DO NOT UPGRADE TO QUANTUM SPARK R82.00.10 Build 998002242
Unfortunately we ran into some serious issues after installing this on an appliance affected by the recent memory leak bug. We installed this firmware update to resolve the latest memory leak issue and it rendered our firewall useless. Cloud connection service will not work, all blades fail to load, logging no longer works and errors out when loading in the GUI, cannot create network objects, etc. If you run configload_status in Expert mode all blades show failed.
DO NOT INSTALL THIS. I reverted back to the original image we used and the errors plaguing the firewall after upgrade still exist. TAC said my only option is the factory reset.
EDIT 1:
The TAC had me delete everything from \storage\, upload the firmware image to the device via WINSCP and run a safe upgrade with database refresh. They also cleared hashed certificates. This did not do anything at all. Not a knock on the TAC, I just want people to know this will not fix the issue so they can avoid going through this 30 minute process.
After my call I pulled up my trustworthy Checkpoint command document and ran fw_configload. This generated an error showing that there were issues loading various importable objects. Error below:
dst uo found: Known Active Attackers
Error: Updatable object CP_SUSP_SUSPICIOUS was not found on the UO DB
dst uo found: TOR Exit Nodes
Error: Updatable object CP_CPTOR_TOR was not found on the UO DB
I removed all of these objects from my firewall policies, ran fw_configload again and everything came back up.
I wish I would have just did this from the beginning but I panicked because of the time sensitivity requirement for this customer to come back online along with other issues I was dealing with tonight.
I don't want to come off as being mean in my posts but if you look at my Checkmates history, I have been seeing issues like this consistently since we started purchasing the 25xx series in January and running r82. As the main firewall administrator at an MSP for 30+ organizations, these problems have really caused bad client friction.
EDIT 2:
Logging is completely broken. We don't see any inbound drops or accepts in the GUI even though I can see them in the CLI. Also there are just a ton of blank entries like below:
