# Security Group Member in a VSX environment is in a boot loop after creating a new Virtual System with a WRP interface or after upgrading jumbo hotfix accumulator

**Product**: Maestro HyperScale Firewall, Scalable Chassis  
**Version**: R81.10 (EOS), R81.20  
**OS**: Gaia  
**Last Modified**: 2024-11-20

## Symptoms

- A Security Group Member / Security Gateway Module (SGM) is in a boot loop.
  **Notes**:
  - You configured the "Same VMAC" feature or enabled it in the past.
  - The Security Group is configured as a VSX, and a new Virtual System (VS) with a WRP was added.

- The `/var/log/reboot.log` file contains this log:

```
    Reason:Reboot from unknown reason occurred! Type:unknown
    ```

- The `/var/log/start_bfm.log.dbg` file contains this log:

```
        Interface wrpjX should have warp vmac, setting mac address to XX:YYYY
        wrpjX mac changed, set reboot needed to 1
        wrp mac changed, reboot
    ```

## Cause

When the "Same VMAC" feature is enabled or disabled, a new kernel parameter is added to the `fwkern.conf` file: `fwha_ch_same_vmac_enabled_os`. For more information, see [sk165674](https://support.checkpoint.com/results/sk/sk165674).

When you add a new VS that is connected to a Virtual Switch (VSW), a WRP interface is created and assigned a MAC address. Because of a possible race condition, a reboot function is called that causes the SGM to get stuck in a boot loop.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 89
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 170

If you choose not to upgrade, the following workaround is available.

**Note:** value of the `fwha_ch_same_vmac_enabled_os` parameter in the `fwkern.conf` has to be 0 otherwise it will turn off VMAC feature.

1) Remove `fwha_ch_same_vmac_enabled_os=0` entry from `fwkern.conf` file on all Security Group Members
2) To enforce change, Security Group Members requires a reboot

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
