> Source: [sk181056](https://support.checkpoint.com/results/sk/sk181056)

# sk181056 - Threat Emulation updates fail on the Standby Virtual System of the VSX

| Property | Value |
|----------|-------|
| Solution ID | sk181056 |
| Date Created | 2023-05-30 |
| Last Modified | 2025-03-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Threat Emulation updates fail on the Standby Virtual System of the VSX.

* This error appears in the object's **device information** in SmartConsole:

  `Error: Communication error: could not connect to cloud.`
* Changing these parameters does not resolve the issue:

  * `fwha_cluster_hide_active_only=0`
  * `fwha_silent_standby_mode=1`
* The cppcap/tcpdump tool shows that traffic to http://dl3.checkpoint.com is routed to the VS-0 of the active member and exits with the VS's funny IP:

  `192.168.196.50.40924 > 104.85.41.222.80: Flags [S]`  
  `192.168.196.50.40924 > 104.85.41.222.80: Flags [S]`  
  `192.168.196.50.40924 > 104.85.41.222.80: Flags [S]`

  <br />

* The cppcap/tcpdump tool shows that traffic to https://dl3.checkpoint.com or other destinations is routed to the VS-1 of the active member and exits with the VIP correctly:

  Traffic to https://dl3.checkpoint.com:   
  ` 212.187.227.1.10400 > 104.85.41.222.443: Flags [S]`  
  ` 172.30.123.216.55528 > 104.85.41.222.443: Flags [S]`  
  ` 104.85.41.222.443 > 172.30.123.216.55528: Flags [S.]`  
  ` 104.85.41.222.443 > 212.187.227.1.10400: Flags [S.]`

  <br />

  Traffic to 1.1.1.1:80:   
  `212.187.227.8.11699 > 1.1.1.1.80: Flags [S]`  
  `172.30.123.215.27277 > 1.1.1.1.80: Flags [S]`  
  `1.1.1.1.80 > 172.30.123.215.27277: Flags [R.]`  
  ` 1.1.1.1.80 > 212.187.227.8.11699: Flags [R.]`

  <br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
