<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R82.10 Possible Database Corruption in Cloud Firewall</title>
    <link>https://community.checkpoint.com/t5/Cloud-Firewall/R82-10-Possible-Database-Corruption/m-p/280668#M6296</link>
    <description>&lt;P&gt;TAC responded:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;"Over the last few days, our R&amp;amp;D Team has been investigating the issue, and managed to resolve it.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;On the evening of 21.07.2026, we released a fix that would be automatically applied to any FW that is connected to the internet without any actions on the customer's side - It should happen by the night of 22.07.2026 at the very latest.&lt;/LI&gt;&lt;LI&gt;Moreover, previously, it was thought that we needed to perform a Fresh installation&amp;nbsp;or revert&amp;nbsp;to a snapshot from before July 17th to resolve the issue.&lt;/LI&gt;&lt;LI&gt;However, since we discovered the RC, the full solution is much simpler.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Moving forward, I would like to share the steps to completely resolve the issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;First, as mentioned above, our FW should automatically received a fix by the night of July 22nd at the latest.&lt;UL&gt;&lt;LI&gt;We can check if we received the fix by running the following command:&lt;UL&gt;&lt;LI&gt;##&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;md5sum&amp;nbsp;/opt/CPdiag/conf/cpdiag_dynamic_config.dat&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;The output should be "c1ac3d2cb40579a0bd90ef7336ae1bc4 "&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Look for the following entry in&amp;nbsp;&lt;STRONG&gt;$FWDIR/log/cpdiag.elg&lt;/STRONG&gt;:&amp;nbsp;"Found dynamic configuration version : batfish_992100335"&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;The&amp;nbsp;above fix will prevent the corruption from reappearing - However,&amp;nbsp;some of the files that were already corrupted,&amp;nbsp;we need to remove and re-generate as follows:&lt;UL&gt;&lt;LI&gt;First, delete all of the files in the following directory: ## $FWDIR/state/&lt;/LI&gt;&lt;LI&gt;Second, delete the following file: ## $FWDIR/database/fwauth.NDB&lt;/LI&gt;&lt;LI&gt;Run: ## cpstop; cpstart&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;This is restart all Checkpoint process and will cause a short downtime&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Install the Access and Threat-Prevention Policies - Please mark "Do not use Install Policy Acceleration for all targets"&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;_______________&lt;BR /&gt;&lt;BR /&gt;The instructions to recreate the database and state where incomplete and TAC later indicated to follow&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk33328" target="_blank" rel="noopener"&gt;sk33328&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;but that did not work for us either.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;We restored a backup image of the FW (with uncurropted database and state), observed that the online fix was applied and confirmed with TAC that no further action needed to be taken.&lt;BR /&gt;&lt;BR /&gt;I would think that other sites using R82.10 with connection active to Internet have received the fix transparently and are safe.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2026 09:55:23 GMT</pubDate>
    <dc:creator>BorisL</dc:creator>
    <dc:date>2026-08-03T09:55:23Z</dc:date>
    <item>
      <title>R82.10 Possible Database Corruption</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R82-10-Possible-Database-Corruption/m-p/279919#M6276</link>
      <description>&lt;P&gt;We migrated from R81.20 to R82.10 three weeks ago. Instance in AWS.&lt;BR /&gt;Everyhting worked flawlessly until this morning.&lt;/P&gt;&lt;P&gt;Suddenly VPN stopped working (users could not connect) and active tunnels were dropped.&lt;/P&gt;&lt;P&gt;We made a policy install to set additional logging an install failed.&amp;nbsp;&lt;SPAN&gt;"Installation failed. Reason: Load on Module failed - problem with the Commit Function."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Otherwise, FW is routing and logging traffic, but no vpn and cannot update policies.&lt;BR /&gt;&lt;BR /&gt;We have opened TAC case and have been told that it is a critical bug that currupts the database when installing a policy, but we had not installed a policy lately. Waiting to get an update.&lt;BR /&gt;&lt;BR /&gt;Now afraid our other standalone FW on backup site will also fail.&lt;/P&gt;&lt;P&gt;Anybody having this critical problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2026 07:27:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R82-10-Possible-Database-Corruption/m-p/279919#M6276</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2026-07-21T07:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: R82.10 Possible Database Corruption</title>
      <link>https://community.checkpoint.com/t5/Cloud-Firewall/R82-10-Possible-Database-Corruption/m-p/280668#M6296</link>
      <description>&lt;P&gt;TAC responded:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;"Over the last few days, our R&amp;amp;D Team has been investigating the issue, and managed to resolve it.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;On the evening of 21.07.2026, we released a fix that would be automatically applied to any FW that is connected to the internet without any actions on the customer's side - It should happen by the night of 22.07.2026 at the very latest.&lt;/LI&gt;&lt;LI&gt;Moreover, previously, it was thought that we needed to perform a Fresh installation&amp;nbsp;or revert&amp;nbsp;to a snapshot from before July 17th to resolve the issue.&lt;/LI&gt;&lt;LI&gt;However, since we discovered the RC, the full solution is much simpler.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Moving forward, I would like to share the steps to completely resolve the issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;First, as mentioned above, our FW should automatically received a fix by the night of July 22nd at the latest.&lt;UL&gt;&lt;LI&gt;We can check if we received the fix by running the following command:&lt;UL&gt;&lt;LI&gt;##&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;md5sum&amp;nbsp;/opt/CPdiag/conf/cpdiag_dynamic_config.dat&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;The output should be "c1ac3d2cb40579a0bd90ef7336ae1bc4 "&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Look for the following entry in&amp;nbsp;&lt;STRONG&gt;$FWDIR/log/cpdiag.elg&lt;/STRONG&gt;:&amp;nbsp;"Found dynamic configuration version : batfish_992100335"&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;The&amp;nbsp;above fix will prevent the corruption from reappearing - However,&amp;nbsp;some of the files that were already corrupted,&amp;nbsp;we need to remove and re-generate as follows:&lt;UL&gt;&lt;LI&gt;First, delete all of the files in the following directory: ## $FWDIR/state/&lt;/LI&gt;&lt;LI&gt;Second, delete the following file: ## $FWDIR/database/fwauth.NDB&lt;/LI&gt;&lt;LI&gt;Run: ## cpstop; cpstart&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;This is restart all Checkpoint process and will cause a short downtime&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;Install the Access and Threat-Prevention Policies - Please mark "Do not use Install Policy Acceleration for all targets"&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;_______________&lt;BR /&gt;&lt;BR /&gt;The instructions to recreate the database and state where incomplete and TAC later indicated to follow&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk33328" target="_blank" rel="noopener"&gt;sk33328&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;but that did not work for us either.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;We restored a backup image of the FW (with uncurropted database and state), observed that the online fix was applied and confirmed with TAC that no further action needed to be taken.&lt;BR /&gt;&lt;BR /&gt;I would think that other sites using R82.10 with connection active to Internet have received the fix transparently and are safe.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2026 09:55:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Cloud-Firewall/R82-10-Possible-Database-Corruption/m-p/280668#M6296</guid>
      <dc:creator>BorisL</dc:creator>
      <dc:date>2026-08-03T09:55:23Z</dc:date>
    </item>
  </channel>
</rss>

