> Source: [sk162358](https://support.checkpoint.com/results/sk/sk162358)

# sk162358 - R80.30  cluster, with CCP Encryption enabled, managed by an R80.10 Security Management comes up in Active/Active state

| Property | Value |
|----------|-------|
| Solution ID | sk162358 |
| Date Created | 2019-09-10 |
| Last Modified | 2020-02-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * R80.30 cluster, with CCP Encryption enabled, comes up in Active/Active mode when the cluster is managed by an R80.10 Security Management
* CCP Encryption feature is **enabled** and CCP is sent and received on both cluster members.   
  CCP Encryption default configuration:  
  - On kernel 3.10 - the feature is **Enabled** by default  
  - On kernel 2.6 - the feature is **Disabled** by default
* cluster debug shows the following:  

  ```
  @;1490; 9Sep2019 17:19:46.634202;[vs_0];[tid_1];[fw4_1];fwha_load_ccp_enc_key: Sending CCP Encryption key trap;
  @;1490; 9Sep2019 17:19:46.634204;[vs_0];[tid_1];[fw4_1];fwha_change_ccp_enc_key: called by fwha_decrypt_fwhap_msg;
  @;1490; 9Sep2019 17:19:46.634205;[vs_0];[tid_1];[fw4_1];fwha_change_ccp_enc_key: CCP Encryption key was not loaded during policy installation;
  @;1490; 9Sep2019 17:19:46.634207;[vs_0];[tid_1];[fw4_1];FW-1: fwhamultik_event_add: changing multik value fwha_event_queue_tail.;
  @;1490; 9Sep2019 17:19:46.634211;[vs_0];[tid_1];[fw4_1];fwha_set_ccp_dec_key_status: member 1 decryption key changed to ;
  @;1490; 9Sep2019 17:19:46.634212;[vs_0];[tid_1];[fw4_1];fwha_set_ccp_dec_key_status: member 2 decryption key changed to ;
  @;1490; 9Sep2019 17:19:46.634213;[vs_0];[tid_1];[fw4_1];fwha_change_ccp_dec_key: CCP Encryption key was not loaded during policy installation;
  @;1490; 9Sep2019 17:19:46.634214;[vs_0];[tid_1];[fw4_1];fwha_decrypt_ccp_init: CCP Decryption key not configured for mem 2;
  @;1490; 9Sep2019 17:19:46.634215;[vs_0];[tid_1];[fw4_1];fwha_decrypt_ccp: Failed to initialize key for mem 2;
  @;1490; 9Sep2019 17:19:46.634216;[vs_0];[tid_1];[fw4_1];fwha_decrypt_fwhap_msg: failed to decrypt data;
  ```

## Cause

The cluster CCP Encryption feature is only supported on Security Management version R80.20 or higher.

Since R80.30 kernel 3.10 has the CCP encryption feature enabled by default - the issue will occur on kernel 3.10  
However, as R80.30 kernel 2.6 has CCP encryption feature disabled by default - the issue will not occur on kernel 2.6 (unless enabled by the administrator)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
