- Products
- Learn
- Local User Groups
- Partners
- More
Secure Your AI Transformation
9 April @ 12pm SGT / 3pm CET / 2PM EDT
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
HI All,
I am having issues with route advertisement in BGP ( between Check Points).
Site to Site VPN between firewalls
Tunnels UP and can ping ip-addresses behind the firewall via tunnel interface IP
can ping tunnel interface from all three gateways.
all 3 single gateways.
Prefix-list and Routemaps used but not seeing routes being advertise on any 3 checkpoints firewalls.
However, if I use interface route-redistribution it works.
Version: R81.20
Jumbo T120
Appliance: VMWare
Management same version as firewalls.
Please see the attached configuration and help to identify the issue.
For information I have also tried used nat-pool with no joy, here is the nat-pool config I used as an example,
GW1
set nat-pool 10.153.255.0/24 on
set nat-pool 20.20.10.0/24 on
set nat-pool 20.20.11.0/24 on
set nat-pool 20.20.12.0/24 on
set route-redistribution to bgp-as 65000 from nat-pool 10.153.255.0/24 on
set route-redistribution to bgp-as 65000 from nat-pool 20.20.10.0/24 on
set route-redistribution to bgp-as 65000 from nat-pool 20.20.11.0/24 on
set route-redistribution to bgp-as 65000 from nat-pool 20.20.12.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 10.153.255.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 20.20.10.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 20.20.11.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 20.20.12.0/24 on
GW2
set nat-pool 10.152.255.0/24 on
set nat-pool 30.30.10.0/24 on
set nat-pool 30.30.11.0/24 on
set nat-pool 30.30.12.0/24 on
set route-redistribution to bgp-as 65001 from nat-pool 10.152.255.0/24 on
set route-redistribution to bgp-as 65001 from nat-pool 30.30.10.0/24 on
set route-redistribution to bgp-as 65001 from nat-pool 30.30.11.0/24 on
set route-redistribution to bgp-as 65001 from nat-pool 30.30.12.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 10.152.255.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 30.30.10.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 30.30.11.0/24 on
set route-redistribution to bgp-as 65050 from nat-pool 30.30.12.0/24 on
GW3
set nat-pool 10.10.10.0/24 on
set nat-pool 10.10.11.0/24 on
set nat-pool 10.10.12.0/24 on
set nat-pool 10.200.0.0/16 on
et route-redistribution to bgp-as 65000 from nat-pool 10.10.10.0/24 on
set route-redistribution to bgp-as 65000 from nat-pool 10.10.11.0/24 on
set route-redistribution to bgp-as 65000 from nat-pool 10.10.12.0/24 on
set route-redistribution to bgp-as 65000 from nat-pool 10.200.0.0/16 on
set route-redistribution to bgp-as 65001 from nat-pool 10.10.10.0/24 on
set route-redistribution to bgp-as 65001 from nat-pool 10.10.11.0/24 on
set route-redistribution to bgp-as 65001 from nat-pool 10.10.12.0/24 on
set route-redistribution to bgp-as 65001 from nat-pool 10.200.0.0/16 on
Note: NAT-Pool did not help so I have removed from the configuration attached.
What is the origin of your routes?
Your match protocol for outbound route-map might be a conflict...
Hi Chris,
The routes advertised are directly connected. ( in my attachments if have supplied fw getifs output)
I can try to remove the match protocol from the outbound route-map!
Please let us know if that solved the issue, but likely it will be needed in addition to the correct form of redistribution.
We don't have a "network" statement under the BGP process like in Cisco...
Just looking at your GW2 config, the LOCAL-OUT routemap 'match protocol' statement is set to BGP. These local routes are not coming from BGP, so this routemap won't match anything. You should remove this match statement.
Thanks all for your response. @Chris_Atkinson @emmap
I have now remove the match protocol statement from all three gateways where used under export-routemap.
I have added statement match protocol on all three for import-route map
try run restart bgp all
BGP established but no routes being advertise???
Do you have route redistribution configured after you removed the NAT pools or no?
Did you already try "match protocol direct" for the export routemap?
Thanks Chris,
Indeed, this trick works, and I can see the routes on other firewalls and only routes being advertised used in the Prefix list not all directly connected..That's great
Thanks for your help.
I have attached full config of all three, just to help anyone looking this thread and find helpful with full configuration, as I was struggling to find config of both ends.
Here is the final config or all three working firewalls.
No worries - Glad that it's all working now 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 66 | |
| 42 | |
| 26 | |
| 14 | |
| 12 | |
| 10 | |
| 10 | |
| 10 | |
| 9 | |
| 9 |
Thu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesWed 08 Apr 2026 @ 07:00 PM (CST)
ERM al Descubierto: Amenazas Ocultas que Pondrán a Prueba tu Empresa en 2026Thu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 14 Apr 2026 @ 03:00 PM (PDT)
Renton, WA: Securing The AI Transformation and Exposure ManagementThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY