> Source: [sk115871](https://support.checkpoint.com/results/sk/sk115871)

# sk115871 - Alert log with "Rematch Info" field set to "Additional engines are required for new policy enforcement and cannot be activated on established old connection"

| Property | Value |
|----------|-------|
| Solution ID | sk115871 |
| Date Created | 2017-02-27 |
| Last Modified | 2025-02-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Alert log with "Rematch Info" field set to "Additional engines are required for new policy enforcement and cannot be activated on established old connection"
* Log with "Reason" field set to "Additional engines are required for new policy enforcement and cannot be activated on established old connection"

## Cause

Connections that have been put into the Connections Table are examined against the newly installed policy according to 'Connection Persistence' configuration.

In Unified Policy the terminology of 'Connection Persistence' configuration has slightly changed, due to the fact that connections can reach final match decision not only on first packet but also on following data packets, when content inspection is involved.

As a result keeping existing connections open and enforcing newly installed policy only for new connection cannot be guaranteed, because old connections continue to pass rule base examination depending on their connection state.

Moreover Unified Policy has extended the variety of filter criteria, allowing new types of objects in the policy (e.g. URL Category or File Type),which require the activation of dedicated inspection engine (blade) on the connection (such as URLF, Content Awareness).

Thus the rematch, or the enforcement of the new policy can lead to a permanent no final match, as the activation of necessary engines for new policy is impossible on existing connections.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
