> Source: [sk173485](https://support.checkpoint.com/results/sk/sk173485)

# sk173485 - Policy installation fails on a Cluster R80.40 / R81 with Management Data Plane Separation (MDPS) and User Space Firewall (USFW)

| Property | Value |
|----------|-------|
| Solution ID | sk173485 |
| Date Created | 2021-05-18 |
| Last Modified | 2021-12-04 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Policy installation on a Cluster with Management Data Plane Separation (MDPS - [sk138672](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk138672)) and User Space Firewall (USFW - [sk167052](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk167052)) fails with this error in SmartConsole:

  `"/opt/.../conf/<Policy_Name>.pf", line <X>: ERROR: Duplicate keys <IP Address in Hex format> in table 'cluster_members_ids_by_ips'`
* The issue occurs after the administrator :

  1. Installed a Jumbo Hotfix on the Cluster:  
     * The R81 Jumbo Hotfix (a Take lower than 42) on the R81 Cluster
     * The R80.40 Jumbo Hotfix (a Take between 114 and 125) on the R80.40 Cluster
  2. Opened the Cluster object \> "`Network Management`", and clicked "`Get Interfaces`" \> "`Get Interfaces With Topology`".
* The issue does not occur if Cluster Members run the Firewall in the Kernel Space mode (KSFW).

## Cause

The Cluster pulls the MDPS interface "`mdps_tun`" into the USFW configuration, even though it is not part of the topology.

## Solution

This problem was fixed. The fix is included starting in:

* [Check Point R81.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)
* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) from Take 42
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) from Take 126

If you choose not to upgrade, this **workaround** is available in SmartConsole:

1. Open the Cluster object.
2. From the left tree, click **Network Management**.
3. Select each "`mdps_tun`" interface.
4. From the toolbar, click **Actions** \> **Delete Interface**.
5. Click **OK**.
6. Install the Access Control policy.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
