sk180792 - "Requested policy X does not match currently installed policy Y on gateway Z" error after running install-policy from API
"Requested policy X does not match currently installed policy Y on gateway Z" error after running install-policy from API
Product Multi-Domain Security Management, Security Management
Version R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
Last Modified 2025-01-20
Symptoms
install-policyfrom API fails with " _Requested policy X does not match currently installed policy Y on gateway Z. To ignore this warning, set the 'ignore-warnings' flag to 'true'".
Cause
The API verifies if the requested policy matches the policy currently installed on the Security Gateway. If it does not, the installation fails with the above message.
Solution
This problem was fixed. The fix is included in:
- Check Point Quantum R82
Starting from R82, the default behavior is to verify if the requested policy matches the currently installed policy. - Jumbo Hotfix Accumulator for R81.20 starting from Take 14
- Jumbo Hotfix Accumulator for R81.10 starting from Take 110
- Jumbo Hotfix Accumulator for R81 starting from Take 87
- Jumbo Hotfix Accumulator for R80.40 starting from Take 198
Note - This verification is disabled by default in versions R80.40 - R81.20 to keep compatibility with 3rd party scripts and tools.
To enable this verification:
- For a one-time use:
[Expert@HostName]# $MDS_FWDIR/scripts/reload_env_vars.sh -e ENABLE_CHECK_POLICY_MISMATCH=1
- Permanently:
[Expert@HostName]# $MDS_FWDIR/scripts/override_server_settings.sh -e ENABLE_CHECK_POLICY_MISMATCH 1
To disable this verification:
- For a one-time use:
$MDS_FWDIR/scripts/reload_env_vars.sh -u ENABLE_CHECK_POLICY_MISMATCH
- Permanently:
Back up the current
$MDS_FWDIR/conf/cpmEnvVars.conffile :[Expert@HostName]# cp -v $MDS_FWDIR/conf/cpmEnvVars.conf{,_BKP}Edit the current
$MDS_FWDIR/conf/cpmEnvVars.conffile :[Expert@HostName]# vi $MDS_FWDIR/conf/cpmEnvVars.confRemove this line:
ENABLE_CHECK_POLICY_MISMATCH=1;export ENABLE_CHECK_POLICY_MISMATCHSave the changes in the file and exit the Vi editor.
If this verification is enabled, you can add ignore-warnings true to the install-policy API command to ignore it.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level General
Status Approved by TAC
Date Created 2023-03-28
Last Modified 2025-01-20