> Source: [sk83420](https://support.checkpoint.com/results/sk/sk83420)

# sk83420 - Traffic issues in F5 BIG-IP environment during failover in Check Point ClusterXL

| Property | Value |
|----------|-------|
| Solution ID | sk83420 |
| Date Created | 2012-08-27 |
| Last Modified | 2026-07-21 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- Traffic issues in F5 BIG-IP environment during failover in Check Point ClusterXL

## Cause

F5 BIG-IP caches the last hop MAC address to overcome connectivity issues when network topology is changed. This feature is called "*auto last hop*".

When "*auto last hop* " is enabled on F5 that is connected to a Check Point ClusterXL in the High Availability mode, the "*auto last hop* " will cache the last MAC address associated with the ClusterXL Virtual IP address (i.e., the physical MAC address of the *former* Active Cluster Member) even though the ARP table learns the new MAC address associated with the Cluster Virtual IP address (i.e., MAC address of the former Standby Cluster Member that became the new Active Cluster Member).

As a result, when a ClusterXL failover occurs, the traffic arriving from F5 towards the Cluster Virtual IP address will be addressed to the MAC address of the *former* Active Cluster Member. Because the *former* Active Cluster Member is in the cluster state "Down", it does not process any incoming traffic.

Even if you enable the VMAC mode on the Check Point ClusterXL, the Active Cluster Member sends information about the Virtual MAC address (associated with the Cluster Virtual IP address) in Gratuitous ARP frames only in the "Destination MAC Address" field. The "Source MAC Address" field of these G-ARP frames still contains the physical MAC address of the Active Cluster Member. When the Active Cluster Member sends regular TCP / UDP / ICMP traffic, it still uses its physical MAC address in the "Source MAC Address" field in the Ethernet frames.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
