> Source: [sk129232](https://support.checkpoint.com/results/sk/sk129232)

# sk129232 - IPS shared Layer cannot be removed from Threat Prevention Policy

| Property | Value |
|----------|-------|
| Solution ID | sk129232 |
| Date Created | 2018-06-12 |
| Last Modified | 2025-10-30 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- IPS shared layer is added to the Threat Prevention policies automatically when it is created. This IPS shared layer cannot be deleted or removed.

## Cause

**Environment:**An R77.30 and below Gateway exists or previously existed in the Database.

A pre-R80 Gateway is using the IPS blade or was using the IPS while the Threat Prevention policy still existed. This is done so policies that have been upgraded from previous versions will not be modified automatically.

## Solution

**No fix is required, the inability to remove the IPS layer is an expected behavior.**

If a pre-R80 Gateway exists in the Environment and is using IPS, it **will not** be possible to remove the IPS layer. However, the default rules on the Layer will only apply to the relevant Gateway (Can be seen through the "Install On" Column).

This is because installing the IPS rules on pre-R80 gateways still happens through installing Access Control Policies.

**If all gateways are R80.10 or above**, then installing IPS rules is through installing Threat Prevention Policies. As a result, you can modify your threat prevention policy to include IPS rules. Check Point does not modify policies on behalf of its users. We leave that to the user to decide on his policies' architecture. See how you can remove IPS Layers in case your gateways are R80.10 or above:

1. In the Threat Prevention layer, make sure that your gateway will be matched to the appropriate profile.
2. In the IPS layer, delete the gateway rule.
3. Once all the rules on the IPS layer have been removed, the layer should disappear.

For more, see <https://community.checkpoint.com/thread/5701-threat-prevention-policies-after-r7730-to-r8010-migration-is-it-correct>

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
