> Source: [sk171551](https://support.checkpoint.com/results/sk/sk171551)

# sk171551 - Policy installation fails with "Error code: 1-2000008"

| Property | Value |
|----------|-------|
| Solution ID | sk171551 |
| Date Created | 2021-02-08 |
| Last Modified | 2024-10-27 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS) |

## Symptoms

- Policy installation fails with "Error code: 1-2000008"

## Cause

The Access Control Policy contains more than 231 layers (both inline and ordered).

The maximum number of Policy Layers in an Access Control Policy is 251.

A Security Gateway that runs versions from R80.10 to R81.10 has a limit of 4900 kernel tables.

Each Access Control Policy Layer creates 21 kernel tables on the Security Gateway.

Each Access Control Policy creates 40 global kernel tables on the Security Gateway (that apply to all Policy Layers).

Therefore, the additional calculation is:

(4900 tables - 40 tables) / 21 tables per Policy Layer = 231 Policy Layers.

## Solution

1. Change the Access Control Policy to contain fewer than 231 Policy Layers.

   You can move rules between layers, or disable layers.
2. Install the Access Control Policy.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
