> Source: [sk108848](https://support.checkpoint.com/results/sk/sk108848)

# sk108848 - Output of "cphaprob -a if" command shows a Loopback interface as "Down" on all cluster members

| Property | Value |
|----------|-------|
| Solution ID | sk108848 |
| Date Created | 2015-11-30 |
| Last Modified | 2023-01-30 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- Output of "`cphaprob -a if`" command shows a Loopback interface (e.g., "`loop00`") as "Down" on all cluster members.

## Cause

More than one virtual loopback interface was configured with an IP address on each cluster member.

Later, these virtual loopback interfaces were configured to be part of Cluster Topology in the Cluster object in SmartDashboard - with Network Objective "Cluster" or "Monitored Private".

Since these virtual loopback interfaces do not have a network cable attached, the CCP packets can not be sent/received between these virtual loopback interfaces. This, by design, causes the interfaces to be declared as "Down".

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416)

Check Point recommends to always upgrade to the [Recommended version](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk95746) ([Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=435) / [VSX](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=359) / [Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=184) / [Multi-Domain Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=166) / [SmartConsole](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=191)).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Management Server and Security Gateways / Cluster Members involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

**Workaround Procedure**   
In versions R81 and lower, it is **not supported**to use virtual loopback interfaces with Network Objective "Cluster" or "Monitored Private" in Cluster Topology.

Follow these steps in SmartConsole / SmartDashboard to remove virtual loopback interfaces:

1. Remove the IP addresses from the additional virtual loopback interfaces on each cluster member.
2. Correct the Cluster Topology.
3. Install the policy.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
