> Source: [sk155253](https://support.checkpoint.com/results/sk/sk155253)

# sk155253 - Policy installation shows a message about expired Time objects and shows "See sk155253 for more details"

| Property | Value |
|----------|-------|
| Solution ID | sk155253 |
| Date Created | 2019-06-05 |
| Last Modified | 2025-09-25 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Policy installation succeeds with a warning message:

  `Some Access rules have time objects that are expired at least 2 days ago and were not loaded to the GW. See sk155253 for more details."`

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk155253/warning1906160657.png)
* Policy installation fails with the error message:

  `All the rules in layer <Name of Layer> contain only expired time objects. See sk155253 for more details.`

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk155253/error1906160657.png)
* Rules with expired Time objects are not installed on the Security Gateway.

  As a result, traffic through the Security Gateway may be interrupted.

## Cause

#### Policy Installation Warning

> If a policy installation shows a warning, it means there are some rules, in which all Time objects expired.
>
> You can view a list of these rules in the `$FWDIR/log/expired_rules_per_layer.txt` file on a Security Gateway (on a VSX Gateway / VSX Cluster Member, go to the context of the involved Virtual System with the "`vsenv <VSID>`" command)

#### Policy Installation Failure

> If a policy installation fails with an error, it means all Time objects have expired at least two days ago in all the rules in this layer.

#### Explanation

> By design, the Management Server does not install expired rules on the managed Security Gateways. As a result, traffic **will never be matched** to these rules.
>
> A rule is expired if all the Time objects in this rule are expired at least two days ago.
>
> Example:
>
> ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk155253/rule1906060646.PNG)
>
> When we open the Time objects in this rule, we see that the "**End** " of the "**Time Period**" has passed at least two days ago:
>
> ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk155253/times1906060647.png)

## Solution

You mustdo one of these and install the Access Control policy:

* Update the end date in the Time objects in these rules
* Remove the expired Time objects from these rules
* Remove the rules with expired Time objects

However, if there are no expired time objects in the relevant policy layer, and the issue also occurs intermittently, please proceed with the steps below.

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/R81.10-List-of-all-Resolved-Issues.htm?tocpath=_____4) - since *Take 177*
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20-List-of-all-Resolved-Issues.htm?tocpath=_____4) - since *Take 101*
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82-List-of-all-Resolved-Issues.htm?tocpath=_____4) - since *Take 25*

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

**In case the Jumbo Hotfix Accumulator does not resolve the issue:**   
[Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) for further investigation

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
