sk184887 - Maestro Security Group Member status frequently changes to "Down"

Maestro Security Group Member status frequently changes to "Down"

Product

Scalable Chassis, VSX (Traditional)

Version

R81.20, R82, R82.10

Last Modified

2026-05-10

Symptoms

` ... ...

time fwk: State change: ACTIVE -> DOWN | Reason: VSX PNOTE due to problem in Virtual System 1

... time fwk: State change: DOWN -> ACTIVE | Reason: USER DEFINED PNOTE ...

time fwk: State change: DOWN -> ACTIVE | Reason: Member state has been changed due to issue in Virtual System 0 `

h_iterate: invalid return value from callback

[instance_0]: Received thread_blocker signal [instance_0]: [1] 0x72b678d0 [/lib64/libpthread.so.0] (offset 0xf8d0) [instance_0]: [2] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x2c009da) [instance_0]: [3] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x2c96440) [instance_0]: [4] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x1353890) [instance_0]: [5] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x15a5a90) [instance_0]: [6] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0x15b4850) [instance_0]: [7] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_10.so] (offset 0xf25be0) [instance_0]: [8] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_0.so] (offset 0xf26730) [instance_0]: [9] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_0.so] (offset 0x2e35506) [instance_0]: [10] ... [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_sp_0.so] (offset 0x2cac456)

Cause

The CPHWD table (related to the SecureXL/Hardware Acceleration infrastructure) was configured with a size that was too small. When the CPHWD table is full, kernel processes that need to iterate over the entire table (for example, for cleanup, synchronization, or hardware offload operations) may not complete successfully or efficiently.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:

Refer to sk168597 - How to install a Hotfix.

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General

Status: Approved by TAC

Date Created: 2026-05-07

Last Modified: 2026-05-10