> Source: [sk185219](https://support.checkpoint.com/results/sk/sk185219)

# sk185219 - IPv6 Proxy NDP related traffic is not processed correctly after ClusterXL failover until policy installation

| Property | Value |
|----------|-------|
| Solution ID | sk185219 |
| Date Created | 2026-08-03 |
| Last Modified | 2026-08-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * After a ClusterXL failover, Proxy NDP-related traffic destined for an IPv6 server behind the Cluster is not processed correctly by the newly active cluster member.

  The affected traffic continues to be associated with the cluster member that was active before the failover.
* No relevant packet drops are displayed in the output of the `"fw ctl zdebug"` on either cluster member.

* Packet captures on the standby member do not show traffic for the affected IPv6 server.

* Debug logs on the newly active member show that the traffic is ultimately matched by the Cleanup Rule.

* Installing a policy on the Security Gateway immediately restores normal traffic handling.

* IPv4 traffic is not affected.

## Cause

An issue in the ClusterXL IPv6 and NAT64 failover flow prevents the relevant IPv6 traffic ownership state from being transferred correctly to the newly active cluster member during failover.

As a result, IPv6 and NAT64 traffic may continue to be associated with the member that was active before the failover. Because the Security Gateway does not make a visible firewall drop decision for this traffic path, no relevant drops are displayed in `fw ctl zdebug`.

IPv4 traffic is not affected because the issue is specific to the IPv6 and NAT64 failover handling path.

Installing the policy refreshes the runtime state on the Security Gateway and restores correct IPv6 and NAT64 traffic handling until the issue recurs.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
