> Source: [sk163455](https://support.checkpoint.com/results/sk/sk163455)

# sk163455 - Threat Prevention topology warning when installing policy on VSX

| Property | Value |
|----------|-------|
| Solution ID | sk163455 |
| Date Created | 2019-12-16 |
| Last Modified | 2020-08-31 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- When installing policy on a VS the following warning message appear in policy installation details:  
`
"At least one internal, one external and no undefined interfaces are required.
Incorrectly defined topology impacts performance and security.
Please install both Access Control and Threat Prevention policies after fixing the topology."`  
Although the topology on the VS is configured with 1 internal 1 external interfaces, and no undefined interfaces.

## Cause

There was a fix that changed the verification of clusters to verify the interfaces of the members as well as the cluster itself, since both must be well defined. However, in VSX cluster, the topology in the fwset of the VSX cluster members is unidentified, but the members get their topology from the cluster itself. Therefore, only the cluster's interfaces has to be verified.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
