Hey Check Mates,
I recently upgraded a 3920 appliance from R82.10 Build 271 JHF-22 to the recently released R82.10 GA Build 464. After the upgrade completed successfully, the appliance did not recover successfully from the reboot. I was able to console into the appliance and discovered the issue and everything made sense.
After the upgrade the appliance was using a default policy and was attempting to contact the SMS to retrieve the proper policy; however, it could not do this because OSPF would not establish. OSPF does not establish unless you have a defined rule (sk39960 ). Creating a temporary static route to the SMS quickly resolved my issue as the policy installed and OSPF established.
Now the reason for my post, why is this a thing? As in, why do I have to create a firewall rule to make OSPF work? The initial configuration is all performed in Gaia, and even when the connection comes up the traffic becomes an "Implied Rule" anyway.

The firewall allows random peers to try and establish IPsec tunnels via Implied Rules, so I do not understand the reason why OSPF connections can't be allowed as well.