<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policy installation failed on gateway. (Error code: 0-1-2000229) in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245741#M47876</link>
    <description>&lt;P&gt;I did a fresh install of R82.&lt;/P&gt;
&lt;P&gt;Configured it as ElasticXL + vsnext machine in FTW.&lt;/P&gt;
&lt;P&gt;eth0 is management, eth1 is sync, eth2 is shared between VS0 and VS2, eth3 is for VS0, eth4 is for VS2.&lt;/P&gt;
&lt;P&gt;Initial setup is 192.168.2.21 for SmartCenter, 192.168.2.211 for VS0 and 192.168.2.212 for VS2.&lt;/P&gt;
&lt;P&gt;The blooper I made was use NONE instead of ANY in the added rule on top to allow net 192.168.2.0/24 acess to all Check Point machines.&lt;/P&gt;
&lt;P&gt;So I shut myself out for anything but the console of the machine. When I noticed the mistake and tried to correct the rule to go from NONE to ANY the installation failed. However it also failed when I switch back to NONE as service.&lt;/P&gt;
&lt;P&gt;It's a lab so if needed I can redo it but this time use the proper rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 05 Apr 2025 10:02:23 GMT</pubDate>
    <dc:creator>Hugo_vd_Kooij</dc:creator>
    <dc:date>2025-04-05T10:02:23Z</dc:date>
    <item>
      <title>Policy installation failed on gateway. (Error code: 0-1-2000229)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245718#M47869</link>
      <description>&lt;P&gt;I was setting up a lab with vsnext/elasticxl with R82 and sort of got things working but I noticed i lost connectivity to GAIA.&lt;/P&gt;
&lt;P&gt;Somehow the policy with explicit access was not matched. So I want to fix that with a more explict rule.&lt;/P&gt;
&lt;P&gt;But on policy install I now hit this dreaded error:&lt;/P&gt;
&lt;P&gt;Gateway: fw01-0&lt;BR /&gt;Policy: Standard&lt;BR /&gt;Status: Failed&lt;BR /&gt;- Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: 0-1-2000229).&lt;BR /&gt;--------------------------------------------------------------------------------&lt;/P&gt;
&lt;DIV id="tinyMceEditorHugo_vd_Kooij_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;Not sur if it is part of a design issue or just me breaking new stuff.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 15:11:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245718#M47869</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2025-04-04T15:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Policy installation failed on gateway. (Error code: 0-1-2000229)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245719#M47870</link>
      <description>&lt;P&gt;Could not find anything on support site about it, but below is what came from AI Copilot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;The error code&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;0-1-2000229&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;during policy installation typically indicates an issue with the policy installation process on the gateway. Here are some steps you can take to troubleshoot and resolve this issue:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Check the Policy Installation Logs:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Connect to the command line on the Security Gateway.&lt;/LI&gt;
&lt;LI&gt;Review the&lt;CODE&gt;$FWDIR/log/install_policy_report.txt&lt;BUTTON&gt;&lt;/BUTTON&gt;&lt;/CODE&gt;file for any specific error messages or indications of what might be causing the failure.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Verify Object Configuration:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Ensure that all objects referenced in the policy are correctly configured and do not contain any invalid or missing information.&lt;/LI&gt;
&lt;LI&gt;Check for any objects with invalid IP addresses or other configuration errors.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Dynamic Objects:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you are using dynamic objects, run the&lt;CODE&gt;dynamic_objects -l&lt;BUTTON&gt;&lt;/BUTTON&gt;&lt;/CODE&gt;command on the Security Gateway to ensure there are no empty or incorrectly configured dynamic objects.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Custom Scripts:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If you are using custom scripts to collect and translate URLs to IP addresses, verify that these scripts are functioning correctly and not introducing any invalid data into the dynamic objects list.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Corrupted Files:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Sometimes, policy installation issues can be caused by corrupted files on the Security Gateway. You can try to fetch the policy again using the command:
&lt;PRE&gt;&lt;CODE class="language-bash"&gt;fw fetch &amp;lt;IP Address of Management Server&amp;gt;
&lt;BUTTON&gt;&lt;/BUTTON&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;/LI&gt;
&lt;LI&gt;If fetching the policy fails, you may need to investigate further for any corrupted files or configurations.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;STRONG&gt;Contact Check Point Support:&lt;/STRONG&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;If the problem persists after performing the above steps, it is recommended to contact Check Point Support for further assistance. Provide them with the error code and any relevant log files to help diagnose the issue.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;For more detailed troubleshooting steps, you can refer to the Check Point Support Knowledge Base or open a support ticket at&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://support.checkpoint.com/" target="_blank"&gt;Check Point Support Center&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 15:43:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245719#M47870</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-04T15:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Policy installation failed on gateway. (Error code: 0-1-2000229)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245740#M47875</link>
      <description>&lt;P&gt;Is it related to a specific rule you created (explicit rule)?&lt;/P&gt;
&lt;P&gt;Can you give additional details so that I can try reproducing it internally?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 09:52:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245740#M47875</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-04-05T09:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Policy installation failed on gateway. (Error code: 0-1-2000229)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245741#M47876</link>
      <description>&lt;P&gt;I did a fresh install of R82.&lt;/P&gt;
&lt;P&gt;Configured it as ElasticXL + vsnext machine in FTW.&lt;/P&gt;
&lt;P&gt;eth0 is management, eth1 is sync, eth2 is shared between VS0 and VS2, eth3 is for VS0, eth4 is for VS2.&lt;/P&gt;
&lt;P&gt;Initial setup is 192.168.2.21 for SmartCenter, 192.168.2.211 for VS0 and 192.168.2.212 for VS2.&lt;/P&gt;
&lt;P&gt;The blooper I made was use NONE instead of ANY in the added rule on top to allow net 192.168.2.0/24 acess to all Check Point machines.&lt;/P&gt;
&lt;P&gt;So I shut myself out for anything but the console of the machine. When I noticed the mistake and tried to correct the rule to go from NONE to ANY the installation failed. However it also failed when I switch back to NONE as service.&lt;/P&gt;
&lt;P&gt;It's a lab so if needed I can redo it but this time use the proper rule.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 10:02:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245741#M47876</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2025-04-05T10:02:23Z</dc:date>
    </item>
    <item>
      <title>Re: Policy installation failed on gateway. (Error code: 0-1-2000229)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245744#M47877</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/918"&gt;@Hugo_vd_Kooij&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to make sure we got this right, are you saying same error happens regardless if NONE or ANY is used?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 11:46:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245744#M47877</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-05T11:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Policy installation failed on gateway. (Error code: 0-1-2000229)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245745#M47878</link>
      <description>&lt;P&gt;So if you unload the policy (from the machine) change the setting to Any (or a Network Object or Services &amp;amp; Applications) and Install Policy again it should work.&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 12:13:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/245745#M47878</guid>
      <dc:creator>Tal_Paz-Fridman</dc:creator>
      <dc:date>2025-04-05T12:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Policy installation failed on gateway. (Error code: 0-1-2000229)</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/247985#M48441</link>
      <description>&lt;P&gt;I am unable to unload the policy. Thanks to VSNEXT being active.&lt;/P&gt;
&lt;P&gt;Need to schedule a lab day to get this tested properly.&lt;/P&gt;</description>
      <pubDate>Fri, 02 May 2025 08:11:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Policy-installation-failed-on-gateway-Error-code-0-1-2000229/m-p/247985#M48441</guid>
      <dc:creator>Hugo_vd_Kooij</dc:creator>
      <dc:date>2025-05-02T08:11:18Z</dc:date>
    </item>
  </channel>
</rss>

