sk182572 - Virtual Systems in a Maestro Security Group fail to load the Threat Prevention (AMW) policy

Virtual Systems in a Maestro Security Group fail to load the Threat Prevention (AMW) policy

Product: Maestro HyperScale Firewall, VSX (Traditional)

Version: R81 (EOS), R81.10 (EOS), R81.20

OS: Gaia

Last Modified: 2025-07-22

Symptoms

This issue occurs on a Security Group Member after it was rebooted or added as a new Security Group Member.

Example for VS ID 17 on R81.20:

127.0.0.1:12872/reload?state_dir=/opt/CPsuite-R81.20/fw1/CTX/CTX00017/state/__tmp/AMW&mode=TRADITIONAL rc=4
boolean_cpt malware_tp_conf_reload(const char*, char*, int): Reload(/opt/CPsuite-R81.20/fw1/CTX/CTX00017/state/__tmp/AMW) failed ()
malware_load: malware_tp_conf_reload( dir=/opt/CPsuite-R81.20/fw1/CTX/CTX00017/state/__tmp/AMW ) failed
vsenv <VSID>
cpstop ; cpstart

Cause

The issue is caused by a short internal timeout.

It affects large environments with many Virtual Systems in which the data transfer from VS ID 0 (main VSX context) to all relevant Virtual Systems takes longer than this internal timeout.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2024-08-07

Last Modified: 2025-07-22