Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
BorisL
Collaborator
Jump to solution

R82.10 Possible Database Corruption

We migrated from R81.20 to R82.10 three weeks ago. Instance in AWS.
Everyhting worked flawlessly until this morning.

Suddenly VPN stopped working (users could not connect) and active tunnels were dropped.

We made a policy install to set additional logging an install failed. "Installation failed. Reason: Load on Module failed - problem with the Commit Function."

Otherwise, FW is routing and logging traffic, but no vpn and cannot update policies.

We have opened TAC case and have been told that it is a critical bug that currupts the database when installing a policy, but we had not installed a policy lately. Waiting to get an update.

Now afraid our other standalone FW on backup site will also fail.

Anybody having this critical problem?

 

0 Kudos
1 Solution

Accepted Solutions
BorisL
Collaborator

TAC responded:

"Over the last few days, our R&D Team has been investigating the issue, and managed to resolve it.

  • On the evening of 21.07.2026, we released a fix that would be automatically applied to any FW that is connected to the internet without any actions on the customer's side - It should happen by the night of 22.07.2026 at the very latest.
  • Moreover, previously, it was thought that we needed to perform a Fresh installation or revert to a snapshot from before July 17th to resolve the issue.
  • However, since we discovered the RC, the full solution is much simpler.

Moving forward, I would like to share the steps to completely resolve the issue:

  • First, as mentioned above, our FW should automatically received a fix by the night of July 22nd at the latest.
    • We can check if we received the fix by running the following command:
      • ## md5sum /opt/CPdiag/conf/cpdiag_dynamic_config.dat
      • The output should be "c1ac3d2cb40579a0bd90ef7336ae1bc4 "
    • Look for the following entry in $FWDIR/log/cpdiag.elg: "Found dynamic configuration version : batfish_992100335"
  • The above fix will prevent the corruption from reappearing - However, some of the files that were already corrupted, we need to remove and re-generate as follows:
    • First, delete all of the files in the following directory: ## $FWDIR/state/
    • Second, delete the following file: ## $FWDIR/database/fwauth.NDB
    • Run: ## cpstop; cpstart
    • This is restart all Checkpoint process and will cause a short downtime
    • Install the Access and Threat-Prevention Policies - Please mark "Do not use Install Policy Acceleration for all targets"

_______________

The instructions to recreate the database and state where incomplete and TAC later indicated to follow sk33328 but that did not work for us either.

We restored a backup image of the FW (with uncurropted database and state), observed that the online fix was applied and confirmed with TAC that no further action needed to be taken.

I would think that other sites using R82.10 with connection active to Internet have received the fix transparently and are safe.

View solution in original post

0 Kudos
1 Reply
BorisL
Collaborator

TAC responded:

"Over the last few days, our R&D Team has been investigating the issue, and managed to resolve it.

  • On the evening of 21.07.2026, we released a fix that would be automatically applied to any FW that is connected to the internet without any actions on the customer's side - It should happen by the night of 22.07.2026 at the very latest.
  • Moreover, previously, it was thought that we needed to perform a Fresh installation or revert to a snapshot from before July 17th to resolve the issue.
  • However, since we discovered the RC, the full solution is much simpler.

Moving forward, I would like to share the steps to completely resolve the issue:

  • First, as mentioned above, our FW should automatically received a fix by the night of July 22nd at the latest.
    • We can check if we received the fix by running the following command:
      • ## md5sum /opt/CPdiag/conf/cpdiag_dynamic_config.dat
      • The output should be "c1ac3d2cb40579a0bd90ef7336ae1bc4 "
    • Look for the following entry in $FWDIR/log/cpdiag.elg: "Found dynamic configuration version : batfish_992100335"
  • The above fix will prevent the corruption from reappearing - However, some of the files that were already corrupted, we need to remove and re-generate as follows:
    • First, delete all of the files in the following directory: ## $FWDIR/state/
    • Second, delete the following file: ## $FWDIR/database/fwauth.NDB
    • Run: ## cpstop; cpstart
    • This is restart all Checkpoint process and will cause a short downtime
    • Install the Access and Threat-Prevention Policies - Please mark "Do not use Install Policy Acceleration for all targets"

_______________

The instructions to recreate the database and state where incomplete and TAC later indicated to follow sk33328 but that did not work for us either.

We restored a backup image of the FW (with uncurropted database and state), observed that the online fix was applied and confirmed with TAC that no further action needed to be taken.

I would think that other sites using R82.10 with connection active to Internet have received the fix transparently and are safe.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events