> Source: [sk184653](https://support.checkpoint.com/results/sk/sk184653)

# sk184653 - Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000.

| Property | Value |
|----------|-------|
| Solution ID | sk184653 |
| Date Created | 2026-02-10 |
| Last Modified | 2026-07-23 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82, R81.20, R81.10 (EOS) |
| OS | Gaia |
| Platform | 64000 |

## Symptoms

- * Creation of a Virtual System Extension (VSX) fails on Scalable Chassis with SSM440 when the Maximum Transmission Unit (MTU) exceeds 9000.

  As a result:
  * The new Security Group Member remains in a down state.
  * A `VSX config` Critical Device appears.
  * Virtual Systems (VSs) are not created on the affected Security Group Member.
* The following error appears during the operation:

  `db_set error: Failed to set MTU 9216 on interface bond3. Maximum value allowed is 9000.`

## Cause

The VSX database was originally created on a version lower than R81.10 (for example, R80.20SP).

In these versions, it was possible to configure interface MTU values up to 12000.

Starting from R81.10, the maximum allowed MTU is 9000.

If the existing VSX configuration contains interfaces with MTU values greater than 9000, adding a new Security Group Member running R81.10 fails during the VSX fetch process because the configured MTU exceeds the allowed limit.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

If you choose not to upgrade, since this issue arise when configuring **not supported MTU value** , you should proceed with changing the MTU for the maximum supported value:  
1. Log in to the SmartConsole  
2. Open each Virtual object and lower the MTU on each interface, set it to up to 9000  
3. Push configuration  
4. Push policy  
5. Add the new Security Group Member to the Security Group  

You can increase the maximum MTU supported value to 9416 by installing a hotfix.  
['Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
