> Source: [sk178964](https://support.checkpoint.com/results/sk/sk178964)

# sk178964 - Security Group Member (SGM) remains in the "Down" state for an hour after reboot

| Property | Value |
|----------|-------|
| Solution ID | sk178964 |
| Date Created | 2022-05-02 |
| Last Modified | 2023-10-29 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * After a reboot, SGMs stay in the "down" state with a PNOTE of "Cluster Full sync."

* The `asg_blade_config full_sync ` command fails.

* The *$FWDIR/log/blade_config* log shows unsuccessful connection attempts from the local SGM to the SGM with the role of Single Management Object (SMO).

* `fw ctl zdebug + drop` shows dropped connection attempts for TCP port 263 in the Chassis synchronization network.

* SmartLog shows dropped connections from network 192.0.2.0/24 to network 192.0.2.0/24 TCP port 263.

## Cause

Internal communication in the internal Cluster Sync network 192.0.2.X fails because the communication fails for the *cxld* processes over the TCP port 263.

In addition, the fallback mechanism to the *fwd* processes over the TCP port 256 fails.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.20](https://support.checkpoint.com/results/sk/sk173903)
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 75
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 72
* [Jumbo Hotfix Accumulator for R80.20SP](https://support.checkpoint.com/results/sk/sk155832) starting from Take 334

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ([Maestro](https://support.checkpoint.com/product/520) / [Scalable Chassis 64000](https://support.checkpoint.com/product/493) / [Scalable Chassis 44000](https://support.checkpoint.com/product/492)).

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

<br />

**This workaround is available:**

1. Create a new **Network** object:

   1. In the **Name** field, enter a desired name (for example, "Net_192.0.2.0")

   2. In the **IPv4** section \> **Network address** field, enter **192.0.2.0**

   3. In the **IPv4** section \> **Net mask** field, enter **255.255.255.0**

2. Create a new **Service** object of type **TCP**:

   1. In the **Name** field, enter a desired name (for example, "FW1-CXLD")

   2. In the **Protocol** field, leave the default option "**No item selected**"

   3. In the **Port** field, enter **263**

   Example:

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1651239746587/CXLD2202204291633382.png)
3. Add this explicit rule in the Access Control policy:

   |-----------------------------------|---------------|---------------|-------|--------------------------|--------|
   | Name                              | Source        | Destination   | VPN   | Services \& Applications | Action |
   | Allow Full Sync in Security Group | Net_192.0.2.0 | Net_192.0.2.0 | \*Any | FW1-CXLD                 | Accept |

4. Install the Access Control policy on the Security Gateway object for this Security Group.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
