> Source: [sk138894](https://support.checkpoint.com/results/sk/sk138894)

# sk138894 - In VSX cluster with VMAC mode, traffic does not pass through VSX Cluster members if SecureXL is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk138894 |
| Date Created | 2018-10-25 |
| Last Modified | 2020-10-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * With SecureXL enabled, traffic does not pass from Virtual Router to Virtual System in the following VSX member topology:  

  Network_1 - \[(VR)-(VS)\] - Network_2  
  SecureXL is enabled on both Virtual Router (VR) and on Virtual System (VS).  

* SmartView Tracker does not shows any related drops and VMAC mode is enabled per sk50840.  

  <br />

  <br />

* Cluster kernel debug (`fw ctl debug -vs VSID -m cluster + select`) on the Active VSX cluster member shows:  

  `FW-1: fwha_select_ip_packet: Packet with vmac address which is not belonging to ifn IF IF_NAME (IF_NUMBER - vmac - VMAC_ADDRESS) - dropping packet;`

## Cause

SecureXL does not modify the Source and Destination MAC addresses of the packet when it is moved from Virtual Router to Virtual System ("warp jump"). As a result, Virtual System clustering code drops the packet because packet's MAC addresses do not belong to this Virtual System

PPACK is not and does not need to be aware of VMAC, wrp interface connected to virtual router does not have MAC as it loopback device so cluster code should skip VMAC check in such cases.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
