> Source: [sk144733](https://support.checkpoint.com/results/sk/sk144733)

# sk144733 - Reply traffic originated by the Cluster Standby member is dropped with "fwha_select_ip_packet: dropping not private packet ..."

| Property | Value |
|----------|-------|
| Solution ID | sk144733 |
| Date Created | 2019-01-15 |
| Last Modified | 2019-01-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Reply traffic originated by the Cluster standby member is dropped with "`fwha_select_ip_packet: dropping not private packet to <Cluster_VIP_address> in state STANDBY`" message when running a cluster + drop debug.
* The traffic originated from the Standby member is returned to the MAC address of the Standby member and has the Source IP address of the Cluster Virtual IP (VIP).

## Cause

When the Standby Cluster member initiates the connection in High Availability cluster, the reply packets to such connection are expected to reach the Active Cluster member instead.   

When the traffic from the Standby member has the Cluster VIP as the Source IP and reaches the adjacent Layer-2 device on that interface, since the Layer-2 device associates the Cluster VIP address with the Physical MAC address of the Cluster Active member, the Layer-2 device is thus expected to return the traffic to the Active Cluster member.  

The Active Cluster member in turn is expected to forward the packet to the Standby member over the Synchronization interface.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
