> Source: [sk184420](https://support.checkpoint.com/results/sk/sk184420)

# sk184420 - Cluster enters an Active/Active split-brain state, causing both members to become active simultaneously

| Property | Value |
|----------|-------|
| Solution ID | sk184420 |
| Date Created | 2025-12-10 |
| Last Modified | 2025-12-11 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- The following may occur in a ClusterXL environment:

* The cluster enters an Active/Active split-brain state, causing both members to become active simultaneously.
* Frequent port flapping and intermittent loss of Cluster Control Protocol (CCP) communication.
* Repeated failover events and rapid state changes (examples: Active ? Active(!) ? Down ? Standby ? Lost).
* Soft-lockup warnings, time-related violations, or delays in the `fwk.elg` file.
* Temporary recovery after rebooting both cluster members.

## Cause

When Management Data Plane Separation (MDPS) is enabled and IPv6 is disabled on a Security Gateway running in User Mode (UPPAK), IPv6 Member Discovery packets may trigger a leak in IPv6 memory buffers.
If IPv6 Member Discovery packets reach the cluster under these conditions, they can cause:  

* Progressive SKB/mbuf memory leakage
* Inability to process CCP traffic
* Loss of cluster synchronization
* An Active/Active split-brain event and potential service outage

To identify the issue:  

* Check the `$FWDIR/log/fwk.elg` file for these error:  
  `fwmultik_process_entry: no corresponding ipv6 instance for opcode 2, instance 0`
* Allocation failures in `/var/log/usim_x86.elg`:  
  `[uspace];[tid_1];[UPPAK];fwk_snd_alloc_mbuf_for_fw: failed to alloc mbuf for fw, vsid: 0, instance: 10, (nil)`  
  `[uspace];[tid_1];[UPPAK];fwk_snd_msg_queue_dequeue_msg: failed to alloc mbuf for fw, vsid: 0, instance: 10, ipv6: 0`  
  `[uspace];[tid_1];[UPPAK];m_get: allocation failure`

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
