> Source: [sk105170](https://support.checkpoint.com/results/sk/sk105170)

# sk105170 - Configuration requirements / considerations and limitations for VRRP cluster on Gaia OS

| Property | Value |
|----------|-------|
| Solution ID | sk105170 |
| Date Created | 2015-03-11 |
| Last Modified | 2026-03-10 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Solution

This article lists the configuration requirements / considerations and limitations for VRRP cluster running on Gaia OS.

Enter the string to filter this table:

|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Configuration / Feature / Software Blade                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Notes                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| More than two members in a VRRP cluster                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Not supported by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Synchronization Interfaces on VRRP cluster members                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | In a VRRP cluster (that supports only cluster members), the synchronization interfaces must always be connected directly to each other. VRRP clusters do not use ARP to communicate over synchronization interfaces between VRRP cluster members. This behavior is by design and relies on the internal Cluster Control Protocol (CCP) broadcast to share the MAC address and IP address of VRRP cluster members. A unique type of CCP broadcast is sent every few seconds, containing interface details (MAC address, IP address, and other details) for VRRP cluster members. This broadcast encapsulates all necessary information for member-to-member communication, eliminating the need for ARP. If a switch or third-party device is used to facilitate connectivity between synchronization interfaces, it must fully support the VRRP synchronization mechanism, especially the broadcast behavior of the Check Point Cluster Control Protocol (CCP) broadcast. Refer to third-party device documentation for compatibility and configuration guidance before deployment. If support for a switch is required, then submit an RFE as described in [sk71840](https://support.checkpoint.com/results/sk/sk71840). |
| MDPS routing separation ([sk138672](https://support.checkpoint.com/results/sk/sk138672))                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | MDPS routing separation is not supported with a VRRP cluster.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VRRP Active-Active in a ClusterXL environment                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     | Not supported by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Synchronization of Dynamic Routes between VRRP cluster members for any protocols                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  | Routes learned from OSPF and BGP are synchronized from the VRRP Master to the VRRP Backup. With **Graceful Restart** enabled, on a cluster failover, neighboring routers do not remove the routes learned from the VRRP cluster. The previously synchronized routes keep traffic flowing while the protocol state is rebuilt.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| VRRP configuration in the VSX mode                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                | Not supported by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Simplified VRRP configuration (Monitored-Circuit) *and* Advanced VRRP configuration on the same cluster                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           | Not supported by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Dynamic Routing neighborship with a VRRP *Backup* member                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          | Not supported by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Standalone configuration (Security Gateway and Security Management Server on the same cluster)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                    | Not supported by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Configuring the number of critical interfaces when using Bond (*$FWDIR/conf/cpha_bond_ls_config*)                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 | Not supported by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| |---------------------------------------------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| | Multiple **Backup Addresses** configured on the same subnet on the same interface (the same VRID) | *Example* : [![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105170/Example.png)](https://sc1.checkpoint.com/sc/SolutionsStatics/sk105170/Example.png "Click the image to see it in full size in a new tab/window") | | Not supported by design when VRRP cluster is configured per [sk92061 - How to configure VRRP on Gaia](https://support.checkpoint.com/results/sk/sk92061) (meaning, the ClusterXL is enabled in the cluster object). Only one Backup address is supported per interface.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| VRRP configuration on all routers in a Virtual Router                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | * System time must be identical on *all* routers by design. * VRRP Hello Interval must be identical on *all* routers by design. * Virtual Router IDs must be the identical on *all* routers by design. * Priority Delta must be sufficiently large for the Effective Priority to be lower than the Master router by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| Virtual Address support for *any* supported Dynamic Routing protocol (advertising the Virtual IP address, rather than the real (physical) IP address of the interface, establishes neighbor relationship by using the Virtual IP address as the Source IP address of Dynamic Routing packet)                                                                                                                                                                                                                                                                                                                                                                      | Dynamic Routing protocols must be enabled *only* on interfaces running VRRP. The Virtual Address option must be enabled for these protocols: OSPF, OSPFv3, RIP, and PIM.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| RIP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | RIP runs only on the VRRP *Master* by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| OSPFv2                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | OSPF runs only on the VRRP *Master* by design. Router ID must be *identical* on all VRRP members.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| OSPFv3                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            | OSPFv3 runs only on the VRRP *Master* by design. Router ID must be identical on all VRRP members.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| BGP                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | You must enable BGP *only* on interfaces running VRRP. The Virtual Address option is automatically used.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| PIM                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               | PIM runs only on the VRRP *Master* by design.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| IPv6 Router Discovery                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             | Advertisements are sent with the Virtual IP Address as the Source IP Address. The Source MAC Address used depends on the VRRP VMAC configuration.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |

{#Unique_IDTable}

**Additional Notes:**

* Must configure a firewall rule to accept VRRP packets sent from VRRP routers to the multicast IP address 224.0.0.18.
* When using VRRP VMAC mode, you must disable both Spanning Tree and IGMP snooping disabled to avoid the split brain scenario.

**Related Documentation:**

* See the [*Gaia Administration Guide*](https://support.checkpoint.com/product/531#f-commonsource=C.%20Documentation) for your version.

* See the [*Gaia Advanced Routing Administration Guide*](https://support.checkpoint.com/product/531#f-commonsource=C.%20Documentation) for your version.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
