> Source: [sk26874](https://support.checkpoint.com/results/sk/sk26874)

# sk26874 - Cannot simultaneously ping Virtual IP address of the cluster and IP addresses of physical interfaces on cluster members from a remote host

| Property | Value |
|----------|-------|
| Solution ID | sk26874 |
| Date Created | 2004-08-30 |
| Last Modified | 2026-09-23 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Unable to simultaneously ping the Cluster VIP address and physical IP address of a cluster member from a remote host.  

* Unable to simultaneously ping multiple interfaces of the Security Gateway / cluster member.  

* Kernel debug (`fw ctl debug -m fw + conn vm drop`) shows:  

  `;fwconn_set_link: failed to set the link (-3);`  
  `;fwconn_set_link: link collision ignored by SXL;`  
  `;fw_handle_first_packet: fwconn_init_links failed. Dropping packet;`  
  `;fw_log_drop: Packet proto=1 x.x.x.x:M -> x.x.x.x:N dropped by fw_handle_first_packet Reason: fwconn_init_links (INBOUND) failed`

## Cause

1. When the Check Point Security Gateway / cluster member creates an ICMP connection in the Connections Table, a dummy port is allocated in order to make this connection unique (ICMP packets do not have real port numbers). The dummy port is calculated based on protocol-level session IDs.  

   Under certain conditions, the dummy port is calculated to be the same for multiple connections, which causes a conflict in the Connections Table that then causes the drop.  

2. In ClusterXL configured in High Availability New Mode / VRRP cluster, the ICMP Requests sent to the Cluster Virtual IP (VIP) address and to the IP address of the physical interface on the Active/Master member are processed by Active/Master member ("NAT-folded" from physical IP address of Active member). Because these two ICMP Requests have the same parameters, the Active/Master member cannot distinguish between them. As a result, the first of these two ICMP Requests is processed correctly, and the second of these two ICMP Requests is dropped.

## Solution

**Table of Contents:**

* Explanation
* Solution
* Procedure
* Important Notes

### Explanation {#Explanation}

By design, to process any packet, Check Point kernel uses a "tuple" - \<`Source_IP, Source_Port, Dest_IP, Dest_Port, Protocol`\>.

By default, the 'ICMP Identifier' in ICMP Request packets is used as `Source_Port`. In some configurations of a High Availability/VRRP cluster, this can cause problems for the Check Point kernel to distinguish the ICMP packets.

### Solution {#Solution}

To deal with such cases, use the global kernel parameter - **`fw_allow_simultaneous_ping`**.

This parameter changes the behavior of Check Point kernel for ICMP packets. After enabling this special kernel parameter (it is disabled by default), 'ICMP Sequence Numbers' are used as `Source_Port` in a "tuple". This allows the kernel to always distinguish the ICMP packets. Kernel debug includes the ability to find and match every ICMP packet.

### Procedure {#Procedure}

* To **enable** the global kernel parameter '**`fw_allow_simultaneous_ping`**', set its value to 1 (one):

  * To get the current value, run:

    **`[Expert@MEMBER]# fw ctl get int fw_allow_simultaneous_ping`**
  * To enable the parameter *temporarily*, run:

    **`[Expert@MEMBER]# fw ctl set int fw_allow_simultaneous_ping 1`**
  * To enable the parameter *permanently*, run:

    **`[Expert@MEMBER]# fw ctl set -f int fw_allow_simultaneous_ping 1`**
* To **disable** the global kernel parameter '**`fw_allow_simultaneous_ping`**', set its value to 0 (zero):

  * To get the current value, run:

    **`[Expert@MEMBER]# fw ctl get int fw_allow_simultaneous_ping`**
  * To disable the parameter *temporarily*, run:

    **`[Expert@MEMBER]# fw ctl set int fw_allow_simultaneous_ping 0`**
  * To disable the parameter *permanently*, run:

    **`[Expert@MEMBER]# fw ctl set -f int fw_allow_simultaneous_ping 0`**

**Note:** For detailed instructions on setting the Check Point Firewall kernel parameters, refer to [sk26202](https://support.checkpoint.com/results/sk/sk26202).

### Explanation {#Limitations}

When you enter the command '`fw_allow_simultaneous_ping=1`' SecureXL tags ICMP Echo Request / ICMP Echo Reply packets originating from the Security Gateway instead of offloading these pings as a temporary connection to SecureXL.  

This prevents a CoreXL firewall instance mismatch between the same ICMP connection key when a user simultaneously pings the cluster VIP address and IP addresses of cluster members from a remote host, if one ICMP connection is recorded when ClusterXL is stopped.

### Important Notes {#Important Notes}

* On a single Security Gateway (not a cluster member) with working SecureXL, if this parameter is enabled, then *currently existing* ICMP connections might be adversely affected. ICMP connections that were established after enabling this parameter are handled correctly.  
  On ClusterXL members, there is no such impact - regardless of SecureXL status.

* In a cluster environment, this kernel parameter must be set to the same value on *all* cluster members.

### Related Solutions:

* [sk102327 - Unable to ping cluster Virtual IP address from the Active member of ClusterXL in High Availability mode](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk102327)
* [sk107843 - Unable to ping cluster Virtual IP address from within the VSX Cluster itself](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107843)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
