> Source: [sk184846](https://support.checkpoint.com/results/sk/sk184846)

# sk184846 - "Ping" and "Traceroute" commands fail for non-root RADIUS users on VSX with "Error : SUPSH0361 Failure setting current vrfid"

| Property | Value |
|----------|-------|
| Solution ID | sk184846 |
| Date Created | 2026-03-29 |
| Last Modified | 2026-03-30 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Non-local (RADIUS) users with a UID other than 0 (non-root) cannot run `ping` and `traceroute` commands on Virtual System Extension (VSX) and receive the following error:

  `Error : SUPSH0361 Failure setting current vrfid`
* The issue occurs even when the user's Role-Based Administration (RBA) explicitly allows these commands.

* Commands not permitted by the RBA are blocked earlier with a standard `invalid command` message.

## Cause

In a VSX environment, commands such as `ping` and `traceroute` must execute within the correct Virtual System (VS) context.

To achieve this, the system performs a context switch to the relevant Virtual Routing and Forwarding (VRF) instance. This operation requires root privileges (UID 0).

As a result, users with a non-root UID cannot perform the required context switch, even if the RBA role permits the command.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
