> Source: [sk171545](https://support.checkpoint.com/results/sk/sk171545)

# sk171545 - After an upgrade of an SP Security Group in VSX mode from R80.20SP/R80.30SP to R81 or R81.10, all non-SMO Security Group Members are down due to the Critical Device "Policy"

| Property | Value |
|----------|-------|
| Solution ID | sk171545 |
| Date Created | 2021-01-13 |
| Last Modified | 2022-11-22 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R81.10 (EOS), R81 (EOS), R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * After a second policy installation on Virtual Systems (including the VSX Gateway itself), all non-SMO Security Group Members are in the state "Down".

* Output of the "`cphaprob stat`" command on the non-SMO Security Group Members in the context of all Virtual Systems (other than VS0) shows that the Critical Device "Policy" reports its state as "problem".

* Output of the "`cphaprob stat`" command on the non-SMO Security Group Members in the context of the Virtual System 0 (VSX Gateway itself) shows that the Critical Device "VSX" reports its state as "problem".

* In SmartConsole, the Accelerated Policy installation icon appears when an administrator installs a policy on a VSX Gateway object or Virtual System objects.

## Cause

From R81, the Accelerated Policy installation feature is enabled from the second attempt of the policy installation. However, this feature does not support Scalable Platforms.

Chain of events during the upgrade of a Security Group in VSX mode from R80.20SP/R80.30SP to R81 or R81.10:

1. The version of the VSX object is changed to R81 or R81.10.
2. A new parameter **scalable_platform** is created in the database in the VSX Gateway object and Virtual System objects.
3. The "`vsx_util reconfigure`" command is executed for a new Security Group (see [sk170696](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170696&partition=Basic&product=Maestro)).
4. The SMO reboots.
5. The SMO fails to update the value of the parameter **scalable_platform** to **true**.

As a result, the Accelerated Policy installation feature is applied even though it should not be.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.20 for Scalable Platforms](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk177624)
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 61
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 69

If you used "`vsx_util`" to upgrade the Security Gateway object on older Jumbo Hotfix Takes, the issue will not be solved by installing the Jumbo Hotfix Takes above. Proceed to the steps below.   

If you do not want to upgrade to the versions above, follow these steps on the Management Server that manages this VSX Security Gateway:

1. Close all SmartConsole windows.

   Verify by running the "*cpstat mg* " command on Security Management Server / in the context of *each* Domain Management Server.
2. Connect with [GuiDBedit Tool](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk13009) to Security Management Server / Domain Management Server.

3. In the upper left pane, go to ***Table*** - ***Network Objects*** - ***network_objects***.

4. In the upper right pane, select the relevant VSX Gateway object and object of each Virtual System configured on this VSX Gateway.

5. Press CTRL+F (or go to ***Search*** menu - ***Find*** ) - paste ***scalable_platform*** - click on ***Find Next***.

   Example:
   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk171545/guidbedit-screenshot-false202101141116441.jpg)
6. In the lower pane, right-click on the ***scalable_platform*** - select ***Edit...*** - select "***true*** " - click on ***OK***.

   ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk171545/guidbedit-screenshot202101140936161.jpg)
7. Save the changes: go to ***File*** menu - click on ***Save All***.

8. Close the GuiDBedit Tool.

9. Connect with SmartConsole to the applicable Security Management Server / Domain Management Server.

10. Install the Access Control policy on the VSX Gateway object.

11. Install the Access Control policy on each Virtual System object.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
