> Source: [sk167352](https://support.checkpoint.com/results/sk/sk167352)

# sk167352 - Policy Installation fails with error message: "Policy installation is blocked. VPN tunnels encryption key was initialized"

| Property | Value |
|----------|-------|
| Solution ID | sk167352 |
| Date Created | 2020-10-19 |
| Last Modified | 2020-12-03 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R81 (EOS), R81 (EOS) |

## Symptoms

- Policy Installation fails with one of the following error messages:  

* "Policy installation is blocked. VPN tunnels encryption key was initialized"
* "Policy installation failed. VPN tunnels encryption and decryption keys no longer match"
* "Policy installation failed. 'fwauth.NDB' file is missing"

## Cause

In every Security Management there is a file named `fwauth.NDB` that contains encryption values and user information. One of the encryption values in this file is the Patch-ID - a key used to encrypt all VPN Communities' private shared keys (PSKs).  

If the user sees one of the above messages during policy installation it means that the Patch-ID key is corrupted, or that `fwauth.NDB` was somehow deleted, and the key must be re-generated.  

As the Patch-ID is used to encrypt all VPN Communities PSKs, re-generation of its value will result in a VPN tunnels drop. This is because the decryption of the PSKs will now be done with the new generated value that is different than the one used for their encryption.  
**In order to avoid such drops, policy installation is blocked until specific action items are performed.**

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
