> Source: [sk181384](https://support.checkpoint.com/results/sk/sk181384)

# sk181384 - Installing Security policy to LSM profile fails with "Unable to start policy installation"

| Property | Value |
|----------|-------|
| Solution ID | sk181384 |
| Date Created | 2023-08-28 |
| Last Modified | 2023-09-04 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R81.10 (EOS), R81.10 (EOS) |
| OS | Gaia |
| Platform | Smart-1, VMWare ESX, Open Server |

## Symptoms

- * SmartConsole policy installation for R81.10 Large-Scale Management (LSM) profile fails with "Unable to start policy installation"
* $FWDIR/log/install_policy.elg on the Quantum Security Management/Multi-Domain Management Server shows this output:   
  `XX/XX/XX XX:XX:XX,156 ERROR `  
  `com.checkpoint.management.policy_installation_is.PathsManager.makeDirHierarchy:209 [qtp1567614120-27000]: Caught an unexpected exception during dir hierarchy creation, removin`  
  `
  java.nio.file.NoSuchFileException: `  
  `/opt/CPmds-R81.10/customers/`/CPSFWR81CMP-R81.10/conf/vpn_route.conf   
  at sun.nio.fs.UnixException.translateToIOException(UnixException.java:98)  
  at sun.nio.fs.UnixException.rethrowAsIOException(UnixException.java:114)
* The **Install Database** operation may fail.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903)

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ([Security Management Server](https://support.checkpoint.com/product/Quantum/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/Quantum/166)).

<br />

If you choose not to upgrade, use this **workaround**:

1. Copy a default *vpn_route.conf* file from another Security Management Server/Domain Management Server to the problematic path in the *$FWDIR/log/install_policy.elg* file.
2. Save and install the Security policy.

**Note:** The *vpn_route.conf* file should be a default/non-populated *vpn_route.conf* file to prevent unexpected traffic changes related to the VPN routing.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
