> Source: [sk181804](https://support.checkpoint.com/results/sk/sk181804)

# sk181804 - Traffic stops passing through Maestro Security Group after policy installation

| Property | Value |
|----------|-------|
| Solution ID | sk181804 |
| Date Created | 2023-12-14 |
| Last Modified | 2023-12-21 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Before installing a policy on a Security Group, the "tcpdump" tool shows traffic through an uplink port that is assigned to that Security Group.

* After installing a policy on that Security Group:

  1. The "tcpdump" traffic capture on an uplink port that is assigned to that Security Group does not show traffic anymore through

  2. The "tcpdump" traffic capture on backplane interfaces of the Orchestrator does not show traffic for that uplink port

* Traffic through the uplink port resumes after unloading the policy from the Security Group.

## Cause

Incorrect configuration of VLANs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
