> Source: [sk181803](https://support.checkpoint.com/results/sk/sk181803)

# sk181803 - Possible failure to boot on a Security Gateway with IPS, Anti-Bot, or Application Control enabled

| Property | Value |
|----------|-------|
| Solution ID | sk181803 |
| Date Created | 2023-12-16 |
| Last Modified | 2024-01-16 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Security Gateway with IPS, Anti-Bot, or Application Control enabled might fail to boot after one of these actions:

  * A policy installation
  * An update of the IPS signatures package
  * An update of the Anti-Bot signatures package
  * An update of the Application Control signatures package

  On a Quantum Spark appliance, during boot it might revert to factory defaults.
* Security Gateway with IPS, Anti-Bot, or Application Control enabled might experience these issues after a policy installation or after an update of a signatures package described above (before a reboot):

  * Security Gateway drops connections unexpectedly
  * No SSH access to Security Gateway
  * Memory exhaustion on Security Gateway
  * CPUSE Deployment Agent (DA) stops unexpectedly or fails to install packages
  * Missing files on the filesystem (for example, in `$FWDIR/bin/` and `/bin/`)
* This applies to Security Gateways that run these versions:

  * R81.10
  * R81
  * R80.40
  * R80.30
  * R80.20
  * R80.30SP for Maestro
  * R80.20SP for Maestro and Chassis
  * R80.20.00 - R80.20.35 for Quantum Spark
* This applies to Security Gateways that run:

  * on physical on-premises servers
  * in virtual machines

## Cause

During policy installation or signatures package update, a rare memory corruption might occur that leads to a corruption of the filesystem. As a result, Gaia OS cannot boot.

## Solution

Versions that are not affected by this issue
--------------------------------------------

These versions that are not affected by this issue:

* [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903) and higher
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 130
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 92
* [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 206
* [Check Point Quantum Spark R80.20.40](https://support.checkpoint.com/results/sk/sk176145) and higher

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ([Security Gateway](https://support.checkpoint.com/product/73) / [VSX](https://support.checkpoint.com/product/359) / [Security Management Server](https://support.checkpoint.com/product/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [SmartConsole](https://support.checkpoint.com/product/191)).

To prevent this issue
---------------------

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version to prevent this issue.

**Important** - This hotfix is planned to be integrated into Jumbo Hotfix Accumulators for R81 and R80.40 versions (lower versions need to be upgraded to one of the [supported versions](http://www.checkpoint.com/support-services/support-life-cycle-policy/)).

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

To resolve this issue after it occurred
---------------------------------------

Restore your Security Gateway to factory defaults.  
Show / Hide this section  
* On Check Point Appliances that run the R80.20 / R80.30 / R80.40 / R81 / R81.10 versions,

  Maestro Security Appliances that run the R80.20SP / R80.30SP / R81 / R81.10 versions,

  and Scalable Chassis that run the R80.20SP / R81 / R81.10 versions
  > 1. Connect to the console port on the appliance.
  > 2. Reboot the appliance.
  > 3. During boot, press any key to get into the Boot Menu.
  > 4. Select the option "`Reset to factory defaults`".
  > 5. Wait for the appliance to restore itself to the factory default image and boot.
  > 6. Run the Gaia First Time Configuration Wizard.  
  >    Note for Maestro - This happens automatically. This appliance gets the required configuration from other appliances in the Security Group.
  > 7. Install the required hotfix / version to prevent this issue.  
  >    Note - In Maestro and Chassis, install it on the Security Group.
  >
  > For additional information, refer to the:
  > * Gaia Administration Guide ([R81.10](https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_AdminGuide/Default.htm), [R81](https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Default.htm), [R80.40](https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_Gaia_AdminGuide/Default.htm), [R80.30](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_Gaia_AdminGuide/html_frameset.htm), [R80.20](https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_Gaia_AdminGuide/html_frameset.htm)) \> Chapter "Maintenance" \> Section "Snapshot Management" \> Section "Restoring a Factory Default Image on Check Point Appliance"
  > * Scalable Chassis Installation and Upgrade Guide ([R80.20SP](https://sc1.checkpoint.com/documents/R80.20SP/WebAdminGuides/EN/CP_R80.20SP_Chassis_Installation_and_Upgrade_Guide/html_frameset.htm)) \> Chapter "Installing the Gaia Operating System on Scalable Platform"
* On Check Point Quantum Spark Appliances that run the R80.20.X versions

  > Use **one** of these options:
  > * To restore factory defaults with the button on the back panel:
  >
  >   1. Press the Factory Default button with a pin.  
  >      Hold for at least 12 seconds.
  >   2. When the Power LED is lit blue, release the button.  
  >      The appliance reboots itself and starts to restore factory defaults immediately.
  >   3. While factory defaults are restored, the Power LED blinks blue to show progress.
  >   4. This takes several minutes.  
  >      When this completes, the appliance reboots automatically.
  > * To restore the Quantum Spark Appliance to its default factory configuration using U-boot (boot loader):
  >
  >   1. Connect to the appliance with a console connection (use the serial console connection on the back panel of the appliance).
  >   2. Boot the appliance and press CTRL+C.
  >   3. The "`Gaia Embedded Boot Menu`" appears.
  >   4. Enter 4 to select "`Restore to Factory Defaults (local)`".
  >   5. When the prompt appears "`Are you sure? (y/n)`", enter `y` to continue and restore the appliance to its factory defaults settings.
  >   6. While factory defaults are restored, the Power LED blinks blue to show progress.  
  >      This takes several minutes.  
  >      When completed, the appliance boots automatically.
  >
  > For additional information, refer to the [Quantum Spark 1500, 1600, 1800 Appliance Series R80.20.35 Locally Managed Administration Guide](https://sc1.checkpoint.com/documents/SMB_R80.20.35/AdminGuides/Locally_Managed/EN/Default.htm) \> Chapter "Advanced Configuration" \> Section "Restoring Factory Defaults".

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
