> Source: [sk107434](https://support.checkpoint.com/results/sk/sk107434)

# sk107434 - Unable to establish SIC with the peer member on a Full HA cluster

| Property | Value |
|----------|-------|
| Solution ID | sk107434 |
| Date Created | 2015-09-01 |
| Last Modified | 2020-04-15 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * "`Failed to connect to Security Gateway`" error when attempting to establish SIC with the peer cluster member in Full HA cluster.

* Kernel debug ('`fw ctl debug -m fw + drop`') on cluster members shows that TCP traffic between cluster members is dropped:  

  `fw_log_drop: Packet proto=6 `*IP_Address_of_Member_A* `:`*Source_Port*` -> `*IP_Address_of_Member_B* `:`*Destination_Port*` dropped by fw_cluster_ttl_anti_spoofing Reason: ttl check drop`

* At least one of the cluster members already has policy installed on it.

## Cause

There is at least one Layer 3 networking device (router) separating the Management interfaces of both cluster members.

When reply packets are sent from one cluster member to another, and Extended Cluster Anti-Spoofing is enabled, the packets are dropped for spoofing, because their TTL is less than 255 and their Source IP address belongs to the cluster member.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
