Generally if things are impacted during a policy push even with "keep all connections set", that indicates a firewall that is severely overloaded or in desperate need of some tuning. When running a continuous large-packet ping through the firewall during a policy push do you see high latency for an extended period of time, packet loss, or both?
I'd suggest running the Super Seven commands here and posting the results for analysis:
Super Seven Performance Assessment Commands (s7pac)
--
CheckMates Break Out Sessions Speaker
CPX 2019 Las Vegas & Vienna - Tuesday@13:30
Attend my online "Be your Own TAC: Part Deux" CheckMates event
March 27th with sessions for both the EMEA and Americas time zones