> Source: [sk159112](https://support.checkpoint.com/results/sk/sk159112)

# sk159112 - DHCP relay traffic drop after ClusterXL upgrade to R80.x

| Property | Value |
|----------|-------|
| Solution ID | sk159112 |
| Date Created | 2019-07-24 |
| Last Modified | 2019-07-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * DHCP relay (legacy services) stopped working after upgrade of one cluster member from R77.30 to R80.X and moving the traffic to the upgraded member.

* DHCP Discover received and forwarded to DHCP server as expected.

* DHCP Offer received from DHCP server to VIP IP and translated to physical IP.

* Then, the active Gateway "R80.X" forwards this traffic, which is destined to its interface physical IP, toward the standby Gateway "R77.30" over the sync interface.

* As a result the standby member "R77.30" drops the traffic due to anti-spoofing

## Cause

During the Cluster upgrade, Policy with new DHCP rules was pushed to R80.X member, and not to the R77.30 member. Due to the difference in Policies, both Cluster members were assigned with the same Cluster ID (0).  
This caused the situation where the DHCP offer directed to a given interface could not be matched with a specific cluster member.  
Thus the R80.X member "assumed" the packet is destined to the R77.30 member and forwarded it to the other member (via Sync interface).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
