> Source: [sk117414](https://support.checkpoint.com/results/sk/sk117414)

# sk117414 - "Internal problem in policy installation process on gateway side" error when installing Threat Prevention policy

| Property | Value |
|----------|-------|
| Solution ID | sk117414 |
| Date Created | 2017-05-17 |
| Last Modified | 2024-02-12 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * "`Internal problem in policy installation process on gateway side`" error when installing Threat prevention policy:

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk117414/sk117414error1705180713.png)
* Output of `fw amw fetchlocal -d /opt/CPsuite-R77/fw1/state/__tmp/AMW/` debug shows:  

  ```
  
  [DATE TIME] malware_policy_ioc_fill_obsrv_overrides: No overrides for indicator ioc_AF461936-A11C-4F89-8E6B-AED90E170166
  [DATE TIME] malware_policy_ioc_generate_ldb: indicator 0: filename {818147E0-0D43-48FE-902A-E898C8759078}(UID for example)
  [DATE TIME] malware_policy_ioc_generate_ldb: new indicator
  Installing Threat Prevention policy from local
   malware_policy_ioc_get_new_ldb: Indicator_Parser() failed
  ```

* `[ ...]@Host[DATE TIME] Indicator_Parser_Wrapper: messages_vector.size() 2`  
  `[ ...]@Host[DATE TIME]] Indicator_Parser_Wrapper:sending warning to CPTA: Indicator DNS-CERT-IL-W-826A.csv - the records have more than the expected number of fields, ignoring the last fields for the indicator, in row:1`  
  `[ ...]@Host[DATE TIME] addCommitMsg: Adding warning message: 'Indicator DNS-CERT-IL-W-826A.csv - the records have more than the expected number of fields, ignoring the last fields for the indicator, in row:1'`  
  `[ ...]@Host[DATE TIME] Indicator_Parser_Wrapper:sending warning to CPTA: One or more observable name are empty`  
  `[ ...]@Host[DATE TIME] addCommitMsg: Adding warning message: 'One or more observable name are empty'`  
  `Installing Threat Prevention policy from local `  
  `malware_policy_ioc_get_new_ldb: Indicator_Parser() failed`  

* `[Expert@localhost:0]# fw amw fetch localhost $FWDIR/state/local/AMW/`  
  `Installing Threat Prevention policy from localhost malware_policy_ioc_package_extract_cur_dir_num: amw_ioc_cp_readlink() failed to access link /opt/CPsuite-R80/fw1/amw/ioc/cur `*cpfile_unlink: failed to unlink /opt/CPsuite-R80/fw1/amw/ioc/cur: Is a directory malware_policy_prepare_ioc_package_forward_sym_links: failed to unlink /opt/CPsuite-R80/fw1/amw/ioc/cur malware_policy_prepare_ioc_package_forward_sym_links:
  amw_ioc_cp_symlink() failed to create link /opt/CPsuite-R80/fw1/amw/ioc/cur->/opt/CPsuite-R80/fw1/amw/ioc/1* ` malware_policy_prepare_ioc_package:`  
  ` malware_policy_prepare_ioc_package_forward_sym_links() failed prepare_ioc:`  
  ` malware_policy_prepare_ioc_package() failed configload_download:`  
  ` configload_gw_vtable_extra_data() failed Internal problem in policy installation process on gateway side cpfile_unlink: failed to unlink /opt/CPsuite-R80/fw1/amw/ioc/cur: Is a directory Fetching Threat Prevention policy failed`

## Cause

The imported Indicator file is corrupted.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
