> Source: [sk111635](https://support.checkpoint.com/results/sk/sk111635)

# sk111635 - Traffic outage after a fail-over between Virtual Systems in VSLS Bridge Mode when SecureXL is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk111635 |
| Date Created | 2016-05-23 |
| Last Modified | 2016-05-23 |
| Technical Level | Advanced |
| Products | Security Gateway, Hardware |
| Versions | R82.10, R82, R81.20, Not Version-Specific |
| OS | Gaia |
| Platform | 15000, 3000, 5000, VMWare ESX |

## Symptoms

- * Traffic outage after a fail-over between Virtual Systems in VSLS Bridge Mode (e.g., by running the "`vsx_util vsls`" command on Security Management Server and selecting option "`4. Manually set priority and weight`").

* Traffic flow resumes when switches send ARP Request and new active Virtual Systems respond with relevant MAC Address.

* Disabling SecureXL on VSX cluster members resolves the issue (no traffic outage after a fail-over between Virtual Systems).

* Bridge Active/Standby state is configured as Check Point ClusterXL, and not as standard Layer 2 loop detection (STP).

## Cause

During the fail-over, Virtual Systems in VSLS Bridge Mode do not send CCP MAC Learning packets. As a result, switches can not update their MAC Address tables with the MAC Address of the new Active Virtual Systems.

When SecureXL is enabled, accelerated packets do not update Linux kernel shadow table, and, as a result, Check Point kernel table *fdb_shadow*.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
