank you for installing Check Point R80.10 - The cyber security platform of the future. This
release integrates R80 management features with new Security Gateway features and
enhancements.
Important Links
For more about R80.10 and to download the software, see the R80.10 Home Page: sk111841
http://supportcontent.checkpoint.com/solutions?id=sk111841
• Before you upgrade, see the latest upgrade tools on the Home Page.
• Read the Known Limitations: sk110519
http://supportcontent.checkpoint.com/solutions?id=sk110519
• See issues resolved in this release: sk110518
http://supportcontent.checkpoint.com/solutions?id=sk110518
Visit the Check Point Checkmates Community https://community.checkpoint.com/
• Start discussions
• Get answers from experts
• Join the API community to get code samples and share yours
Visit http://www.checkpoint.com/architecture/infinity/ to learn more about Infinity R80.10.
What's New
R80.10 creates a breakthrough in Check Point Security Gateway, matching the R80 security
management innovations.
R80.10 is part of Check Point Infinity, a consolidated cyber security architecture that spans
networks, cloud, and mobile. It provides the highest level of threat prevention against both known
and unknown targeted attacks to keep you protected now and in the future.
Management Enhancements
These enhancements were first introduced in R80.
• Multi-Domain Security Management
• Unified architecture and management console for Security Management and Multi Domain
Security Management.
• New and improved views for Domain management and Global Assignment.
• Role-based & Concurrent Administration - Several administrators can work in parallel on the
same security policy, with granular and flexible privilege delegation to each administrator.
• A new advanced locking mechanism ensures administrators do not overwrite each others'
work.
• Rich administrator profiles for exact privileges each administrator will have, including
managing specific policies or network segments, viewing specific logs, and conducting
security operations, such as installing policy.
• Secured Automation and Orchestration - CLI and API for security management enables full
integration with 3rd party systems and automation of daily operations. Automation and
SmartConsole management operations are allowed based on the same privilege profile.
• Faster Day to Day Operations
• Integrated logging to see all logs related to a rule in the same screen.
• Detailed rule information of who created the rule and when, hit counts, and user-defined
data, such as ticket numbers.
• Enhanced search capabilities to quickly find any rule or object in the system.
• Enhanced Management High Availability synchronizes only changes between servers,
significantly improving efficiency.
• Next Generation Logs, Events and Reports
• Analyze hundreds of millions of logs per day with graphical views and reports, customized
to address specific requirements.
• Logging, monitoring, and report aspects also available in the Web-based interface.
• Free-text search of logs and events with auto-suggest and favorites, with results in
seconds.
• New and Enhanced Revision Management Capabilities
• Built-in automatic policy revision.
• Install a specific version of policies.
• Change to a specific version of IPS package.
• Cloud Demo - Experience R80.10 management scenarios on any computer. sk103431
http://supportcontent.checkpoint.com/solutions?id=sk103431
• vSEC Controller - Natively integrates with the leading private and public cloud platforms:
VMware vCenter & NSX, CISCO ACI, Amazon Web Services (AWS), Microsoft Azure, and
OpenStack.
vSEC Controller provides dynamic security policy and visibility, which automatically adapts to
changes in the cloud environments. This provides simple automated security across physical,
virtual, and cloud environments, from a single unified management solution.
Behavior Changes
• Management
• Management API commands and the SmartView Web-based interface replace the
Management Portal. Use the API commands to install a policy and show a list of Gateways
and Servers. Use SmartView to see logs.
• The new tags for objects replace the renaming of object colors. You can name a tag
according to a color. The tags make it easier to manage objects in SmartConsole.
• New and improved management abilities replace the Database Revision function. To learn
about the enhanced Revisions Management in R80 and higher, see sk113615
http://supportcontent.checkpoint.com/solutions?id=sk113615.
• The mdsstop and mdsstart commands on the Multi-Domain Server are the only way to
start and stop Domain Management Servers function. Most Domain Management Server
components are handled in one process. This reduces memory consumption and CPU
usage.
• Logs, Events, and Reports
• The Logs tab of the SmartConsole Logs & Monitor view replaces SmartLog and SmartView
Tracker. The Logs tab allows you to search through logs with simple and fast searches.
Search results are fast and immediately show the log records.
• SmartEvent replaces SmartReporter and SmartEvent Intro.
• Scheduled reports have been integrated to SmartConsole, and are no longer available from
SmartEvent legacy GUI.
• Threat Prevention and IPS
• The new IPS Optimized Profile replaces the Recommended Profile with excellent security
and improved gateway performance. When upgrading with the Recommended Profile, we
recommend that you change to the Optimized Profile.
• Additional granularity in Threat Prevention permission profiles - Set permissions for IPS
Updates.
• User Center authentication is synchronized with Management Servers to allow IPS and
Threat Prevention updates without explicit login to the User Center. This applies only to
users with permissions to run updates.
• New IPS Protections are marked as "Staging" by default. The Staging configuration can be
changed from the Threat Prevention profile > IPS. You can search and filter Staging
protections from the Protections view, and see corresponding logs. This replaces the
follow up flag.
• Software Blades
• Session Authentication and UserAuthority are replaced by Identity Awareness.
• Overviews, which were part of the Threat Prevention and Application Control tabs in R77
versions, are now shown in the Logging and Monitoring view. This requires SmartEvent
activation and license.
• VPN Traditional Mode is replaced by VPN Simplified Mode.
Licensing
Contact Account Services mailto:[email protected]?subject=Licensing Issues for
all license issues.
From R75.40, R75.45, R75.46, R75.47, R75.40VS, R76, R77, R77.10, R77.20, R77.30 to
R80.10:
Component Supported Methods
Security Management Server CPUSE Upgrade
CPUSE Clean Install
Multi-Domain Server
Advanced Database Migration
To upgrade from R77.20 or R77.30 with the Add-on: It is not necessary to uninstall the Add-on.
Remove these unsupported features: Modbus support with the Application Control Software
Blade, "SAML" Cloud Connector for web based single sign on.
Note: User Defined reports will be migrated during the upgrade to the SmartConsole reports.
Report Scheduling and email server definitions will not be migrated and need to be defined.
If you do not have enough disk space, you can use the Logical Volume Manager (lvm) to increase
the disk space of logical volumes on Gaia. This space is taken from the unallocated disk space,
which is usually used for snapshots and upgrades. See sk95566
http://supportcontent.checkpoint.com/solutions?id=sk95566.
Management Servers
Component Smart-1 Smart-1
25b, 205, 210, 225, 405, 410 50, 150, 3050, 3150
Security Management
Log Server
SmartEvent Server
Multi-Domain Security
Management
Multi-Domain Log Server
Smart-1 25b, 205, and 210 appliances can run Security Management OR Log Server OR
SmartEvent.
3000
4000 *
5000
12000 12600*
13000
15000
21000
23000
Open Servers:
Hardware Sensors: Use the WebUI or SNMP to monitor fan speed, motherboard voltages, power
supply health, and temperatures. Some open servers are supported with an IPMI interface card
that requires an IPMI card.
Note - IPMI is an open standard. We cannot guarantee the Hardware Health Monitoring
performance on all systems and configurations.
Total Cores 2 2 2 8
Supported Platforms
Component Red Hat Enterprise VMware ESXi Microsoft Hyper-V
Linux*
Security Management 5.5, 6.8, 7.3 5.x, 6.x Windows 2012 R2
Multi-Domain Security
5.5, 6.8, 7.3 5.x, 6.x Windows 2012 R2
Management
R80.10 Management Servers can manage appliance Security Gateways of these versions:
Logging Requirements
Logs can be stored on:
• A Security Management Server that collects logs from the Security Gateways. This is the
default.
• A Log Server on a dedicated machine. This is recommended for organizations that generate
many logs.
A dedicated Log Server has greater capacity and performance than a Security Management Server
with an activated logging service. On dedicated Log Servers, the Log Server must be the same
version as the Management Server.
SmartEvent Requirements
You can install a SmartEvent Server on a Security Management Server or on a different, dedicated
server. SmartEvent R80.10 can connect to a different version of Log Server - R77.xx or earlier.
Usually SmartEvent and a Correlation Unit are installed on the same server. You can also install
them on separate servers, for example, to balance the load in large logging environments. The
Correlation unit must be the same version as SmartEvent.
To deploy SmartEvent and to generate reports, a valid license or contract is required.
Management Console
Console Hardware Requirements
This table shows the minimum hardware requirements for console applications:
Component Windows
CPU Intel Pentium Processor E2140 or 2 GHz equivalent processor
Memory 4 GB
Gaia WebUI
The Gaia WebUI, also known as the Gaia Portal, is supported on these browsers:
Build Numbers
Software Blade / Product Build Number Verifying Build Number
Gaia 421 show version all
Threat Emulation
The Threat Emulation requirements are different based on the emulation location:
• ThreatCloud - Gaia operating system (64 or 32-bit)
• Local or Remote emulation - Threat Emulation Private Cloud Appliance on the Gaia
operating system (64-bit only)
Emulation on local Threat Emulation appliances running R80.10 is not supported.
SecureWorkspace
Clientless Citrix
Web mail
Browser Compatibility
Endpoint Browser Compatibility Internet Google Mozilla Macintosh Opera for
Explorer Chrome Firefox Safari Windows
Mobile Access Portal
SecureWorkspace *
Clientless Citrix
Web mail
* Google Chrome support for Mobile Access Portal on-demand clients, such as SSL Network
Extender, Secure Workspace, and Endpoint Security on Demand, requires Java JRE 32 bit
installed on the end-user’s computer.
Third-party 8
UserCheck Client
Check Point Product Server 2008 Server 2008R2 Server Server 2012 Server 2016
(SP1-2) 32 / (+SP1) 2012 R2 64-bit
64
UserCheck Client
Identity Agent
For earlier server versions, use the R77.30 DLP Exchange Agent.