> Source: [sk175549](https://support.checkpoint.com/results/sk/sk175549)

# sk175549 - Maestro Sites lose connectivity after an administrator changes the state of a port on one of the Orchestrators in a Dual Site environment

| Property | Value |
|----------|-------|
| Solution ID | sk175549 |
| Date Created | 2021-09-23 |
| Last Modified | 2022-05-11 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R82.20, R82.10, R82, R81.20 |
| OS | Gaia |
| Platform | Maestro Orchestrator |

## Symptoms

- * In a Dual Site environment, when running the "`set maestro port X/Y/Z admin-state {down | up}`" command on one Orchestrator (for example, MHO 1_1), the corresponding port on the peer Orchestrator on the other site (in our example, MHO 2_1) also goes down/up.

* When the administrator changes the state of a Downlink port, then the state of Security Group Members changes to "Down", and the cluster state is inconsistent between thee Security Group Members.

* Example for changing the state (to "Down") of a Downlink port that connects to a Security Group Member "SGM1":

  * Output of the "`asg monitor`" command on "SGM1_01" or "SGM2_01" shows the state of the local Security Group Member as "DOWN" and the state of all other Security Group Members as "DETATCHED"

  * Output of the "`asg monitor`" command on any other Security Group Members shows the state of "SGM1_01" and "SGM2_01" as "DETATCHED" and the state of all other Security Group Members as "UP"

## Cause

If the port state is changed on one Orchestrator, the peer Orchestrator on the other site automatically changes the state of the peer port.

If the state of the port changes on both Orchestrators on both Sites because of a link state change (for example, a failed DAC cable), then this behavior does not occur.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
