I have some Crossbeam X80 hardware running R67 VSX for some virtual firewalls. Life is good and everything worked fine. I planned and executed an upgrade plan for these blades to move to Checkpoint R77.10 VS. The policy upgrade process and software upgrade process went with zero errors. When we tried to push the policy to the firewalls, it would fail. The errors, during a debug, were ambiguous at best.
What was the eventual issue? CIFS Resources with greater then 25 file shares. It seems the IPS in R77 has a hard limit of 25 shares in CIFS resources. We use CIFS resources as an extra level of protection when 3rd Parties access our Windows File Shares.
Most of our CIFS resources had less then 25 file shares, so they needed no change. But, a single 3rd party accessed quite a few shares. So, the revert back to a straight CIFS service group on these rules and removal of the CIFS resource in the firewall policy allowed a successful push of the policy to the gateway.
NOTE TO SELF: Keep that one in your back pocket.