sk184233 - Maestro Orchestrator fails to add a new Security Appliance to a Security Group when Fastforward is enabled

Maestro Orchestrator fails to add a new Security Appliance to a Security Group when Fastforward is enabled

Product: Maestro HyperScale Firewall
Version: R82, R82.10
OS: Gaia
Platform: Maestro Orchestrator
Last Modified: 2026-04-06

Symptoms

set maestro security-group apply-new-config

Traceback (most recent call last):
    File "/usr/lib/smo/libssm_sg.py", line XXX, in calc_summary_on_local
      rc = running_sgdb.sanity()
    File "/usr/lib/smo/libssm_sg.py", line XXX, in sanity
      self._sanity_fastforward()
    File "/usr/lib/smo/libssm_sg.py", line XXX, in _sanity_fastforward
      used_interfaces = output[0].split(',')
                        ^^^^^^^^^^^^^^^^^^
TypeError: a bytes-like object is required, not 'str'
<DATE TIME>,XXX _sanity_fastforward INFO Sanity - Checking fastforward used interfaces

<DATE TIME>,XXX is_fastforward_enabled INFO Executing: tor_util fastforward feature state, res = 0, output = b'1'

<DATE TIME>,XXX _sanity_fastforward INFO Executing: tor_util fastforward show _used_interfaces 1, res = 0

<DATE TIME>,XXX calc_summary_on_local ERROR Failed to verify changes. Exception: a bytes-like object is required, not 'str' with traceback: Traceback (most recent call last):

File "/usr/lib/smo/libssm_sg.py", line XXX, in calc_summary_on_local

orch_sg_config.sanity()

File "/usr/lib/smo/libssm_sg.py", line XXX, in sanity

self._sanity_fastforward()

File "/usr/lib/smo/libssm_sg.py", line XXX, in _sanity_fastforward

used_interfaces = output[0].split(',')

^^^^^^^^^^^^^^^^^^^^
TypeError: a bytes-like object is required, not 'str'

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

As an immediate temporary workaround:

  1. Disable the Fastforward feature in the Security Group.
  2. Add the new Security Appliance to the Security Group.
  3. Enable the Fastforward feature in the Security Group.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2025-11-03
Last Modified: 2026-04-06