> Source: [sk110074](https://support.checkpoint.com/results/sk/sk110074)

# sk110074 - Virtual Systems are in "Unknown" state after reboot of VSX Cluster Member

| Property | Value |
|----------|-------|
| Solution ID | sk110074 |
| Date Created | 2016-02-11 |
| Last Modified | 2017-07-20 |
| Technical Level | Advanced |
| Products | Security Gateway, Hardware |
| Versions | R82.10, R82, R81.20, Not Version-Specific |
| OS | Gaia |
| Platform | 15000 |

## Symptoms

- * After reboot of VSX Cluster Member, output of "*cphaprob state*" command shows:

  * VSX Cluster Member is "Down"

  * The following failure for the context of the affected Virtual Systems:

    ```
    
    vsid <VSID>:
    ------
     Unable to open '/vs<ID>/dev/fw0': Connection refused
     Failed to query kernel for interface no. 0
    ```

* After reboot of VSX Cluster Member, output of "*vsx stat -v*" command shows the following state of the affected Virtual Systems::

  ```
  
   ID    | Type & Name         | Security Policy   | Installed at    | SIC Stat
  -------+---------------------+-------------------+-----------------+---------
  <VSID> | S MemberName-VsName | Unknown           | Unknown         | Unknown
  ```

* Restarting the affected Virtual System with "*$FWDIR/scripts/vs_start.bash \<VSID\>*" command resolves the issue - but only until the next reboot.

## Cause

VSX Cluster Member fails to load the local VSX configuration in the following scenario:

1. VSX Cluster is managed by Multi-Domain Security Management Server.
2. Global Objects for Primary and Backup Domain Management Servers were defined and used in the policy.

Chain of events:

1. By design, Cluster Member tries to pull the policy/configuration from the peer member and from the Security Management Server / Domain Management Server based on the IP addresses of the relevant objects in SmartDashboard.
2. Each connection between Check Point machines is based on SIC.
3. VSX Cluster Member is able to obtain the SIC Name of the peer VSX Cluster Member, but pulling of VSX configuration is not allowed from peer VSX Cluster Members.
4. VSX Cluster Member fails to obtain the SIC Name of its Primary and Backup Domain Management Servers because (by design) their Global Objects do not have such attribute (SIC Name). This fails the pulling of VSX configuration from the Management Server.
5. As a result, the entire fetch process fails.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
