> Source: [sk62432](https://support.checkpoint.com/results/sk/sk62432)

# sk62432 - Source MAC Address of Cluster Control Protocol (CCP) frames in ClusterXL before installing the policy for the first time

| Property | Value |
|----------|-------|
| Solution ID | sk62432 |
| Date Created | 2011-04-15 |
| Last Modified | 2012-11-12 |
| Technical Level | General |

## Symptoms

- * Check Point Security Gateway software was installed on the machines that will serve as cluster members   

* During the initial configuration of Check Point Security Gateway software via '`cpconfig`' the option of `State Synchronization` was enabled (CPHA, CPLS)  

* Machines that will serve as cluster members were rebooted after completing all the steps of initial configuration of Check Point Security Gateway software  

* After reboot, Cluster Control Protocol (CCP) traffic was captured on the interfaces that will be used in Cluster Topology  

* Traffic capture shows the following :  
  * Source MAC Address of CCP frames is the same on all cluster members on all cluster interfaces - `00:00:00:00:FE:21`
  * on each local interface the CCP frames are Broadcasted to all local subnets

  <br />

  <br />

## Cause

This behavior is by design. This MAC address 00:00:00:00:FE:21 distinguishes the unconfigured cluster members.

## Solution

1. Open SmartDashboard.

2. Configure cluster object.

3. Configure rulebase.

4. Install the Policy onto this cluster object.

**Related Solutions:**

[sk25977 - Connecting multiple clusters to the same network segment (same VLAN, same switch)](primus://:sk25977)

*** ** * ** ***

*Example (R75 version , SecurePlatform OS)*:

```
[Expert@MemberA]# grep 'HighAvailability' $CPDIR/registry/HKLM_registry.data 
                                        :HighAvailability ("[4]1")
[Expert@MemberA]# 




[Expert@MemberA]# cpstat -f policy fw

Product name:           Firewall
Policy name:            InitialPolicy
Policy install time:    Sun Feb 13 19:01:05 2011
.............................................
[Expert@MemberA]# 




[Expert@MemberA]# fw getifs
localhost eth0 192.168.204.111 255.255.255.0
localhost eth1 1.1.1.111 255.255.255.0
localhost eth2 2.2.2.111 255.255.255.0
[Expert@MemberA]#




[Expert@MemberA]# cphaprob -a if
HA module not started.
[Expert@MemberA]#




[Expert@MemberA]# ps auxw | grep cphamcset
root      3782  0.0  0.1   1644   472 pts/0    R+   19:09   0:00 grep cphamcset
[Expert@MemberA]# 




[Expert@MemberA]# cpstat ha

Product name: High Availability
Version:      N/A
Status:       problem
HA installed: 1
Working mode: 
HA started:   no
[Expert@MemberA]# 




[Expert@MemberA]# cpstat -f all ha

Product name:        High Availability
Major version:       6
Minor version:       0
Service pack:        2
Version string:      N/A
Status code:         2
Status short:        problem
Status long:         
HA installed:        1
Working mode:        
HA protocol version: 2
HA started:          no
HA state:            ClusterXL inactive or machine is down
HA identifier:       0


Interface table
------------------------------------------------
|Name|IP|Status|Verified|Trusted|Shared|Netmask|
------------------------------------------------
------------------------------------------------


Problem Notification table
-------------------------------------------------
|Name           |Status |Priority|Verified|Descr|
-------------------------------------------------
|Synchronization|problem|       0|     937|     |
|Filter         |OK     |       0|     937|     |
|fwd            |OK     |       0|     944|     |
-------------------------------------------------


Cluster IPs table
-----------------------------------------------
|Name|IP|Netmask|Member Network|Member Netmask|
-----------------------------------------------
-----------------------------------------------


Sync table
-----------------
|Name|IP|Netmask|
-----------------
-----------------

[Expert@MemberA]#




[Expert@MemberA]# tcpdump -e -i eth0 udp port 8116
tcpdump: listening on eth0
19:12:52.732895 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:12:52.749985 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:12:52.752739 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
19:12:53.026813 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:12:53.028027 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:12:53.028780 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
19:12:53.280808 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:12:53.280809 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:12:53.280810 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
.............................................
[Expert@MemberA]# 




[Expert@MemberA]# tcpdump -e -i eth1 udp port 8116
tcpdump: listening on eth1
19:13:07.653348 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:13:07.659253 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:13:07.660421 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
19:13:07.986312 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:13:08.184200 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:13:08.184287 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
19:13:08.489166 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:13:08.670126 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:13:08.670209 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
.............................................
[Expert@MemberA]# 




[Expert@MemberA]# tcpdump -e -i eth2 udp port 8116
tcpdump: listening on eth2
19:13:28.579835 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:13:28.584872 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:13:28.586964 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
19:13:28.913780 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:13:28.913936 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:13:29.415927 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
19:13:29.414911 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 192.168.204.0.8116: udp 40
19:13:29.415902 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 1.1.1.0.8116: udp 40
19:13:29.609971 0:0:0:0:fe:21 Broadcast ip 82: 0.0.0.0.8116 > 2.2.2.0.8116: udp 40
.............................................
[Expert@MemberA]# 
```

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
