> Source: [sk169777](https://support.checkpoint.com/results/sk/sk169777)

# sk169777 - ClusterXL HA with Gaia kernel 3.10 is in Active/Active state due to Interface Active Check

| Property | Value |
|----------|-------|
| Solution ID | sk169777 |
| Date Created | 2020-10-05 |
| Last Modified | 2021-02-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Cluster members are showing Active status on each member without the other member visible in output of `#cphaprob stat` command.

* Interface Active Check PNOTE shows the following reason: `"Interface ethX is down (Cluster Control Protocol packets are not received)`

* Sync interface is showing Inbound: UP Outbound: DOWN in the output of `#cphaprob -a if` command.

* Timestamp of installed policy does not match and installing policy does not resolve the issue.

## Cause

Since R80.30 kernel 3.10 has the CCP encryption feature is enabled by default.

During a policy push the encryption key is changed and pushed to both gateways.

In case the cluster members run on different policies they will not have the same encryption keys and CCP packets will not be shared between the members.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
