- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
The State of Ransomware Q1 2026
Key Trends and Their Impact
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Determined that Policy installation fails with "Error code 2000025" and for sk177710 this also applies to R81.20.
sk177710 notes applies to versions R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS) and R81.10 but experienced this for R81.20 (see attached).
Mgmt Server R81.20 HF-111
Gateways R81.20 HF-105
ShemHunter
Sorry for now posting the detailed findings and resolution:
Determined the issue was with the "Check Point IPsec VPN services" application category:
Although this object was not being actively used in the policy, in its services was a group of services that an admin created/added to AppC Web Browsing services (in AppC and URLF blade settings).
After removing the group and adding the services individually, the policy is installing correctly.
ShemHunter
We figured this out by reviewing the Audit Logs.
In Smart Console under Applications/Categories for 'Check Point IPsec VPN Services'. The admin edited that category under Match Settings>Customize and if I recall then added add group of services. Which was allowed to save and publish but failed at policy installation time.
Did you forget the attachment?
You can verify further with TAC or submit feedback on the SK if you feel it needs updating.
I just read the sk and you are correct, does not mention R81.20, but what I find really odd is that it mentions the issue can be with the service used. I had never seen that be the case with error like one you got. If I were you, would double check SIC, communication is fine between gw and mgmt, routing, etc.
Andy
Hello!
I'm getting a similar error in the test lab:
Gateway: GW-A
Policy: Standard
Status: Failed
- Policy installation failed on gateway. If the problem persists, contact Check Point support (Error code: 1-2-2000025).
This error occurs when the policy specifies an object in the Services & Applications column + Drop with Blocked Message. This happens in the test lab, so I'm having trouble submitting a ticket to TAC. Currently, version 81.20 takes 120.
ShemHunter
Sorry for now posting the detailed findings and resolution:
Determined the issue was with the "Check Point IPsec VPN services" application category:
Although this object was not being actively used in the policy, in its services was a group of services that an admin created/added to AppC Web Browsing services (in AppC and URLF blade settings).
After removing the group and adding the services individually, the policy is installing correctly.
Thank you!
I'll check this out and report back, but I think it'll definitely help. I've already sent feedback to this sk, and I hope they'll reply soon.
Could you tell me what services are installed by default? I know I can add them in the managenet&services settings.
ShemHunter
We figured this out by reviewing the Audit Logs.
In Smart Console under Applications/Categories for 'Check Point IPsec VPN Services'. The admin edited that category under Match Settings>Customize and if I recall then added add group of services. Which was allowed to save and publish but failed at policy installation time.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 6 | |
| 4 | |
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 2 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeThu 04 Jun 2026 @ 07:00 PM (IDT)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - AmericaFri 12 Jun 2026 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 47: Continuous Threat Exposure ManagementFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY