> Source: [sk180980](https://support.checkpoint.com/results/sk/sk180980)

# sk180980 - Policy installation failure with error message "Policy installation failed on gateway. Cluster policy installation failed (see sk125152)"

| Property | Value |
|----------|-------|
| Solution ID | sk180980 |
| Date Created | 2023-05-17 |
| Last Modified | 2023-10-19 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * When installing policy on a gateway that is not part of any cluster, this error message appears in SmartConsole: "*Policy installation failed on gateway. Cluster policy installation failed (see sk125152)*".

* Running `$MDS_FWDIR/scripts/policy_debug.sh` as per [sk159452](https://support.checkpoint.com/results/sk/sk159452) shows "*Detected the policy install flow moved to 'fwm load'*"

* On the Security Gateway, *$FWDIR/state/__tmp* is updated, but *$FWDIR/state/local* is not.

* "*tail $FWDIR/state/__tmp/FW1/install_policy_report.txt*" shows:

  ```
  
  13:00:25        87              GuiMsg                  FW1                             ERROR           install_policy_mgr.cpp          2293            postLoadPrepare                                     Policy installation failed on gateway.
  Cluster policy installation failed (see sk125152).
  13:00:25        2000244         InternalMsg             InstallPolicyMgr                ERROR           install_policy_mgr.cpp          316             runInstallPolicy                                    Post load prepare failed
  Messages End
  ```

* "`cpconfig`" on the Security Gateway contains an option to disable cluster membership: "Disable cluster membership for this gateway"

## Cause

Starting in R81, additional measures were put in place to check the cluster membership and state of the Security Gateway during policy installation. If a gateway cluster membership is enabled but not configured as part of a cluster in the management server, the policy installation fails with the error message mentioned in the Symptoms section.

The `cpconfig` output shows that the gateway cluster membership is enabled, even though it is not configured as part of a cluster in the Management Server.

This failure does not change whether Installation Mode checkbox "For gateway clusters, if installation on a cluster member fails, do not install on that cluster" is checked or not.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
