> Source: [sk175165](https://support.checkpoint.com/results/sk/sk175165)

# sk175165 - Cluster drops traffic when Check Point services are stopped on the Standby cluster member 

| Property | Value |
|----------|-------|
| Solution ID | sk175165 |
| Date Created | 2021-11-29 |
| Last Modified | 2021-12-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * An administrator executed the `cphastop` or `cpstop` command on the standby cluster member.

* Kernel debug on the active cluster member shows these drops:

  `IPP 6: failed to send to member <ID of the standby member>, dropping;`
* Kernel debug on the standby cluster member shows these drops:

  `dropped by fw_cluster_ttl_anti_spoofing Reason: ttl check drop;`
* Hosts on the network are configured to send their traffic to the cluster Virtual IP address

* There is no routing to the physical IP addresses of the cluster members

## Cause

Connection to the standby member through the active member requires the Cluster Forwarding Layer, which does not work when Check Point services are stopped on the standby member, in which case:

1. The standby member does not send CCP packets.  
   As are result, it does not respond to the active member when it asks for the MAC address of the applicable interface on the standby member.
2. When the active member receives the traffic packet, it inspects the traffic and may decide to forward it to the standby member. But because the active member is not aware of the MAC address of the standby member, it drops the traffic packet.
3. The connection between cluster members requires a special handling of Anti-Spoofing to keep reliable connectivity between cluster members.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
