> Source: [sk185115](https://support.checkpoint.com/results/sk/sk185115)

# sk185115 - Maestro VSX operations cause Configuration PNOTE, member DOWN, and topology push failures

| Property | Value |
|----------|-------|
| Solution ID | sk185115 |
| Date Created | 2026-07-13 |
| Last Modified | 2026-07-23 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * In a Maestro VSX environment, VSX operations fail. These operations include Virtual System creation, Virtual System deletion, and Virtual System topology push.
* The cluster reports one or more of these Critical Devices: Configuration, VSX, ROUTED, or USER_DEFINED.
* Topology and policy installation to Virtual Systems fails on the affected Security Group Members.
* One Security Group Member stays in the DOWN state. At the same time, the peer member stays in the ACTIVE or ACTIVE(!) state.
* When you run the `vsx stat -v` command on different Security Group Members, a Virtual System that you recently added or deleted shows as `unknown` or does not show at all.

## Cause

When you add or remove a Virtual System, a race condition can occur between the freeze operation and the Critical Device operation. The freeze operation can complete before the Critical Device operation completes.  

This timing condition causes an inconsistent VSX configuration state between the Security Group Members.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
