> Source: [sk184355](https://support.checkpoint.com/results/sk/sk184355)

# sk184355 - R82 CloudGuard Controller for VMware NSX-T Data Center objects are deleted after scan failure

| Property | Value |
|----------|-------|
| Solution ID | sk184355 |
| Date Created | 2025-11-20 |
| Last Modified | 2025-11-30 |
| Technical Level | General |
| Products | Cloud Firewall |
| Versions | R82 |
| OS | Gaia |

## Symptoms

- R82 CloudGuard Controller for NSX-T Data Center deleting all objects after data center scan failure.

## Cause

A failure in CloudGuard Controller's Data Center for NSX-T objects checksum mechanism is causing it to fail checksum verification on all objects after a Data Center scan failure.

Data Center scan failure can occur when:

* There is a connectivity issue
* NSX-T manager certificate change
* NSX-T API call maximum rate exceeded (aka "Throttling")

As a result, CloudGuard Controller deletes all the Data Center objects originating from the Data Center that failed the scan.

The deleted Data Center objects are propagated to the applicable Security Gateways as "deleted" making security policy rules to stop hitting on them, causing drops.  

<br />

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

**Note:**This issue affects only R82 Controller for NSX-T. Other versions and Data Center types are not affected.

As an immediate **workaround** , run `# vsec stop;vsec start`

This forces the Controller to fetch and propagate all data center objects.

### R82 CloudGuard Controller self updatable package

[R82 CloudGuard Controller self updatable package](https://support.checkpoint.com/results/sk/sk181842) Take 23 or higher (TBD) include this fix.

To check the currently installed take of CloudGuard Controller, run:

`Autoupdater_cli show all `

Search for CloudGuard Controller: `component-name: cloudGuard_controller`, for example:

`component-branch: cloudGuard_ControIIer R82`  
`GA-Version: 1`  
`download-scheduler-active: true`  
`install-scheduler-active: true`  
`download-action: idle`  
`install-revert-action: idle`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
