<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to debug Policy Installation Errors in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5240#M101159</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've had exactly the same problem with that exact error message, where the policy would verify fine but fail to install. I've logged a TAC case and the engineer fixed it by doing this on the Secure Management server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;[Expert@MGMT:0]# cd $FWDIR/conf&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;[Expert@MGMT:0]# grep -e $'^\t\t: (' objects_5_0.C -e "is_mail_server (false)" -e mail_server_prop | grep -v "mail_server_prop ()" | grep mail_server_prop -B 2 | grep ":is_mail_server (false)" -B 1 | grep -e $'^\t\t: ('&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will list objects that are configured as servers. Go through each object and un-tick everything under Servers. Once that is done, publish changes and push policy. The policy should install fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 03 May 2018 02:54:58 GMT</pubDate>
    <dc:creator>Marcel_Talos</dc:creator>
    <dc:date>2018-05-03T02:54:58Z</dc:date>
    <item>
      <title>How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5235#M101154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I get some BETA Dejavu experiences. Where I would break the EA version by activating the DNS server on the object for my Active Directory server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ia noe have this gracefull error "Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: 0-2000040)." But I can't even recall having put anything as naughty as a DNS server in my policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;..... Checking myself again ....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Guess what. I actually did enable the DNS server on my Domain Controller. So what is the logic of this failure?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 09:59:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5235#M101154</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-08-14T09:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5236#M101155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this an object setting in SmartConsole?&lt;/P&gt;&lt;P&gt;Because it doesn't sound familiar and I don't see a setting for it offhand.&lt;/P&gt;&lt;P&gt;Can you post a screenshot?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 16:30:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5236#M101155</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-14T16:30:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5237#M101156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG alt="Object for Active Directory" class="image-1 jive-image j-img-original" src="/legacyfs/online/checkpoint/58189_2017-08-15 09_24_10-Host.png" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;It's this simple to break your policy. And the error is not giving any clues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a note in SK110519:&lt;/P&gt;&lt;TABLE border="1" cellpadding="4" cellspacing="2" style="color: #000000; background-color: #ffffff; font-size: 14px;" width="100%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;02496239&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;Policy installation fails with "&lt;EM&gt;Policy installation failed on gateway 0-2000040&lt;/EM&gt;" error and log: "&lt;EM&gt;fw_atomic_add_spii_parameter: Failed to get object named &amp;lt;object_name&amp;gt;&lt;/EM&gt;".&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Workaround: for all hosts with a server configuration, unselect the servers. Publish. Select the servers again, and publish again.&lt;/LI&gt;&lt;/UL&gt;&lt;/TD&gt;&lt;TD&gt;R80.10&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;So there is a workaround and the issue is known. But it seems be part of the list "unresolved bugs".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2017 07:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5237#M101156</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-08-15T07:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5238#M101157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This feature is an artifact that goes back several versions and was necessary for some IPS Protections to be applied to the correct hosts only.&lt;/P&gt;&lt;P&gt;In R80.x, these options are no longer necessary.&lt;/P&gt;&lt;P&gt;That said, policy compilation would ideally handle this situation, or at least print a more clear error message.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Aug 2017 16:45:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5238#M101157</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-15T16:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5239#M101158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is a way you can set it in R80.10 that makes it even more odd.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58838_pastedImage_1.png" style="width: 620px; height: 475px;" /&gt;&lt;/P&gt;&lt;P&gt;Let's face it. This question makes a lot of sense to most people. Doesn't it?&lt;/P&gt;&lt;P&gt;But it will change the host object:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/58839_pastedImage_2.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;And I am back to a time and place where brown stuff collides at high velocity with rotating blades.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think that Check Point could do a lot better. It invites people to make sens of their policy and then you end up with a policy that will not install.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is a lot to fix yet in R80.10!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Sep 2017 12:55:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5239#M101158</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2017-09-22T12:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5240#M101159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've had exactly the same problem with that exact error message, where the policy would verify fine but fail to install. I've logged a TAC case and the engineer fixed it by doing this on the Secure Management server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;[Expert@MGMT:0]# cd $FWDIR/conf&lt;/SPAN&gt;&lt;BR style="color: #000000; font-size: 12px;" /&gt;&lt;SPAN style="color: #000000; background-color: #ffffff; font-size: 12px;"&gt;[Expert@MGMT:0]# grep -e $'^\t\t: (' objects_5_0.C -e "is_mail_server (false)" -e mail_server_prop | grep -v "mail_server_prop ()" | grep mail_server_prop -B 2 | grep ":is_mail_server (false)" -B 1 | grep -e $'^\t\t: ('&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will list objects that are configured as servers. Go through each object and un-tick everything under Servers. Once that is done, publish changes and push policy. The policy should install fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marcel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 May 2018 02:54:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5240#M101159</guid>
      <dc:creator>Marcel_Talos</dc:creator>
      <dc:date>2018-05-03T02:54:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5241#M101160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The error message "Policy installation failed on gateway" and its predecessor "Load on module failed" indicate that the policy passed SMS verification and was compiled &amp;amp; successfully transferred to the gateway, but the atomic load of the policy into the running firewall kernel failed.&amp;nbsp; These are frustratingly generic error messages for the simple reason that the SMS has no idea why the load failed, only the gateway does.&amp;nbsp; Debugging of this problem needs to take place on the gateway.&amp;nbsp; The linked SK below lays out some of the different situations that can cause this, but in my experience it generally boils down to one of the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Memory or other resource shortage on the gateway, in the case of a long-term memory leak a reboot of the gateway may help&lt;/P&gt;&lt;P&gt;2) The compiled policy is "corrupt" and should not have passed verification in the first place on the SMS.&amp;nbsp; This can be caused by damaged files referenced during policy compilation on the SMS, or the user being improperly allowed to enable settings/features that the target gateway software version cannot understand or support&lt;/P&gt;&lt;P&gt;3) Error in policy compilation not caught by the SMS such as the same variable getting included in the compiled policy more than once, or conflicting settings for the same object&lt;/P&gt;&lt;P&gt;4) Possible corruption on the gateway, once again a reboot may help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33893&amp;amp;partition=Advanced&amp;amp;product=Security" style="max-width: 840px;"&gt;sk33893: 'Installation &lt;STRONG&gt;failed&lt;/STRONG&gt;. Reason: &lt;STRONG&gt;Load&lt;/STRONG&gt; on &lt;STRONG&gt;Module&lt;/STRONG&gt; &lt;STRONG&gt;failed&lt;/STRONG&gt; - &lt;STRONG&gt;failed&lt;/STRONG&gt; to &lt;STRONG&gt;load&lt;/STRONG&gt; security policy' error during policy installation&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt; Second Edition of my "Max Power" Firewall Book&lt;BR /&gt; Now Available at &lt;A href="http://www.maxpowerfirewalls.com" target="_blank"&gt;http://www.maxpowerfirewalls.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2018 23:46:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/5241#M101160</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2018-05-10T23:46:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/56729#M101161</link>
      <description>&lt;P&gt;I got the exact same error on R80.20 standalone just now.&lt;/P&gt;&lt;P&gt;It appeared after specifying internal DNS server under Malware DNS Trap on the IPS Profile.&lt;/P&gt;&lt;P&gt;I managed to solve the policy installation error by modifying the DNS server host objects as follows.&lt;/P&gt;&lt;P&gt;On the host object, DNS Server/Configuration/Protection, change Protected by: from All to the gateway object that the host actually resides behind.&lt;/P&gt;&lt;P&gt;Hope this helps for you as well&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/918"&gt;@Hugo_vd_Kooij&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jun 2019 14:39:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/56729#M101161</guid>
      <dc:creator>Johan_Hillstrom</dc:creator>
      <dc:date>2019-06-26T14:39:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to debug Policy Installation Errors</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/60397#M101162</link>
      <description>&lt;P&gt;Thank you for pointing me to SK110519. Turning on DNS server, publish, and turn off DNS server, publish fixed the problem I had pushing policy. Interesting that I could fetch policy from the gateway, just could not push it from the Smartconsole.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 15:03:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-debug-Policy-Installation-Errors/m-p/60397#M101162</guid>
      <dc:creator>John_Tomasetti</dc:creator>
      <dc:date>2019-08-15T15:03:52Z</dc:date>
    </item>
  </channel>
</rss>

