sk184194 - Policy installation on a Virtual System fails without an error message
Policy installation on a Virtual System fails without an error message
Product: VSX (Traditional)
Version: R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Platform: 23000 (EOL)
Last Modified: 2026-07-23
Symptoms
Policy installation on one Virtual System (VS) fails without a visible error message.
The
FW_FULLprocess unexpectedly exits and generates a core dump file during the policy installation.Note: The
FW_FULLcore dump file (fw_full.#pid#.core.gz) appears in the/var/log/dump/usermode/directory.The Watchdog process (
CPWD) automatically restarts theFW_FULLprocess.A spike in CPU usage (see the
var/log/messagesfile) occurs on the affected thread and core when theFW_FULLprocess unexpectedly exits.Repeated log messages refer to:
- Invalid table names
- Missing or inaccessible content security components
- Failures related to file access, port configuration, or policy retrieval
Example:
Invalid argument fwauthd_is_acapd_needed: malware_policy_get_is_anti_bot_blade() failed
is_urlf_ssl_enabled: advanced_uf_blade not-installed fwd_reload_event
Cause
A memory handling issue in the FW_FULL process caused the policy installation to fail.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 36
- Jumbo Hotfix Accumulator for R82 starting from Take 118
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.