> Source: [sk184857](https://support.checkpoint.com/results/sk/sk184857)

# sk184857 - ARP Packets Contain Invalid MAC Address

| Property | Value |
|----------|-------|
| Solution ID | sk184857 |
| Date Created | 2026-03-29 |
| Last Modified | 2026-04-13 |
| Technical Level | Advanced |
| Products | Scalable Platforms |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |

## Symptoms

- * Address Resolution Protocol (ARP) packets sent by a cluster member contain an unexpected or invalid MAC address in the ARP payload.

* Traffic disruption occur when connected switches enforce strict MAC consistency checks.

* Traffic between Virtual Systems (VSs) through the Virtual Switch (VSW) does not pass as expected.

## Cause

Both the legacy Same Virtual MAC (VMAC) mechanism and the newer OS-based Same VMAC mechanism are enabled simultaneously.

* The legacy Same VMAC implementation modifies the MAC address inside ARP packets before transmission.
* The OS-based Same VMAC implementation updates the MAC address at the operating system level for all data interfaces and does not modify packet contents.

When both mechanisms are enabled, they operate concurrently and interfere with each other. As a result, the MAC address in the ARP payload does not match the effective interface MAC address, which can cause switches to drop traffic or mislearn MAC entries.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
