> Source: [sk170158](https://support.checkpoint.com/results/sk/sk170158)

# sk170158 - The "asg diag verify" command shows that the "MAC Setting" test failed

| Property | Value |
|----------|-------|
| Solution ID | sk170158 |
| Date Created | 2020-10-22 |
| Last Modified | 2025-01-19 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * The output of the "`asg diag verify`" command on the Security Group shows that the "MAC Setting" test fails.

  <br />

* The output of the "`mac_verifier -v`" command on the Security Group shows:


  ```
  
  Verifying FW1 mac magic value in /etc/smodb.json...
  FW1 mac magic value (1 None.) is different than /etc/smodb.json value (254)"
  ```

* After policy installation, the last octet in the MAC Address of uplink pseudo-interfaces on the Security Group changes from "FE" to "01".

  Example output of the "`ifconfig`" command:

  ```
  
  eth1-07     Link encap:Ethernet  HWaddr 00:1C:7F:81:07:01
              inet addr:1.1.1.1  Bcast:1.1.1.255  Mask:255.255.255.0
              UP BROADCAST MULTICAST  MTU:1500  Metric:1
              RX packets:0 errors:0 dropped:0 overruns:0 frame:0
              TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
              collisions:0 txqueuelen:0
              RX bytes:0 (0.0 b)  TX bytes:0 (0.0 b)
  ```

## Cause

Scalable Platforms use the internal MAC Magic value to build MAC addresses of internal pseudo-interfaces for a Security Group. The internal MAC Magic value is used as the last octet in MAC addresses.

Scalable Platforms take the last octet of the IP address assigned to the Management interface of a Security Group and use it as the default MAC Magic value (converted to the HEX format).

Due to this design, when the last octet of the Management IPv4 address is "X.X.X.254", or if no IPv4 address is configured on the Management interface, the internal pseudo-interfaces of uplinks get the wrong MAC address.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
