> Source: [sk182092](https://support.checkpoint.com/results/sk/sk182092)

# sk182092 - First policy installation from Smart-1 Cloud in the Infinity Portal fails with "Operation Incomplete due to timeout."

| Property | Value |
|----------|-------|
| Solution ID | sk182092 |
| Date Created | 2024-03-11 |
| Last Modified | 2024-03-21 |
| Technical Level | Advanced |
| Products | Smart-1 Cloud |
| Versions | Cloud |
| Platform | Smart-1 |

## Symptoms

- * After connecting a Security Gateway to Smart-1 Cloud, the first policy installation from the Infinity Portal fails with error: `"Operation Incomplete due to timeout."`

* Testing SIC communication with the Security Gateway fails with error:  
  `
  SIC Status is unknown.`  
  `
  Could not establish TCP connection with <MAAS IP address of Gateway>.`  
  `
  Please make sure that Check Point Services <IP address of Gateway>, Port 18191 are running on <Gateway name> and that TCP connectivity is allowed from Security Management Server to IP <MAAS IP address of Gateway>, Port 18191.`

* Kernel debug of dropped traffic with the command: `# fw ctl zdebug + drop`, shows similar messages:  

  `
  @;91994.411;[cpu_1];[SIM4];sim_pkt_send_drop_notification: (0,0) received drop, reason: Anti-Spoofing (11), conn: <"IP address of Tenant" 0,"IP address of Gateway",16423,1>;`  
  `
  @;91994.412;[cpu_1];[SIM4];sim_pkt_send_drop_notification: sending packet dropped notification drop mode: 0 debug mode: 1 send as is: 0 track_lvl: -1, conn: <"IP address of Tenant" 0,"IP address of Gateway",16423,1>;`  
  `
  @;91994.413;[cpu_1];[SIM4];sim_pkt_send_drop_notification: sending single drop notification, conn: <"IP address of Tenant" 0,"IP address of Gateway",16423,1>;`  
  `
  @;91995.414;[cpu_1];[SIM4];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:<"IP address of Tenant" 0,"IP address of Gateway",16423,1>;`  
  `
  @;91995.415;[cpu_1];[fw4_0];cphwd_notif_packet_dropped: recieved packet dropped notification, reason: Anti-Spoofing;`  
  `
  @;91995.416;[cpu_1];[fw4_0];cphwd_notif_packet_dropped: notification holds a single drop;`  
  `
  @;91995.417;[cpu_1];[SIM4];pkt_handle_no_match: packet dropped (spoofed address), conn: <"IP address of Tenant" 0,"IP address of Gateway",16423,1>;, ifn 9, macs:;`

* First time policy installation works fine from Web SmartConsole or Desktop SmartConsole.

## Cause

Anti-Spoofing is set to prevent on the Maas Tunnel interface of the Security Gateway.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
