# Policy installation on a Maestro Security Group fails after enabling the Maestro Fastforward feature

**Product**: Maestro HyperScale Firewall  
**Version**: R81.20  
**OS**: Gaia  
**Last Modified**: 2025-01-16

## Symptoms

- After enabling the Maestro Fastforward feature, policy installation on a Maestro Security Group fails with this error in SmartConsole:

```
  Maestro acceleration (MXL) failed, reason: General error. Please check /var/log/acl_cli.log on the security group SMO for more details.
  ```

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 43

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix prerequisite:**  
The Security Group Members must have the [R81.20 Jumbo Hotfix Accumulator Take 26](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) installed.

1. Connect to the command line on the Security Group.
2. Examine the list of the installed hotfixes:
   
   ```
   cpinfo -y all
   ```

**Hotfix installation instructions:**

1. Copy the hotfix package to the Security Group to some directory (for example, _/var/log/_).
2. Connect to the command line on the Security Group.
3. If your default shell is Gaia gClish, log in to the Expert mode:
   
   ```
   expert
   ```
4. Assign the required permissions to the hotfix package:
   
   ```
   chmod -v 777 /var/log/maestro_hft_gw-1-8.i386.rpm
   ```
5. Install the hotfix package:
   
   ```
   rpm -Uhv --force --nodeps /var/log/maestro_hft_gw-1-8.i386.rpm
   ```
6. In SmartConsole, install policy on the Security Gateway object for this Security Group.

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
