<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Upgrade from R77.20 to R80.10,and failed to verify policy. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6175#M100702</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.It should be announced in docs or some kind of SKs.&lt;/P&gt;&lt;P&gt;I have correct manually the packages for about 3 days .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 20 Sep 2017 05:06:41 GMT</pubDate>
    <dc:creator>Dawei_Ye</dc:creator>
    <dc:date>2017-09-20T05:06:41Z</dc:date>
    <item>
      <title>Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6159#M100686</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you guys meet this &amp;nbsp;situation?&lt;/P&gt;&lt;P&gt;The policy packages could install successfully.&lt;/P&gt;&lt;P&gt;But when I verify policies after upgrading to R80.10 ,I get a failure errors.&lt;/P&gt;&lt;P&gt;There are so many hide policy in R80.10.It could be about more than one thousands policies to be reported hide another policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any methods&amp;nbsp;to solve the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&amp;amp;Regards,&lt;/P&gt;&lt;P&gt;Dawei Ye&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 05:18:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6159#M100686</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-11T05:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6160#M100687</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I do know the rule validation logic changed somewhat in R80.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you confirm this EXACT policy installed successfully with no errors prior to upgrading to R80.10?&lt;/P&gt;&lt;P&gt;Can you also confirm this policy installed successfully in R80.10 and did you see errors in this case?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be helpful if you could post the exact error messages you saw.&lt;/P&gt;&lt;P&gt;A screenshot of a couple of the rules in question might also be helpful.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 06:01:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6160#M100687</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-11T06:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6161#M100688</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this is the errors from two versions.It's from a same package.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="58446" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58446_pastedImage_1.png" style="width: 620px; height: 309px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't install policy in R80.10 due to the errors above.&lt;/P&gt;&lt;P&gt;and this is rules according to the first error.&lt;/P&gt;&lt;P&gt;the source and destination is the same.and only one service port hide.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="58447" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58447_pastedImage_2.png" style="width: 620px; height: 375px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 06:37:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6161#M100688</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-11T06:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6162#M100689</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I did a mistake .&lt;/P&gt;&lt;P&gt;the policy can only install in R77.20.And failed in R80.10.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 06:39:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6162#M100689</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-11T06:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6163#M100690</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dawei.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By chance did you use the R80 Upgrade Verification service to see if there would be any issues with porting your config into R80.x?&amp;nbsp; If not, you might want to consider it because there are other hidden items that you might not know about.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110267"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110267&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 16:50:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6163#M100690</guid>
      <dc:creator>Jason_Dance</dc:creator>
      <dc:date>2017-09-11T16:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6164#M100691</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To me, at least, this shouldn't trigger a verification failure.&lt;/P&gt;&lt;P&gt;It might be worth a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That said, it looks like there is some opportunity for optimization, either using an inline layer and/or consolidating rules.&lt;/P&gt;&lt;P&gt;I also agree with &lt;A href="https://community.checkpoint.com/migrated-users/46542"&gt;https://community.checkpoint.com/people/jdanc6ca94357-c3d4-325b-9d5c-a8a71c5d2e9c&lt;/A&gt;‌ that it's probably a good idea to look through the R80.x Upgrade Verification service to make sure there are no other issues.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 17:02:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6164#M100691</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-11T17:02:08Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6165#M100692</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Turns out rule matching logic isn't run as part of the&amp;nbsp;Pre-Upgrade Verifier.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Further, I'm told the reason these rules validated in R77.20 at all is due to&amp;nbsp;bugs that were fixed in R77.30 and R80.10.&lt;/P&gt;&lt;P&gt;In other words, this is working as designed.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 06:27:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6165#M100692</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-12T06:27:58Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6166#M100693</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;oh……&lt;/P&gt;&lt;P&gt;I found it could be a bug yet.&lt;/P&gt;&lt;P&gt;even the exactly the same rule could install in R77.20.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58505_pastedImage_1.png" style="width: 620px; height: 83px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And Dameon, could you offer me some docs about the rule matching logic changing in R80.10?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 07:03:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6166#M100693</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-12T07:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6167#M100694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;I ran some times in R77.20 with Pre-Upgrade Verifier(did &lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;R80 Upgrade Verification service means this?&lt;/SPAN&gt;&amp;nbsp;).&lt;/P&gt;&lt;P&gt;It only some warning about non-English characters.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 07:05:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6167#M100694</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-12T07:05:35Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6168#M100695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Which pretty much seems to support the idea of gettings things stable in R77.30 first before you considere migrating to higher versions.&lt;/P&gt;&lt;P&gt;You would have caught the issues in that stage.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 07:09:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6168#M100695</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-09-12T07:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6169#M100696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The actual logic should be the same, what's improved is the efficiency of validating that logic.&lt;/P&gt;&lt;P&gt;Two (or more) rules with the same source, destination, and service are not allowed and should cause a validation error.&lt;/P&gt;&lt;P&gt;The fact it did not do this in R77.20 was a defect&amp;nbsp;corrected in R77.30 and R80.10.&lt;/P&gt;&lt;P&gt;Which explains why you are seeing those errors after upgrading to R80.10.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 07:20:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6169#M100696</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-12T07:20:40Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6170#M100697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So there is no any way to correct the errors ?&lt;/P&gt;&lt;P&gt;I can just correct the validation error by hands?&lt;/P&gt;&lt;P&gt;anyway,Demeon, thanks for your help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 07:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6170#M100697</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-12T07:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6171#M100698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hugo,&lt;/P&gt;&lt;P&gt;woo……but for now ,if I upgrade to R77.30 first,I would still catch up with this issue.&lt;/P&gt;&lt;P&gt;I'd prefer to correct it in R80.10 directly.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 07:37:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6171#M100698</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-12T07:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6172#M100699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know there is no automated way to correct the issue.&lt;/P&gt;&lt;P&gt;They will need to be modified by hand.&lt;/P&gt;&lt;P&gt;Personally, I would take the opportunity to cleanup the policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Sep 2017 14:39:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6172#M100699</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-12T14:39:58Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6173#M100700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For me it looks like, rule 119 hides rule 200 - because for the same ip-ranges (for source and target) the &lt;STRONG&gt;SAME port-range&lt;/STRONG&gt; is again - even if the names are different.&lt;/P&gt;&lt;P&gt;tcp_31000-310100 in rule 119&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;tcp31001to31010 in rule 200&lt;/P&gt;&lt;P&gt;And with the same name of the port for the "Bionet-Setup".&lt;/P&gt;&lt;P&gt;Delete this port range in rule 200 rule (because this port-range seems to be a subset of the port-range in rule 119) and verifiy again. Let us know the result.&lt;/P&gt;&lt;P&gt;P.S.: Normally by defining a port-range (or single ports) it will be checked that the same range will not exists before, but it maybe that what was defined here was changed later (or because the range of rule 200 is a subset of the range in rule 119).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2017 04:20:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6173#M100700</guid>
      <dc:creator>14KME</dc:creator>
      <dc:date>2017-09-15T04:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6174#M100701</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From my prospective the upgrade verifier didn´t solve the issue. it is "just" a engine improvement of the rule verifier.&lt;/P&gt;&lt;P&gt;There is no automatic way to solve it as far as I know. Just correct manually and use the opportunity to clean-up.&lt;/P&gt;&lt;P&gt;This is the way we did it too.&lt;/P&gt;&lt;P&gt;Honestly this should been announced in the upgrade documents to be aware of and plan time for it.&lt;/P&gt;&lt;P&gt;Depends on the size of your Management area.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Sep 2017 08:49:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6174#M100701</guid>
      <dc:creator>Joachim_Zint</dc:creator>
      <dc:date>2017-09-15T08:49:25Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6175#M100702</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.It should be announced in docs or some kind of SKs.&lt;/P&gt;&lt;P&gt;I have correct manually the packages for about 3 days .&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Sep 2017 05:06:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6175#M100702</guid>
      <dc:creator>Dawei_Ye</dc:creator>
      <dc:date>2017-09-20T05:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6176#M100703</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Faced similar but this time MDM is running R77.30 Gaia. Is there any other possible way except manually fix the issue?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Sep 2017 14:57:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6176#M100703</guid>
      <dc:creator>Anthony_Kwang</dc:creator>
      <dc:date>2017-09-24T14:57:15Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6177#M100704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have this sort of issue (specifically "rule hiding" issues) the only way to fix them is manually.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Sep 2017 15:57:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6177#M100704</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-09-24T15:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Upgrade from R77.20 to R80.10,and failed to verify policy.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6178#M100705</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dawei,&lt;/P&gt;&lt;P&gt;Have you considered that the amount of hidden rules might be an indication of making the policy too specific?&lt;/P&gt;&lt;P&gt;I tend to go to the situation where you need less rules and don't be go with rules like:&lt;/P&gt;&lt;P&gt;Src: Server-A, Dst: Server-B, Service: Port-C&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Specifically with R80.10 I would considere to scratch such a polciy and rebuild your policy from the ground up.&lt;/P&gt;&lt;P&gt;Layered approach as a starting point. and try to keep away from micro management. Most certainly if you have to do it by hand.&lt;/P&gt;&lt;P&gt;Let IPS and such take care of part of the management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to see examples of how you can automate this with the API in a large network. It may still rresult in micro management but don't do this by hand.&lt;/P&gt;&lt;P&gt;Having worked with Telco solutions where no-one even actually configures every device by hand to define a Path from A to B for a service has shown me that we have a long way to go befor we see this in computer networks for most companies.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Sep 2017 07:21:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Upgrade-from-R77-20-to-R80-10-and-failed-to-verify-policy/m-p/6178#M100705</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-09-25T07:21:05Z</dc:date>
    </item>
  </channel>
</rss>

