> Source: [sk182565](https://support.checkpoint.com/results/sk/sk182565)

# sk182565 - New Maestro Security Appliance QLS / MLS does not send or receive traffic if SecureXL runs in the User Space (UPPAK) mode in R81.10 Jumbo Hotfix Accumulator

| Property | Value |
|----------|-------|
| Solution ID | sk182565 |
| Date Created | 2024-08-06 |
| Last Modified | 2025-06-22 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R81.10 (EOS) |
| OS | Gaia |
| Platform | LightSpeed QLS, LightSpeed MLS |

## Symptoms

- * A new LightSpeed QLS / MLS appliance that was added to a Maestro Security Group does not send or receive traffic through the LightSpeed acceleration card, although the card ports show a physical link and appear active.

* On the Security Group, output of the "`asg monitor`" command in the Expert mode shows the state "`DETACHED`" for the new Security Group Member ID.

* On the Security Group, traffic capture with the "`tcpdump`" command in the Expert mode on the backplane bond subordinate interfaces (e.g., ethsBP1-01, ethsBP3-01, etc.) shows the incoming and outgoing traffic.

  However, traffic capture with the "`tcpdump`" command on the backplane bond interfaces (e.g., BPEth0, BPEth1, etc) does not show any traffic passing.
* On the Security Group, the `/var/log/usim_x86.elg` file contains a line that indicates a problem during the initialization of a backplane bond subordinate interface.

  Example:

  `dpdk_get_drv_info: firmware version (22312302 : 22352302) is not supporting on dev ethsBP3-01`

## Cause

Maestro LightSpeed Appliances were first supported in the **R81.10 Jumbo Hotfix Accumulator Take 106.**Installing this Take (or higher) allow users to configure SecureXL to work in the User Space (UPPAK) mode on specific appliance models (including QLS-250, QLS-450, MLS-200, and MLS-400).

As part of the Jumbo Hotfix Accumulator update process, the R81.10 Jumbo Hotfix Accumulator introduces the ability to automatically update the firmware on the LightSpeed acceleration card to make sure the correct firmware version is deployed in synchrony with important NIC driver updates. This update takes place when the Jumbo Hotfix Accumulator is installed with CPUSE.

A scenario can arise, whereby a new Security Group Member can be added to an existing Security Group that runs SecureXL in the User Space (UPPAK) mode without the necessary firmware updates on the LightSpeed acceleration card to correctly initialize the NIC driver.

This problem is encountered when the SMO Image Cloning feature is enabled in a Security Group, and a compatible LightSpeed appliance is added. While the SMO Image Cloning successfully copies the necessary software and drivers to the new Security Group Member, the NIC firmware update is not handled by this process. Upon reboot, since the LightSpeed NIC firmware does not match the capabilities of the software, the backplane NICs fail to fully initialize. Any ingress traffic to this device is dropped, meaning it cannot be accessed from the Maestro Orchestrators and other Security Group Members.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
