> Source: [sk179794](https://support.checkpoint.com/results/sk/sk179794)

# sk179794 - Upgrade fails on Secondary Management Server due to SIC Communication issue

| Property | Value |
|----------|-------|
| Solution ID | sk179794 |
| Date Created | 2022-08-05 |
| Last Modified | 2025-05-26 |
| Technical Level | Advanced |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R81.20, R81.10 (EOS), R81.10 (EOS), R81.20 |
| OS | Gaia |

## Symptoms

- * Upgrade of a Secondary Management Server with CPUSE fails with this message in Gaia Portal / Gaia Clish:

  > Check install failed - Installation of \<Name of CPUSE Package\> is not allowed (Reason: **\<Name of CPUSE Package\>**   
  >
  > **Clean Install:**   
  > Installation is allowed.   
  >
  > **Upgrade:**   
  > The following results are not compatible with the package:   
  >
  > - Verification failed:  
  > 1. Upgrade operation is not supported in the current configuration. Make sure that SIC is established with the primary machine and try again. Contact Check Point Support for further assistance.
* Upgrade Report shows a Blocking Pre-Export Verification:

  > Verifying the Management before Export
  >
  > <br />
  >
  >
  > Verifying SIC connectivity
  >
  > <br />
  >
  >
  > There is a connectivity issue with the Primary Management Server.
  >
  > <br />
  >
  >
  > **Checklist:**   
  >
  > 1) Make sure all the required process are up and running on the Primary Management Server.  
  >
  > In the Expert mode, run: cpwd_admin list  
  >
  > 2) Make sure this server can access the Primary Management Server.  
  >
  > From this server, send a ping to the Primary Management Server: X.X.X.X  
  >
  > 3) If you changed the IP address of the Primary Management Server using the /var/log/mdss.json file, then make sure this file exists on all the Management Servers.  
  >
  > 4) On each Management Server, make sure the server is listening on the TCP port 18264.  
  >
  > In the Expert mode, run this command: netstat -anp \| grep -E "PID\|18264"
  >
  > <br />
  >
  >
  > Make sure the Primary Management Server is up and accessible until the upgrade completes.

## Cause

The Secondary Management Server fails to communicate with / get a response from the Primary Management Server to check that the Primary Management Server was already upgraded.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
