- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
After upgrading 1570R firewalls from R81.10.05 b254 to R81.10.08 b711 , recommended by Check Point, we experienced outages on VPNs with third-party entities, primarily Cisco.
We noticed the IKEv2 IDr field transitioned from containing the IP address to now containing the hostname of the gateway. The problem was resolved by downgrading, and a comparison of the two "legacy_ikev2.xmll" files revealed the difference. In our case, the remote end was not able to change the field as this was a mandatory requirement.
https://support.checkpoint.com/results/sk/sk33822 scenario 1 does not seems to be applicable on spark devices.
TAC case is open, so normally, in 4 months, we will have a solution ! Keep this in mind when upgrading to this version when having VPN's with 3th parties .
It is now documented : https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Conf...
In the R81.10.X releases, this feature is available starting from the R81.10.10
version.
Quantum Spark Spark gateways can configure IKEv2 ID Type to one of these:
When did you first perform the upgrades, per sk181079 can you confirm if it was impacting a GA build 1608 / 1683 vs something provided privately by TAC?
Upgrades are recently done and Build 1711 was provided by TAC as it resolves at least 3 issues we have with the 1683 build.
We can't even get a simple BGP peering up with this code.
The versions tested on the 1595r
R81.10.08 …558 (…683) (…610) ( BGP NOT Established)
Versions on the 1570r
R81.10.05 …254 (BGP Established_
R81.10.08 ….683 (BGP NOT Established)
Something is up with code.
Thank you for the heads up! It seems to be following on the same steps of enterprise Gaia, which also changed the behavior to use the main IP instead of the external IP.
I would recommend overriding the ID in the tunnel or in the global config first and then upgrade.
That sounds right to me.
Best,
Andy
The problem can be resolved following scenario 2 in sk108600 (https://support.checkpoint.com/results/sk/sk108600) :
To enable IKE MM-ID based on routing on the Security Gateway:
It is currently unknown why this behavior has changed in this version. The documentation still indicates that the default setting is the IP address, not the FQDN.
It is now documented : https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Conf...
In the R81.10.X releases, this feature is available starting from the R81.10.10
version.
Quantum Spark Spark gateways can configure IKEv2 ID Type to one of these:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY