> Source: [sk184887](https://support.checkpoint.com/results/sk/sk184887)

# sk184887 - Maestro Security Group Member status frequently changes to "Down"

| Property | Value |
|----------|-------|
| Solution ID | sk184887 |
| Date Created | 2026-05-07 |
| Last Modified | 2026-05-10 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R82, R81.20 |

## Symptoms

- * The /var/log/messages log reveals that the cluster state change was triggered by an issue on VS Gateway, which resolved itself automatically within one to two minutes. Below are some log excerpts: `
  > ... ...`  
  > `
  > time fwk: State change: ACTIVE -> DOWN | Reason: VSX PNOTE due to problem in Virtual System 1`  
  > `
  > ...
  > time fwk: State change: DOWN -> ACTIVE | Reason: USER DEFINED PNOTE
  > ...`  
  > `
  > time fwk: State change: DOWN -> ACTIVE | Reason: Member state has been changed due to issue in Virtual System 0`  
* The $FWDIR/log/fwk.elg file contains a recurring line: `h_iterate: invalid return value from callback`
* The $FWDIR/log/fwk_softlock.elg file includes these lines about instance 0. `[instance_0]: Received thread_blocker signal
  > [instance_0]: [1] 0x72b678d0 [/lib64/libpthread.so.0] (offset 0xf8d0)
  > [instance_0]: [2] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x2c009da)
  > [instance_0]: [3] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x2c96440)
  > [instance_0]: [4] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x1353890)
  > [instance_0]: [5] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x15a5a90)
  > [instance_0]: [6] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x15b4850)
  > [instance_0]: [7] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0xf25be0)
  > [instance_0]: [8] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_0.so] (offset 0xf26730)
  > [instance_0]: [9] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_0.so] (offset 0x2e35506)
  > [instance_0]: [10] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_0.so] (offset 0x2cac456)`

## Cause

The CPHWD table (related to the SecureXL/Hardware Acceleration infrastructure) was configured with a size that was too small. When the CPHWD table is full, kernel processes that need to iterate over the entire table (for example, for cleanup, synchronization, or hardware offload operations) may not complete successfully or efficiently.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 115
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 183

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
