- Products
- Learn
- Local User Groups
- Partners
- More
Check Point WAF TechTalk:
Introduction and New Features
AI Security Masters E6: When AI Goes Wrong -
Hallucinations, Jailbreaks, and the Curious Behavior of AI Agents
Ink Dragon: A Major Nation-State Campaign
Watch HereAI Security Masters E5:
Powering Prevention: The AI Driving Check Point’s ThreatCloud
CheckMates Go:
CheckMates Fest
3600 gateways running R82 Take 60 gateways managed by R82.10 SMART-1 Cloud
I have been noticing issues with a Route based VPN that connects two sites at our company since we upgraded the gateways up to R82. Prior to this the VPN functioned just fine. Been doing some reading today and one article suggested it may be a problem with dynamic routing configuration, so I had a look see.
When the new gateways were built they were put on temporary IPs and run in parallel with the old gateways. Once we were confident they were configured correctly and all traffic was flowing the old gateways were retired and the new gateways were moved on to the original gateway IPs so we could give the temporary IPs back to our datacentre host company.
It appears that the engineer that built them for us forgot to change the BGP Router IDs to match the WAN IP when the IPs were changed over. Both gateways still have the temporary IPs as their BGP Router IDs.
Is someone able to guide me on how I amend the BGP Router IDs. I assume I must do it in Clish, as GIAI wont let me as its in use, but am unsure of the steps and commands.
Hoping the community can guide me 🙂
I have solved it.
In GIAI
In Smart Console
Tested all working as expected and no more errors showing. Hopefully that is the end of it all now.
Thanks all for guidance
I believe its set router-id, but below should cover it.
Thanks for the reply, I really appreciate it.
I have already seen this and I was getting lost with it if I am honest. The guide spends a lot of time detailing how in GAIA, but I cant do this while its active as its all locked out. When you get to clish part of the guide it becomes a big list of commands, which is great if you know which ones to use in which order.
I need to know how to release that lock/stop the service (whatever is required) , apply the change, restart the service, etc. I'm looking for a sequence commands on how do this.
You can try run restart bgp command and see if that helps. However, if not, then I would verify with TAC if there is another way to di it, but if not, Im afraid you may need to delete the bgp config and reconfigure it using same settings, just different router ID.
Thanks again. I wil have a rummage around the guide somemore and in clish, see if I can figure it out.
I have opened a ticket with our support. I will have to give them time to figure it out before they will escalate to CP for assistance. Which will be Tuesday at the earliest sadly. I was hoping I might be able to sort it over the weekend.
Living in the hope that one day I get to work for a company that actually trains me to do the jobs expected of me.
If you allow remote, be free to message me, we can check together.
Is this a cluster and is the router-id set to the same address on both?
Hey Chris,
Lee and I connected offline, so will most likely do remote Monday. I will update the thread afterwards.
I have solved it.
In GIAI
In Smart Console
Tested all working as expected and no more errors showing. Hopefully that is the end of it all now.
Thanks all for guidance
Excellent!
Standalone gateway
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 56 | |
| 33 | |
| 20 | |
| 12 | |
| 11 | |
| 11 | |
| 10 | |
| 9 | |
| 8 | |
| 8 |
Tue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementTue 24 Mar 2026 @ 04:00 PM (CET)
Maestro Masters EMEA: Hyperscale Firewall Architectures and OptimizationTue 24 Mar 2026 @ 03:00 PM (EDT)
Maestro Masters Americas: Hyperscale Firewall Architectures and OptimizationTue 07 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Check Point WAF and IO River: Multi-CDN Security in ActionWed 08 Apr 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: The Cloud Firewall with near 100% Zero Day prevention - In 7 LanguagesTue 24 Mar 2026 @ 06:00 PM (COT)
San Pedro Sula: Spark Firewall y AI-Powered Security ManagementThu 26 Mar 2026 @ 06:00 PM (COT)
Tegucigalpa: Spark Firewall y AI-Powered Security ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY