> Source: [sk57100](https://support.checkpoint.com/results/sk/sk57100)

# sk57100 - Adding or removing an interface in ClusterXL High Availability topology might cause fail-over

| Property | Value |
|----------|-------|
| Solution ID | sk57100 |
| Date Created | 2010-11-08 |
| Last Modified | 2026-03-11 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- Adding or removing an interface (either physical, or logical (e.g. VLAN)) in ClusterXL High Availability topology might cause fail-over due to Critical Device "`Interface Active Check`" reporting its state as "`problem`".

## Cause

**Adding an interface** (either physical, or logical) on a cluster member is done in Operating System. Check Point kernel always attaches itself to the interface. As a result, Cluster Layer also detects a new interface, and by design, expect to receive and to send CCP packets through that interface. Since this new interface is not defined yet in cluster Topology, CCP packets will not be sent/received through that interface. As a result, Cluster Layer declares that interface as failed, which in turn causes fail-over.

**Removing an interface** (either physical, or logical) on a cluster member cause the Cluster Layer to detect less interfaces than on the other member. By design, fail-over occurs in such case.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
