> Source: [sk183398](https://support.checkpoint.com/results/sk/sk183398)

# sk183398 -  "Threat Emulation - Communication Error: Could Not Connect to Cloud" alert on a standby cluster member

| Property | Value |
|----------|-------|
| Solution ID | sk183398 |
| Date Created | 2025-04-28 |
| Last Modified | 2025-05-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20 |
| OS | Gaia |

## Symptoms

- * "*Threat Emulation - Communication Error: Could Not Connect to Cloud*" alerts on a standby cluster member.

* The alert resolves itself after performing a failover.

## Cause

This issue occurs because the standby cluster member does not handle outbound connections to the Threat Emulation cloud services correctly. By default, the standby member sends outbound traffic through the active member. However, because of asymmetric routing, some reply packets from the Threat Emulation cloud return directly to the standby member. This results in asymmetric connections. Although the firewall kernel can process asymmetric connections, some features, like Threat Emulation, may not function correctly in this state.  

In one example, a packet capture showed that the active member used its physical IP address instead of the VIP (Virtual IP). As a result, the cloud service responded directly to the standby member's physical IP address, bypassing the active member.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
