> Source: [sk182805](https://support.checkpoint.com/results/sk/sk182805)

# sk182805 - During the ClusterXL upgrade to R82, the "cphaprob state" command shows "Mismatch in the number of CoreXL FW instances has been detected"

| Property | Value |
|----------|-------|
| Solution ID | sk182805 |
| Date Created | 2024-11-03 |
| Last Modified | 2026-07-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82 |
| OS | Gaia |

## Symptoms

- During the ClusterXL upgrade to R82, the output of the "`cphaprob state`" command shows:

* The column "`State`" shows "`ACTIVE(!)`" for the upgraded ClusterXL Member
* The row "`Active PNOTEs`" shows "`COREXL`"
* The row "`Reason for state change`" shows "`Mismatch in the number of CoreXL FW instances has been detected`"

Example output:

```

Cluster Mode:   High Availability (Active Up) with IGMP Membership

ID         Unique Address  Assigned Load   State          Name

1          192.168.2.1     0%              STANDBY        MemberA
2 (local)  192.168.2.2     100%            ACTIVE(!)      MemberB


Active PNOTEs: COREXL

Last member state change event:
   Event Code:                 CLUS-113905
   State change:               STANDBY -> ACTIVE(!)
   Reason for state change:    Mismatch in the number of CoreXL FW instances has been detected
   Event time:                 XXX
```

## Cause

If a ClusterXL Member has 20 or more CPU cores and it runs the version R81.20 (or lower) in the User Space Firewall mode (USFW, see [sk167052](https://support.checkpoint.com/results/sk/sk167052)), then CoreXL automatically assigns one dedicated CPU core to the FWD daemon.

Starting in R82, this design was changed - CoreXL does **not** assign one dedicated CPU core to the FWD daemon automatically anymore.

This means:

* **Before** the upgrade to R82 (or higher), such a ClusterXL Member has:

  \["X" CoreXL instances, Firewall and SND\] + \[1 CoreXL SND instance for FWD daemon\]
* **After** the upgrade to R82 (or higher), such a ClusterXL Member has:

  \["X+1" CoreXL instances, Firewall and SND\]

As a result, the ClusterXL mechanism shows the message about the mismatch in the number of CoreXL Firewall instances.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
