> Source: [sk184724](https://support.checkpoint.com/results/sk/sk184724)

# sk184724 - ClusterXL Instability After Policy Installation When DynamicID Provider URL Contains Percent Character (%)

| Property | Value |
|----------|-------|
| Solution ID | sk184724 |
| Date Created | 2026-02-23 |
| Last Modified | 2026-02-24 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When the Security Gateway installs a policy that includes a DynamicID SMS/Email provider URL with percent?encoded values (such as %40 or %20), ClusterXL becomes unstable.
* The kernel log on the Security Gateway shows that ClusterXL user?mode components stop responding. For example:   
  `kernel: cphamcset[12345]: segfault at 0 ip 0x7f... sp 0x7f... error 4 in libc-2.17.so[...]`
* Cluster members report Down, because the ClusterXL process cphad stops.
* On the Security Gateway, the command: `cphawd_admin list` shows that the *CPHAMCSET* process is not running.
* User?mode core dumps (for example, cphamcset, cphaconf, cphastart) appear in: `/var/log/dump/usermode/`

## Cause

A software condition in the ClusterXL policy?parsing logic occurs when the installed policy includes percent?encoded characters in the DynamicID provider URL.  

When ClusterXL reads this content, the parsing operation triggers unexpected termination of related user?mode processes.  
This causes cphad to stop, which leads cluster members to enter the Down state.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
