sk184653 - Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000.
Newly added SGM remains "Down" on Scalable Chassis with SSM440 configured with MTU higher than 9000.
Product: Scalable Chassis, VSX (Traditional)
Version: R81.10 (EOS), R81.20, R82, R82.10
OS: Gaia
Platform: 64000
Last Modified: 2026-07-23
Symptoms
- Creation of a Virtual System Extension (VSX) fails on Scalable Chassis with SSM440 when the Maximum Transmission Unit (MTU) exceeds 9000.
As a result:
- The new Security Group Member remains in a down state.
- A
VSX configCritical Device appears. - Virtual Systems (VSs) are not created on the affected Security Group Member.
- A
- The following error appears during the operation:
db_set error: Failed to set MTU 9216 on interface bond3. Maximum value allowed is 9000.
Cause
The VSX database was originally created on a version lower than R81.10 (for example, R80.20SP).
In these versions, it was possible to configure interface MTU values up to 12000.
Starting from R81.10, the maximum allowed MTU is 9000.
If the existing VSX configuration contains interfaces with MTU values greater than 9000, adding a new Security Group Member running R81.10 fails during the VSX fetch process because the configured MTU exceeds the allowed limit.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 19
- Jumbo Hotfix Accumulator for R82 starting from Take 118
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
If you choose not to upgrade, since this issue arises when configuring not supported MTU value, you should proceed with changing the MTU for the maximum supported value:
Log in to the SmartConsole
Open each Virtual object and lower the MTU on each interface, set it to up to 9000
Push configuration
Push policy
Add the new Security Group Member to the Security Group
You can increase the maximum MTU supported value to 9416 by installing a hotfix.
'Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member / Security Group involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.