> Source: [sk182819](https://support.checkpoint.com/results/sk/sk182819)

# sk182819 - VSX Cluster Members with VLAN interfaces change their cluster state to "Down" and "Active!" after installing a Jumbo Hotfix Accumulator

| Property | Value |
|----------|-------|
| Solution ID | sk182819 |
| Date Created | 2024-11-06 |
| Last Modified | 2024-11-25 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * In a VSX Cluster with VLAN interfaces, VSX Cluster Members may change their cluster state after installing one of these packages:

  * R81.20 Jumbo Hotfix Accumulator, Take 89
  * R81.10 Jumbo Hotfix Accumulator, Take 170
  * R81 Jumbo Hotfix Accumulator, Take 99

  Problematic cluster states:
  * The VSX Cluster Member with the new Jumbo Hotfix Accumulator Take changes its cluster state to "`Down`"
  * The current Active VSX Cluster Member changes its cluster state to "`Active!`"
* Output of the "`cphaprob -a -m if`" command on the VSX Cluster Member with the new Jumbo Hotfix Accumulator Take might show the string "`not configured`" in the column "`High VLAN`" (meaning the highest configured VLAN is not monitored).

## Cause

A temporary VLAN monitoring mismatch occurs during the installation of the Jumbo Hotfix Accumulator on the Standby VSX Cluster Member.

The Standby VSX Cluster Member starts monitoring only the lowest VLAN, while the Active VSX Cluster Member continues to monitor both the lowest VLAN and the highest VLAN (which is the default behavior).

This VLAN monitoring mismatch issue does **not** affect traffic flow or cluster failover functionality. The VSX Cluster Members continue to synchronize all connections.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 90
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 171
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 107

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

**Important Note** -  
If you installed:  

* R81.20 Jumbo Hotfix Accumulator Take 89,
* R81.10 Jumbo Hotfix Accumulator Take 170,
* R81 Jumbo Hotfix Accumulator Take 99,  
  then the same issue will occur one more time during the installation of:
* R81.20 Jumbo Hotfix Accumulator Take 90,
* R81.10 Jumbo Hotfix Accumulator Take 171,
* R81 Jumbo Hotfix Accumulator Take 107.

Available options:

* You can ignore the VLAN monitoring mismatch and proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members.

* Perform a manual failover and then proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members:

  1. Connect to the command line on **each** VSX Cluster Member.

  2. Log in to Gaia Clish or the Expert mode.

  3. Examine the cluster state and the Critical Devices:

     * In Gaia Clish, run:

       `show cluster state`
     * In the Expert mode, run:

       `cphaprob state`

     If the row "`Active PNOTEs`" shows only "`LPRB`" or "`IAC`", then continue to the next step.

     Otherwise, stop the workaround procedure - ignore the VLAN monitoring mismatch and proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members.
  4. Initiate a manual failover:

     * If a VSX Cluster Member with the new Jumbo Hotfix Accumulator Take has the cluster state "`Down`", then on the current Active VSX Cluster Member run the "`cpstop`" command.

     * If a VSX Cluster Member with the new Jumbo Hotfix Accumulator Take has the cluster state "`Standby`", then on the current Active VSX Cluster Member, run:

       * In Gaia Clish, run:

         `set cluster member admin down`
       * In the Expert mode, run:

         `clusterXL_admin down`
  5. Proceed with the Jumbo Hotfix Accumulator installation on other VSX Cluster Members

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
