> Source: [sk121451](https://support.checkpoint.com/results/sk/sk121451)

# sk121451 - VSX Security ClusterXL Bridge Mode Member is down

| Property | Value |
|----------|-------|
| Solution ID | sk121451 |
| Date Created | 2017-12-01 |
| Last Modified | 2019-06-21 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * The output of the command "cphaprob stat" on Active/Standby member in ClusterXL in bridge mode shows that HA Cluster member state is DOWN.
* The output of the command "cphaprob stat" on Active/Standby member in ClusterXL in bridge mode shows that the Cluster state is ACTIVE/ACTIVE.

## Cause

Configuration may not be complete; fwkern.conf might be missing parameter definitions. In VSX Cluster, according to the kernel state code, Virtual Systems in Bridge Mode act as Active/Standby, however "cphaprob stat" output will show them with Active/Active status. Spanning Tree Protocols are suppose to make sure that only one of the Virtual Systems receives the packets. (fwha_active_standby_bridge_mode=1 allows this).

Interface link state might also not be monitored (fwha_monitor_if_link_state=1 allows this).

Enabling 'Check Point ClusterXL for Bridge Active/Standby' using CPConfig is suppose to set these needed parameters accordingly.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
