> Source: [sk184927](https://support.checkpoint.com/results/sk/sk184927)

# sk184927 - Cloud Firewall cluster failovers caused by monitored Smart-1 Cloud tunnel interface

| Property | Value |
|----------|-------|
| Solution ID | sk184927 |
| Date Created | 2026-05-22 |
| Last Modified | 2026-05-25 |
| Technical Level | Advanced |
| Products | Cloud Firewall |
| Versions | R82.10, R81.20, R82 |
| OS | Gaia |

## Symptoms

- * A new Cloud Firewall cluster managed by Smart-1 Cloud switches repeatedly between Active and Standby roles (cluster flapping).
* On the Active cluster member, the **maas_tunnel** interface shows a persistent DOWN state in ClusterXL, while all other cluster interfaces show UP.
* The Smart-1 Cloud tunnel remains fully operational and connected to the Check Point Portal.
* Each cluster failover resets the BGP session on the upstream router or switch.

## Cause

The cluster flapping occurs because the **maas_tunnel** interface is incorrectly configured as a monitored ClusterXL port in the cluster object topology.  

This misconfiguration typically occurs after you migrate an existing on-premises cluster object into Smart-1 Cloud.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
