> Source: [sk183602](https://support.checkpoint.com/results/sk/sk183602)

# sk183602 - R81.20 / R81.10 / R81 Security Gateways may fail to fetch the Threat Prevention policy from their R82 Management Server

| Property | Value |
|----------|-------|
| Solution ID | sk183602 |
| Date Created | 2025-06-26 |
| Last Modified | 2025-08-21 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82, R82 |
| OS | Gaia |

## Symptoms

- * R81.20 / R81.10 / R81 Security Gateways, Cluster Members, and Scalable Platform Security Groups may fail to fetch the Threat Prevention policy from their R82 Security Management Server/ Multi-Domain Security Management Server.

* Upgrade of Security Gateway / Security Group / Cluster Member fails because it cannot install the Threat Prevention policy in this scenario:

  1. Security Gateway / Security Group is upgraded to the version R81, R81.10, or R81.20
  2. The Management Server runs the version R82
* Indication during an upgrade on a VSX Gateway / VSX Cluster Member:

  The output of the Expert mode command "`vsx stat -v`" in the main context VS0 shows one of these issues:
  * In the section "`VSX Gateway Status`",  

    in the field "`Threat Prevention Policy`" the value is empty, or "`<No Policy>`", or "`default filter`"

  * In the section "`Virtual Devices Status`",  

    the cell "`Threat Prevention Policy`" is empty, or shows "`<No Policy>`", or shows "`default filter`"  

    for one or more of the Virtual Systems

* Indication during an upgrade on a Security Group (Maestro / Scalable Chassis) in the Gateway mode:

  1. The output of the script "`sp_upgrade`" shows:

     `Fetching the policy from the Management Server and installing it... Succeeded`  
     `
     Fetching the Anti-Malware (AMW) policy from the Management Server Failed on members <ID>`  
     `
     Fetching the Anti-Malware (AMW) policy from the <IP Address of Management Server> Failed on members <ID>`
  2. The output of the Expert mode command "`cphaprob stat`" shows that the cluster state is "`DOWN`" and shows "`Active PNOTEs: AMW`".

  3. The output of the Expert mode command "`cphaprob list`" shows that the Critical Device "`AMW`" reports its state as "`problem`".

* Indication during an upgrade on a Security Group (Maestro / Scalable Chassis) in the Traditional VSX mode:

  1. The output of the script "`sp_upgrade`" shows:

     `Fetching the policy from the Management Server and installing it... Succeeded`  
     `
     Fetching the Anti-Malware (AMW) policy from the Management Server Failed on members <ID>`  
     `
     Fetching the Anti-Malware (AMW) policy from the <IP Address of Management Server> Failed on members <ID>`
  2. The output of the Expert mode command "`cphaprob stat`" in the main context VS0 shows that the cluster state is "`DOWN`" and shows "`Active PNOTEs: VSX Config`".

  3. The output of the Expert mode command "`cphaprob list`" in the the main context VS0 shows that the Critical Device "`VSX Config`" reports its state as "`problem`".

  4. The output of the Expert mode command "`vsx stat -v`" in the main context VS0 shows one of these issues:
     * In the section "`VSX Gateway Status`",  

       in the field "`Threat Prevention Policy`" the value is empty, or "`<No Policy>`", or "`default filter`"

     * In the section "`Virtual Devices Status`",  

       the cell "`Threat Prevention Policy`" is empty, or shows "`<No Policy>`", or shows "`default filter`"  

       for one or more of the Virtual Systems

## Cause

The R82 Management Server compiles the Threat Prevention (AMW) policy using its own version (internal value "6.0.5.5"), instead of the required Security Gateway version (internal value "6.0.5.2").

The Security Gateway fails the Threat Prevention policy installation because of this internal version mismatch.

## Solution

This problem was fixed. The fix is included in the Management Server starting from:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 33

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
