> Source: [sk185079](https://support.checkpoint.com/results/sk/sk185079)

# sk185079 - Policy installation fails after migration due to incorrect primary IP address in the external.if file

| Property | Value |
|----------|-------|
| Solution ID | sk185079 |
| Date Created | 2026-06-25 |
| Last Modified | 2026-07-01 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |
| Platform | Smart-1 |

## Symptoms

- * Policy installation fails after migration.

* eth1 is manually configured as the management interface and as the primary IP address for the Security Management Server object.

* After migration (export/import), the Security Management Server object shows the same IP address on both eth0 and eth1 interfaces:


  * Primary IP address: 192.168.1.10
  * Interfaces:  
    * eth1: 192.168.1.10
    * eth0: 192.168.1.10

  <br />

## Cause

During the migration import, the system reads `/etc/sysconfig/external.if` to identify the management interface. If the file points to the wrong interface, the import process sets the primary IP address to the wrong address and overwrites the correct configuration.

In this case:

* The primary IP address of the Security Management Server object changed to an incorrect address taken from an unconnected/default interface.
* The manually configured eth1 IP address was lost.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
