> Source: [sk34180](https://support.checkpoint.com/results/sk/sk34180)

# sk34180 - Outgoing connections from cluster members are sent with cluster Virtual IP address instead of member's Physical IP address

| Property | Value |
|----------|-------|
| Solution ID | sk34180 |
| Date Created | 2008-01-15 |
| Last Modified | 2026-04-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- Outgoing connections from cluster members are sent with Source IP address of Cluster Virtual IP address instead of member's Physical IP address.

## Cause

By default, the Cluster Hide and Fold is enabled (controlled via the attribute "perform_cluster_hide_fold" in Cluster Object in Security Management Server database).

Value of attribute *perform_cluster_hide_fold* in Cluster Object controls the following:

* Whether *outgoing* connections from cluster members will be hidden behind Cluster Cluster Virtual IP address - i.e., sent with Source IP address of Cluster Virtual IP address, or sent with Source IP address of member's Physical IP address
* Whether *incoming* connections sent to Cluster Virtual IP address will be folded to member's Physical IP address, or the Destination IP Address will remain as Cluster Virtual IP address.

|------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| Value of attribute     | How connections are Hidden / Folded by Cluster                                                                                                                                                                                                                                                                                                                                                              |
| *true* ("1") (default) | * Outgoing connections from cluster members will be sent with Source IP address of Cluster Virtual IP address (hidden behind Cluster VIP) * Incoming connections sent to Cluster Virtual IP address will be folded to member's Physical IP address (in case of VSX cluster, with Destination IP address that belongs to cluster Internal Communication Network)                                             |
| *false* ("0")          | * Outgoing connections from cluster members will be sent with Source IP address of member's Physical IP address (in case of VSX cluster, with Source IP address that belongs to cluster Internal Communication Network) * Incoming connections sent to Cluster Virtual IP address will not be folded to member's Physical IP address (the Destination IP Address will remain as Cluster Virtual IP address) |

<br />

**Note** : Disabling the `perform_cluster_hide_fold` feature causes all connections initiated by cluster members to use their native IP addresses instead of the VIP. If you are using Identity Awareness brokering, this can break the setup, as brokering files require publishers and subscribers to be defined by their VIPs. To fix this, you must add a NAT rule that translates brokering traffic between clusters back to the VIP.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
