# VSNext Virtual Gateway drops traffic when it is connected to a Virtual Switch

**Product:** VSNext  
**Version:** R82  
**OS:** Gaia  
**Last Modified:** 2025-06-15

## Symptoms

- Traffic does not pass through between networks in this VSNext topology:
  
  (Network 1) --- \[ (Virtual Gateway) --- (Virtual Switch) \] --- (Network 2)

- Kernel debug on the Virtual Gateway (g_fw ctl zdebug + drop route | grep <IP Address>) shows:
  
  `;fwmultik_f2p_routing: fw_os_route_retrieve_streaming failed;`
  
  `;fw_os_route_retrieve_streaming: failed to find device for ifnum <XXX>`
  
  `;fwmultik_f2p_cookie_outbound_and_routing: fwmultik_f2p_routing Failed;`
  
  `;fw_log_drop_ex: Packet proto=<XX> <Source> -> <Destination> dropped by fwmultik_process_f2p_cookie_inner Reason: fwmultik_f2p_cookie_outbound_and_routing failed;`

## Cause

The FireWall and SecureXL do not have the required information about the interfaces from all Virtual Switches.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 25

If you choose not to upgrade, as an immediate **workaround**:

1. Connect to the command line on the Security Gateway.  
2. Log in.  
3. If the default shell is Gaia gClish, then go to the Expert mode:
   
   `expert`
4. Bring down and then bring up the relevant interface in the Virtual Switch (see the ID of the Virtual Switch in Gaia Portal):
   
   1. Bring down the physical interface, to which this Virtual Switch is connected:
   
      `gexec -a -c 'vsx_exec -v <ID of Virtual Switch> -c "ifdown <Name of Interface>"' >/dev/null 2>&1`
   
      Example:
   
      `gexec -a -c 'vsx_exec -v 100 -c "ifdown eth3"' >/dev/null 2>&1`
   
   2. Bring up the physical interface, to which this Virtual Switch is connected:
   
      `gexec -a -c 'vsx_exec -v <ID of Virtual Switch> -c "ifup <Name of Interface>"' >/dev/null 2>&1`
   
      Example:
   
      `gexec -a -c 'vsx_exec -v 100 -c "ifup eth3"' >/dev/null 2>&1`
5. Modify the `/etc/rc.d/init.d/virtual_systems` script:
   
   1. Go to the main context:
   
      `g_all -a vsenv`
   
   2. Back up the current `/etc/rc.d/init.d/virtual_systems` script:
   
      `g_all -a cp -v /etc/rc.d/init.d/virtual_systems{,_ORIGNAL}`
   
   3. Download the [improved "virtual_systems" script](https://support.checkpoint.com/results/download/137743) to your computer.
   
   4. Copy the improved script from your computer to the Virtual Gateway to some directory (for example, `/home/admin/`).
   
   5. Assign the required ownership to the script:
   
      `chown -v admin:root /home/admin/virtual_systems.script`
   
   6. Assign the permissions to the script:
   
      `chmod -v 755 /home/admin/virtual_systems.script`
   
   7. Copy the improved script (without the file extension) to all Security Group Members:
   
      `asg_cp2blades /home/admin/virtual_systems.script /etc/rc.d/init.d/virtual_systems`

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

**Access Level:** General  
**Status:** Approved by TAC  
**Date Created:** 2025-05-13  
**Last Modified:** 2025-06-15
