> Source: [sk111884](https://support.checkpoint.com/results/sk/sk111884)

# sk111884 - After cluster failover, VPN traffic dropped with "vpn_inbound_tagging_ex Reason: failed to get msa for mspi;"

| Property | Value |
|----------|-------|
| Solution ID | sk111884 |
| Date Created | 2016-06-27 |
| Last Modified | 2017-04-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- Kernel debug ('`fw ctl debug -m fw + drop`') shows that after a cluster failover is triggered, the new Active member drops traffic:

* Drops the VPN traffic:  
  `dropped by vpn_inbound_tagging_ex Reason: failed to get msa for mspi;`
* Drops the Cluster Delta Sync traffic:  
  `0.0.0.0:8116 -> X.X.X.X:8116 dropped by fwkdrv_enqueue_packet_user_ex Reason: Instance is currently fully utilized;`

## Cause

Since the Delta Synchronization traffic between the cluster members was dropped, some of the VPN kernel tables were not fully synchronized from the Active member to the Standby member. Therefore, upon a failover, the new Active member drops the VPN traffic, as a result of not getting the relevant "meta" SA values.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
