sk184233 - Maestro Orchestrator fails to add a new Security Appliance to a Security Group when Fastforward is enabled
Maestro Orchestrator fails to add a new Security Appliance to a Security Group when Fastforward is enabled
Product: Maestro HyperScale Firewall
Version: R82, R82.10
OS: Gaia
Platform: Maestro Orchestrator
Last Modified: 2026-04-06
Symptoms
Gaia Portal on the Maestro Orchestrator shows "
Failed to apply topology" after adding a new Security Appliance to a Security Group and clicking " Apply" (in the "Orchestrator Management" section, click the "Security Groups" page).Adding a new Security Appliance to a Security Group in Gaia Clish on the Maestro Orchestrator fails with:
set maestro security-group apply-new-config
Traceback (most recent call last):
File "/usr/lib/smo/libssm_sg.py", line XXX, in calc_summary_on_local
rc = running_sgdb.sanity()
File "/usr/lib/smo/libssm_sg.py", line XXX, in sanity
self._sanity_fastforward()
File "/usr/lib/smo/libssm_sg.py", line XXX, in _sanity_fastforward
used_interfaces = output[0].split(',')
^^^^^^^^^^^^^^^^^^
TypeError: a bytes-like object is required, not 'str'
- These errors appear in the
/var/log/ssm_sg.log.dbgfile on the Maestro Orchestrator:
<DATE TIME>,XXX _sanity_fastforward INFO Sanity - Checking fastforward used interfaces
<DATE TIME>,XXX is_fastforward_enabled INFO Executing: tor_util fastforward feature state, res = 0, output = b'1'
<DATE TIME>,XXX _sanity_fastforward INFO Executing: tor_util fastforward show _used_interfaces 1, res = 0
<DATE TIME>,XXX calc_summary_on_local ERROR Failed to verify changes. Exception: a bytes-like object is required, not 'str' with traceback: Traceback (most recent call last):
File "/usr/lib/smo/libssm_sg.py", line XXX, in calc_summary_on_local
orch_sg_config.sanity()
File "/usr/lib/smo/libssm_sg.py", line XXX, in sanity
self._sanity_fastforward()
File "/usr/lib/smo/libssm_sg.py", line XXX, in _sanity_fastforward
used_interfaces = output[0].split(',')
^^^^^^^^^^^^^^^^^^^^
TypeError: a bytes-like object is required, not 'str'
- Maestro Fastforward is enabled in the Security Group.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 6
- Jumbo Hotfix Accumulator for R82 starting from Take 73
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
As an immediate temporary workaround:
- Disable the Fastforward feature in the Security Group.
- Add the new Security Appliance to the Security Group.
- Enable the Fastforward feature in the Security Group.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-11-03
Last Modified: 2026-04-06