> Source: [sk172444](https://support.checkpoint.com/results/sk/sk172444)

# sk172444 - Sudden connectivity issues after policy install to VRRP cluster

| Property | Value |
|----------|-------|
| Solution ID | sk172444 |
| Date Created | 2021-03-12 |
| Last Modified | 2021-03-15 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * There are connectivity issues after the policy installs to VRRP Cluster.
* The VRRP is in INIT or Backup state.
* The firewall passes traffic.

## Cause

In the cluster object properties "ClusterXL and VRRP," when you set the Cluster Mode to**ClusterXL** rather than **VRRP** you cause problems.  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk172444/wrong202103121416561.png)
Problems occur when you migrate to a VRRP member with Clustering Disabled (INIT State). When you select **Cluster XL**, Cluster XL sends a Gratuitous ARP to the switch flipping the VIP MAC to the gateway's physical interface. Cluster XL does not use the VMAC of the VRRP cluster. The cluster member becomes active in error.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
