Technical data

36 Known limitations and considerations in this release
217316-A Rev 00
General limitations (based on ASF 5100 release 2.2.7.0)
The following features are not supported in this release:
Check Point FloodGate
VRRP Active-Active
—VPN
—VSX
Check Point Cluster XL
ClusterXL configuration is not supported even though the menu
/cfg/net/vrrp/clusterxl exists.
SNMP v3 target addresses on the CLI and JDM must include a prefix value of
'0x'. (Q01067472)
If you are using SmartDefence Fingerprint Scrambling (TTL) feature, make
sure that the default TTL is set to 255. Otherwise, VRRP Active-Hot Standby
does not work properly.
Nortel suggests not enabling worm catcher on SDM platforms where the total
concurrent connections are less than 50,000.
Check Point HTTP Security server vulnerability. Check Point Hot fix is
available in R55.
TCP Reset vulnerability. Check Point Hot fix/patch is available in R55.
Executing some CLI commands after long period of inactivity (more than 12
hours) may give an error. Ignore this error, and continue entering the
command until it works properly. (The command should work within three
retries.)
Note: When a Firewall iSD is deleted from a cluster, an error message is
generated by the BBI for the port configuration on the remaining
Firewall iSD. Since you must reconfigure the Firewall iSD once it is
deleted from the cluster anyway, this error message does not affect
functionality. (Q00994834)