sk183697 - Import of a Large Policy Package Fails with Validation and API Errors in the Multi-Domain Server

Import of a Large Policy Package Fails with Validation and API Errors in the Multi-Domain Server

Product: Multi-Domain Security Management
Version: R81.20, R82
OS: Gaia
Platform: 6000, Open Server
Last Modified: 2026-02-18

Symptoms

  More than one object named ... exists.

Cause

The issue is caused by a combination of:

When the import script encounters pre-existing objects in the target Domain (such as hosts), it attempts to skip them, using the --skip-duplicate-objects true parameter. However, the API still performs strict validation and returns blocking errors for duplicate objects. This results in incomplete rule definitions (for example, destination field set to None) and leaves the policy package in a corrupt state.

Additionally, the high volume of API calls during import causes the API to become unresponsive, resulting in 502 Proxy Errors and further operational failures in the Domain Management Server.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

After you install the Hotfix, do these actions:

  1. Backup the Multi-Domain Server and affected Domains.

  2. Run this script to remove all validation errors from the affected Domain (Note - this step is only necessary if there are many validation errors due to a failed import):

    # ./deleteValidationIncidents_noSolr.sh
    
  3. Restart the Multi-Domain Server services. Run:

    # mdsstop;mdsstart
    
  4. Set this environment variable to allow the import script to handle duplicate objects more gracefully:

    # export ACCESS_RULE_IGNORE_CASE_SENSITIVITY=1
    
  5. Re-run the import script with the --skip-duplicate-objects true parameter.

  6. Verify import success and make sure that the policy package is usable without further validation or API errors.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-07-24
Last Modified: 2026-02-18