> Source: [sk98316](https://support.checkpoint.com/results/sk/sk98316)

# sk98316 - Traffic ignores specific policy rules when IPS automatic policy installation is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk98316 |
| Date Created | 2014-01-27 |
| Last Modified | 2017-12-31 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Windows, Gaia |

## Symptoms

- * With IPS automatic policy installation enabled, legitimate traffic is dropped.

* Kernel debug shows the following drops:  

  * `fw_handle_first_packet: Rulebase returned DROP;`
  `
  `
  * dropped by fw_handle_first_packet Reason: Rulebase drop - NO match;
  * fw_filter_chain: handle_first_packet returned action DROP for new conn;
  * fw_filter_chain: Final switch, action=DROP;
  * VM Final action=DROP;

  <br />

* # fw ctl zdebug + drop shows:
  dropped by fw_handle_first_packet Reason: Rulebase drop - NO match;

## Cause

This happens because of the combination of IPS automatic policy installation after successful update, and rule-base that is installed on multiple Security Gateways, with different rule-set of 'policy targets' in the 'Install On' field.

In this scenario, when policy targets in 'Install On' field are frequently changed, after IPS update policy will be installed only on the last target that was installed manually.

Example for the chain of events:

1. Gateway is **ASSIGNED** as a Policy Target

<br />

[![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1514675976266/Screenshot_31712301542.jpg)](https://skcenter.checkpoint.com/skcenter//SolutionsStatics/NEW_SK_NOID1514675976266/Screenshot_31712301542.jpg)  

2. IPS Scheduled Update is enabled and "On Successful update perform Install Policy" is selected.

<br />

[![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1514675976266/Screenshot_21712301543.jpg)](https://skcenter.checkpoint.com/skcenter//SolutionsStatics/NEW_SK_NOID1514675976266/Screenshot_21712301543.jpg)  

3. Gateway is **REMOVED** from Policy Target and Policy was never installed to the gateway, just saved.

<br />

[![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk122174/Screenshot_41712301547.jpg)](https://skcenter.checkpoint.com/skcenter//SolutionsStatics/sk122174/Screenshot_41712301547.jpg)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
