> Source: [sk120072](https://support.checkpoint.com/results/sk/sk120072)

# sk120072 - Policy installation fails with "Unexpected Termination" errors if there are more than 16384 NAT rules

| Property | Value |
|----------|-------|
| Solution ID | sk120072 |
| Date Created | 2017-08-17 |
| Last Modified | 2025-07-04 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82.20, R81.20, R82, R82.20 |

## Symptoms

- * Policy installation fails with "Unexpected Termination" errors.

* After enabling generation of core dump files per [sk92764](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92764) / [sk53363](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk53363), core dump files for '*fw_loader* ' process were generated in the */var/log/dump/usermode/* directory.

## Cause

Policy contains more than 16384 NAT rules (which is the allowed maximum - refer to [sk178325](https://support.checkpoint.com/results/sk/sk178325)).

Note: If a Network or Host object is configured to use Static NAT, then two Automatic NAT rules are added to the policy.

*Example scenario*: Management Database contains more than 8000 Network / Host objects with configured Static NAT.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R80.20](https://support.checkpoint.com/results/sk/sk141173)

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ([Security Gateway](https://support.checkpoint.com/product/73) / [VSX](https://support.checkpoint.com/product/359) / [Security Management Server](https://support.checkpoint.com/product/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [SmartConsole](https://support.checkpoint.com/product/191)).

**Code was improved:**

* Verification was added to block the policy load if it contains more than 16384 NAT rules.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
