> Source: [sk106660](https://support.checkpoint.com/results/sk/sk106660)

# sk106660 - ClusterXL member is down due to Monitor Mode being enabled on a cluster interface

| Property | Value |
|----------|-------|
| Solution ID | sk106660 |
| Date Created | 2015-06-30 |
| Last Modified | 2020-12-15 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Output of "*cphaprob state*" command shows that cluster member is "Down".

* Output of "*cphaprob list*" command shows that Critical Device "Active Interface Check" reports its status as "problem".

* Output of "*cphaprob -a if* " command shows for one of the interfaces (eth*X*) "Inbound: UP Outbound: DOWN:".

* Output of "*ifconfig -a* " command shows interface called "brS-eth*X*", which is not a physical interface and was not created by the administrator.

* Output of "*cphaprob state*" command also shows:

  * On one cluster member "Active/Active in Bridge mode"
  * On the other member "Active/Standby"

## Cause

Interface eth*X* is configured in Monitor Mode, which is *not* supported in cluster - refer to "Limitations" section in [sk101670 - Monitor Mode on Gaia OS and SecurePlatform OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101670#Limitations).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
