> Source: [sk184302](https://support.checkpoint.com/results/sk/sk184302)

# sk184302 - VPN traffic is dropped when a secondary Maestro site is in standby

| Property | Value |
|----------|-------|
| Solution ID | sk184302 |
| Date Created | 2025-11-12 |
| Last Modified | 2025-11-17 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R81.10 (EOS) |

## Symptoms

- * In a Quantum Maestro deployment, when the secondary site is in STANDBY, VPN traffic is dropped with the message:

  `fw_conn_inspect Reason: Frozen connection`
* If the solution from [sk156752](https://support.checkpoint.com/results/sk/sk156752) is applied, then traffic is dropped with:

  `cpxl_chain_flush_callback Reason: Failed to unhold`

  **Note**: Only VPN traffic is affected.

## Cause

Connections are synchronized over the global buffer, but a sequence gap between the global buffer and the unicast member buffers can cause the connection state to freeze.

Current Jumbo Hotfixes introduce new behavior where all VPN traffic is synced globally. If the secondary site remains down or in standby for an extended period, the lack of sequence updates from the active site may cause the Flush and Ack (FNA) synchronization mechanism to get stuck, resulting in frozen drops.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).  

**Note** : If you applied the procedure in [sk156752](https://support.checkpoint.com/results/sk/sk156752), revert the changes. sk156752 does not apply to Scalable Platforms.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
