> Source: [sk106588](https://support.checkpoint.com/results/sk/sk106588)

# sk106588 - R8x.xx Policy installation errors and warnings

| Property | Value |
|----------|-------|
| Solution ID | sk106588 |
| Date Created | 2017-03-02 |
| Last Modified | 2025-01-16 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

This article lists the error and warning messages that can be generated when policy installation fails on an R8x.xx Security Gateway.

If the policy installation fails with one of the errors below, follow the instruction in the message and see the additional information in the "Comments" column.

For pre-R80.x issues, refer to [sk33893 - 'Installation failed. Reason: Load on Module failed - failed to load security policy' error during policy installation](https://support.checkpoint.com/results/sk/sk33893)

### Table of Contents

* Errors
* Warnings

Errors {#Errors}
----------------

|----|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| #  | **Error message**                                                                                                                                                                                                                               | **Comments**                                                                                                                                                                                                                                               |
| 1  | Policy installation failed on gateway. No memory.                                                                                                                                                                                               | Not enough memory on the Security Gateway. Refer to [sk84700](https://support.checkpoint.com/results/sk/sk84700).                                                                                                                                          |
| 2  | Policy installation failed. Security Gateway not installed.                                                                                                                                                                                     | The policy is not installed on the Security Gateway. Run "`fw ctl install`" on the Security Gateway.                                                                                                                                                       |
| 3  | Policy installation failed on gateway. A policy must be installed on the VSX gateway prior to installing a policy on a Virtual Device.                                                                                                          | -                                                                                                                                                                                                                                                          |
| 4  | Policy installation failed on gateway. There is no valid license for the security gateway. To view existing licenses and add new licenses, use SmartUpdate (see sk11054).                                                                       | No valid license for the Security Gateway. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                                                                          |
| 5  | Policy installation failed on gateway. VE license can be used only on gateways running on VMware. To view existing licenses and add new licenses, use SmartUpdate (see sk11054).                                                                | No suitable license for the Security Gateway. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                                                                       |
| 6  | Policy installation failed on gateway. Insufficient licenses installed for ClusterXL load sharing cluster. Please install suitable licenses on Security Gateways (see sk11054).                                                                 | No suitable license is installed on the Security Gateway. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                                                           |
| 7  | Policy installation failed on gateway. The gateway has a Cluster member license but is not defined as a Cluster member in SmartConsole. To view existing licenses and add new licenses, use SmartUpdate (see sk11054).                          | No suitable license is installed on the Security Gateway. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                                                           |
| 8  | Policy installation failed on gateway. The gateway has a Dedicated VPN license but is not defined as a Dedicated VPN in SmartConsole. To view existing licenses and add new licenses, use SmartUpdate (see sk11054).                            | No suitable license is installed on the Security Gateway. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                                                           |
| 9  | Policy installation failed on gateway because the gateway version, as defined in SmartConsole, does not match the version installed on the gateway. To resolve this issue, correct the version property in SmartConsole or upgrade the gateway. | The version of the Security Gateway that is defined in SmartConsole is different than the version installed on the Security Gateway. Correct the version in SmartConsole \> Security Gateway object properties, or upgrade the Security Gateway.           |
| 10 | Policy installation failed on gateway. No Authentication installed.                                                                                                                                                                             | -                                                                                                                                                                                                                                                          |
| 11 | Install Policy/Update process is already running. Try again in several minutes. If the problem persists contact Check Point support.                                                                                                            | -                                                                                                                                                                                                                                                          |
| 12 | Policy installation failed on gateway. IPV6 was enabled on the Security Gateway without rebooting the Gateway. Please reboot the Security Gateway.                                                                                              | -                                                                                                                                                                                                                                                          |
| 13 | Policy installation failed on DAIP gateway. Failed to find a dynamic interface on DAIP module (see sk33893).                                                                                                                                    | The DAIP Gateway is misconfigured. Refer to [sk33893](https://support.checkpoint.com/results/sk/sk33893).                                                                                                                                                  |
| 14 | Policy installation failed on DAIP gateway. External interface is not defined. Please run cpconfig to define it (see sk103819).                                                                                                                 | DAIP Gateway is misconfigured. Refer to [sk103819](https://support.checkpoint.com/results/sk/sk103819).                                                                                                                                                    |
| 15 | Policy installation failed on gateway. DLP blade failed with the following message: Mail relay and Portal must be configured.                                                                                                                   | Refer to the [Data Loss Prevention Administration Guide](https://support.checkpoint.com/product/433#f-commonsource=C.%20Documentation) for your version \> Section "Configuring the Mail Relay".                                                           |
| 16 | Policy installation failed on gateway. DLP blade failed with the following message: Watermark feature requires that mail relay will be configured                                                                                               | Refer to the [Data Loss Prevention Administration Guide](https://support.checkpoint.com/product/433#f-commonsource=C.%20Documentation) for your version \> Section "Configuring the Mail Relay".                                                           |
| 17 | Policy installation failed on gateway. DLP blade failed with the following message: Mail relay or Portal were not configured.                                                                                                                   | Refer to the [Data Loss Prevention Administration Guide](https://support.checkpoint.com/product/433#f-commonsource=C.%20Documentation) for your version \> Section "Configuring the Mail Relay".                                                           |
| 18 | Policy installation failed on gateway. DLP blade failed with the following message: Data Loss Prevention Portal is not enabled.                                                                                                                 | Refer to the [Data Loss Prevention Administration Guide](https://support.checkpoint.com/product/433#f-commonsource=C.%20Documentation) for your version \> Section "DLP Portal".                                                                           |
| 19 | Policy installation failed on gateway. DLP blade failed with the following message: ClusterXL in VRRP mode can't be used with Ask User action.                                                                                                  | -                                                                                                                                                                                                                                                          |
| 20 | Policy installation failed on gateway. DLP blade failed with the following message: ClusterXL LS can't be used with Ask User action.                                                                                                            | -                                                                                                                                                                                                                                                          |
| 21 | Policy installation failed on gateway. DLP blade failed with the following message: Cyclic data types                                                                                                                                           | Cyclic data type is a compound data type which points to itself.                                                                                                                                                                                           |
| 22 | Policy installation failed on gateway. DLP blade failed with the following message: Gateway's hostname must contain at least one alphabetic character                                                                                           | -                                                                                                                                                                                                                                                          |
| 23 | Policy installation failed on gateway. DLP blade failed with the following message: Mail Relay configuration failed: domain name might be misconfigured                                                                                         | -                                                                                                                                                                                                                                                          |
| 24 | Policy installation failed on gateway. DLP blade failed with the following message: Credentials are missing in mail server object.                                                                                                              | Refer to the [Data Loss Prevention Administration Guide](https://support.checkpoint.com/product/433#f-commonsource=C.%20Documentation) for your version \> Section "Configuring the Mail Relay".                                                           |
| 25 | Policy installation failed on gateway. DLP blade failed with the following message: CPcode failed to compile.                                                                                                                                   | Failed to read the dictionary file.                                                                                                                                                                                                                        |
| 26 | Policy installation failed on gateway. DLP blade failed with the following message: Data type 'X' requires at least one CPcode file.                                                                                                            | Failed to read the dictionary file.                                                                                                                                                                                                                        |
| 27 | Policy installation failed on gateway. DLP blade failed with the following message: X - Error in file uploaded.                                                                                                                                 | Failed to read the dictionary file.                                                                                                                                                                                                                        |
| 28 | Policy installation failed on gateway. DLP blade failed with the following message: Error in pattern 'X'                                                                                                                                        | Failed to read the dictionary file.                                                                                                                                                                                                                        |
| 29 | Policy installation failed on gateway. DLP blade failed with the following message: CPcode failed to compile - X, line: Y                                                                                                                       | Failed to read the dictionary file.                                                                                                                                                                                                                        |
| 30 | Policy installation failed on gateway. Data Type should not reuse Data Types in a cyclic matter.                                                                                                                                                |                                                                                                                                                                                                                                                            |
| 31 | Content Awareness override mapping file \<file name\> contains mapping without extension, id or content-type.                                                                                                                                   | The Content Awareness Software Blade's override mapping file is not properly defined. Refer to [sk114954](https://support.checkpoint.com/results/sk/sk114954).                                                                                             |
| 32 | Content Awareness override mapping file \<file name\> contains mapping with more than 1 key. There should be only one type of key per mapping: file_id or extension or content-type.                                                            | The Content Awareness Software Blade's override mapping file is not properly defined. Refer to [sk114954](https://support.checkpoint.com/results/sk/sk114954).                                                                                             |
| 33 | Content Awareness override mapping file \<file name\> content-type: \<content-type name\> too long. Max length is X.                                                                                                                            | The Content Awareness Software Blade's override mapping file is not properly defined. Refer to [sk114954](https://support.checkpoint.com/results/sk/sk114954).                                                                                             |
| 34 | Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: \<number\>).                                                                                                                            | An internal error has occurred. [Contact Check Point support](https://www.checkpoint.com/support-services/contact-support/) with the exact error message and attach the *$FWDIR/state/__tmp/FW1/install_policy_report.txt* file from the Security Gateway. |
| 35 | Policy installation failed on gateway.                                                                                                                                                                                                          | An internal error has occurred. [Contact Check Point support](https://www.checkpoint.com/support-services/contact-support/) with the exact error message and attach *$FWDIR/state/__tmp/FW1/install_policy_report.txt* file from the Security gateway.     |

Warnings {#Warnings}
--------------------

|----|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| #  | Warning message                                                                                                                                                                                                                                                   | Comments                                                                                                                                                                              |
| 1  | IP Reputation is disabled due to insufficient licensing.                                                                                                                                                                                                          | Check the licenses.                                                                                                                                                                   |
| 2  | New DHCP relay services were found, please disable legacy configuration according to sk104114.                                                                                                                                                                    | Refer to [sk104114](https://support.checkpoint.com/results/sk/sk104114).                                                                                                              |
| 3  | No services are defined in Content Awareness blade settings - blade is disabled. Go to blades -\> data awareness -\> advanced settings -\> add services to supported services container.                                                                          | Misconfiguration of Content Awareness Software Blade.                                                                                                                                 |
| 4  | Data Loss Prevention blade contract is about to expire.                                                                                                                                                                                                           | -                                                                                                                                                                                     |
| 5  | Data Loss Prevention blade contract has expired. Data Loss Prevention blade will soon be disabled. If you have a valid contract, go to "Update Contracts" tab on SmartUpdate in order to update the machine's contracts.                                          | -                                                                                                                                                                                     |
| 6  | Data Loss Prevention blade contract has expired. Data Loss Prevention blade has been disabled. If you have a valid contract, go to "Update Contracts" tab on SmartUpdate in order to update the machine's contracts.                                              | -                                                                                                                                                                                     |
| 7  | No valid Data Loss Prevention contract found. Data Loss Prevention blade has been disabled. If you have a valid contract, go to "Update Contracts" tab on SmartUpdate in order to update the machine's contracts.                                                 | -                                                                                                                                                                                     |
| 8  | Application Control blade Trial license has expired - there is no APCL license installed.                                                                                                                                                                         | No license. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                                    |
| 9  | Application Control blade Trial license will expire today.                                                                                                                                                                                                        | License is going to expire. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                    |
| 10 | Application Control blade Trial license will expire in X days.                                                                                                                                                                                                    | License is going to expire. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                    |
| 11 | URL Filtering blade Trial license has expired - there is no URLF license installed.                                                                                                                                                                               | No license. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                                    |
| 12 | URL Filtering blade Trial license will expire today.                                                                                                                                                                                                              | License is going to expire. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                    |
| 13 | URL Filtering blade Trial license will expire in X days.                                                                                                                                                                                                          | License is going to expire. Refer to [sk11054](https://support.checkpoint.com/results/sk/sk11054).                                                                                    |
| 14 | This gateway supports SecureXL traffic acceleration. TCP Sequence Verifier (SmartDefense) will not be enforced on accelerated connections. To allow Sequence Verification, turn off acceleration on the gateway by running cpconfig \[ SecureXL warning no. X \]. | **Applies only Security Gateways R77.30 and lower:** To allow Sequence Verification, disable acceleration on the Security Gateway by running *cpconfig*.                              |
| 15 | This gateway supports flows traffic acceleration. TCP Sequence Verifier (SmartDefense) will not be enforced on accelerated connections \[ Flows warning no. X \].                                                                                                 | -                                                                                                                                                                                     |
| 16 | Since acceleration is not supported for Load Sharing Unicast Mode, acceleration will be disabled. To enable acceleration, please select Load Sharing Multicast Mode from Gateway Cluster Properties -\> ClusterXL \[SecureXL warning no. X\].                     | In SmartConsole, open the Cluster object \> ClusterXL page \> select Load Sharing Multicast Mode \> click OK \> install policy.                                                       |
| 17 | Since the acceleration device on this gateway does not support Cluster configuration, acceleration will be disabled. Please refer to the acceleration device documentation for more details \[ SecureXL warning no. X \].                                         | Refer to [sk32578](https://support.checkpoint.com/results/sk/sk32578)                                                                                                                 |
| 18 | Connection templates will not be offloaded to the SecureXL accelerator due to restrictions defined in the rulebase \[ SecureXL warning no. X \].                                                                                                                  | -                                                                                                                                                                                     |
| 19 | Since acceleration is not supported with Sticky Decision Function, acceleration will be disabled. To enable acceleration, please uncheck sticky decision function from Gateway Cluster Properties -\> ClusterXL -\> Advanced \[ SecureXL warning no. X \].        | In SmartConsole, open the Cluster object \> ClusterXL \> Advanced page \> clear "Sticky Decision Function" \> click OK \> install policy.                                             |
| 20 | Dynamic object 'X' is used in the policy but not defined on the Security Gateway.                                                                                                                                                                                 | Define the Dynamic Object X using the *dynamic_objects* command on the Security Gateway. For more information, refer to [sk45086](https://support.checkpoint.com/results/sk/sk45086). |

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
