> Source: [sk185239](https://support.checkpoint.com/results/sk/sk185239)

# sk185239 - ElasticXL drops return traffic on non-pivot members

| Property | Value |
|----------|-------|
| Solution ID | sk185239 |
| Date Created | 2026-08-05 |
| Last Modified | 2026-08-10 |
| Technical Level | General |
| Products | Scalable Platforms |
| Versions | R82.10, R82 |
| OS | Gaia |

## Symptoms

- * ElasticXL drops return traffic on non-pivot / non-Single Management Object (SMO) members.

* Connectivity issues occur for affected connections.

* Traffic works as expected when only one ElasticXL member is active.

* The `fw ctl zdebug` output shows drops with these reasons:
  *CPHWD_STAT_VIOL_FWD_NON_PIVOT Cluster Error*

* Debug output shows pivot forwarding failure messages before the packet drop.


  Example:


  *CPHWD_STAT_VIOL_FWD_NON_PIVOT Cluster Error*


  *pivot_prepare_forward: zero MAC address, failed to forward*


  *packet dropped by CPLS*

## Cause

The dispatcher and Performance Pack (PPAK) components do not receive the required MAC address updates.
Because these components do not have the required MAC address information, the ElasticXL forwarding logic cannot process the affected traffic correctly.  

As a result, the Security Group Member drops the packet with this reason:   
*CPHWD_STAT_VIOL_FWD_NON_PIVOT*

Debug output can also show pivot forwarding failures related to a zero MAC address.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
