> Source: [sk33893](https://support.checkpoint.com/results/sk/sk33893)

# sk33893 - 'Installation failed. Reason: Load on Module failed - failed to load security policy' error during policy installation

| Property | Value |
|----------|-------|
| Solution ID | sk33893 |
| Date Created | 2007-11-24 |
| Last Modified | 2024-09-05 |
| Technical Level | General |
| Products | Security Gateway, SmartConsole |
| Versions | R81.20, R81.10 (EOS), R81 (EOS), R81.20, R81.10 (EOS), R81 (EOS) |

## Solution

Introduction
------------

This article describes different scenarios when policy installation fails with "***Installation failed. Reason: Load on Module failed - failed to load security policy*** " error.  
Each Scenario has additional details, mostly received from debug, additional error messages, its own cause and solution. See the Table of Contents below.

**Note** : Most of these Scenarios happen on pre-R80.x versions. For R80.x, refer to **[sk106588 - R80.10 Policy installation errors and warnings](https://support.checkpoint.com/results/sk/sk106588)**

### Table of Contents

1. **General Problems**
   1. Traditional Anti-Virus and the Anti-Virus blade are both enabled
   2. Problem with UserCheck objects
2. **Problem started after upgrade to R80.x**
   1. Only Threat Prevention policy can be installed
   2. Problem with corrupted objects in R80.x
   3. CloudGuard policy installation failure
   4. Policy installation fails on AWS gateways
   5. Corruption in Anti-Malware policy
   6. APPI Conversion
3. **Problem started after enabling Application Control \& URL Filtering / Anti-Virus / HTTPS Inspection / IPS**
   1. Policy installation failure for URL Filtering \& Application Control blade
   2. Problem with corrupted *$FWDIR/appi/update/appi_db.C* file
   3. Problem with HTTPS Inspection
   4. Anti-Virus and/or Anti-Virus blade is enabled
   5. Problem with duplicate entries for the '*http_methods*' in IPS database
   6. "*gen_appi_set*" warning message
   7. Problem with *string_dictionary_table* getting full
4. **Problems with License**
   1. Problem with cluster member HA license
   2. Problem with EVAL license
5. **Problems whith additional symptoms when running *fw fetch* or fetching the policy under debug**
   1. "*Duplicate entries in table* " error when running '*fw fetch*' on the Security Gateway.
   2. "*Failed to find a dynamic interface on DAIP module* " error in the output of '*fw -d fetch \<Management IP address\>*' command
   3. Problem with empty *$FWDIR/conf/applications_entitlement.C* file
   4. Problem with corrupted *$FWDIR/conf/fwc_handler_id_cache.conf* file
   5. Problem with corrupted *$FWDIR/conf/rad_services.C* file
   6. Problem with URL Regular Expression
   7. "*Illegal sequence beginning with*..." error on fetching the policy under debug
   8. "*bad dlpactivated value* " error in the output of "*fw fetchlocal*" debug
6. **Other Problems**
   1. Problem with Suspicious Activity Monitoring (SAM)
   2. Problem with Pattern Matcher cache
   3. Rule name contains non-ASCII characters
   4. Output of '*fwm load -d* ' command contains '*error number 16*'
   5. Problem with CIFS
   6. Problem with kernel table '*spii_multi_pset2kbuf_map*'
   7. Problem with corrupted *$FWDIR/conf/file_types.C* file
   8. Problem with long IPS Profiles names after IPS update
   9. Problem with Smart-1 appliance that manages multiple Virtual Systems
   10. Problem with identical ports used by load balancers in AWS / Azure
   11. Problem with VSX Gateway / Cluster that has a corrupted database.
7. **Old Issues**
   1. Problem with SmartView Monitor
   2. Problem in VSX environment when running the '*vsx_util add_member*' command
   3. Problem with IPS Profiles other than the *Default_Profile*
   4. Problem with *cmik_loader_sync_htab_table* kernel table
   5. Problem with Security Gateway R76 managed by Security Management Server R77.x
   6. Problem with size of kernel table string_dictionary_table

Show the Entire Article

(1) General Problems {#Section 1}
---------------------------------

This section lists problems that do not have any additional symptoms. First check if the solutions from this section help. If they don't, please continue to below sections

1.

   ### Traditional Anti-Virus and the Anti-Virus blade are both enabled {#Scenario 1a}

   **Symptoms:**
   * "*Installation failed. Reason: Load on module failed, failed to load security policy*" error in SmartDashboard during policy installation when Traditional Anti-Virus and the Anti-Virus blade are both enabled.

   <br />

   Show / Hide the solution  
   **Cause:**

   Traditional Anti-Virus and the Anti-Virus blade cannot be enabled simultaneously. Choose one method of Anti-Virus to use and disable the other.

   **Solution:**
   * To disable Traditional Anti-Virus:

     1. In the SmartDashboard, open the Security Gateway / Cluster object
     2. Browse to Other -\> More Settings
     3. Clear the "Enable Traditional Anti-Virus" checkbox
     4. Click OK
     5. Save and install the Security policy
   * To disable the Anti-Virus blade:

     1. In the SmartDashboard, open the Security Gateway / Cluster object
     2. In the General Properties page, clear the "Anti-Virus" checkbox
     3. Click OK
     4. Save and install the Security policy

2.

   ### Problem with UserCheck objects {#Scenario 1b}

   **Symptoms:**
   * "*Installation failed. Reason: Load on module failed, failed to load security policy*" error in SmartDashboard during policy installation.

   <br />

   Show / Hide the solution  
   **Cause:**

   UserCheck objects were the root cause of this failure (when Application Control Blade was disabled, policy installation succeeded).

   **Solution:**

   Delete all custom (user-created) UserCheck objects, and re-create them from the scratch in SmartDashboard - '*Application \& URL Filtering*' tab - left pane - UserCheck.

(2) Problems started after upgrade to R80.x {#Section 2}
--------------------------------------------------------

1.

   ### Only Threat Prevention policy can be installed {#Scenario 2a}

   **Symptoms:**
   * "*Installation failed. Reason: Load on Module failed - failed to load security policy*" error during policy installation after upgrade to R80.
   * Fetching policy under debug shows: "*Management rejected fetch for this module - sic name does not match*".
   * Threat Prevention policy can be installed without errors.

   <br />

   Show / Hide the solution  
   **Cause:** There is a mismatch in some hosts objects definitions (for example, Mail, Web or DNS server) during the upgrade.

   **Solution:**

   [Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a fix for this issue.   
   For faster resolution and verification please collect [CPinfo](https://support.checkpoint.com/results/sk/sk92739) files from the Security Management and Security Gateways involved in the case.

2.

   ### Problem with corrupted objects in R80.x {#Scenario 2b}

   **Symptoms:**
   * "*Installation failed. Reason: Load on Module failed - failed to load security policy*" error in R80.x SmartConsole during policy installation on R77.30 Security Gateway.

   * Fetching policy under debug on R77.30 Security Gateway shows:

     *\[Expert@GW_HostName:0\]# fw -d fetchlocal -d $FWDIR/state/__tmp/FW1
     fw_atomic_add_spii_resources: **failed to add parameters. ret=-1, p_num=12.: No such file or directory**
     fw_atomic_add_spii_resources: **failed to load multi set 2.: No such file or directory**
     fw_atomic_add_spii_resources: returning.
     fw_atomic_download: unlocking mutex: install_policy_mutex
     ... ...
     **Failed to Load Security Policy: No such file or directory**
     fw_rfetchx_local_ex: failed to load Security Policy
     ... ...*

     OR

     *fw_atomic_add_spii_parameter: **reading parameter 'operating_system'**
     fw_atomic_add_spii_resources: **failed to add parameters. ret=-1, p_num=12**
     fw_atomic_add_spii_resources: **failed to load multi set 1**
     fw_atomic_add_spii_resources: returning
     fw_atomic_download: unlocking mutex: install_policy_mutex*

   Show / Hide the solution  
   **Cause:**

   There are corrupted objects in the R80 Management database - objects, that were not properly created during the database migration to R80. As a result, there are network objects that contain different values for activated fields in SmartConsole and activated fields in the database. These activated fields are Mail Server, Web Server or DNS server.  
   For example, if the ***is_mail_server*** attribute is ***false*** , then R80 Management Server expects the ***mail_server_prop*** field to be empty while it is not.  
   The same applies to ***is_web_server*** being ***false*** and ***web_server_prop*** not being empty.

   **Solution:**
   1. Connect to the command line on the Security Management Server / Multi-Domain Security Management Server and log in to the Expert mode.

   2. On the Multi-Domain Security Management Server, switch to the context of the relevant Domain Management Server / CMA:

      *\[Expert@HostName:0\]# mdsenv \<Name of IP of Domain Management Server\>*
   3. On the Security Management, run the following command to find the objects that have the different values for activated fields:

      *\[Expert@MGMT:0\]# cd $FWDIR/conf
      \[Expert@MGMT:0\]# grep -e $'\^\\t\\t: (' objects_5_0.C -e "is_mail_server (false)" -e mail_server_prop \| grep -v "mail_server_prop ()" \| grep mail_server_prop -B 2 \| grep ":is_mail_server (false)" -B 1 \| grep -e $'\^\\t\\t: ('*

      The output will shows all objects in which the ***mail_server*** attribute is ***false*** , and the ***mail_server_prop*** field is not empty.
   4. Once the corrupted objects have been identified, there are 2 options in R80 SmartConsole:

      * Either delete each corrupted object, if it is not needed anymore

      * Or correct the "Server" attributes in each corrupted object:

        1. Open the corrupted object
        2. On General Properties pane, click on "*Configure Servers...*" button
        3. *Check* the box for an unselected Server (e.g., "*Mail Server*")
        4. Do **not** click OK
        5. *Clear* the box for that Server (e.g., "*Mail Server*")
        6. Click OK to close the "*Configure Servers*" window
        7. Click OK to close the properties window
        8. Perform the above steps in the same object for the next unselected "Server" checkbox
        9. When done with all corrupted objects, publish and then install the policy

        **Notes**:
        * The order of actions is important
        * Do not check more than one Server at the time (check one, save, clear it, save, and so on)
        * This operation should be done for all unselected Servers (i.e., **if "DNS Server" is selected, then do NOT touch it**)

3.

   ### CloudGuard policy installation failure {#Scenario 2c}

   **Symptoms:**
   * Policy installation of CloudGuard gateway fails with "*Load on module failed* " error.  

   * Output of FWM debug on the affected gateways shows:

     ```
     [ PID]@gw[DATE TIME] fw_atomic_fill_multiportal_info: Is ReverseProxySSL Portal enabled= 0, Is ReverseProxyClear Portal enabled= 0
     [ PID]@gw[DATE TIME] fw_atomic_fill_multiportal_info: enter.
     [ PID]@gw[DATE TIME] fw_atomic_fill_multiportal_info: could not read the multiportals_array
     [ PID]@gw[DATE TIME] fw_atomic_fill_multiportal_info: failed
     [ PID]@gw[DATE TIME] fw_atomic_fill_multiportal_info: about to exit.
     [ PID]@gw[DATE TIME] fw_atomic_download: fw_atomic_fill_multiportal_info failed
     [ PID]@gw[DATE TIME] fw_atomic_destroy: set FWHA_CUL_POLICY_STATE_FREEZE to: FWHA_CUL_POLICY_STATE_FREEZE_OFF        
                  
                  
     ```

   Show / Hide the solution  
   **Cause:** There are more than 30 portals configured on the relevant gateway object. Usually this is caused by duplicate portals.

   **Solution:**

   To resolve this issue, perform:
   1. Close all SmartConsole windows and open [GuiDBedit Tool](https://support.checkpoint.com/results/sk/sk13009).
   2. On the left pane select "Network Objects" and open the table "network_objects".
   3. On the right pane select the relevant gateway.
   4. Click on a random field on the bottom pane.
   5. Press the "P" key until you reach the line that says "portals"
   6. Scroll down and observe the various portals configured there.   
      There should be multiple portals with the same configuration (duplicates of a single portal).
   7. Delete the duplicate portals.   
      **Note:**If there are no duplicate portals, do not delete the portals!
   8. Save the changes.

4.

   ### Policy installation fails on Amazon Web Services (AWS) gateways {#Scenario 2d}

   **Symptoms:**
   * Policy installation on R77.30 AWS gateways fails with "Load on Module failed - failed to load Security policy" error.
   * "*service autoprovision test* " command on Controller returns "*port duplication*" error.
   * AutoProvisioning feature does not work

   <br />

   Show / Hide the solution  
   **Cause:** Port duplication on AWS protal caused gateway provisioning failure.

   **Solution:**
   To resolve the problem, remove the port duplication on AWS portal setting.  
   The latest Auto Provisioning version has the port duplication check (refer to section 5-A in [sk112575](https://support.checkpoint.com/results/sk/sk112575)).   
   Update the add-on package and make sure the "*service autoprovision test*" does not fail on duplicated port.

5.

   ### Corruption in Anti-Malware policy {#Scenario 2e}

   **Symptoms:**
   * Fetching policy from the Security gateway results in the following error:   
     `fw_atomic_get_cmi_loader_malware_policy: malware_policy_get_overrides_hash_from_ktable() failed Failed to Load Security Policy: `  
     ` No such file or directory Failed to Load Security Policy: `  
     ` No such file or directory Fetching Security Policy Failed.`
   * Problem occurs even if only the Access policy is installed. Fetching the policy locally from the `$FWDIR/state/local/AMW/` directory fails as well.
   * Policy can be installed on a different member of the Cluster or the same policy can be installed on a different Security gateway

   <br />

   Show / Hide the solution  
   **Cause:** Corruption in Anti-Malware policy.

   **Solution:**
   To resolve the problem, peform:
   1. Backup allfiles in the *$FWDIR/state/local/AMW/* directory.
   2. Copy and replace the files from a gateway that you are able to install the policy on.
   3. Fetch only the AMW policy from the directory the files were copied to:  
      *fw -d amw fetchlocal -d $FWDIR/state/local/AMW/ \>\& /var/log/amw.txt*
   4. Attempt the fetch again on the gateway from the Security Management and it should succeed:  
      *fw fetch \<IP address\>*

6.

   ### APPI Conversion {#Scenario 2f}

   **Known Limitations**: PMTR-21449, PMTR-22977, PMTR-22975, PMTR-25205

   **Symptoms:**
   * "*Installation failed. Reason: Load on Module failed - failed to load security policy*" error during policy installation on R80.10 Security gateway.

   * Kernel debug shows:

     ```
     ;[cpu_0];[fw4_0];fwk_get_new_global_settings: rulebase_uids_in_log param is: 1;
     ;[cpu_0];[fw4_0];fw_rules_uid_prepare: fw_rules_uid_max_dic_entries_new = 20000;
     ;[cpu_0];[fw4_0];FW1: fwloghandle_register_string: unable to put entry into table.;
     ;[cpu_0];[fw4_0];fw_rules_uid_handle_uid: couldn't allocate dictionary string id for rule no. 0
     In order to solve this problem, try setting rulebase_uids_in_log to false;
     ;[cpu_0];[fw4_0];fwk_atomic_load_prepare: fw_rules_uid_prepare failed;
     ;[cpu_0];[fw4_0];fwk_atomic_cleanup: cleaning up allocations in fw_lists_future;
     ;[cpu_0];[fw4_0];fwkplugin_cleanup: called;
     ;[cpu_0];[fw4_0];fwk_free_services_array: Array is already empty;     
         
     ```

   * The string_dictionaly_table is full:

     ```
     # fw tab -t string_dictionary_table -s
     HOST NAME ID #VALS #PEAK #SLINKS
     localhost string_dictionary_table 8135 196608 196608 196608          
             
     ```

   <br />

   Show / Hide the solution  
   **Cause:** there are \~500 new services in each policy; this caused the string dictionary to overload and fail to install the policy.

   **Solution:**
   [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
   A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
   For faster resolution and verification please collect [CPinfo](https://support.checkpoint.com/results/sk/sk92739) files from the Security Management and Security Gateways involved in the case.

(3) Problems started after enabling Application Control \& URL Filtering / Anti-Virus / HTTPS Inspection / IPS {#Section 3}
---------------------------------------------------------------------------------------------------------------------------

1.

   ### Policy installation failure for URL Filtering \& Application Control blade {#Scenario 3a}

   **Symptoms:**
   * Policy installation fails for URL Filtering and Application Control blade.
   * Output of '*fwm -d load* ' command on Management Server shows: "*CPTA_InstallFailReasonTranslate: **error number 16***"
   * Output of '*fw -d fetchlocal -d* ' command on Security Gateway shows:  
     *kiss_rem_operator_eval_verify: syntax error - KLEENE (\*) requires 1 operands, and there are only 0 operands in the stack*   
     *kiss_pm_compile_get_lss_from_pattern: Error while trying to find LSS for pattern*
   * Output of '*fw -d fetchlocal -d* ' command on Security Gateway shows:  
     *fw_atomic_add_rad_sgen_buffers:rad add buffer is OK
     fw_atomic_add_appi_sgen_buffers:SGen_appi_policy_struct_load failed: **No such file or directory**
     fw_atomic_add_sgen_buffers: failed to add appi_sgen_buffer: **No such file or directory**
     fw_atomic_add_sgen_buffers: failed to add sgen buffer, freeing remaining buffers: **No such file or directory**
     fw_atomic_download: unlocking mutex: install_policy_mutex Failed to Load Security Policy: **No such file or directory***

   <br />

   Show / Hide the solution  
   **Cause:**

   In a custom sites case, a custom Application/Site has been defined with a wildcard (i.e., *\*.example.com* ) and the "*URLs are defined as Regular Expression*" checkbox has been selected. Because the URL is not a regular expression, Security Gateway fails to interpret it as one.

   **Solution:**
   1. If the intention is to simply block this domain and any of its sub-domains, then clear the box "*URLs are defined as Regular Expression* " for any custom site, which is not actually using regular expressions.  

   2. If the intention is to block any domain ending with "*example.com* " (e.g., *www.myexample.com* ), then use a correct regular expression.   
      For example, if the intention is to block any sub-domain of "*example.com* ", the expression should be "*.\*\\.example.com*".

   **Additional Possible Cause:**
   * Definition files on the Management Server need to be modified.
   * Problem can happen with Sites or Apps that are not categorized. In this case, categorize them and problem will be resolved.

   **Solution:**

   Perform the following procedure on the Security Management Server:
   1. Connect to command line and log in to Expert mode.  

   2. Stop Check Point services: *\[Expert@HostName:0\]# cpstop*   

   3. Backup and edit the *$FWDIR/conf/appfw_general.C* file with vi editor.   

   4. Search for *:acct_interval_percent ()*   

   5. Change it to *:acct_interval_percent (**1**)*   

   6. Save the file.  

   7. Backup and edit the *$FWDIR/conf/appfw_misc.C* file with vi editor.  

   8. Search for *:acct_interval_percent ()*   

   9. Change it to *:acct_interval_percent (**1**)*   

   10. Save the file.  

   11. Start Check Point services: *\[Expert@HostName:0\]# cpstart*   

   12. Connect with SmartDashboard to Security Management Server and install the Security Policy.

   **Additional symptoms:**

   **Known Limitation:** 01502990, 01503007
   * Policy installation fails when "*Uncategorized category* " is used for custom URL under the "*Override categorization session*" on the Application control tab.
   * Fetching the policy on Security Gateway (with Application Control \& URL Filtering blades enabled) under debug shows:   
     *{policy} \[ERROR\]: appi_app_db_generate_attribs_strings_for_application: failed getting attrib object ... from hash - first iteration
     {policy} \[ERROR\]: appi_app_db_add_application_um: appi_app_db_generate_attribs_strings_for_application
     {policy} \[ERROR\]: **appi_cmi_handler_deal_with_apps: appi_app_db_add_application_um failed**
     {policy} \[ERROR\]: **appi_user_cmi_handler_add_signatures_cb: appi_cmi_handler_deal_with_apps failed**
     {module} \[ERROR\]: **cmi_loader_update_apps: add_signatures_cb failed for app APPI_USER (6)**
     ... ... ...
     {module} \[ERROR\]: **cmi_loader_install_policy_ex: cmi_loader_update_apps failed**
     {module} \[ERROR\]: cmi_loader_install_policy_ex: Policy installation failed. error is:
     \[ PID ...\]@HostName\[Date Time\] fw_atomic_cmi_add: cmi_loader_install_policy failed.
     ... ... ...
     Failed to Load Security Policy: No such file or directory
     ... ... ...
     Fetching Security Policy Failed*

   <br />

   Show / Hide the solution for additional symptom  
   **Solution:**
   1. In SmartDashboard, go to *Application \& URL Filtering* tab -\> on the left, expand *Advanced* -\> click on *Override Categorization* .   

   2. In the filter type/paste *Uncategorized* , look at the '*Primary Category* ' column.   

   3. Double-click on *every* Application / URL that is assigned to the '*Uncategorized* ' category - in the '*New Primary Category* ' field select either '*Unknown Traffic* ' category, or any other relevant category - click OK.   

   4. Verify that there are no Applications / URLs that assigned to the '*Uncategorized* ' category.   

   5. Save the changes: go to *File* menu -\> click *Save* .   

   6. Install the policy.

   <br />

   OR  
   1. Go to *Application \& URL Filtering* tab -\> on the left, click on *Applications/Sites* .   

   2. In the filter type/paste *Uncategorized* , look at the '*Primary Category* ' column.   

   3. Double-click on *every* Application / URL that is assigned to the '*Uncategorized* ' category - in the '*New Primary Category* ' field select either '*Unknown Traffic* ' category, or any other relevant category - click OK.   

   4. Verify that there are no Applications / URLs that assigned to the '*Uncategorized* ' category.   

   5. Save the changes: go to *File* menu -\> click *Save* .   

   6. Install the policy.

2.

   ### Problem with corrupted *$FWDIR/appi/update/appi_db.C* file {#Scenario 3b}

   **Symptoms:**
   * Kernel debug on Security Gateway ('*fw ctl debug -m CMI_LOADER + error module* ') during policy installation shows:  
     *{policy} \[ERROR\]: **appi_decrypt_obj_from_file: sio_sread failed**
     ... ...
     {policy} \[ERROR\]: appi_cmi_handler_add_signatures_cb: **failed open appi_feed file**
     ... ...
     {module} \[ERROR\]: cmi_loader_install_policy_ex: cmi_loader_update_apps failed
     {module} \[ERROR\]: cmi_loader_install_policy_ex: Policy installation failed. error is:
     \[ *PID* ...\]@*HostName* \[*Date Time* \] fw_atomic_cmi_add: cmi_loader_install_policy failed.
     ... ...
     Failed to Load Security Policy: No such file or directory*   
     *Failed to load security policy: Illegal seek*
   * Policy installation succeeds after disabling the Application Control and URL Filtering blades.

   <br />

   Show / Hide the solution  
   **Cause:** The *$FWDIR/appi/update/appi_db.C* file is corrupted.

   **Solution:**
   1. Download the relevant Application Control and URL Filtering database from Check Point site:

      <http://secureupdates.checkpoint.com/appi/v3_1_0/gw/appi_urlf_db_pkg.tar>
   2. Transfer the downloaded Application Control and URL Filtering database to the problematic Security Gateway / Cluster member (into some directory, e.g., */some_path_to_db/*).

   3. Connect to command line on the problematic Security Gateway / Cluster member and log in to Expert mode.

   4. Unpack the Application Control and URL Filtering database:

      *\[Expert@HostName:0\]# cd /some_path_to_db/*   
      *\[Expert@HostName:0\]# tar xvf appi_urlf_db_pkg.tar*

      You should see the following two files:
      * *appi_db.C.tmp*
      * *urlf_db.bin.tmp*
   5. Backup the current Application Control and URL Filtering database:

      *\[Expert@HostName:0\]# mv -v $FWDIR/appi/update/appi_db.C $FWDIR/appi/update/appi_db.C_CORRUPTED*
   6. Copy the downloaded Application Control and URL Filtering database to the relevant directory:

      *\[Expert@HostName:0\]# cp -v /some_path_to_db/appi_db.C.tmp $FWDIR/appi/update/appi_db.C*
   7. Connect with SmartDashboard to Security Management Server / Domain Management Server.

   8. Install the policy onto the relevant Security Gateway / Cluster object.

3.

   ### Problem with HTTPS Inspection {#Scenario 3c}

   **Symptoms:**
   * Policy installation on Security Gateway with enabled HTTPS Inspection fails with "*Installation failed. Reason: Load on module failed, failed to load security policy* " error.  

   * Kernel debug on Security Gateway during policy installation (might cause high CPU load) shows failures similar to this:  

     *{policy} appi_cmi_handlers_common_open_file: going to read the '/opt/CPshrd-R77/database/downloads/HTTPS_INSPECTION/1.0/1.7/https_domain_ignore_list.bin' file. _try_clear is FALSE
     {policy} appi_decrypt_obj_from_file: called for file /opt/CPshrd-R77/database/downloads/HTTPS_INSPECTION/1.0/1.7/https_domain_ignore_list.bin
     {policy} \[ERROR\]: appi_decrypt_obj_from_file: failed to open file /opt/CPshrd-R77/database/downloads/HTTPS_INSPECTION/1.0/1.7/https_domain_ignore_list.bin
     {policy} \[ERROR\]: appi_cmi_handlers_common_open_file: appi_decrypt_obj_from_file failed
     {policy} \[ERROR\]: appi_https_cmi_loader_open_https_wl_file: appi_cmi_handlers_common_open_file() failed
     {policy} \[ERROR\]: appi_https_cmi_handler_add_signatures_cb: failed to read white list file*

   <br />

   Show / Hide the solution  
   **Cause:**

   Security Gateway did not download the HTTPS Inspection whitelist files - either *$CPDIR/database/downloads/HTTPS_INSPECTION/* directory on the Security Gateway is empty, or contains corrupted file(s).

   **Solution:**

   Follow these procedures:
   * **If Security Gateway is connected to the Internet**

     1. Verify the connectivity from Security Gateway to the Internet.   

     2. Connect to command line on Security Gateway and log in to Expert mode.
     3. Stop Check Point services: *\[Expert@HostName:0\]# cpstop*

     4. Delete the *$CPDIR/database/downloads/HTTPS_INSPECTION/* directory:

        *\[Expert@HostName:0\]# cd $CPDIR
        \[Expert@HostName:0\]# rmdir -v -p /database/downloads/HTTPS_INSPECTION/*
     5. Backup and edit the current *$CPDIR/conf/downloads/dl_prof_HTTPS_INSPECTION.xml* file.

     6. Change the value of '*\<Interval\>1440\</Interval\>* ' attribute from ***1440*** (minutes) to *several minutes only* - this will cause the update process to start several minutes after starting Check Point services.
     7. Start Check Point services: *\[Expert@HostName:0\]# cpstart*

     8. Check the contents of the '*$CPDIR/database/downloads/HTTPS_INSPECTION/* ' directory after some time.  
        If update succeeded, then complete this procedure to the end.  
        If update failed, then complete this procedure to the end, and try the other procedure, or [contact Check Point Support](http://www.checkpoint.com/services/contact/index.html).
     9. Stop Check Point services: *\[Expert@HostName:0\]# cpstop*

     10. Edit the current *$CPDIR/conf/downloads/dl_prof_HTTPS_INSPECTION.xml* file with vi editor.

     11. Change the value of '*\<Interval\>1440\</Interval\>* ' attribute back to ***1440*** (minutes).
     12. Start Check Point services: *\[Expert@HostName:0\]# cpstart*

   * **If Security Gateway offline, or if update from the Internet fails**

     This procedure assumes that you have another *working* Security Gateway (which has HTTPS Inspection enabled and on which the policy installation does not fail) in your environment of the same version as the problematic Security Gateway.
     1. Connect to the command line on the *working* Security Gateway and log in to Expert mode.
     2. Copy the contents on the '*$CPDIR/database/downloads/HTTPS_INSPECTION/*' directory:

        *\[Expert@HostName:0\]# cd $CPDIR
        \[Expert@HostName:0\]# tar cvf COPY_HTTPS_INSPECTION.tar database/downloads/HTTPS_INSPECTION/\**   

     3. Transfer the *COPY_HTTPS_INSPECTION.tar* file from the *working* Security Gateway to the *problematic* Security Gateway (into some directory, e.g., */some_path_to_tar/* ).   

     4. Connect to the command line on the *problematic* Security Gateway and log in to Expert mode.
     5. Stop Check Point services: *\[Expert@HostName:0\]# cpstop*

     6. Delete the *$CPDIR/database/downloads/HTTPS_INSPECTION/* directory:

        *\[Expert@HostName:0\]# cd $CPDIR
        \[Expert@HostName:0\]# rmdir -v -p /database/downloads/HTTPS_INSPECTION/*
     7. Copy the *COPY_HTTPS_INSPECTION.tar* file to *$CPDIR* directory:

        *\[Expert@HostName:0\]# cp -v /some_path_to_tar/COPY_HTTPS_INSPECTION.tar $CPDIR/*
     8. Extract the *COPY_HTTPS_INSPECTION.tar* file:

        *\[Expert@HostName:0\]# tar xvf COPY_HTTPS_INSPECTION.tar*
     9. Check that the relevant directories were extracted ('*$CPDIR/database/downloads/HTTPS_INSPECTION*'):

        *\[Expert@HostName:0\]# ls -la $CPDIR/database/downloads/HTTPS_INSPECTION*
     10. Start Check Point services: *\[Expert@HostName:0\]# cpstart*

     If this procedure fails, then [contact Check Point Support](http://www.checkpoint.com/services/contact/index.html).

4.

   ### Anti-Virus and/or Anti-Virus blade is enabled {#Scenario 3d}

   **Symptoms:**
   * "*Installation failed. Reason: Load on module failed, failed to load security policy* " error in SmartDashboard during policy installation when Anti-Virus and/or Anti-Virus blade are enabled.  

   * Fetch debug (taken with *export TDERROR_ALL_ALL=5* command) shows: *malware_handler_add_signatures_cb: malware_sig_parser_parse() failed, file_name /opt/CPsuite-R77/fw1/conf/malware.eng
     \[ERROR\]: cmi_loader_update_apps: add_signatures_cb failed for app MALWARE (2)
     \[ERROR\]: cmi_loader_install_policy_ex: cmi_loader_update_apps failed
     \[ERROR\]: cmi_loader_install_policy_ex: Policy installation failed. error is: Failed to parse file
     (/opt/CPsuite-R77/fw1/amw/ioc/cur/sigs/malware_ioc.eng) - failed to open file (errno No such file or directory)
     \[ERROR\]: cmi_loader_install_policy_ex: Policy installation failed. error is: Failed to parse file
     (/opt/CPsuite-R77/fw1/amw/ioc/cur/sigs/malware_ioc.eng) - failed to open file (errno No such file or directory)
     Failed to Load Security Policy: No such file or directory*

   <br />

   Show / Hide the solution  
   **Cause:** Anti-Malware signature files were not created on the Security Gateway.

   **Solution:**
   1. Connect to command line on Security Gateway and log in to Expert mode.
   2. Run the following commands:

      ```
      [Expert@HostName:0]# mkdir /opt/CPsuite-R77/fw1/amw/ioc/ 
      [Expert@HostName:0]# cd /opt/CPsuite-R77/fw1/amw/ioc/ 
      [Expert@HostName:0]# mkdir 0
      [Expert@HostName:0]# ln -s /opt/CPsuite-R77/fw1/amw/ioc/0 cur 
      [Expert@HostName:0]# cd 0
      [Expert@HostName:0]# mkdir md5
      [Expert@HostName:0]# mkdir rep
      [Expert@HostName:0]# mkdir sigs
      [Expert@HostName:0]# touch /opt/CPsuite-R77/fw1/amw/ioc/0/md5/av_hash_ioc.eng 
      [Expert@HostName:0]# touch /opt/CPsuite-R77/fw1/amw/ioc/0/rep/urlrep_ioc.eng 
      [Expert@HostName:0]# touch /opt/CPsuite-R77/fw1/amw/ioc/0/sigs/malware_ioc.eng 
      [Expert@HostName:0]# touch /opt/CPsuite-R77/fw1/amw/ioc/cur/md5/av_hash_ioc.eng 
      [Expert@HostName:0]# touch /opt/CPsuite-R77/fw1/amw/ioc/cur/rep/urlrep_ioc.eng 
      [Expert@HostName:0]# touch /opt/CPsuite-R77/fw1/amw/ioc/cur/sigs/malware_ioc.eng 
      ```

5.

   ### Problem with duplicate entries for the 'http_methods' in IPS database {#Scenario 3e}

   **Symptoms:**
   * "*Installation failed. Reason: Load on module failed, failed to load security policy* " error in SmartDashboard during policy installation on Security Gateway with enabled IPS blade.   

   * Policy installation on Security Gateway succeeds when IPS blade is disabled.
   * Relevant failures in the policy fetch debug:

     * :{regexp} ws_trie_add_pattern: \[WARNING\]: pattern MKACTIVITY already exists;  
       :{policy} http_methods_policy_init_trie: \[FATAL ERROR\]: failed to insert methods into methods trie;  
       ;fwk_get_new_global_settings: failed to load web security policy (ws_module_policy_load() failed).;   

     * :{regexp} ws_trie_add_pattern: \[WARNING\]: pattern CHECKOUT already exists;  
       :{policy} http_methods_policy_init_trie: \[FATAL ERROR\]: failed to insert methods into methods trie;  
       ;fwk_get_new_global_settings: failed to load web security policy (ws_module_policy_load() failed).;   

     * :{regexp} ws_trie_add_pattern: \[WARNING\]: pattern MERGE already exists;  
       :{policy} http_methods_policy_init_trie: \[FATAL ERROR\]: failed to insert methods into methods trie;  
       ;fwk_get_new_global_settings: failed to load web security policy (ws_module_policy_load() failed).;   

     * :{regexp} ws_trie_add_pattern: \[WARNING\]: pattern REPORT already exists;  
       :{policy} http_methods_policy_init_trie: \[FATAL ERROR\]: failed to insert methods into methods trie;  
       ;fwk_get_new_global_settings: failed to load web security policy (ws_module_policy_load() failed).;   

     * :{regexp} ws_trie_add_pattern: \[WARNING\]: pattern RPC_IN_DATA already exists;  
       :{policy} http_methods_policy_init_trie: \[FATAL ERROR\]: failed to insert methods into methods trie;  
       ;fwk_get_new_global_settings: failed to load web security policy (ws_module_policy_load() failed).;   

     * :{regexp} ws_trie_add_pattern: \[WARNING\]: pattern RPC_OUT_DATA already exists;  
       :{policy} http_methods_policy_init_trie: \[FATAL ERROR\]: failed to insert methods into methods trie;  
       ;fwk_get_new_global_settings: failed to load web security policy (ws_module_policy_load() failed).;   

     * :{regexp} ws_trie_add_pattern: \[WARNING\]: pattern RPC_CONNECT already exists;  
       :{policy} http_methods_policy_init_trie: \[FATAL ERROR\]: failed to insert methods into methods trie;  
       ;fwk_get_new_global_settings: failed to load web security policy (ws_module_policy_load() failed).;

   <br />

   Show / Hide the solution  
   **Cause:**

   There are duplicate entries for the 'http_methods' in the IPS database (*$FWDIR/conf/asm.C* file) on the Management Server: *MKACTIVITY* , *CHECKOUT* , *MERGE* , *REPORT* , *RPC_IN_DATA* , *RPC_OUT_DATA* , *RPC_CONNECT*.

   **Solution:**

   **Note** : Manually editing the *$FWDIR/conf/asm.C* will NOT resolve the issue because that file is regenerated from the SQL database *$FWDIR/conf/ips_tables.sqlite* during each policy installation.
   1. Connect with SmartDashboard to Security Management Server / Domain Management Server.   

   2. Go to '*File* ' menu - click on '*Database Revision Control...* ' - create a revision snapshot.   

   3. Close all SmartConsole windows (SmartDashboard, SmartView Tracker, SmartView Monitor, etc.).   

   4. Connect with [GuiDBedit Tool](http://supportcontent.checkpoint.com/solutions?id=sk13009) to Security Management Server / Domain Management Server.
   5. Delete the following *http_methods* from IPS database:

      |---|--------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
      | # | http_method  | Instructions                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
      | A | MKACTIVITY   | 1. In the upper left pane, go to '*Table* ' - open '*Managed Objects* ' - click on '*asm* '. 2. Press CTRL+F (or go to '*Search* ' menu - '*Find* ') - check the box '*Values* ' - paste *MKACTIVITY* - click on '*Find Next* '. 3. An object will be found in the upper right pane. 4. In the lower pane, check the '*http_method_type* ' - if its value is '*Unsafe* ', then right-click on the object that was found in the upper right pane - select '*Delete* ' - confirm. 5. Repeat the above Steps i-ii-iii-iv to delete all http_methods with *pattern_name* '*MKACTIVITY* ' and *http_method_type* '*Unsafe*'.           |
      | B | CHECKOUT     | 1. In the upper left pane, go to '*Table* ' - open '*Managed Objects* ' - click on '*asm* '. 2. Press CTRL+F (or go to '*Search* ' menu - '*Find* ') - check the box '*Values* ' - paste *CHECKOUT* - click on '*Find Next* '. 3. An object will be found in the upper right pane. 4. In the lower pane, check the '*http_method_type* ' - if its value is '*Unsafe* ', then right-click on the object that was found in the upper right pane - select '*Delete* ' - confirm. 5. Repeat the above Steps i-ii-iii-iv to delete all http_methods with *pattern_name* '*CHECKOUT* ' and *http_method_type* '*Unsafe*'.               |
      | C | MERGE        | 1. In the upper left pane, go to '*Table* ' - open '*Managed Objects* ' - click on '*asm* '. 2. Press CTRL+F (or go to '*Search* ' menu - '*Find* ') - check the box '*Values* ' - paste *MERGE* - click on '*Find Next* '. 3. An object will be found in the upper right pane. 4. In the lower pane, check the '*http_method_type* ' - if its value is '*Unsafe* ', then right-click on the object that was found in the upper right pane - select '*Delete* ' - confirm. 5. Repeat the above Steps i-ii-iii-iv to delete all http_methods with *pattern_name* '*MERGE* ' and *http_method_type* '*Unsafe*'.                     |
      | D | REPORT       | 1. In the upper left pane, go to '*Table* ' - open '*Managed Objects* ' - click on '*asm* '. 2. Press CTRL+F (or go to '*Search* ' menu - '*Find* ') - check the box '*Values* ' - paste *REPORT* - click on '*Find Next* '. 3. An object will be found in the upper right pane. 4. In the lower pane, check the '*http_method_type* ' - if its value is '*Unsafe* ', then right-click on the object that was found in the upper right pane - select '*Delete* ' - confirm. 5. Repeat the above Steps i-ii-iii-iv to delete all http_methods with *pattern_name* '*REPORT* ' and *http_method_type* '*Unsafe*'.                   |
      | E | RPC_IN_DATA  | 1. In the upper left pane, go to '*Table* ' - open '*Managed Objects* ' - click on '*asm* '. 2. Press CTRL+F (or go to '*Search* ' menu - '*Find* ') - check the box '*Values* ' - paste *RPC_IN_DATA* - click on '*Find Next* '. 3. An object will be found in the upper right pane. 4. In the lower pane, check the '*pattern_update_version* ' - if its value is '*602* ', then right-click on the object that was found in the upper right pane - select '*Delete* ' - confirm. 5. Repeat the above Steps i-ii-iii-iv to delete all http_methods with *pattern_name* '*RPC_IN_DATA* ' and *pattern_update_version* '*602*'.   |
      | F | RPC_OUT_DATA | 1. In the upper left pane, go to '*Table* ' - open '*Managed Objects* ' - click on '*asm* '. 2. Press CTRL+F (or go to '*Search* ' menu - '*Find* ') - check the box '*Values* ' - paste *RPC_OUT_DATA* - click on '*Find Next* '. 3. An object will be found in the upper right pane. 4. In the lower pane, check the '*pattern_update_version* ' - if its value is '*602* ', then right-click on the object that was found in the upper right pane - select '*Delete* ' - confirm. 5. Repeat the above Steps i-ii-iii-iv to delete all http_methods with *pattern_name* '*RPC_OUT_DATA* ' and *pattern_update_version* '*602*'. |
      | G | RPC_CONNECT  | 1. In the upper left pane, go to '*Table* ' - open '*Managed Objects* ' - click on '*asm* '. 2. Press CTRL+F (or go to '*Search* ' menu - '*Find* ') - check the box '*Values* ' - paste *RPC_CONNECT* - click on '*Find Next* '. 3. An object will be found in the upper right pane. 4. In the lower pane, check the '*pattern_update_version* ' - if its value is '*602* ', then right-click on the object that was found in the upper right pane - select '*Delete* ' - confirm. 5. Repeat the above Steps i-ii-iii-iv to delete all *http_methods* with *pattern_name* '*RPC_CONNECT* ' and *pattern_update_version* '*602*'. |

      <br />

      <br />

   6. Save the changes: go to '*File* ' menu - click on '*Save All* '.   

   7. Close the GuiDBedit Tool.   

   8. Connect with SmartDashboard to Security Management Server / Domain Management Server.   

   9. Install the policy onto the relevant Security Gateway / Cluster object.

6.

   ### "*gen_appi_set*" warning message {#Scenario 3f}

   **Symptoms:**
   * Policy installation fails with:

     * Warning Message: *gen_appi_set: error in reading 'appfw_misc' set*
     * Error: Policy Installation failed. Reason: Load on Module failed - failed to load Security Policy

     <br />

     *Example* :  
     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk33893/gen_appi_set1505050547.png)

   Show / Hide the solution  
   **Cause:** Corruption of *$FWDIR/conf/appfw_misc.C* file - it contains the rules under the *appfw_policy* type object, named "*##*".

   **Solution:**
   * **If the Application Control Blade is *disabled*:**

     1. Enter Expert mode and run the *cpstop* command  

     2. Backup the following files:  

        *\[Expert@HostName:0\]# cp -v **$FWDIR/conf/appfw_misc.C** $FWDIR/conf/appfw_misc.C_ORIGINAL*   

        *\[Expert@HostName:0\]# cp -v **$FWDIR/conf/fw-gas/appfw_misc.C** $FWDIR/conf/fw-gas/appfw_misc.C_ORIGINAL*   

     3. Replace those files with *$FWDIR/conf/defaultDatabase/appfw_misc.C* :  

        *\[Expert@HostName:0\]# cp -f $FWDIR/conf/defaultDatabase/appfw_misc.C $FWDIR/conf/fw-gas/appfw_misc.C*   

        *\[Expert@HostName:0\]# cp -f $FWDIR/conf/defaultDatabase/appfw_misc.C $FWDIR/conf/appfw_misc.C*   

     4. Delete the SmartConsole cache files per [sk100507](http://supportcontent.checkpoint.com/solutions?id=sk100507).  

     5. Run the *cpstart* command.

     <br />

     <br />

   * **If the Application Control Blade is *enabled* :** [Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get an assistance for this issue.   
     For faster resolution and verification please collect [CPinfo](http://supportcontent.checkpoint.com/solutions?id=sk92739) file from the Security Management involved in the case.

7.

   ### Problem with *string_dictionary_table*getting full {#Scenario 3g}

   **Known Limitations:** PMTR-22975, PMTR-21449

   **Symptoms:**
   * The string dictionary table is increasing on each policy installation. Once it becomes full, the policy will fail with the following error message:   
     "Installation failed. Reason: Load on Module failed - failed to load security policy"  

     Kernel errors:  
     `FW1: fwloghandle_register_string: unable to put entry into table.;`  
     ` fw_rules_uid_handle_uid: couldn't allocate dictionary string id for rule no. `  
     ` In order to solve this problem, try setting rulebase_uids_in_log to false;`  
     ` fwk_atomic_load_prepare: fw_rules_uid_prepare failed;`  

     Fetch errors:  
     `Failed to Load Security Policy: Bad address`  
     ` fw_rfetchx_local_ex: failed to load Security Policy`
   * Increasing the string dictionary table size resolve the issue for awhile, however the issue reoccurs.
   * Issue happens only when Application Control blade is enabled.

   Show / Hide the solution  
   **Cause:** Each policy load, Application Control generates different unique services names, so each policy installation additional unique strings will be added to the string dictionary table.

   **Solution:**

   [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
   A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
   For faster resolution and verification please collect [CPinfo](https://support.checkpoint.com/results/sk/sk92739) files from the Security Management and Security Gateways involved in the case.

(4) Problems with license {#Section 4}
--------------------------------------

1.

   ### Problem with cluster member HA license {#Scenario 4a}

   **Symptoms:**
   * Debug Error: "*Cannot install policy because this module has a Cluster member license but is not marked as a Cluster member in the management. Failed to Load Security Policy*"
   * Debug of policy installation (*env TDERROR_ALL_INSTMGR=5 fwm -d load POLICY_NAME FW_OBJECT_NAME* ) on Security Management Server shows:  
     *... ... ...
     \[FW_LOADER PID ...\]@HOST\[DATE TIME\] **CPTA_SingleInstallCB - Policy installation failed for Security Gateway \<FW_OBJECT_NAME\>, Product FW1**
     \[FW_LOADER PID ...\]@HOST\[DATE TIME\] **CPTA_InstallFailReasonTranslate: error number 16 Ip = X.X.X.X
     Security Gateway policy installation failed for Security Gateway \<FW_OBJECT_NAME\>...
     Installation failed. Reason: Load on Module failed - failed to load Security Policy.
     Security Gateway policy installation completed with errors
     Security Gateway policy installation failed for: \<FW_OBJECT_NAME\>** ...*

   <br />

   Show / Hide the solution  
   **Cause:**

   The license installed contains High Availability (HA) feature strings (for example *CPSB-FW-HA* instead of *CPSB-FW* ), but the Security Gateway is not an HA member of a cluster.  
   During policy installation, Management Server checks the current license on the target Security Gateway. In case the license contains the "*-HA*" string, Management Server expects that this Security Gateway is configured as a member of a cluster. Otherwise, policy installation would fail with "Load on Module Error: policy not installed on Security Gateway" due to licensing verification failure.

   **Solution:**

   High Availability (HA) licenses cannot be installed on Security Gateways that are not High Availability cluster members. Install a full, non-HA evaluation license.

   If the target Security Gateway should be configured as a member of a cluster, then add it to the relevant cluster object:
   1. Open the relevant cluster object in SmartDashboard.  

   2. Go to '*Cluster Members* ' pane.  

   3. Click on '*Add...* ' button - click '*Add Existing Gateway...* '.  

   4. Select the involved target Security Gateway.  

   5. Click on OK to close the '*Add Gateway to Cluster* ' window.  

   6. Click on OK to close the '*Cluster Properties* ' window.  

   7. Save the changes: go to '*File* ' menu - click on '*Save* '.  

   8. Install the policy on the Cluster object.  

   **Notes**:
   * If the target Security Gateway should remain a single Security Gateway, then remove the cluster license and attach the relevant license.
   * If you feel that the license is a non-HA license, then for further assistance, [contact Check Point Account Services](http://www.checkpoint.com/support-services/contact-support/index.html):  
     * by using [Live Chat](https://supportcenter.checkpoint.com/supportcenter/ChatRedirect.jsp)
     * by completing an [Online Form](http://www.checkpoint.com/form/contact_account.html)
     * by phone: Americas: +1-972-444-6600 option 5, or International: +972-3-611-5100 option 5

2.

   ### Problem with EVAL license {#Scenario 4b}

   **Symptoms:**
   * "*Installation failed. Reason: Load on Module failed - failed to load security policy*" error during policy installation when DLP is enabled.
   * The *"fw -d fetchlocal -d $FWDIR/state/__tmp/FW1"* debug output shows:

     ```
     [PID]@...[DATE TIME] fw_dlp_config: failed to load dlp policy due to lack of valid license
     [PID]@...[DATE TIME] [fw_dlp_config] [End]
     [PID]@...[DATE TIME] fw_atomic_download: unlocking mutex: install_policy_mutex
     [PID]@...[DATE TIME] addCommitMsg: Adding warning message: 'DLP blade is enabled while no DLP license found.'
     [PID]@...[DATE TIME] fw_atomic_destroy: set FWHA_CUL_POLICY_STATE_FREEZE to: FWHA_CUL_POLICY_STATE_FREEZE_OFF
     [PID]@...[DATE TIME] [fw_atomic_download] [End]
     [PID]@...[DATE TIME] [fw_download] [End]
      Failed to Load Security Policy
     [PID]@...[DATE TIME] [filter_load] [End]
     [PID]@...[DATE TIME] fw_rfetchx_local_ex: failed to load Security Policy
     ```

   <br />

   Show / Hide the solution  
   **Cause:** An EVAL license has expired.
   **Solution:** Add a valid license.

(5) Problems whith additional symptoms when running fw fetch or fetching the policy under debug {#Section 5}
------------------------------------------------------------------------------------------------------------

1.

   ### "*Duplicate entries in table* " error when running the '*fw fetch*' command on the Security Gateway {#Scenario 5a}

   <br />

   Show / Hide the solution  
   **Cause:** A kernel table is added with duplicate entries that have the same key. This conflict in table entries usually involves identical IP addresses.

   **Solution:**

   If there is a chance that there are duplicate objects with identical IP address (i.e., the output of *fw fetch* shows the 'Duplicate entries in table' message), search the database for the objects that contain the duplicate IP address as follows:
   1. In SmartDashboard, select '*Search* ' - '*Query Network Object...* ' from the top menu.  

   2. From the '*Refine by* ' drop-down menu, select '*Duplicates* ', '*IP/interface mismatch* ' or '*Search by IP* '.  

      The objects are shown on the left side of the window.

   To resolve this duplicate entry conflict, do **one** of the following:
   * Delete one of the duplicate objects.  

   * Change the IP address in one of the duplicate objects.

2.

   ### "*Failed to find a dynamic interface on DAIP module* " error in the output of '*fw -d fetch \<Management IP address*\>' command on Security Gateway {#Scenario 5b}

   <br />

   Show / Hide the solution  
   **Cause:** When Security Gateway was installed, the option to configure as a Dynamically Assigned IP (DAIP) was selected.

   **Solution:**
   1. Disable the Dynamic Address Gateway (DAG) flag in the registry.

      * On Gaia / SecurePlatform / Linux Security Gateways:

        Edit the *$CPDIR/registry/HKLM_registry.data* file:

        *\[Expert@HostName:0\]# cp -v $CPDIR/registry/HKLM_registry.data $CPDIR/registry/HKLM_registry.data_ORIGINAL
        \[Expert@HostName:0\]# vi $CPDIR/registry/HKLM_registry.data*

        Search for "*DAG*".
        Change the value of this attribute from *1* to *0* :  
        from *:DAG ("\[4\]**1**")*
        to *:DAG ("\[4\]**0**")*
      * On Windows Security Gateways:  

        On the Security Gateway, go to Start menu - '*Run...* ' - type *regedit* - click on OK - edit the following registry key:  
        *HKEY_LOCAL_MACHINE\\SOFTWARE\\CheckPoint\\FW1\\5.0\\DAG*   

        Change the value of the REG_DWORD *DAG* key to "*0*"

      <br />

      <br />

   2. In SmartDashboard - open the Security Gateway object.  

   3. Go to '*General Properties* ' pane - uncheck the box "*Dynamic Address* ".  

   4. Go to '*Topology* ' pane - click the 'Get Topology' button to update the topology.  

   5. Configure Anti-Spoofing settings for each interface in the topology section.  

   6. Install the Security Policy.

3.

   ### Problem with empty *$FWDIR/conf/applications_entitlement.C* file {#Scenario 5c}

   **Symptoms:**
   * Output of the '*fw -d fetchlocal -d* ' command on the Security Gateway shows:   
     *{policy} \[ERROR\]: appi_cmi_handlers_common_check_entitlement: appi_decrypt_obj_from_file **failed for applications_entitlement.C***   
     *malware_handler_add_signatures_start_cb: appi_cmi_handlers_common_check_entitlement() failed*   
     *{module} \[ERROR\]: cmi_loader_update_apps: begin_update_cb failed for app MALWARE (2)*   
     *Failed to Load Security Policy: Illegal seek*
   * Policy installation fails with "*Load on Module failed - failed to load Security Policy*" error.

   <br />

   Show / Hide the solution  
   **Cause:** The *$FWDIR/conf/applications_entitlement.C* file is empty or corrupted.

   **Solution:**

   This problem was fixed. The fix is included in:
   * [Check Point R80](https://support.checkpoint.com/results/sk/sk108623)

   If you wish not to update, follow these steps:
   1. Transfer the *$FWDIR/conf/applications_entitlement.C* from the freshly installed environment with the same version.  
      **Note:** run the *dos2unix* command to convert format if you moved the file from Windows OS.  

   2. Run the *cpstop* command.  

   3. Copy the transferred *applications_entitlement.C* file to the *$FWDIR/conf/* directory.  

   4. Run the *cpstart* command.

   Check Point recommends to always upgrade to the most recent version ([upgrade Security Management Server](https://support.checkpoint.com/product/184) / [upgrade Multi-Domain Security Management Server](https://support.checkpoint.com/product/166)).

4.

   ### Problem with corrupted *$FWDIR/conf/fwc_handler_id_cache.conf* file {#Scenario 5d}

   **Symptoms:**
   * Fetching the policy under debug ('*fw -d fetchlocal*') shows:

     ```
     [DATE TIME] fw_read: read code 'local.ifs'
     [DATE TIME] fw_read_code: "/opt/CPsuite-R77/fw1/state/__tmp/FW1/local.fc", line X: Badly formed option line '% function: decimal_number protection_name decimal_number'
     [DATE TIME] fw_read: fw_read_code returned -1
     [DATE TIME] fw_read: read tables 'local.ifs'
     [DATE TIME] fw_read: unlocking mutex: install_policy_rename_files_mutex
     Cannot get Security Policy from local
     ```

   Show / Hide the solution  
   **Cause:** Corruption of the *$FWDIR/conf/fwc_handler_id_cache.conf* file on the Security Management server.

   **Solution:**
   1. Connect to command line on Security Management Server.
   2. Backup the current *$FWDIR/conf/fwc_handler_id_cache.conf* file.
   3. Restart the Check Point services: *\[Expert@HostName:0\]# cpstop ; cpstart*

5.

   ### Problem with corrupted *$FWDIR/conf/rad_services.C* file {#Scenario 5e}

   **Symptoms:**
   * Fetching the local policy on Security Gateway under debug (per [sk84700](http://supportcontent.checkpoint.com/solutions?id=sk84700)) shows:  
     *Failed to Load Security Policy: Invalid argument
     Fetching Security Policy Failed*
   * Kernel debug on Security Gateway during policy installation (per [sk84700](http://supportcontent.checkpoint.com/solutions?id=sk84700)) shows: "*Failed to Load Security Policy: Invalid argument*"
   * Kernel debug ('*fw ctl debug -m fw + cmi filter* ' ; '*fw ctl debug -m RAD_KERNEL + global* ' ; '*fw ctl debug -m cmi_loader + module* ') on Security Gateway during policy installation shows:

     ```
     {global} [ERROR]: rad_kernel_policy_get_draft_service_settings: service id <X> does not exist in database;
     {global} [ERROR]: rad_kernel_api_prepare_service: rad_kernel_policy_get_draft_service_settings failed;
     {module} [ERROR]: cmik_loader_load_prepare: load_begin_local_cb() failed, for app (<N>) <ZZZ>;
     fwk_cmi_prepare: cmik_loader_load_prepare failed, error.;
     fwk_atomic_load_prepare: fwk_cmi_prepare failed;
     ```

     The *$FWDIR/state/__tmp/FW1/local.rad_services* file on Security Gateway does not contain the Service IDs that appear in the above kernel debug (search for '`service_id`').
   * "Security Management Server / Multi-Domain Security Management Server is R77.20 / R77.30 (not R80.x).

   <br />

   Show / Hide this section  
   **Cause:**

   Corruption in the *$FWDIR/conf/rad_services.C* file on Security Management Server / Domain Management Server.

   **Solution:**

   Replace the *$FWDIR/conf/rad_services.C* file (*%FWDIR%\\conf\\rad_services.C* file on Windows) with the same file from a freshly installed Security Management server of the **same** version.

   Follow these steps:
   1. Install the same version of Security Management Server (even in VMWare).   

   2. Copy the *$FWDIR/conf/rad_services.C* file (*%FWDIR%\\conf\\rad_services.C* on Windows OS) from the new clean Security Management Server.   

   3. Backup the current corrupted *$FWDIR/conf/rad_services.C* file on production Security Management Server / Domain Management Server.   

   4. Replace the current corrupted *$FWDIR/conf/rad_services.C* file with the clean file copied from the new clean Security Management Server.   

   5. Clear the SmartConsole cache on production Security Management Server / Domain Management Server per [sk100507](http://supportcontent.checkpoint.com/solutions?id=sk100507).   

   6. Connect with SmartDashboard to Security Management Server / Domain Management Server.   

   7. Install the policy onto the relevant Security Gateway / Cluster object.

6.

   ### Problem with URL Regular Expression {#Scenario 5f}

   **Known Limitations:** PMTR-20044

   **Symptoms:**
   * Error when running the '*fw -d fetchlocal -d $FWDIR/state/__tmp/FW1* ' with '*export TDERROR_ALL_ALL=5*' command on Security Gateway:

     ```
     {module} [ERROR]: cmi_loader_serialize_contexts: Failed to gen PM for context 142, 
     error message: (unknown property name after \P or \p)  
     blade name : APPI_USER, pattern: [Regular Expression URL]
     ```

   <br />

   Show / Hide the solution  
   **Cause:** Newly created Application/Site contained URL Regular Expressions that were not recognized or had too many delimiters.

   **Solution:**
   Remove or adjust the newly created URL to comply with Regular Expressions. To do so:   

   1. In the SmartDashboard, go to Application \& URL Filtering -\> Applications/Sites  

   2. Removed the latest site that was added.   

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk33893/RegularExpression1703230707.png)

7.

   ### "Illegal sequence beginning with..." error on fetching the policy under debug {#Scenario 5g}

   **Symptoms:**
   * Error when running the '*fw -d fetchlocal -d $FWDIR/state/__tmp/FW1* ' with '*export TDERROR_ALL_ALL=5*' command on Security Gateway:

     ```
     {module} [ERROR]: cmi_loader_serialize_apps: cmi_loader_serialize_contexts failed
     {module} [ERROR]: cmi_loader_install_policy_ex: cmi_loader_serialize_apps failed
     {module} [ERROR]: cmi_loader_install_policy_ex: Policy installation failed. error is: Failed to gen PM for context 142, 
     error message: (Illegal sequence beginning with '{': '{' must be followed by a digit) blade name : APPI_USER, pattern: (N/A)
     [ PID]@GW[DATE TIME] fw_atomic_cmi_add: cmi_loader_install_policy failed.
     ....
     Failed to Load Security Policy: No such file or directory
     ```

   <br />

   Show / Hide the solution  
   **Cause:** Illegal signatures were defined on applications.

   **Solution:**
   Review Application control and URL filtering policy and categories and find URL recently edited. Can use SmartViewTracker for assistance.   
   Another Workaround is to roll back to a working state database revision.  

   Example for illegal entries:  
   *\^http://(www\\.)?facebook.com*   
   */http://google.com*   
   */http://google....com*

8.

   ### "bad dlpactivated value" error in the output of "fw fetchlocal" debug {#Scenario 5h}

   **Symptoms:**
   * "*bad dlpactivated value* " message in the output of "*fw fetchlocal* " debug (*# fw -d fetchlocal -d $FWDIR/state/__tmp/FW1* )

   <br />

   Show / Hide the solution  
   **Cause:** Registry corruption: the value of *DLPActivated* variable is not 0 or 1, but some other number.

   **Solution:**
   On the Security gateway:
   1. Backup the registry file *$CPDIR/registry/HKLM_registry.data*
   2. Edit the registry file with vi editor and change the value of*DLPActivated* variable to 0.
   3. Save the file.

(6) Other problems {#Section 6}
-------------------------------

1.

   ### Problem with Suspicious Activity Monitoring (SAM) {#Scenario 6a}

   **Symptoms:**
   * Policy installation debug on Security Gateway shows:   
     *fw_sam_recover_state: num of entries=X, strings length=-N
     fw_sam_recover_state: failed to allocate table buffer
     fw_sam_recover_state: failed to read \<number\> entries*

   * Output of '*fw -d fetchlocal -d $FWDIR/state/__tmp/FW1* ' command on Gateway shows:  
     *fw_atomic_download: FWATOMICLOAD failed: Invalid argument
     fw_atomic_download: unlocking mutex: install_policy_mutex
     Failed to Load Security Policy: Invalid argument
     fw_rfetchx_local_ex: failed to load Security Policy
     ......
     Failed to Load Security Policy: Invalid argument
     Fetching Security Policy Failed*

   * Same problem happens when "*Purge SAM file when it reaches \[\] KBytes*" option is enabled in the Security Gateway object and the size of SAM file exceeds the configured limit and gets purged.

   <br />

   Show / Hide the solution  
   **Cause:** The *$FWDIR/log/sam.dat* file either does not have correct permissions and owners, or became corrupted.

   **Solution:**

   This problem was fixed. The fix is included in:
   * [Check Point R80.10](https://support.checkpoint.com/results/sk/sk111841)

   For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
   A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
   For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

   Also, the following workaround is available:
   1. Connect to command line on Security Gateway (over SSH, or console) and log in to Expert mode.
   2. Stop Check Point services: *\[Expert@HostName:0\]# cpstop*

   3. Backup the current *$FWDIR/log/sam.dat* file.

   4. Make sure the *$FWDIR/log/sam.dat* file has correct permissions and owners:

      *\[Expert@HostName:0\]# ls -l $FWDIR/log/sam.dat*

      These are the correct permissions and owners of the file:

      *-rw-rw---- 1 admin root SIZE DATE TIME /opt/CPsuite-R*XX*/fw1/log/sam.dat*

      If the current permissions / owners differ from the required, then set the correct permissions and owners:
      *\[Expert@HostName:0\]# chmod -v u=rw,g=rw $FWDIR/log/sam.dat\< \[Expert@HostName:0\]# chown -v admin:root $FWDIR/log/sam.dat*
   5. Start Check Point services: *\[Expert@HostName:0\]# cpstart*

   6. Install the policy in SmartDashboard.

   If the issue persists, then:
   1. Stop Check Point services on Security Gateway: *\[Expert@HostName:0\]# cpstop*

   2. Delete the current *$FWDIR/log/sam.dat* file:

      *\[Expert@HostName:0\]# rm -i $FWDIR/log/sam.dat*
   3. Start Check Point services: *\[Expert@HostName:0\]# cpstart*

   4. Install the policy in SmartDashboard.

   Check Point recommends to always upgrade to the most recent version ([upgrade Security Management Server](https://support.checkpoint.com/product/184) / [upgrade Multi-Domain Security Management Server](https://support.checkpoint.com/product/166)).

2.

   ### Problem with Pattern Matcher cache {#Scenario 6b}

   **Symptoms:**
   * Kernel debug on Security Gateway ('*fw ctl debug -m fw + filter* ') during policy installation shows:  
     *;thin_nfa_add_transition: Transition \^\<SOME_URL\> -\> BNFA offset NNN - no such state (max XXX);
     ;thin_nfa_validation_scan_tree: Invalid fail state for state \^\<SOME_URL\>;
     ;kiss_thin_nfa_is_valid: Thin NFA YYY validation failed;
     ;kiss_pm_validate: Thin NFA handle is NOT valid;
     ;fwk_atomic_load_prepare: fwk_cmi_prepare failed;*

   <br />

   Show / Hide the solution  
   **Cause:** The *$FWDIR/conf/cache_pm_buffers.bin* file on Security Gateway became corrupted.

   **Solution:**
   1. Connect to command line on Security Gateway (over SSH, or console) and log in to Expert mode.
   2. Stop all Check Point services: *\[Expert@HostName:0\]# cpstop*

   3. Backup the current *$FWDIR/conf/cache_pm_buffers.bin* file*.*

   4. Delete the current *$FWDIR/conf/cache_pm_buffers.bin* file:

      *\[Expert@HostName:0\]# rm -i $FWDIR/conf/cache_pm_buffers.bin*
   5. Start all Check Point services: *\[Expert@HostName:0\]# cpstart*

   6. Install the policy in SmartDashboard.

3.

   ### Rule name contains non-ASCII characters {#Scenario 6c}

   **Known Limitations:** 01382864, 01382987, 01492899

   **Symptoms:**
   * *"\[FP_dbg\] IP_module_dg_handler: Failed to store policy in local storage* " in *$CPDIR/log/cpd.elg* file on the Security Gateway.

   * Kernel debug on Security Gateway (*fw ctl debug -m fw + filter* ) during policy installation shows:  
     *\[DATE TIME\];\[vs_4\];\[tid_1\];\[fw4_0\];fw_rules_uid_handle_uid(76, 1): uid string_id = 1642 name string_id = -1;*   
     *\[DATE TIME\];\[vs_4\];\[tid_1\];\[fw4_0\];fwloghandle_check_string: invalid char in string (ascii 10);*   
     *\[DATE TIME\];\[vs_4\];\[tid_1\];\[fw4_0\];fwloghandle_check_string: invalid char in string (ascii 10);*   
     *\[DATE TIME\];\[vs_4\];\[tid_1\];\[fw4_0\];fw_rules_uid_handle_uid: couldn't allocate dictionary string id for rule no. 76*

   * Fetching the policy under debug ('*fw -d fetch ...* ') shows:  
     *fw_atomic_download: FWATOMICLOAD failed: Bad address*

   * Policy installation debug on the Security Gateway shows:  
     *\[PID\]@Hostname\[DATE TIME\] get_cond_statedir : return state dir = /opt/CPsuite-R77/fw1/state/local/FW1 Failed to Load Security Policy: Bad address
     \[PID\]@Hostname\[DATE TIME\] ... \[fw_rfetchx_local_ex\] \[End\] Fetching Security Policy Failed*

   * Sometimes problem happens only if *fw_rules_uid_max_dic_entries* property is set to any value other than 0.

   Show / Hide the solution  
   **Cause:** Rule name or comment contains a non-ASCII characters, while non-ASCII characters with Extended UTF-8 encoding are not supported.

   **Solution:** Follow instructions in [sk105708](http://supportcontent.checkpoint.com/solutions?id=sk105708) to identify non-ASCII characters and remove them from the rulebase.

4.

   ### Output of '*fwm load -d* ' command contains '*error number 16*' {#Scenario 6d}

   **Symptoms in sub-Scenario 1:**
   * "*Failed to read local.magic* " error during policy installation failure:  

     ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk33893/localmagic1705240433.png)  

   * Output of '*fwm -d load \<policy\>.W \<Object Name\>* ' command contains:  

     *CPTA_SingleInstallCB - Policy installation failed for Security Gateway \<Name_of_Object\>
     CPTA_InstallFailReasonTranslate: **error number 16***   

   * Fetching the policy under debug ('*fw -d fetchlocal -d $FWDIR/state/__tmp/FW1* ') shows:  

     *fw_atomic_cmi_add_enhanced_sigs: **could not find attribute http_enhance_val**.*   
     *fw_atomic_cmi_add_enhanced_sigs: Error: **enhance value missing***   
     *fw_atomic_add_cmi_contexts: fw_attomic_cmi_add_enhanced_sigs() failed*   
     *fw_atomic_ips_cmi_add_signatures__cb: fw_atomic_add_cmi_contexts() failed*

   <br />

   Show / Hide the solution for sub-Scenario 1  
   **Solution:**

   Modify the *$FWDIR/conf/ips_enhance.C* file on the Security Management Server / Multi-Domain Server:
   1. On Multi-Domain server, switch to the context of the relevant Domain Management Server:

      *\[Expert@HostName:0\]# mdsenv \<Name of Domain Management Server\>*
   2. Backup and edit the current *$FWDIR/conf/ips_enhance.C* file with vi editor.

   3. Search for "***LSS*** " entry and remove the sections where the *LSS* parameter is empty.

      Example for an empty parameter:  
      *:LSS ()*   

      To remove the section:  
      * Locate the ":" on top of the section.
      * Press "d" followed by a "%"

      *Example*:

      ```
      : (enhc_obj_ISO 
          :AdminInfo ( 
            :ClassName (ips_signature) 
            :table (ips_signatures) 
          ) 
          :type (ips_signature) 
          :inspect_handler () 
          :signature_log (dylog_facebook_mask) 
          :definition ( 
            :AdminInfo ( 
              :ClassName (basic_signature_definition) 
            ) 
            :type (basic_signature_definition) 
            :contexts ( 
              : (ReferenceObject 
                :Name (HTTP_FILE_TYPE) 
                :Table (ips_contexts) 
              ) 
            ) 
            :advanced_rule ("M^AGI$C57DF0C3CF5C8F702F62D24B848D2DD")
            :pattern () 
            :LSS () 
            :compound_internal_index (0) 
            :http_enhance_val ("M^AGI$C46F4") 
            :threshold ( 
              :AdminInfo ( 
                :ClassName (ips_threshold) 
              ) 
              :condition_type (threshold) 
              :count (0) 
              :time (0) 
              :track_by (src) 
              :type (ips_threshold) 
            ) 
          ) 
          )
      ```

      You need to locate the "*: (enhc_obj_ISO* " line.  

   4. Perform the above steps for all occurrence of empty LSS section  

   5. Save the file and install the Security policy.

   If rulebase is not modified, you need to do the same procedure for compiled policy on each Security Gateway located in *$FWDIR/state/\<Name_of_Security_Gateway_Object\>/FW1/local.ips_enhance*   
   1. Backup the *$FWDIR/database/ips_enhance.C* file on Security Gateway:  

      *# mv -v $FWDIR/database/ips_enhance.C $FWDIR/database/ips_enhance.C_orig
      # mv -v $FWDIR/state/local/FW1/local.ips_enhance $FWDIR/state/local/FW1/local.ips_enhance_orig*   

   2. Install policy on the Security Gateway

   <br />

   If this is done, then run *cpstop* command. Then, when you run *cpstart* command, Security Gateway will come back without any policy including initial.

   **Symptoms in sub-Scenario 2:**
   * Output of*fwm load* debug *(fwm -d load \<policy\>.W \<Object Name\>* ) shows:  

     *\[FW_LOADER PID ...\] CPTA_SingleInstallCB - Policy installation failed for Security Gateway*   
     *\[FW_LOADER PID ...\] CPTA_InstallFailReasonTranslate: **error number 16***   
     *Security Gateway policy installation failed for Security Gateway \<Name_of_Object\>*   
     *Installation failed. Reason: Load on Module failed - failed to load Security Policy.*   
     *\[FW_LOADER PID ...\] CPTA_InstallFailReasonTranslate: **error number 2508***   

   * Fetching the policy under debug ('*fw -d fetchlocal -d $FWDIR/state/__tmp/FW1* ') shows:  

     *fw_sam_recover_state: failed to get kernel action*

   <br />

   Show / Hide the solution for sub-Scenario 2  
   **Solution:** delete the *$FWDIR/log/sam.dat* file and restart the Check Point services by running *cpstop;cpstart* commands.  
   A new copy of *$FWDIR/log/sam.dat* will be created.

   **Symptoms in sub-Scenario 3:**
   * Output of '*fwm -d load ...* ' command shows:  

     *\[FW_LOADER PID ...\] CPTA_SingleInstallCB - Policy installation failed for Security Gateway*   
     *\[FW_LOADER PID ...\] CPTA_InstallFailReasonTranslate: **error number 16***   
     *Security Gateway policy installation failed for Security Gateway \<Name_of_Object\>*   
     *Installation failed. Reason: Load on Module failed - failed to load Security Policy.*   
     *\[FW_LOADER PID ...\] CPTA_InstallFailReasonTranslate: **error number 2508***   

   * Output of '*grep -e vmalloc /var/log/messages* ' command shows:  

     *kernel: allocation failed: out of vmalloc space - use vmalloc=\<size\> to increase size.*

   <br />

   Show / Hide the solution for sub-Scenario 3  
   **Solution:** Increase the *vmalloc* allocated memory per [sk90044](https://support.checkpoint.com/results/sk/sk90044), or switch to 64-bit OS mode.

5.

   ### Problem with CIFS {#Scenario 6e}

   **Known Limitation:** 00574625

   **Symptoms:**
   * Policy installation fails with error "*Load on Module Failed - failed to load security policy*" when complex CIFS resource is used.

   * The following messages are found in *fwm.elg* :
   * Error opening file ...databaseauthkeys.C:: The system cannot find the file specified
   * createInternalNetworkRangesTables: Error reading 'internal_network' attribute on 'all'
   * CPTA_InstallFailReasonTranslate: error number 16 Ip = ... Security Gateway policy installation completed with errors
   * Kernel debug during policy install on the Security Gateway shows:
   * kiss_rem_compile: kiss_nfa2dfa returned NULL;;
   * kiss_pm_compile_rem: failed to copmile rem. pattern id: 0;;
   * kiss_pm_destroy: No more holders of PM handle b1eb70dc, destroying it;;
   * fwk_kbufs_prepare: kiss_pm_compile failed
   * "*fw_atomic_cp: config param name asm_cifs_inspect_ntlm_ess_msgs_mon_only too long (39)* " message in *$CPDIR/log/cpd.elg* file on Security Gateway.

   * "*fw_atomic_cp: config param name asm_dynamic_prop_AMSN20100507_04 too long (32)*" error in the debug output.

   <br />

   Show / Hide the solution  
   **Cause:**

   When a policy with a CIFS resource is installed, Security Gateway creates a DFA (a data structure used for Pattern Matching) for every such resource regardless of it's attachment to policy rules. The issue occurs when the CIFS resource is too complex, which causes the DFA to break the predefined memory limit (4 MB). Meaning the DFA is not created, and policy installation fails.

   **Solution:**

   Perform one of the below solutions:
   1. Run a manual IPS update.  

   2. Break the problematic CIFS resource. Note that if any rule needs all the resource entries, it means cloning all those rules (one resource per rule limitation).  

   3. Perform:  

      1. Close all SmartDashboard clients.  

      2. Connect to Security Management Server with GuiDBEdit (refer to [sk13009](http://supportcontent.checkpoint.com/solutions?id=sk13009)) and search for these strings:   

         "*asm_cifs_inspect_ntlm_ess_msgs_fix* " and "*asm_cifs_inspect_ntlm_ess_msgs_mon_only* "   

         These strings will be objects of type "owned object"  

      3. Right-click the field name in the lower panel, and select "Delete".  

      4. Save changes and exit GuiDBEdit.  

      5. Log in via SmartDashboard Policy - 'Policy' menu - 'Install Database...'  

      6. Install Security Policy.

      <br />

      <br />

   4. Set the value of*kiss_dfa_small_block_size* kernel parameter to 0 (zero), then the Pattern Matcher will not use small blocks.  
      For permanently changing the kernel global parameters on all platforms, refer to [sk26202](https://support.checkpoint.com/results/sk/sk26202).  

   5. Perform the IPS Clean - reset the DataBase to "silent" files.  
      **Note:** this procedure erases your IPS DB and sets you up with a clean environment, so it should be used as a last resort only. [Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) for assistance.

   This scenario replaces sk103860, sk62340, sk60440 and sk65058.

6.

   ### Problem with kernel table '*spii_multi_pset2kbuf_map*' {#Scenario 6f}

   **Known Limitation:** 01647112

   **Symptoms:**
   * Loading the policy from Security Management Server to Security Gateway under debug ('*fwm -d load ...*') fails with:

     *\[FW_LOADER PID ...\]@MGMT_HOSTNAME\[Date Time\] CPTA_SingleInstallCB - Policy installation failed for Security Gateway \<Name_of_Object\>
     \[FW_LOADER PID ...\]@MGMT_HOSTNAME\[Date Time\] CPTA_InstallFailReasonTranslate: error number 16
     Security Gateway policy installation failed for Security Gateway \<Name_of_Object\>
     Installation failed. Reason: Load on Module failed - failed to load Security Policy.
     \[FW_LOADER PID ...\]@MGMT_HOSTNAME\[Date Time\] CPTA_InstallFailReasonTranslate: error number 2508*
   * Kernel debug Security Gateway ('*fw ctl debug -m fw + filter kbuf spii*') during policy installation shows:

     ;*fwk_kbufs_prepare: Entering: nkbufs = XXX, spii objects = XXX, spii global objects = XXX;
     ...
     ;fwk_kbufs_prepare: **ld_create_uncommited failed for table spii_multi_pset2kbuf_map during policy installation!;**
     ;fwk_atomic_load_prepare: fwk_kbufs_prepare failed;*

   Show / Hide the solution  
   **Cause:**

   The number of signatures in the IPS package has reached a hardcoded limit. The internal mapping of IPS protections fails due to the kernel table "*spii_multi_pset2kbuf_map*" getting full. As a result, the entire policy installation fails.

   **Solution:**

   This problem was fixed. The fix is included in (follow the "**Hotfix configuration instructions**" section):
   * [Jumbo Hotfix Accumulator for R77.30](http://supportcontent.checkpoint.com/solutions?id=sk106162) - from *Take_84*
   * [Jumbo Hotfix Accumulator for R77.20](http://supportcontent.checkpoint.com/solutions?id=sk101975) - from *Take_191*
   * [Jumbo Hotfix Accumulator for R77.10](http://supportcontent.checkpoint.com/solutions?id=sk98285) - from *Take_180*

   **Code was improved:** The size of the kernel table "*spii_multi_pset2kbuf_map*" can now be increased from 25000 to 50000 entries.

   If this issue continues:
   > 1. On the Security Gateway / each Cluster Member, install the [R77.30 Jumbo Hotfix Accumulator](https://support.checkpoint.com/results/sk/sk106162), Take 338 (or higher) and reboot.
   > 2. Connect to the command line on the Security Gateway / each Cluster Member.
   > 3. If your default shell is Gaia Clish, then go to the Expert mode:  
   >    `expert`
   > 4. Back up the current file (this file may not exist by default):  
   >    `cp -v $FWDIR/boot/modules/fwkern.conf{,_BKP}`
   > 5. Edit the current file (if this file does not exist, this command will create it):  
   >    `vi $FWDIR/boot/modules/fwkern.conf`
   > 6. Add this line:  
   >    `spii_multi_pset2kbuf_map_tab_limit=100000`
   > 7. Save the changes in the file and exit Vi editor.
   > 8. Reboot the Security Gateway / each Cluster Member.
   > 9. In SmartConsole, install the Threat Prevention policy again.

7.

   ### Problem with corrupted *$FWDIR/conf/file_types.C* file {#Scenario 6g}

   **Symptoms:**
   * With Threat Prevention blade enabled, policy installation fails with "*policy creation failed (message from member)* " and "*Installation failed. Reason: Load on Module failed - failed to load Security Policy (message from member)*" errors.

   * Threat Prevention policy installation fails with error "*Installation failed. Reason: Load on Module failed*" when selecting "Process specific file types families" option in Anti-Virus setting.

   * Fetching policy under debug (*fw -d fetchlocal*') shows:

     *\[PID ...\[DATE TIME\] cl_gw_malware_preload: done
     \[PID ...\[DATE TIME\] configload_download: fwioctl:CONFIG_PRELOAD_GETPOLICY
     \[PID ...\[DATE TIME\] \[fwioctl: CONFIGLOAD_ATOMIC\] \[Start\] Installing Threat Prevention policy from local configload_download: fwioctl: CONFIGLOAD_ATOMIC failed (IPv4 kernel)
     \[PID ...\[DATE TIME\] configload_download: done. failed
     \[PID ...\[DATE TIME\] \[configload_download\] \[End\]
     \[PID ...\[DATE TIME\] malware_load: configload_download() failed policy creation failed*
   * Kernel debug shows:

     *;DATE TIME;... parse: \[SFT_ERROR\] id is not digit;
     ;DATE TIME;... sft_db_loader_load_from_buf: \[SFT_ERROR\] parse() failed, index 3680;
     ;DATE TIME;... sft_mgr_init: \[SFT_ERROR\] sft_db_loader_load_from_buf() failed;
     ;DATE TIME;... sft_mgr_new: \[SFT_ERROR\] sft_mgr_init() failed;
     ;DATE TIME;... \[VSID: 00000\] ci_policy_settings_av_init: \[ERROR\]: sft_mgr_new() failed;
     ;DATE TIME;...{policy} \[VSID: 00000\] ci_policy_settings_av_new: \[ERROR\]: ci_policy_settings_av_init() failed;
     ;DATE TIME;...{policy} \[VSID: 00000\] ci_policy_settings_av_destroy: free s_ci_policy_data_av_settings ptr;
     ;DATE TIME;...{policy} \[VSID: 00000\] ci_policy_data_set_
     params: \[ERROR\]: failed to create feature 0;
     ;DATE TIME;...{policy} \[VSID: 00000\] ci_policy_settings_av_destroy: \[ERROR\]: _policy_data-\>policy_data_av_settings is NULL;
     ;DATE TIME;...{policy} \[VSID: 00000\] ci_policy_data_create: \[FATAL ERROR\]: ci_policy_data_set_params() failed;*
   * The *$FWDIR/log/cpd.elg* file shows:   
     *policy creation failed
     Fetching Threat Prevention policy failed*

   <br />

   Show / Hide the solution  
   **Cause:**

   The *$FWDIR/conf/file_types.C* file is corrupted.   
   If the problem started only after deleting a file type in Anti-Virus, then perhaps it was not deleted completely from the database.

   **Solution:**

   To replace the *$FWDIR/conf/file_types.C*file, run the following commands:
   * On Security Management Server:

     1. *\[Expert@HostName:0\]# cpstop*
     2. *\[Expert@HostName:0\]# mv -v CPMIL\* /var/tmp/*
     3. *\[Expert@HostName:0\]# cp -v $FWDIR/conf/file_types.C $FWDIR/conf/file_types.C_ORIGINAL*
     4. *\[Expert@HostName:0\]# cp -v $FWDIR/conf/defaultDatabase/file_types.C $FWDIR/conf/file_types.C*
     5. *\[Expert@HostName:0\]# dos2unix $FWDIR/conf/file_types.C*
     6. *\[Expert@HostName:0\]# cpstart*
   * On Multi-Domain Management Server:

     1. *\[Expert@HostName:0\]# mdsstop_customer \<Name of Domain Management Server\>*
     2. *\[Expert@HostName:0\]# mdsenv \<Name of Domain Management Server\>*
     3. *\[Expert@HostName:0\]# mkdir $FWDIR/conf/cma_cache*
     4. *\[Expert@HostName:0\]# mv -v CPMIL\* $FWDIR/conf/cma_cache/*
     5. *\[Expert@HostName:0\]# cp -v $FWDIR/conf/file_types.C $FWDIR/conf/file_types.C_ORIGINAL*
     6. *\[Expert@HostName:0\]# cp -v /var/opt/CPsuite-R77/fw1/conf/file_types.C $FWDIR/conf/file_types.C*
     7. *\[Expert@HostName:0\]# dos2unix $FWDIR/conf/file_types.C*
     8. *\[Expert@HostName:0\]# mdsstart_customer \<Name of Domain Management Server\>*

   <br />

   To completely delete the file type entry from *file_type* database:   

   1. Identify the Threat Prevention Profile for which policy installation is getting failed.  

   2. Find out the "*file_type_id* " which was configured for the file type.  

   3. Close all SmartConsole windows.  

   4. Connect to Security Management Server / Domain Management Server with [GuiDBedit Tool](https://support.checkpoint.com/results/sk/sk13009).  

   5. In the left upper pane, go to *Table -\> Other -\> am_profiles* .  

   6. In the right upper pane, there are all defined Anti-Virus profiles. Edit the profile, which enforced the file type.  

   7. While the relevant profile is highlighted in the right upper pane, press CTRL+F (or go to *Search menu -\> Find* -\> select the box only "value" in "Search in"). Paste the *file_types_id* - click on 'Find Next':  

   8. Delete the "*file_types_action* " created for the file type.  

   9. Save the changes: go to *File menu -\> Save All.*   

   10. Close the GuiDBedit Tool.  

   11. Connect to Security Management Server / Domain Management Server with SmartDashboard.  

   12. Install the Threat Prevention policy.

8.

   ### Problem with long IPS Profiles names after IPS update {#Scenario 6h}

   **Known Limitation:** 01479586 , 01494626

   **Symptoms:**
   * Kernel debug on Security Gateway ('*fw ctl debug -m fw + cmi dynlog* ') during policy installation shows:  
     *fwdynlog_prepare: failed translating alert param...* *fwk_atomic_load_prepare: fwdynlog_prepare failed;*

   <br />

   Show / Hide the solution  
   **Solution:**

   This problem was fixed. The fix is included in:
   * [Check Point R77.30](https://support.checkpoint.com/results/sk/sk104859)

   Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://support.checkpoint.com/product/435) / [upgrade Cluster](https://support.checkpoint.com/product/428) / [upgrade VSX](https://support.checkpoint.com/product/359) / [upgrade Security Management Server](https://support.checkpoint.com/product/184) / [upgrade Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [upgrade SmartConsole](https://support.checkpoint.com/product/191)).

   As an *immediate workaround*, limit the length of IPS Profiles names to a maximum of 40 characters:
   1. In SmartDashboard, go to *IPS* tab.
   2. In the upper left pane, click on *Profiles*.
   3. Double-click on the profile to open it.
   4. On *General* pane, refer to *Profile Name* field.
   5. Make sure that the Profile Name is shorter than 40 characters.
   6. Click on OK.
   7. Install policy.

9.

   ### Problem with Smart-1 appliance that manages multiple Virtual Systems {#Scenario 6i}

   **Symptoms:**
   * Fetching policy under debug on VSX Gateway in the context of a Virtual System shows:  
     `[Expert@`*VSX_HostName* `:0]# vsenv <VSID>`  
     ` [Expert@`*VSX_HostName* `:<VSID>]# fw -d fetch localhost `  
     ` ... ...`  
     ` [ `*PID*` ...]@`*VSX_HostName* `[`*Date Time* `] fw_read: read code 'local.ifs'`  
     ` fw_read_code: "/opt/CPsuite-R77/fw1/CTX/CTX00...<VSID>/state/__tmp/FW1/local.fc", line `*N* `: Illegal opcode`  
     ` [ `*PID*` ...]@`*VSX_HostName* `[`*Date Time* `] fw_read: fw_read_code returned -1`  
     ` [ `*PID*` ...]@`*VSX_HostName* `[`*Date Time* `] fw_read: read tables 'local.ifs'`  
     ` [ `*PID*` ...]@`*VSX_HostName* `[`*Date Time* `] fw_read: tables read successfully`  
     ` [ `*PID*` ...]@`*VSX_HostName* `[`*Date Time* `] fw_read: unlocking mutex: install_policy_rename_files_mutex `  

     ` Cannot get Security Policy from local`  
     ` [ `*PID*` ...]@`*VSX_HostName* `[`*Date Time* `] [`*Time* `] [filter_load] [End]`  
     ` [ `*PID*` ...]@`*VSX_HostName* `[`*Date Time* `] fw_rfetchx_local_ex: failed to load Security Policy`  

   Show / Hide the solution  
   **Cause:** Smart-1 appliances are able to manage a limited number of Security Gateways / Virtual Systems (refer to [Smart-1 datasheet](http://www.checkpoint.com/products/downloads/datasheets/Smart-1_SecurityManagement_datasheet.pdf)):

   |--------------------------------------|-----|-----|-----|------|------|
   |                                      | Smart-1 model             |||||
   |                                      | 205 | 210 | 225 | 3050 | 3150 |
   | Supported Number of Managed Gateways | 5   | 10  | 25  | 50   | 150+ |

   **Solution:**

   On Security Management Server / Multi-Domain Security Management Server running on Smart-1 appliance, make sure that the number of managed Virtual Systems does not exceed the supported number of managed gateways.

   Alternatively, use Open Server for Security Management Server / Multi-Domain Security Management Server.

10.

    ### Problem with identical ports used by load balancers in AWS / Azure {#Scenario 6j}

    **Symptoms:**
    * "*Installation failed. Reason: Load on Module failed - failed to load security policy*" error during policy installation on vSEC Gateway for Azure / vSEC Gateway for AWS.

    * *$FWDIR/log/autoprovision.elg* file on the vSEC Controller (Security Management Server) shows:

      ` gateways (after): `  

      ` [{"anti-spoofing": true, "ipv4-address": "X.X.X.X", "topology": "external", "name": "eth0", "ipv4-mask-length": 25}] dev-template {"xxxx.us-east-1.elb.amazonaws.com": {"HTTP-<`**Number_of_Port** `>": `  

      ` gateways (before): `  

      ` [{"anti-spoofing": true, "ipv4-address": "X.X.X.X", "topology": "external", "name": "eth0", "ipv4-mask-length": 25}] dev-template {"x-x-x-x.x.elb.amazonaws.com": {"HTTP-<`**Number_of_Port** `>": `  

      ` updating: <`**Name_of_vSEC_Gateway_object** `> `  

      ` configuration was not complete `  

      ` setting autoprovision restrictive policy name "__monitor__-restrictive-policy" on gw. Traceback (most recent call last): MONITOR INFO File "/opt/CPsuite-R80/fw1/scripts/autoprovision/monitor.py", line 2293, in sync management.set_gateway(instances[name], gw) File "/opt/CPsuite-R80/fw1/scripts/autoprovision/monitor.py", line 2125, in set_gateway self.set_restrictive_policy(gw, restrictive_policy) File "/opt/CPsuite-R80/fw1/scripts/autoprovision/monitor.py", line 2215, in set_restrictive_policy 'targets': gw['name']}) File "/opt/CPsuite-R80/fw1/scripts/autoprovision/monitor.py", line 1323, in __call__ '%s: %s :\n%s' % (command, status, details)) Exception: install-policy: failed :err: Installation failed. Reason: Load on Module failed - failed to load Security Policy. `

    Show / Hide the solution  
    **Cause:** Multiple load balancers are using identical ports.

    **Solution:**
    Make sure that each internal/external load balancer pair has a unique port when managed by the same vSEC Controller.

11.

    ### Problem with VSX Gateway / Cluster that has a corrupted database. {#Scenario 6k}

    **Symptoms:**
    * "*Installation failed. Reason: Load on Module failed - failed to load security policy*" error during policy installation on VSX Gateway / Cluster.

    * The following errors can be seen in fwm_load debug (according to [sk86186](https://support.checkpoint.com/results/sk/sk86186)):  

      ` "/opt/CPmds-R80.20/customers/<CMA/MGMT>/CPsuite-R80.20/fw1/conf/<policy_name>.pf", line 218: ERROR: syntax error&CURRENTVERCMP`  
      ` "/opt/CPmds-R80.20/customers/<CMA/MGMT>/CPsuite-R80.20/fw1/conf/<policy_name>.pf", line 219: ERROR: syntax error&CURRENTVERCMP`  
      ` Compilation Failed.&CURRENTVERCMP`  
      ` Error compiling IPv6 flavor.&CURRENTVERCMP`  
      ` **##MSG_IDENTIFY##** Compilation failed. <NULL > CURRENTVERCMP`  
      ` **##PERF_MSG_IDENTIFY##** {"duration_data":[{"duration":0.3569177890001913,"name":"duration_of_code_generation#<cluster_name>"},`  
      ` {"duration":0.0,"name":"duration_of_policy_compilation#FWVPN3-002"}]}&CURRENTVERCMP`  
      ` Operation ended with errors.&CURRENTVERCMP`  
      ` **##MSG_IDENTIFY##** Operation ended with errors.< NULL >< NULL > CURRENTVERCMP`

    * In the file cpm.elg similar logs are seen:  
      :` [DATE TIME] INFO com.checkpoint.management.dleserver.utils.LogSaverForFailedTasks.buildScriptCommand:53 [unboundedTaskExecutor-2]: title before abbreviate and replace: Policy installation - FW_VSX_Clusters_MGMT_Traffic_Installation failed on <VSX_gateway_member_name>`  
      ` [DATE TIME] INFO com.checkpoint.management.dleserver.utils.LogSaverForFailedTasks.buildScriptCommand:25 [unboundedTaskExecutor-2]: title after abbreviate and replace: Policy_installation___FW_VSX_Clusters_MGMT_Traffic_Installation_failed_on_<VSX_gateway_member_name>`  
      ` [DATE TIME] INFO com.checkpoint.management.dleserver.utils.LogSaverForFailedTasks.buildScriptCommand:32 [unboundedTaskExecutor-2]: failed task logs will be saved to $MDS_FWDIR/log/failed_tasks/Policy_Installation`  
      ` [DATE TIME] INFO com.checkpoint.management.dleserver.utils.LogSaverForFailedTasks.runCopyScript:16 [unboundedTaskExecutor-2]: running command: $MDS_FWDIR/scripts/save_logs_when_task_fails.sh 10 Policy_installation___FW_VSX_Clusters_MGMT_Traffic_Installation_failed_on_<VSX_gateway_member_name> true CP_FW_MGMT_PRI Policy_Installation`  
      ` Running command: [$MDS_FWDIR/scripts/save_logs_when_task_fails.sh 10 Policy_installation___FW_VSX_Clusters_MGMT_Traffic_Installation_failed_on_<VSX_gateway_member_name> true CP_FW_MGMT_PRI Policy_Installation]`

    * In the file fwm.elg similsr logs are seen:  
      :` : (SP4`  
      ` :CurrentMSP (9)`  
      ` : (MSUNIFIED_DOWNLOAD_ERROR_MESSAGE"`  
      ` Login failed: 10.99.x.x is not allowed for remote login`  
      ` [DATE TIME] : reject client IP=10.99.x.x,CN=Gui_Client`  
      ` [FWM PID]@[MDS_NAME][DATE TIME] Time consuming warning: WS command [cp_service] took 5 sec`  
      ` [FWM PID]@[MDS_NAME][DATE TIME] Warning:cp_timed_blocker_handler: A handler [0xf4d37b50] blocked for 5 seconds.`  
      ` [FWM PID]@[MDS_NAME][DATE TIME] Warning:cp_timed_blocker_handler: Handler info: Library [/opt/CPshrd-R80.20/lib/libgsasync.so], Function offset [0x3b50].`  
      ` [FWM PID]@[MDS_NAME][DATE TIME] Warning:cp_timed_blocker_handler: A handler [0xf3ac0ff0] blocked for 5 seconds.`  
      ` [FWM PID]@[MDS_NAME][DATE TIME] Warning:cp_timed_blocker_handler: Handler info: Library [/opt/CPshrd-R80.20/lib/libComUtils.so], Function offset [0x11ff0].`  
      ` 2019.11.05_02:54:03 - FWM mainloop wasn't available for 6 seconds. This may cause UI / Server slow down`  
      ` check_caller_thread_safe: [WARNING] Non thread safe action: Mainloop thread id = 4013325056 while current thread id = 3866839872 (LWP 75299) `

    Show / Hide the solution  
    **Cause:**   

    Bad parameter under (vsls_parameters ) of \<cluster_name\>

    A conflicting detail in the VSID records caused the issue - customer at some point assigned the original VS VSID 'X' with VSID 0.

    **Solution:**
    Please [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to correct the issue using a remote access session.

(7) Old issues {#Section 7}
---------------------------

1.

   ### Problem with SmartView Monitor {#Scenario 7a}

   **Symptoms:**
   * "*Installation failed. Reason: Load on module failed, failed to load security policy*" error in SmartDashboard during policy installation.

   <br />

   Show / Hide the solution  
   **Cause:** SmartView Monitor product was not enabled in the Security Gateway's object. Policy verification looks for this 'SmartView Monitor' entry.

   **Solution:**

   Select 'SmartView Monitor' product on the Products page in Security Gateway's object, and install the policy.

2.

   ### Problem in VSX environment when running the 'vsx_util add_member' command {#Scenario 7b}

   **Symptoms:**
   * In VSX, user is not asked about Sync interface IP address for the new member when running the '*vsx_util add_member* ' command after the '*vsx_util upgrade*' command on the Security Management Server.

   <br />

   Show / Hide the solution  
   **Solution:**

   Before implementing the below solution, verify that the Security policy installation indeed fails because of the duplicate entry in the *cluster_members_ids_by_ips* kernel table.

   To do so, run the '*fw fetchlocal -d $FWDIR/state/__tmp/FW1* ' command and verify you get the "*Load on Module failed - failed to load Security Policy*" error message.

   Also verify in GuiDBedit Tool ([sk13009](http://supportcontent.checkpoint.com/solutions?id=sk13009)) that the Sync IP address of the new VSX member object from the "interfaces" section of the *network_objects* table is identical to Sync IP addresses of other members.

   Procedure:
   1. Connect to command line on Security Management Server and log in to Expert mode.  

   2. Run the *vsx_util remove_member* command to remove the newly added member.  

   3. Install the NGX R65 HFA_30 or above on the SmartCenter Server.  

   4. Run the *vsx_util add_member* command.  

   5. Run the *vsx_util add_member_reconf* command.

   **Note:** Always use the first hop interface from the Security Management Server as your "management interface" and never attempt to route through the VSX Gateway for SIC, nor policy install.

3.

   ### Problem with IPS Profiles other than the 'Default_Profile' {#Scenario 7c}

   **Symptoms:**
   * "*Load on Module failed - failed to load Security Policy* " error when selecting IPS profiles other than the 'Default_Profile'.  

   * Error when running the '*fw fetchlocal -d* ' command on Security Gateway:  
     "*kiss_pcre_compile: pcre compile failed at offset 20 with error message: a numbered reference must not be zero. pattern:\^(Host\[\\x9 \]\*:\[\\x9 \]\*.\*\\gateway.messenger.hotmail.com\*)*"

   <br />

   Show / Hide the solution  
   **Cause:** Invalid pattern in one of the IPS protections (considered invalid from R75, see [sk36848](http://supportcontent.checkpoint.com/solutions?id=sk36848)).

   **Solution:**
   1. In SmartDashboard, go to *IPS* tab -\> expand *Protections* -\> expand *by Protocol* -\> expand *IPS Software Blade* -\> *Web Intelligence* .   
      Double-click on the *Header Rejection* protection.  

   2. On title HTTP Headers Definitions (applies to all profiles) - click *Edit* .  

   3. Look for application name: "*MSN Live Messenger* " - click *Edit* .  

   4. Change its value from "*\\gateway.messenger.hotmail.com* " to "*gateway.messenger.hotmail.com* "  

   5. Save the changes.  

   6. Install Security policy.

   If this does not help, then perform an IPS update to fix the all signatures.

4.

   ### Problem with *cmik_loader_sync_htab_table*kernel table {#Scenario 7d}

   **Known Limitation:** 01249021

   **Symptoms:**
   * Kernel debug during policy installation shows:

     *;FW-1: Attempting to create an already existing table: cmik_loader_sync_htab_table (7999);
     ;fwk_cmi_prepare: failed to create cmik_loader_sync_htab_table table.;
     ;fwk_atomic_load_prepare: fwk_cmi_prepare failed;*

   Show / Hide this section  
   **Solution:**

   This problem was fixed. The fix is included in:
   * [Check Point R76](https://support.checkpoint.com/results/sk/sk91140)

   Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://support.checkpoint.com/product/73) / [upgrade VSX](https://support.checkpoint.com/product/359) / [upgrade Security Management Server](https://support.checkpoint.com/product/184) / [upgrade Multi-Domain Security Management Server](https://support.checkpoint.com/product/166)).

5.

   ### Problem with Security Gateway R76 managed by Security Management Server R77.x {#Scenario 7e}

   **Known Limitation:** 01246785

   **Symptoms:**
   * "*Installation failed. Reason: Load on module failed, failed to load security policy*" error in SmartDashboard when installing policy from Security Management Server R77.x onto Security Gateways R76 and lower.
   * Debug '*fw ctl debug -m kiss + error* ' during policy installation shows:  
     *;kiss_htab_create_internal: reached the maximum number of tables;* *;fwk_mtcounter_prepare: Error could not create a ghtab.;*

   <br />

   Show / Hide this section  
   **Cause:**

   Number of allocated internal Hash Tables (htab) / Global Hash Tables (ghtab) in Check Point kernel on Security Gateway has exceeded the limit. Therefore, new Hash Tables can not be created, which is an integral part of policy installation. As a result, policy installation fails on Security Gateway.

   **Solution:**

   This problem was fixed. The fix is included in:
   * [Check Point R77.30](http://supportcontent.checkpoint.com/solutions?id=sk104859)

   Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://support.checkpoint.com/product/73) / [upgrade Security Management Server](https://support.checkpoint.com/product/184) / [upgrade Multi-Domain Security Management Server](https://support.checkpoint.com/product/166)).

   **Workaround:** Reboot the problematic Security Gateway / cluster member.

6.

   ### Problem with size of kernel table *string_dictionary_table* {#Scenario 7f}

   **Known Limitation:** 02465003

   **Symptoms:**
   * Kernel debug ('`fw ctl debug -m + filter`') on R76 VSX Gateway during the issue shows:

     ` ;[fw6_0];FW1: fwloghandle_register_string: unable to put entry into table.;`  
     ` ;[fw6_0];fw_rules_uid_handle_uid: `**couldn't allocate dictionary string id**` for rule no. XXX`  
     ` ;[fw6_0];fwk_atomic_load_prepare: fw_rules_uid_prepare failed;`
   * ***The solution for policy installation failure*** is to increase the size of the **`string_dictionary_table`** table per [sk66342](https://support.checkpoint.com/results/sk/sk66342) on VSX Gateway (or to clear it by running the "**`fw tab -t string_dictionary_table -x`** " command from the Expert mode).  
     But if after increasing the table size:

     * Output of the "`fw tab -t string_dictionary_table | grep limit`" command shows the new configured size.
     * Output of the "`fw6 tab -t string_dictionary_table | grep limit`" command still shows the original size.
   * Disabling the `rulebase_uid_in_log` option in *SmartDashboard - Global Properties* (per [sk66342](https://support.checkpoint.com/results/sk/sk66342)) resolves the issue - policy installation on R76 VSX Gateway succeeds.

   Show / Hide the solution  
   **Cause:** Kernel parameters defined in the *$FWDIR/boot/modules/fwkern.conf* file are not set correctly for FWv6 instances when IPv6 is enabled.

   **Solution:**

   This problem was fixed. The fix is included in:
   * [Check Point R77](https://support.checkpoint.com/results/sk/sk92965)

   Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://support.checkpoint.com/product/435) / [upgrade Cluster](https://support.checkpoint.com/product/428) / [upgrade Security Management Server](https://support.checkpoint.com/product/184) / [upgrade Multi-Domain Security Management Server](https://support.checkpoint.com/product/166)).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
