# Virtual Systems in a Maestro Security Group fail to load the Threat Prevention (AMW) policy

Product: Maestro HyperScale Firewall, VSX (Traditional)

Version: R81 (EOS), R81.10 (EOS), R81.20

OS: Gaia

Last Modified: 2025-07-22

## Symptoms

- The "`asg monitor`" command shows that a Security Group Member is in the state `DOWN`.

This issue occurs on a Security Group Member after it was rebooted or added as a new Security Group Member.

- The "`cphaprob state`" command shows that the Critical Devices "`VSX`" and "`pull_config`" report their state as "`problem`".

- The "`vsx stat -v`" command shows that some Virtual Systems are missing the AMW (Threat Prevention) policy.

- The `$FWDIR/log/blade_config` log in the context of the problematic Virtual Systems shows that the Virtual Systems failed to pull the AMW (Threat Prevention) policy.

- When fetching the local AMW (Threat Prevention) policy in the context of the problematic Virtual System with the "`fw amw fetch local`" command, the errors show that a Virtual System context failed to reload "AMW".

Example for VS ID 17 on R81.20:

```
127.0.0.1:12872/reload?state_dir=/opt/CPsuite-R81.20/fw1/CTX/CTX00017/state/__tmp/AMW&mode=TRADITIONAL rc=4
boolean_cpt malware_tp_conf_reload(const char*, char*, int): Reload(/opt/CPsuite-R81.20/fw1/CTX/CTX00017/state/__tmp/AMW) failed ()
malware_load: malware_tp_conf_reload( dir=/opt/CPsuite-R81.20/fw1/CTX/CTX00017/state/__tmp/AMW ) failed
```

- Restarting the problematic Virtual System resolves the issue, but only sometimes:

```
vsenv <VSID>
cpstop ; cpstart
```

## Cause

The issue is caused by a short internal timeout.

It affects large environments with many Virtual Systems in which the data transfer from VS ID 0 (main VSX context) to all relevant Virtual Systems takes longer than this internal timeout.

## Solution

This problem was fixed. The fix is included in:

- [Check Point Quantum R82](https://support.checkpoint.com/results/sk/sk181127)
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 89
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 170
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 106

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2024-08-07

Last Modified: 2025-07-22
