This is in the Installation and upgrade guide:
https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui...
You may (or may not) need to run the initial policy compiler first:
$FWDIR/bin/comp_init_policy [-g | -G]
|
Creates the local state Initial Policy
|
Then load the policy manually:
fw fetchlocal -d $FWDIR/state/local/FW1/
InitialPolicy loaded:
[Expert@cpgw01:0]# fw stat
HOST POLICY DATE
localhost InitialPolicy 7Mar2025 0:11:41 : [>eth0] [<eth0]
Please test this on your own before trying on a production gateway, however! After InitialPolicy is loaded, you can still SSH to the gateway and run various CPD management commands from SmartConsole (or wherever). You can't ping the gateway, however.
If you want to build your own custom default filter, review the documentation section:
https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_Installation_and_Upgrade_Gui...