> Source: [sk162953](https://support.checkpoint.com/results/sk/sk162953)

# sk162953 - IGMP traffic dropped by "local interface address spoofing" in VSX HA

| Property | Value |
|----------|-------|
| Solution ID | sk162953 |
| Date Created | 2019-10-10 |
| Last Modified | 2019-12-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- As the traffic is leaving using the funny IP, when it arrives the other VS, it is dropped by: "local interface address spoofing" (it is normal that multiple VS's will use the same internal IP, as mentioned in [sk110345](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110345)).

## Cause

IGMP traffic sent by the cluster mechanism is sent using the internal IP (Funny IP), towards Multicast group 0.0.0.0. The wrp links are trying to reach out multicast group 0.0.0.0.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
