> Source: [sk184841](https://support.checkpoint.com/results/sk/sk184841)

# sk184841 - BMAC VMAC verify diagnostic test fails on Maestro VSX Security Group

| Property | Value |
|----------|-------|
| Solution ID | sk184841 |
| Date Created | 2026-03-29 |
| Last Modified | 2026-03-29 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * On a Security Group Member (SGM), running the following command in Expert mode:

  ```
  asg diag verify
  ```

  shows a failure in Test 10: VMAC BMAC Verify, for example:

  ```
  Test 10 : VMAC BMAC Verify .......................... FAIL
  Reason  : VMAC BMAC Verify failed
  ```

  <br />

* Running the Virtual MAC (VMAC) / Base MAC (BMAC) verification tool on the same SGM

  ```
  mac_verifier -x All
  ```

  reports

  ```
  All VMAC/BMAC configurations are consistent
  ```

  <br />

* On affected VSX interfaces (for example, wrp / warp ports), the diagnostic output shows valid non-zero value, such as:

  ```
  Kernel VMAC is 00:1C:7F:AA:BB:CC
  ```

  <br />

* Rebooting SGMs or adding new SGMs does not change the result.

* Traffic forwarding, failover, and redundancy operate normally.

## Cause

In Maestro VSX environments, a software condition causes the diagnostic component used by `asg diag verify` to report an uninitialized Kernel-level VMAC value.  
The Firewall Kernel (FWK) and configuration databases maintain correct VMAC and BMAC values, which is why `mac_verifier` and `asg_vsx_verify` report consistent results.  
This behavior affects diagnostic output only and does not impact traffic handling or redundancy.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
