> Source: [sk175552](https://support.checkpoint.com/results/sk/sk175552)

# sk175552 - Upon a cluster failover, VPN traffic (UDP 4500) leaves the now active cluster member with the physical MAC address of the old active cluster member

| Property | Value |
|----------|-------|
| Solution ID | sk175552 |
| Date Created | 2021-10-06 |
| Last Modified | 2022-01-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * After a cluster failover, there is a VPN traffic (UDP port `4500`) outage on the new active cluster member.
* The new active cluster member shows the MAC address of the old active cluster member.
* Not all cluster members run on the same Jumbo Hotfix Accumulator take.

## Cause

Routing information of NAT-T traffic is not synchronized correctly to all kernel instances on the standby cluster member. The active member MAC address in routing information is not converted to the standby member MAC address.  
As a result, after cluster failover the new active member uses the wrong MAC address for NAT-T traffic routing (MAC address of the previous active member).

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 126
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 241

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
