> Source: [sk184716](https://support.checkpoint.com/results/sk/sk184716)

# sk184716 - Quantum Maestro Security Group remains in "During Upgrade" state after upgrade and prevents adding new Security Group Members

| Property | Value |
|----------|-------|
| Solution ID | sk184716 |
| Date Created | 2026-02-21 |
| Last Modified | 2026-05-20 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * In a Quantum Maestro deployment, the Security Group continues to show the message below even after the upgrade from R81.20 to R82 completes:

  "System Status - Maestro (During Upgrade)"

  You can observe this on any Security Group Member using the command:

  `asg stat -v`
* The WebUI on the Maestro Hyperscale Orchestrator (MHO) blocks adding an additional Security Group Member to the Security Group and shows an error similar to:

  `You cannot add unassigned gateways to a Security Group which contains gateways that are being upgraded.`
  `
  `

  `Gateway {SGM number and Serial Number} is currently undergoing upgrade`

## Cause

Residual upgrade indicators from the previous upgrade process remained active, causing the system to continue reporting an upgrade?in?progress state.  

These indicators include:  

* Non-zero Scalable Platform High Availability (HA) / upgrade-related kernel parameters that persist in:   
  `/var/opt/fw.boot/modules/fwkern.conf`  
  Examples:
  * `fwha_during_upgrade_from_version`
  * `fwha_during_upgrade`
  * `fwha_sp_during_upgrade`
  * `fwha_mvc_enabled`
  * `fwha_sp_mvc_local_upgrade_success`

  <!-- -->

  * A remaining hidden upgrade marker file:  
    `/etc/.scalable_platform_during_inplace_upgrade`

  Because these indicators remain set, the Security Group reports an `upgrade-in-progress `state.

  The MHO enforces the expected behavior of blocking the addition of new Security Group Members during an upgrade.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
