> Source: [sk33221](https://support.checkpoint.com/results/sk/sk33221)

# sk33221 - Cluster instability when using ClusterXL with IGMP Snooping-enabled switches

| Property | Value |
|----------|-------|
| Solution ID | sk33221 |
| Date Created | 2007-07-04 |
| Last Modified | 2019-10-24 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When using a ClusterXL cluster with an IGMP Snooping-enabled switch, the user experiences cluster instability, e.g., one member will be in '`Down`' state and the other will be in '`Active Attention`' state. The state of the members may also be flapping.  

* When using a ClusterXL Load Sharing Multicast cluster with an IGMP Snooping-enabled switch, traffic will not go through the cluster.

## Cause

When IGMP Snooping is enabled on the switch, it checks the Destination MAC Address of the frames in order to match the frames to IGMP Subscription Group. If IGMP membership is disabled on cluster members (i.e., `fwha_enable_igmp_snooping=0`), they never subscribe to IGMP Group on the switch. As a result, the switch cannot match the CCP packets that are sent to the Multicast MAC address to any IGMP Group and the switch drops these CCP packets. As a result, cluster members do not send or receive CCP packets properly. This triggers the cluster mechanism to assume that cluster members are failing and to declare interfaces as Down and/or to initiate a fail-over.

Note: IGMP Membership is enabled by default starting in R75.40 (i.e., `fwha_enable_igmp_snooping=1`).

## Solution

**Suggested solutions:**

* Disabling IGMP Membership on switches - refer to switch vendor's documentation.  

* Enabling IGMP Membership on cluster members - refer to [sk31934 (ClusterXL IGMP Membership)](http://supportcontent.checkpoint.com/solutions?id=sk31934).  

* Setting CCP mode to broadcast - refer to [sk20576 (How to set ClusterXL Control Protocol (CCP) in Broadcast / Multicast mode in ClusterXL)](http://supportcontent.checkpoint.com/solutions?id=sk20576)   

  **Note:** This will allows ClusterXL HA and ClusterXL Load Sharing Unicast to work with IGMP Snooping-enabled switches. However, it will **not** allow ClusterXL Load Sharing Multicast to work with IGMP Snooping-enabled switches.

Refer to *ClusterXL Administration Guide* ([R55](http://supportcontent.checkpoint.com/documentation_download?id=5677), [R60](http://supportcontent.checkpoint.com/documentation_download?id=5509), [R61](http://supportcontent.checkpoint.com/documentation_download?id=6355), [R62](http://supportcontent.checkpoint.com/documentation_download?id=6824), [R65](http://supportcontent.checkpoint.com/documentation_download?id=7240), [R70](http://supportcontent.checkpoint.com/documentation_download?id=8714), [R71](http://supportcontent.checkpoint.com/documentation_download?id=10641), [R75](http://supportcontent.checkpoint.com/documentation_download?id=11659), [R75.20](http://supportcontent.checkpoint.com/documentation_download?id=12265), [R75.40](http://supportcontent.checkpoint.com/documentation_download?id=13090), [R75.40VS](http://supportcontent.checkpoint.com/documentation_download?id=16221), [R76](http://supportcontent.checkpoint.com/documentation_download?id=22910), [R77](http://supportcontent.checkpoint.com/documentation_download?id=24800)) - Chapter 'High Availability and Load Sharing in ClusterXL' - Hardware Requirements, Compatibility and Cisco Example

**Related Solutions:**

* [sk43984 - Interface flapping when cluster interfaces are connected through several switches](http://supportcontent.checkpoint.com/solutions?id=sk43984)
* [sk25977 - Connecting multiple clusters to the same network segment (same VLAN, same switch)](http://supportcontent.checkpoint.com/solutions?id=sk25977)
* [sk56202 - How to troubleshoot failovers in ClusterXL](http://supportcontent.checkpoint.com/solutions?id=sk56202)
* [sk62570 - How to troubleshoot failovers in ClusterXL - Advanced Guide](http://supportcontent.checkpoint.com/solutions?id=sk62570)
* [sk92723 - Cluster flapping prevention](http://supportcontent.checkpoint.com/solutions?id=sk92723)
* [sk69340 - ClusterXL interfaces are flapping when connected to Juniper switches](http://supportcontent.checkpoint.com/solutions?id=sk69340)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
