- Products
- Learn
- Local User Groups
- Partners
- More
The State of Ransomware Q1 2026
Key Trends and Their Impact
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Hey!
So i have a problem, i have 7ish ClusterXL sites.
and when i try to preform a migration on my ISP they get a loop from my Firewalls.
after i tracked it i see this problem on every ClusterXL site.
They all have the same MAC Address
Site X
0000.0000.0100 dynamic ip,ipx,assigned,other TenGigabitEthernet2/1/4
0000.0000.0101 dynamic ip,ipx,assigned,other TenGigabitEthernet1/1/4
Site Y
0000.0000.0100 DYNAMIC Gi0/20
0000.0000.0101 DYNAMIC Gi0/43
Anyone knows how to disabel this fake address ?
Disable IGMP snooping on the ports that are making issues. All cluster members are using the same "Magic macs" as ID for CCP communications.
Here is another reference for you for that matter: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
You do not want to disable those "fake" MAC addresses, because they represent in fact ClusterID
CCP uses artificial MAC to send ClusterXL probing and status exchange communications. Those MACs are used to identify multiple members of the same cluster.
They are not used to carry any production traffic. For more details, refer to ClusterXL ATRG:https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...,
or attend CCSE courses.
Unless you have connectivity issues on WAN router, there is not harm. If you do, look at ATRG to find a workaround.
Disable IGMP snooping on the ports that are making issues. All cluster members are using the same "Magic macs" as ID for CCP communications.
Here is another reference for you for that matter: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
That is also an option, but you will be flooding your segment with CCP broadcast packets.
It is a global parameter, no way to switch more per interface.
Thank you Val for the help!
I will implement the broadcast and test that,
i am runing a 80.20 already on that way (80.10 on the rest of my clusters) and it seems that 80.20 broad is preferd already.
so it might be a non issue when upgrading.
However, if you have multiple ClusterXL cluster in the same broadcast domains, having default Cluster ID is problematic.
Look here for resolution: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceWed 13 May 2026 @ 11:00 AM (EDT)
TechTalk: The State of Ransomware Q1 2026: Key Trends and Their ImpactThu 14 May 2026 @ 07:00 PM (EEST)
Under the Hood: Presentando Check Point Cloud Firewall como ServicioTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY