sk183602 - R81.20 / R81.10 / R81 Security Gateways may fail to fetch the Threat Prevention policy from their R82 Management Server
R81.20 / R81.10 / R81 Security Gateways may fail to fetch the Threat Prevention policy from their R82 Management Server
Product: Multi-Domain Security Management, Security Management
Version: R82
OS: Gaia
Last Modified: 2025-08-21
Symptoms
R81.20 / R81.10 / R81 Security Gateways, Cluster Members, and Scalable Platform Security Groups may fail to fetch the Threat Prevention policy from their R82 Security Management Server / Multi-Domain Security Management Server.
Upgrade of Security Gateway / Security Group / Cluster Member fails because it cannot install the Threat Prevention policy in this scenario:
- Security Gateway / Security Group is upgraded to the version R81, R81.10, or R81.20
- The Management Server runs the version R82
- Indication during an upgrade on a VSX Gateway / VSX Cluster Member:
The output of the Expert mode command vsx stat -v in the main context VS0 shows one of these issues:
- In the section
VSX Gateway Status,
in the field Threat Prevention Policy the value is empty, or <No Policy>, or default filter
- In the section
Virtual Devices Status,
the cell Threat Prevention Policy is empty, or shows <No Policy>, or shows default filter
for one or more of the Virtual Systems
- Indication during an upgrade on a Security Group (Maestro / Scalable Chassis) in the Gateway mode:
- The output of the script
sp_upgradeshows:
Fetching the policy from the Management Server and installing it... Succeeded
Fetching the Anti-Malware (AMW) policy from the Management Server Failed on members <ID>
Fetching the Anti-Malware (AMW) policy from the <IP Address of Management Server> Failed on members <ID>
The output of the Expert mode command
cphaprob statshows that the cluster state isDOWNand showsActive PNOTEs: AMW.The output of the Expert mode command
cphaprob listshows that the Critical DeviceAMWreports its state asproblem.
- Indication during an upgrade on a Security Group (Maestro / Scalable Chassis) in the Traditional VSX mode:
- The output of the script
sp_upgradeshows:
Fetching the policy from the Management Server and installing it... Succeeded
Fetching the Anti-Malware (AMW) policy from the Management Server Failed on members <ID>
Fetching the Anti-Malware (AMW) policy from the <IP Address of Management Server> Failed on members <ID>
The output of the Expert mode command
cphaprob statin the main context VS0 shows that the cluster state isDOWNand showsActive PNOTEs: VSX Config.The output of the Expert mode command
cphaprob listin the the main context VS0 shows that the Critical DeviceVSX Configreports its state asproblem.
The output of the Expert mode command vsx stat -v in the main context VS0 shows one of these issues:
- In the section
VSX Gateway Status,
in the field Threat Prevention Policy the value is empty, or <No Policy>, or default filter
- In the section
Virtual Devices Status,
the cell Threat Prevention Policy is empty, or shows <No Policy>, or shows default filter
for one or more of the Virtual Systems
Cause
The R82 Management Server compiles the Threat Prevention (AMW) policy using its own version (internal value "6.0.5.5"), instead of the required Security Gateway version (internal value "6.0.5.2").
The Security Gateway fails the Threat Prevention policy installation because of this internal version mismatch.
Solution
This problem was fixed. The fix is included in the Management Server starting from:
- Jumbo Hotfix Accumulator for R82 starting from Take 33
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version, and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-06-26
Last Modified: 2025-08-21
Was this page helpful? Yes/No