> Source: [sk114434](https://support.checkpoint.com/results/sk/sk114434)

# sk114434 - "R80 Gateway (or above) may have enforcement conflicts. See sk114434" enforcement conflicts warning during policy installation of R80.x Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk114434 |
| Date Created | 2016-11-08 |
| Last Modified | 2024-11-10 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- `"R80 Gateway (or above) may have enforcement conflicts. See sk114434"` warning appears during Threat Prevention policy installation on R80.x Security Gateway, on multi-layers configuration.

## Cause

Starting in version R80.10, you can define a multi-layer rule base. Each layer contains its own rule base, and you map each rule to a different profile.

**This means that for a connection, multiple rules are matched (one rule in each layer).**

If you have ***N*** layers, you may have up to ***N*** rules matched on a single connection.

Every matched rule holds its own profile configuration. As a result, conflicts between different profile settings might occur.

## Solution

No fix is required; the system is functioning as designed.

The decision as to which one of the matched rules is enforced on the connection is made based on the strictest action. Prevent is the strictest action: **Inactive** \< **Detect** \< **Ask** \< **Prevent**.

When a protection is matched on a connection, the action of the layer is determined according to this order:

1. Exception action (if matched)
2. Protection override
3. Profile settings (according to the confidence level of the protection).

All layers are independent in their enforcement decision.

The strictest policy between all the matched rules enforces the connection, and its mapped profile is used for additional settings on the connection.

Conflicts, however, may occur between layers. They mostly occur because of differences in the "engine settings".

For example, one profile can limit the SMTP nesting level to "5", while a different profile can set the nesting level to "10".

The Security Gateway behavior during such conflicts in the configuration is to use the "most secure" setting.

In the example above, the Security Gateway takes the maximum nesting level as its limit. When the limit is exceeded, the most severe action among all the layers is used, meaning that the Security Gateway sets its maximum nesting level to 10.

If a virus is found somewhere between nesting level 5-10, the most severe action is taken between the two layers, regardless of the nesting level configuration.

Enforcement may be taken from a layer although its nesting level has already been exceeded.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
