> Source: [sk184152](https://support.checkpoint.com/results/sk/sk184152)

# sk184152 - The "vsx_provisioning_tool" command fails to add a VTI on a Virtual System with "Object contain invalid reference"

| Property | Value |
|----------|-------|
| Solution ID | sk184152 |
| Date Created | 2025-10-23 |
| Last Modified | 2025-10-29 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * The "`vsx_provisioning_tool`" command fails to add a VPN Tunnel Interface (VTI) on a Virtual System.

  Example:

  `[Expert@MGMT:0]# vsx_provisioning_tool -L -o add interface vd <Name of Virtual System Object> vpn_tunnel numbered peer <Name of VPN Peer Object> local <Tunnel Local IP> remote <Tunnel Remote IP> [tunnel_id <Tunnel ID>]`  
  `
  `  
  `
  Version <XXX>`  
  `
  Updating <Name of Virtual System Object>...`  
  `
  `  
  `
  Generating VSX Configuration for <Name of Virtual System Object> on <Name of VSX Gateway Object>.`  
  `
  Pushing VSX Configuration to <Name of VSX Gateway Object>.`  
  `
  `  
  `
  <Name of VSX Gateway Object>: processed 20% of configuration..`  
  `
  <Name of VSX Gateway Object>... VSX configuration was applied successfully.`  
  `
  `  
  `
  Final name for the VTI to peer <Name of VPN Peer Object>: vpnt<ID>`  
  `
  `  
  `
  Generating Topology`  
  `
  `  
  `
  Internal Error: Performing a Rollback...`  
  `
  Updating <Name of Virtual System Object>...`  
  `
  Generating VSX Configuration for <Name of Virtual System Object> on <Name of VSX Gateway Object>.`  
  `
  Pushing VSX Configuration to <Name of VSX Gateway Object>.`  
  `
  <Name of VSX Gateway Object>: processed 20% of configuration..`  
  `
  <Name of VSX Gateway Object>... VSX configuration was applied successfully.`  
  `
  `  
  `
  Failed to update object <Name of Virtual System Object>_<Name of Interface>: Object contain invalid reference`  
  `
  [Expert@MGMT:0]#`
* VSX Provisioning debug ([sk31874](https://support.checkpoint.com/results/sk/sk31874)) shows errors like this in the `$FWDIR/log/fwm.elg` file:

  `CSrvObj::ServerValidate: failed to ValidateReferences - Object contain invalid reference`  
  `
  E R R O R !!! Validation failed for Object '<Name of Virtual System Object>_<Name of Interface>' @ 'network_objects': Validation error in field '' of element #220 at object '<Name of Virtual System Object>_<Name of Interface>' @ 'Network Objects' --> The referenced object '<Name of Network Object>' from table 'network_objects' does not exist in the database (Object contain invalid reference)`

## Cause

In this case, the VSX provisioning process attempted to link to a network object that does not exist in the Security Management Server database.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
