> Source: [sk103438](https://support.checkpoint.com/results/sk/sk103438)

# sk103438 - Security Gateway sending physical MAC in GARP during policy install

| Property | Value |
|----------|-------|
| Solution ID | sk103438 |
| Date Created | 2014-11-20 |
| Last Modified | 2014-11-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * The Security Gateway uses the VMAC to send GARP every minute.  
  However, during policy installation, the Security Gateway uses the physical MAC to send the GARP, instead.
* ClusterXL is configured with VMAC mode ([sk50840](http://supportcontent.checkpoint.com/solutions?id=sk50840))

## Cause

During policy installation, the cluster IP addresses (VIP) of each member are cleared and later on are set again.  

After the cluster IP addresses are cleared, and still during the policy installation process, each member checks if it should enable its VMAC mode.  

If it decides it should, it then checks which interfaces should use VMAC (only interfaces that have a VIP), and assigns them with the relevant VMAC.  

The decision whether an interface should use a VMAC is made according to whether this interface has a cluster IP address. If it has, it should also have a VMAC.  

Since, however at this stage all cluster IP addresses are cleared, the member decides that no interface should use VMAC, and hence clears the VMACs values as well.  

Later on, the cluster IP addresses are set and with them the VMAC as well, but all GARP packets that are being sent during these 2 phases (clearing the cluster IP addresses and resetting them) will carry the physical MAC address of the sending member, since at this time no VMAC is configured.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
