May be it's your case -
https://secureknowledge.checkpoint.c....do?id=sk31538 "This problem was fixed. The fix is included in the following release(s):
VPN-1 Pro NGX R60 HFA_03
After installing HFA_03 follow this procedure:
Backup $FWDIR/lib/implied_rules.def.
Rename the implied_rules_HFA.def file to implied_rules.def and make sure that you verify file permissions.
Backup $FWDIR/hash/implied_rules.def.hash.
Rename the implied_rules_HFA.def.hash to implied_rules.def.hashbase_HFA.def.hash to base.def.hash.
Install the Security Policy.
...
If for some reason an upgrade is currently not possible, the following workaround is available:
Add the following explicit rule at the top of the rulebase:
SOURCE: Any
DESTINATION: Any
SERVICE: fw1_lea
ACTION: accept
Install the security policy."