> Source: [sk167416](https://support.checkpoint.com/results/sk/sk167416)

# sk167416 - "sfw_mac_filtering_config: ioctl SFW_MAC_FILTERING failed" message when pushing policy on a 1500 device

| Property | Value |
|----------|-------|
| Solution ID | sk167416 |
| Date Created | 2020-06-12 |
| Last Modified | 2022-07-20 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1600, 1800 |

## Symptoms

- When the user pushes a policy to a 1500 device, it prints a message related to MAC Filtering:  

`
Hostname> fetch policy mgmt-ipv4-address `  
Fetching policy from   
Fetching Security Policy from   

Local Security Policy is Up-To-Date.  

Installing Security Policy...  

Installing Security Policy Succeeded.  
Done.  
sfw_mac_filtering_config: ioctl SFW_MAC_FILTERING failed.  
ioctl 43 to the sim device failed (ppak_id=0, rc=-1, errno=22)  
sim_arp_spoofing: ioctl to the SecureXL device failed -1  
Unable to configure anti ARP spoofing  

<br />

## Cause

This is a cosmetic issue. MAC filtering is not supported on 1500 appliances.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
