sk183298 - "Management rejected fetch for this module - version matching problem" error when running the "fw vsx fetch" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server
"Management rejected fetch for this module - version matching problem" error when running the "fw vsx fetch" command on an R81.x Scalable Platform (Maestro and Chassis) in VSX mode with an R82 Security Management Server
Product
Maestro HyperScale Firewall, Scalable Chassis, VSX (Traditional)
Version
R81 (EOS), R81.10 (EOS), R81.20, R82
Last Modified
2025-09-14
Symptoms
The "
fw vsx fetch" command fails with this error:"
Management rejected fetch for this module - version matching problem"
Note: The "vsx fetch" command fetches the most current configuration files from the Security Management Server or Multi-Domain Management Server and applies them to the Virtual System Extension (VSX) Gateway, ensuring it is up to date.
- The RMA Restore tool may fail with a similar error when executing the "
fw vsx fetch" command.
Note: The RMA (Return Merchandise Authorization) Restore Tool is part of the Central Deployment Tool (CDT), which automates the process of restoring a backup configuration to a replacement Security Gateway.
- The "
sp_upgrade" script may fail with a similar error when executing the "fw vsx fetch" command.
Note: The "sp_upgrade" script upgrades software on Maestro Security Groups.
Cause
This issue occurs when the VSX policy is compiled using an incorrect version. Specifically, it affects environments where:
- The Security Management Server or Multi-Domain Management Server has been upgraded to version R82.
- The VSX Gateway or VSX Cluster remains version R81.x.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for Quantum Force 3900 Appliances starting from Take 22
- Jumbo Hotfix Accumulator for R82 starting from Take 36
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.