> Source: [sk122575](https://support.checkpoint.com/results/sk/sk122575)

# sk122575 - Policy installation in SmartConsole fails with "Error code: 0-2000111"

| Property | Value |
|----------|-------|
| Solution ID | sk122575 |
| Date Created | 2018-01-25 |
| Last Modified | 2021-08-26 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Solution

### Introduction

This article describes different scenarios when policy installation in SmartConsole fails with the "**Policy installation failed on gateway. If the problem persists contact Check Point support (Error code: 0-2000111)**" message.

Each Scenario has additional details, cause, and solution.

### Scenario 1

Additional Symptoms:
The issue occurs for a Security Gateway after it was upgraded to the R80.10 version.  
Show / Hide this section  
**Cause:**
> There are duplicate objects in the *$FWDIR/conf/asm.C* file on the R80.10 Security Management Server.

**Solution:**
> The issue is fixed in [Check Point Management Server R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122485).
>
> If you do not wish to upgrade, [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue. A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix. For faster resolution and verification, please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

### Scenario 2

Additional Symptoms:
> The */var/log/messages* file on the Security Gateway shows:  
> `kernel: [fw<X>_0];[ERROR]: rad_kernel_dns_cache_sgen_validator: db cache_max_hash_size is 250000, max is 100000`  
> `kernel: [fw<X>_0];[ERROR]: rad_kernel_dns_cache_init: rad_kernel_dns_cache_sgen_validator failed`  
> `[fw<X>_0];[ERROR]: rad_kernel_dns_service_init: rad_kernel_dns_cache_ctor failed`  
> `[fw<X>_0];[ERROR]: rad_kernel_dns_service_ctor: rad_kernel_dns_service_init failed`  
> `[fw<X>_0];[ERROR]: rad_kernel_dns_cache_dtor: Invalid parameter`  
> `[fw<X>_0];[ERROR]: rad_kernel_api_create_service: ctor of service <N> failed`  
> `[fw<X>_0];[ERROR]: fwk_install_policy_app_load_prepare: fwk_atomic_load_prepare() failed, error: (14)`  
`[fw<X>_0];[ERROR]: install_policy_mgr_k_load_prepare: load_prepare failed for app: (FW), app_id: (0), app_position: (0)`  
Show / Hide this section  
**Solution:**
> 1. Take a backup of the Security Management Server.  
>
> 2. Close all SmartConsole windows.  
>
> 3. Connect with [GuiDBedit Tool](http://supportcontent.checkpoint.com/solutions?id=sk13009) to the Security Management Server / Domain Management Server.  
>
> 4. In the upper left pane, go to ***Table \> Other \> rad_services*** .  
>
> 5. In the upper right pane, select***dns_rad_service_0*** .  
>
> 6. In the lower pane:  
>
>    1. Right-click ***cache_max_hash_size*** \> select ***Edit*** ... - set the desired limit (no more than 100000) - click **OK** :  
>
>       ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk167394/1202006281738381.png)
>    2. Right-click ***policy_install_cache_override*** \> select ***Edit*** ... \> select "***true*** " \> click ***OK*** :   
>
>       ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk167394/Window2202006281739222.png)
> 7. Save the changes: go to the ***File*** menu \> click ***Save All*** .  
>
> 8. Close the GuiDBedit Tool.  
>
> 9. Connect with SmartConsole to the Security Management Server / Domain Management Server.  
>
> 10. Install the policy only on the involved Security Gateway / Cluster object.  
>
> 11. **CRUCIAL STEP** : Restore the default value for ***policy_install_cache_override*** ("***false*** "):  
>
>     Note: If the default value ("***false*** ") is not restored, the dns kernel cache will be cleared on each policy installation.  
>
>     1. Close all SmartConsole windows (SmartDashboard, SmartView Tracker, SmartView Monitor, etc.).  
>
>     2. Connect with the GuiDBedit Tool to the Security Management Server / Domain Management Server.  
>
>     3. In the upper left pane, go to ***T** **able \> Other \> rad_services*** .  
>
>     4. In the upper right pane, select ***dns_rad_service_0*** .  
>
>     5. In the lower pane, right-click ***policy_install_cache_override*** \> select ***Edit*** ... \> select "***false*** " - click ***OK*** .  
>
>     6. Save the changes: go to the ***File*** menu \> click ***Save All*** .  
>
>     7. Close the GuiDBedit Tool.  
>
> 12. Connect with SmartConsole to the Security Management Server / Domain Management Server.  
>
> 13. Install the policy on the relevant Security Gateway / Cluster object.

### Scenario 3

Additional Symptoms:
> Kernel debug on the Security Gateway during policy installation shows:
>
`"fw_stack_size(1) param is smaller then the default(1024) policy will fail;"`  
Show / Hide this section  
**Cause:**
> The value of the "stack_size" parameter is between 1 and 1023.

**Solution:**
> Configure the value of the "stack_size" parameter to 0 (zero):
>
> 1. In SmartConsole, click **Menu** \> **Global properties**.
>
> 2. From the left tree, click **Advanced**.
>
> 3. Click the **Configure...** button.
>
> 4. Click**FireWall-1** \> **System**.
>
> 5. Change the value the "**stack_size**" parameter to 0:
>
>    ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1622461621053/image-2021-05-02-15-13-19-700202105311452051.png)
> 6. Click **OK**.
>
> 7. Install policy on each managed Security Gateway / Cluster.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
