When we migrated to R80.40, after some random time of normal operations, traffic traversing the firewall using static nat rules stopped working. We could not identify the cause nor resolve it.
We have the feeling that the process of upgrading Check Point versions is very fragile. Our only alternative seems to do fresh installs and manually enter all the objects and rules, risking errors. We also need to upgrade two standalone R80.30 systems running on intel servers. We could do it "in-place" using CPUSE but the only way to go back if things don't work is a fresh install of old version and restore from a backup. All alternatives seem difficult.