> Source: [sk182285](https://support.checkpoint.com/results/sk/sk182285)

# sk182285 - Cluster logs cannot reach an internal Log Server when Cluster Virtual IP Addresses are configured on different subnets than physical IP addresses

| Property | Value |
|----------|-------|
| Solution ID | sk182285 |
| Date Created | 2024-06-02 |
| Last Modified | 2025-01-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Logs that cluster members send for inspected traffic do reach an internal Log Server when Cluster Virtual IP Addresses are configured on different subnets than physical IP addresses of the cluster members.

* Traffic capture on cluster members shows:


  1. The connection from the cluster members to the Log Server has the Source IP address that is the Cluster Virtual IP.
  2. A reply from the Log Server is never received.

## Cause

This behavior is by design.

By design, ClusterXL Members always hide their traffic behind the Cluster Virtual IP address configured on the corresponding interfaces.

For configuration steps, see the [R81.20 ClusterXL Administration Guide](https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_ClusterXL_AdminGuide/Content/Topics-CXLG/Example-of-cluster-IP-addresses-on-different-subnets.htm) \> Chapter "Advanced Features and Procedures" \> Section "Cluster IP Addresses on Different Subnets" \> Section "Example of Cluster IP Addresses on Different Subnets".

Example network topology:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1715242740120/cluster_ip_vip202405091620581.png)

1. A router separates between the Internal Log Server (on the network 10.10.10.0 / 24) and the ClusterXL members (on the network 192.168.1.0 / 24)
2. The Internal Log Server has the IP address 10.10.10.1 / 24
3. The physical IP addresses of the ClusterXL Members on the interfaces eth0 are 192.168.1.1 / 24 and 192.168.1.2 / 24
4. The Cluster Virtual IP address on the interfaces eth0 is 172.16.6.100 / 24
5. ClusterXL Members have a static route to send traffic that is destined to 10.10.10.0 / 24 through the interface eth0
6. It is not possible to configure a static route to send traffic from 172.16.6.0 / 24 to 10.10.10.0 / 24 because the Virtual IP address 172.16.6.100 does not belong to any interface on the ClusterXL Members

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
