> Source: [sk56481](https://support.checkpoint.com/results/sk/sk56481)

# sk56481 - Policy push to VSes in Target CMAs fails after migration of VSX main CMA to a new IP

| Property | Value |
|----------|-------|
| Solution ID | sk56481 |
| Date Created | 2010-10-29 |
| Last Modified | 2022-02-16 |
| Technical Level | Advanced |
| Products | Security Gateway, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R81.20, R82 |

## Symptoms

- Policy push to VS fails after migrating the main CMA

## Cause

Following scenario: One or more CMA managing a VSX cluster/gateway and VSes is being upgraded or moved to a new machine and also new IP addresses.

The security policy for the VSX VS 0 allows access from the old AND the new CMA to VS 0 to allow the migration.

Policy push to VS 0 and all VSes in this CMA from the new main CMA works fine and has no problems.

After this has been done, the policy to VS0 is restricted again, only the implied rules are enabled and all explicit rules allowing Check Point management access are disabled while the implied rules are still enabled.

Then changing the topology of VSes in the target CMA still works fine, but when pushing a security policy from the target CMA to its VSes fails with connectivity errors.

This failure is due to the fact that despite the implied rules are enabled and the policy to VS 0 has been pushed, the target CMA VSes still don't know about the implied rules and objects and does not accept the policy push while VS 0 has a policy not allowing access from the target CMAs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
