sk182615 - Dynamic Balancing is stuck at initialization after upgrade
Dynamic Balancing is stuck at initialization after upgrade
Product: CoreXL
Version: R81.10 (EOS), R81.20
Last Modified: 2025-03-20
Symptoms
- After you upgrade to R81.20 Jumbo Hotfix Take 70 or 76 from a lower version, Dynamic Balancing does not start. The
# dynamic_balancing -pcommand shows:
"Dynamic Balancing is currently Initializing".
- In R81.10 after upgrading to take 152 or above, the
show mdps statecommand will show:
"Dedicated resource: Enabled (Temporarily disabled due to insufficient CPU / FW-instance num)"
- The
$FWDIR/log/dsd.elgfile contains these lines:>> ds_init_blades_conf: Blades conf = NGTP-like
ds_dmd_init_runtime_state: Initializing DMD state
ds_init_mdps_instances: Failed to get mdps instances
ds_init_instances: Failed to init mdps instances
ds_init_mappings: Failed to init instances
ds_init_basic_state: ds_init_mappings failed
ds_init failed
- The `show mdps state` command shows:
Management Data plane separation:
Routing plane: Enabled
Dedicated resource: Enabled (Temporarily disabled due to insufficient CPU / FW-instance num)
Management interface: Mgmt
- The `cpwd_admin list` command shows that "dsd" is terminated.
## Cause
- In R81.20 Jumbo Hotfix Take 70, a change was made to include support for Dynamic Split/Dynamic Balancing. When IPv6 is enabled, Dynamic Split/Dynamic Balancing requires the same number of IPv4 and IPv6 firewall instances.
- The behavior happens because of previous configuration of MDPS. If MDPS is configured after Jumbo hotfix take 70, it will not allow to apply MDPS without equal number of IPv4 and IPv6 firewall instances.
## Solution
This problem was fixed. The fix is included in:
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 99
Make sure the number of IPv4 and IPv6 firewall instances is the same.
**To change the number of instances**:
1. Run `#cpconfig`
2. Change the number of firewall instances
3. Configure the same number of instances for both IPv4 and IPv6.
Note, this operation requires a reboot.
If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.
**Hotfix installation instructions:**
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).
#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.