> Source: [sk114233](https://support.checkpoint.com/results/sk/sk114233)

# sk114233 - VPN RDP (UDP Port 259) sent from ClusterXL Standby Member using Virtual IP Address

| Property | Value |
|----------|-------|
| Solution ID | sk114233 |
| Date Created | 2016-10-30 |
| Last Modified | 2020-10-28 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * RDP Traffic is sent from the Standby Member with the Source IP of the Virtual IP, but with the MAC Address of the Standby Member causing impact to SDN (ACI / NSX)
* Creating a No-Nat rule, or excluding the port and protocol in *$FWDIR/lib/table.def* does not have effect.
* Nat from the Standby Member IP address to the Cluster Virtual IP address is done on the "vpn nat outbound" chain.

## Cause

(**Environment:** Local VPN Peers (Managed by the same Management Server) Link Selection is configured to "Link Probing" for Redundancy.

When a Cluster Member initiates a VPN tunnel that has Link Probing defined, the member will initiate RDP traffic towards that peer to determine which link is alive.

A temporary solution is to push the policy to clear the link resolving related Kernel table. However the standby will initiate RDP packets again as soon as there is a trigger for a VPN tunnel.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
