# CloudGuard Controller fails to connect to Cluster with MDPS enabled

## Product
CloudGuard Controller

## Version
R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20

## OS
Gaia

## Platform
All

## Last Modified
2024-03-31

## Symptoms
- CloudGuard Controller fails to connect to Cluster with Management Data Plane Separation (MDPS) enabled.
- In the _$FWDIR/log/cloud_proxy.elg_ file on the Security Management server you can see that an error occurs when the Management sends the _vsecUpdate.sh_ file to the Security Gateway, with exit code 255. For example:
```
[DATE TIME] ERROR datacenter.util.CommandExec [gateway-updater_]: command: [/opt/CPshrd-R81.10/bin/cprid_util, -server, , -timeout, 120, -stdout, /etc/fw/tmp/_vsecUpdate.sh.stdout, -verbose, rexec, -rcmd, /bin/bash, /etc/fw/tmp/_vsecUpdate.sh, , ] failed with exit code: 255
```

## Cause
The default behavior of the CloudGuard Controller is to send the _vsecUpdate.sh_ script to the Cluster VIP. With MDPS enabled, the Management can connect on the Management Plane only. The Cluster VIP resides in the Data Plane, so no connection is possible.

## Solution
This problem was fixed. The fix is included in:
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 95
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/R81.20/R81.20_Downloads.htm) starting from Take 26

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect [CPinfo](https://support.checkpoint.com/results/sk/sk92739) files from the Management Server and Security Gateways / Cluster Members involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

**After the Hotfix installation:**

1. Back up and edit the _vsec.conf_ file on the Security Management server.

Locations of the _vsec.conf_ file:
   - **On a Security Management Server :**

_$FWDIR/conf/vsec.conf_
   - **On a Multi-Domain Management Server :**

_$MDSDIR/conf/vsec.conf_

2. Add these lines to the configuration file:
```
# In version R81.10 with Jumbo HFA Take 95 and higher:
# Send Data Center updates from the CloudGuard Controller to the main IP address of Active member
# on the Management Plane instead of the cluster VIP address on the Data Plane
updateClusterMemberAndNotVip=true
```
3. All configuration values are read from the _vsec.conf_ file only when CloudGuard Controller is loaded. If you change one of the parameters, you must restart the CloudGuard Controller with the commands: "`vsec stop ; vsec start`"

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-05-29
Last Modified: 2024-03-31
