> Source: [sk183855](https://support.checkpoint.com/results/sk/sk183855)

# sk183855 - Unexpected Access Policy Rule Behavior After Upgrade to R81.10.15 or R81.10.17 on Spark Firewall Appliances

| Property | Value |
|----------|-------|
| Solution ID | sk183855 |
| Date Created | 2025-08-26 |
| Last Modified | 2026-05-03 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1575R, 1500, 1900, 2000, 1600, 1800, 1595R |

## Symptoms

- After upgrading from R77.20.xx ? R80.20.xx ? R81.10.15 or R81.10.17 on a Spark Firewall Appliance, you may observe the following:

* Access Policy rules no longer work as expected.
* Rules that previously allowed or blocked only specific Uniform Resource Locators (URLs) over Hypertext Transfer Protocol Secure (HTTPS) now allow or block all HTTPS traffic, regardless of the URL.
* Rules intended for a single website or application affect all traffic for the entire protocol (for example, HTTPS).
* Users gain access to websites that company policy should block.

## Cause

During the upgrade sequence, the system did not remove Service objects (for example, HTTPS) from rules that also included Application objects (for example, specific URLs).

Starting in R81.10.15, the system merges both Service and Application objects into a new field called **AppsAndServices**, which applies OR logic instead of AND logic.

As a result, rules matched either the Service or the Application, instead of both, causing unexpected behavior.

## Solution

This problem was fixed. The fix is included starting from:

* [R81.10.17](https://support.checkpoint.com/results/sk/sk183153) Jumbo Hotfix Accumulator Build 996004691
* [R82.00.00](https://support.checkpoint.com/results/sk/sk183407) Jumbo Hotfix Accumulator Build 998000719

**Note** : These Builds include a migration fix that prevents the unintended OR logic by ensuring the Service object is not added to the rule if an object already exists in the **AppsAndServices** field.  

Manual **workaround** for already upgraded appliances:  

If the Spark Firewall Appliance was already upgraded to an affected version (R81.10.15 General Accessibility to R81.10.17 build 4653 or related Hotfixes), upgrading to the fixed version does not automatically resolve the issue. You must manually delete the Service value from the affected rule:  

1. Log in to the Spark Firewall Appliance management interface.
2. Identify rules where both Service and Application objects appear in the AppsAndServices field.
3. Remove the Service object (for example, HTTPS) from these rules.
4. Save and install the policy.
5. Confirm that rules now match only the intended URLs.
6. Make sure rules no longer apply to all traffic for the protocol.

**Notes** :

This issue occurs only when:

* The configuration originated in R77.20.xx.
* The upgrade path went through R80.20.xx before moving to R81.10.15 GA or R81.10.17 GA (including 4653-based Hotfixes).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
