> Source: [sk95218](https://support.checkpoint.com/results/sk/sk95218)

# sk95218 - Disconnected monitored VLAN can cause ClusterXL upgrade failure

| Property | Value |
|----------|-------|
| Solution ID | sk95218 |
| Date Created | 2013-09-30 |
| Last Modified | 2015-04-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- Disconnected monitored VLAN can cause ClusterXL upgrade failure.

## Cause

ClusterXL monitors low and high VLANs. This causes problems during upgrade for customers with a **disconnected monitored VLAN.**

1. When the lowest and highest VLANs are connected, upgrade completes successfully and both VLAN interfaces (low and high VLANs) are monitored.  

2. When the highest VLAN is disconnected, during upgrade this VLAN interface is marked as "UP" by cluster mechanism. Therefore, during the upgrade, the "`Interface active check`" device reports its status as "problem".

As a result, one member goes into "`Active Attention`", and the other member goes into "`Down`" state (run the '`cphaprob state`' command).

The same issue occurs in both Full Connectivity Upgrade (FCU) and Zero Downtime Upgrade.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
