# ElasticXL VSX cluster members fail over several times per day due to HTTP/2 Explicit Proxy process termination

## Product
Security Gateways

## Version
R82

## OS
Gaia

## Last Modified
2026-07-23

## Symptoms
- In an ElasticXL (EXL) Virtual System Extension (VSX) cluster, cluster members fail over repeatedly and unexpectedly several times per day.
- When you run `cphaprob show_failover` in Expert mode on each VSX Cluster Member Security Gateway, the output shows frequent, unplanned state changes (for example, Active ↔ Standby)

### Sample output:
```
[Expert@vsx-member1:0]# cphaprob show_failover
Functional machine ID: 1
Cluster failover log:
...
2026-04-15 10:12:03 member 1 -> Problem
2026-04-15 10:12:03 member 2 -> Active
```
- On some Virtual Systems (VSs), the Firewall kernel (fwk) process unexpectedly exits and generates core dump files. These VS‑level process terminations can trigger cluster instability and cause failovers.

## Cause
A specific HTTP/2 explicit proxy handling condition on VSX Virtual Systems can cause the fwk process to exit unexpectedly. When this occurs on active cluster members, the resulting VS‑level disruption leads the ElasticXL cluster to initiate failovers between members.

## Solution
This problem was fixed. The fix is included starting from:
- [Check Point R82.10](https://support.checkpoint.com/results/sk/sk183506)  
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.

For faster resolution and verification, collect these files:
1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
Access Level: General  
Status: Approved by TAC  
Date Created: 2026-05-23  
Last Modified: 2026-07-23
