> Source: [sk185128](https://support.checkpoint.com/results/sk/sk185128)

# sk185128 - Threat Emulation updates on standby Virtual System fail in VSLS cluster

| Property | Value |
|----------|-------|
| Solution ID | sk185128 |
| Date Created | 2026-07-07 |
| Last Modified | 2026-07-13 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Threat Emulation updates fail on a standby Virtual System in a VSLS cluster:

  * Traffic to http://dl3.checkpoint.com fails from the standby Virtual System
  * Traffic to https://dl3.checkpoint.com succeeds
  * On the active Virtual System, both HTTP and HTTPS succeed

  <br />

  Environment:
  * VSX Cluster is in VSLS mode
  * SecureXL runs in UPPAK mode (`# fwaccel stat`)
  * The Synchronization interface of the VSX cluster is VLAN-based
  * The traffic includes multiple Virtual Systems and Virtual Switches.

  <br />

* When running this manual test:

  * curl_cli http://dl3.checkpoint.com (tcp/80) fails
  * curl_cli https://dl3.checkpoint.com (tcp/443) succeeds

  <br />

  both are accepted by the Access Control Rule Base and NATed correctly.

  <br />

## Cause

The issue occurs in environments that include: VSLS + SecureXL   
(UPPAK) + VLAN based Synchronization + Virtual Switches:

* The FDT process (running in FWD on VS0) generates HTTP (port 80) traffic
* The Virtual System accepts and NATs the traffic correctly
* However, this HTTP traffic is not synchronized to the active member

As a result, the traffic does not reach the active Virtual System, and is not forwarded to the next hop.

FDT operates in 2 modes:

* Legacy - on port 80 (HTTP)
* New - on port 443 (HTTPS)

HTTPS traffic (port 443) follows a different processing path and works correctly.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a solution for this issue.

A Support Engineer will make sure the solution is compatible with your environment before providing it.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
