> Source: [sk185009](https://support.checkpoint.com/results/sk/sk185009)

# sk185009 - NTP update fails on Standby Site Security Group Members when using the parameter fwha_standby_hide_new_mode

| Property | Value |
|----------|-------|
| Solution ID | sk185009 |
| Date Created | 2026-05-29 |
| Last Modified | 2026-05-31 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R81.20 |

## Symptoms

- * This article applies to Maestro HyperScale Firewall R81.20 environments that use Management Data Plane Separation (MDPS) and have "standby hide mode" enabled with this parameter:

  `fwha_standby_hide_new_mode=1`
* These commands show a time skew between Security Group Members (SGMs):

  * `clock_verifier -v`
  * `g_all clock`
* The NTP time update fails on the Standby Site SGMs with this error although the configuration is correct:

  `no server suitable for synchronization found`


  The NTP commands fail from the Data Plane (dplane).
* Running this script resolves the issue temporarily:

  `$SMODIR/scripts/asg_ntp_update_time`
* These SecureKnowledge articles do not resolve the issue:

  * [sk172245 - Network Time Protocol (NTP) on Scalable Platform Security Groups](https://support.checkpoint.com/results/sk/sk172245)
  * [sk179385 - ime is not synchronized between Security Group Members although NTP is used](https://support.checkpoint.com/results/sk/sk179385 )

## Cause

MDPS uses separate management and data planes.

In this specific scenario, "standby hide mode" and MDPS together can prevent locally initiated NTP traffic from the data plane on Standby Site SGMs from completing correctly.

As a result, NTP synchronization fails on those members even when the NTP configuration is correct. [sk138672](https://support.checkpoint.com/results/sk/sk138672)confirms that MDPS separates interfaces, routes, sockets, and processes between planes and that DNS and NTP are plane-sensitive services in this design.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
