> Source: [sk179700](https://support.checkpoint.com/results/sk/sk179700)

# sk179700 - Policy installation fails with "Segmentation fault" or with "INTERNAL ERROR in PutBlock: dangling block at PutBlock"

| Property | Value |
|----------|-------|
| Solution ID | sk179700 |
| Date Created | 2022-07-20 |
| Last Modified | 2026-08-10 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server, Multi-Domain Security Management Server |
| Versions | R82, R81.20, R81.10 (EOS), R82, R81.20, R81 (EOS), R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |
| OS | Gaia |

## Symptoms

- * Policy installation fails with "*Segmentation fault* " or with "*INTERNAL ERROR in PutBlock: dangling block at PutBlock*".

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk179700/PI1202207191710001.png)

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk179700/PI2202207191711082.jpg)
* Debug of fw_loader per sk103918 shows:   
  \[FW_LOADER 243898 4108367744\]HOSTNAME\[24 Jul 17:02:23\] nat_nrb_gen_default_columns_tables: creating tables for target (null) Operation failed, install/uninstall has been improperly terminated.
* Policy Installation Failes with error:   
  Operation failed, install/uninstall has been improperly terminated.\&CURRENTVERCMP   
  Error: Gateway: Failed - Operation failed, install/uninstall has been improperly terminated

## Cause

Starting in R81, NAT rule-base uses a new infrastructure to support non-IP objects, such as Updateable Object, Domain Objects, Security Zones, etc.  

A customer who upgrades from R80.x to R81 and above and has a policy with more than 2000 rules can experience a policy installation failure.   

The cause of the policy installation failure is high use of memory in the compilation step when IP ranges in NAT rules are greater than the NAT table limit.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/R82.00/R82-List-of-all-Resolved-Issues.htm?tocpath=_____4) starting from Take 14
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 99
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 82
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 79

If you choose not to upgrade,

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Management Server and Security Gateways / Cluster Members involved in the case.

**Note:** In case you run with version lower than R81, have policy with more than 2000 NAT rules, and plan to upgrade, you can ask for this hotfix in advance .**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).  

The hotfix must be installed on versions R81 and higher, Security Gateway and Security Management, and all Security Gateways/Clusters members that are managed by the relevant CMA / Management (with more than 2000 rules).  
The hotfix is OFF by default and you can enable it per CMA.  

\*\*All gateways in the domain must have the hotfix installed, there can be adverse effects to the NAT policy if a cluster does not have the fix installed and the registry modification on the management is made   

**Order of activation:**   
After upgrade, verify that hotfix is installed on all relevant CMA / Security Management and their Security Gateways/Clusters members.  
Enable the hotfix on CMA / Security Management and install the policy.

* For Management with MDS :

  `mdsenv <relevant CMA ip>`   
  `ckp_regedit -a SOFTWARE\\CheckPoint\\MGMT\\6.0 NAT_RULEBASE_USE_ANY_LISTS 1`
* For regular Security Management :

  `ckp_regedit -a SOFTWARE\\CheckPoint\\MGMT\\6.0 NAT_RULEBASE_USE_ANY_LISTS 1`

<br />

**To disable this hotfix:**

* For Management with MDS :

  `mdsenv <relevant CMA ip>`

  `ckp_regedit -a SOFTWARE\\CheckPoint\\MGMT\\6.0 NAT_RULEBASE_USE_ANY_LISTS 0`
* For regular Security Management :

  `ckp_regedit -a SOFTWARE\\CheckPoint\\MGMT\\6.0 NAT_RULEBASE_USE_ANY_LISTS 0`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
