> Source: [sk146952](https://support.checkpoint.com/results/sk/sk146952)

# sk146952 - Adding/Removing VLANs post-cluster-configuration on locally-managed SMB appliances causes various issues

| Property | Value |
|----------|-------|
| Solution ID | sk146952 |
| Date Created | 2019-02-12 |
| Last Modified | 2022-07-21 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1600, 1800, 910 |

## Symptoms

- Adding/Removing VLANs post-cluster-configuration on locally-managed SMB appliances may randomly cause the following issues:

* The output of 'cphaprob state' command shows IP addresses that differ from the IP addresses of Sync interfaces according to [sk61546](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk61546).
* Enabling High Availability on the new added VLANs takes a lot of time
* Error messages regarding connectivity and configuration might pop up
* Standby member becomes the active one (failover)

## Solution

This feature is not included in the product. If you need it, please submit a [Request for Enhancement](https://www.checkpoint.com/rfe/login.htm).

**As a workaround:**

In a maintenance window, do the following:

1. Reset the cluster on the secondary (standby) member.
2. Add/Remove the needed VLANs on both appliances.
3. Enable High Availability on the new added VLANs on the primary (active).
4. Reconfigure the cluster on the secondary one.

**Notes:**

* You should create all the needed VLANs on the switches (non CP) before adding the VLANs to the CP appliances, otherwise the VLANs will be considered as 'Down' which may cause cluster instability and failover according to [sk57100](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk57100&partition=Advanced&product=ClusterXL%22).
* After reseting the cluster on the secondary (standby) member, the internal CA 'CRL' should be reinitlized.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
