> Source: [sk183393](https://support.checkpoint.com/results/sk/sk183393)

# sk183393 - Unusual MAC address �0208.xxxx.xxxx� observed when packets are forwarded from the standby member to the active member via Sync interface

| Property | Value |
|----------|-------|
| Solution ID | sk183393 |
| Date Created | 2025-05-05 |
| Last Modified | 2025-05-05 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * When traffic is sent from the standby member to the active member via the Sync interface, a MAC address in the format "0208.xxxx.xxxx" is observed in tcpdump or cppcap, originating from the standby member Sync interface.
* The MAC address "0208.xxxx.xxxx" does not appear on any physical interface or as part of the VMAC address, even if VMAC is enabled.
* Example: \[Expert@FW2:0\]# cppcap -DNT -f "host 10.30.118.48 and port 181" 08:42:03.278176 Out \[Sync\] 10.11.34.30:1416 \> 10.10.10.1:181 IPP 17 MAC \[02:08:85:00:00:01 \> 00:1c:7f:9f:6

## Cause

By default, in ClusterXL High Availability mode, the cluster hides connections initiated from the standby member to external hosts behind the Cluster Virtual IP.  
With the kernel parameter fwha_cluster_hide_active_only enabled on both members, traffic from the standby member is redirected to the active member via the Sync interface.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
