> Source: [sk92456](https://support.checkpoint.com/results/sk/sk92456)

# sk92456 - Traffic loss on different subnets when ClusterXL interface fails back after a failure, or after a cable is reconnected

| Property | Value |
|----------|-------|
| Solution ID | sk92456 |
| Date Created | 2013-03-07 |
| Last Modified | 2017-09-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Traffic loss on different subnets when ClusterXL interface fails back after a failure, or after a cable is reconnected.  

* ClusterXL configuration comprises:
  * Interfaces with Different Subnets (VSX is considered different subnets)
  and  
  * Either VMAC mode is enabled per sk50840,  
    Or Layer 3 devices, which can learn MAC addresses from ARP Requests or ICMP packets

  <br />

  <br />

* When VMAC mode is enabled, switches get confused when ClusterXL interface fails back.  

* Layer 3 devices get confused as if failover has taken place when ClusterXL interface fails back.

## Cause

In some cases, Cluster Control Protocol (CCP) packets might arrive few seconds after interface changed its state to 'UP'. During that period, all cluster members have interface with link up, but they are not able to hear each other (receive each other's CCP packets).

By design, when a cluster member does not receive CCP packets from a peer member (or not able to send its own CCP packets), cluster member uses probing mechanism in order to determine the problematic interface and the problematic member. All cluster members send series of ARP Requests and series of ICMP Requests to all hosts on the subnet.

Since interfaces on all cluster members are OK, these series of ARP Requests and ICMP Requests might confuse ARP tables on Layer 2 / Layer 3 devices.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
