> Source: [sk159732](https://support.checkpoint.com/results/sk/sk159732)

# sk159732 - Connectivity issues when multiple service objects with identical match criteria are defined in same cell

| Property | Value |
|----------|-------|
| Solution ID | sk159732 |
| Date Created | 2019-08-05 |
| Last Modified | 2020-02-03 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server, SmartConsole |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.10, R82.20, R82.20, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Traffic might be dropped when multiple service objects with identical match criteria are defined in the same cell
* Connectivity issues after upgrade when traffic match a rule with multiple service objects with identical match criteria.

## Cause

The rule base is not designed to work with multiple services with identical match criteria. This configuration in not supported and the service enforcement might be changed under rule modification or version upgrade (only one service's object will be selected randomly, and only this service will take place in rulebase enforcement).

Example - FTP, FTP-passive, FTP-active (match criteria is TCP port 21)

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1564903747156/ftp_service1908040635.png)

The enforcement will be carried out by the serivce's object that chosed in the rule creation, therefore there is no meaning for the other services with the same criteria.

Note: the service's object that was chosen might be changed in upgrade.

Example:

Let's assumed that the service's opject that was chosen is ftp-passive (as mention above the other services has no meaning ftp and ftp-active) in that case the Gateway enforce the rulebase with service ftp-passive, in that case ftp-active will break and drop.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
