> Source: [sk146812](https://support.checkpoint.com/results/sk/sk146812)

# sk146812 - Missing dynamic object configuration on ClusterXL standby member causes outage after failover

| Property | Value |
|----------|-------|
| Solution ID | sk146812 |
| Date Created | 2019-02-13 |
| Last Modified | 2019-12-29 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * After failover, newly elected active ClusterXL member stops processing traffic.
* In kernel debug (fw ctl zdebud + drop), traffic is getting dropped by dynamic object rule (any/dynamic \> dynamic/any drop).
* Dynamic routing (OSPF and BGP) neighborship with peers is not formed anymore.
* zdebug drop might show below drop dropped by fw_first_packet_xlation Reason: Dynamic object is already being resolved

## Cause

Dynamic object was defined on the Security Management server and policy was installed.  
But, the IP range was defined only on the ClusterXL active member.  
As soon as the cluster fails over, the traffic starts to drop.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
