- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
After upgrading 1570R firewalls from R81.10.05 b254 to R81.10.08 b711 , recommended by Check Point, we experienced outages on VPNs with third-party entities, primarily Cisco.
We noticed the IKEv2 IDr field transitioned from containing the IP address to now containing the hostname of the gateway. The problem was resolved by downgrading, and a comparison of the two "legacy_ikev2.xmll" files revealed the difference. In our case, the remote end was not able to change the field as this was a mandatory requirement.
https://support.checkpoint.com/results/sk/sk33822 scenario 1 does not seems to be applicable on spark devices.
TAC case is open, so normally, in 4 months, we will have a solution ! Keep this in mind when upgrading to this version when having VPN's with 3th parties .
It is now documented : https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Conf...
In the R81.10.X releases, this feature is available starting from the R81.10.10
version.
Quantum Spark Spark gateways can configure IKEv2 ID Type to one of these:
When did you first perform the upgrades, per sk181079 can you confirm if it was impacting a GA build 1608 / 1683 vs something provided privately by TAC?
Upgrades are recently done and Build 1711 was provided by TAC as it resolves at least 3 issues we have with the 1683 build.
We can't even get a simple BGP peering up with this code.
The versions tested on the 1595r
R81.10.08 …558 (…683) (…610) ( BGP NOT Established)
Versions on the 1570r
R81.10.05 …254 (BGP Established_
R81.10.08 ….683 (BGP NOT Established)
Something is up with code.
Thank you for the heads up! It seems to be following on the same steps of enterprise Gaia, which also changed the behavior to use the main IP instead of the external IP.
I would recommend overriding the ID in the tunnel or in the global config first and then upgrade.
That sounds right to me.
Best,
Andy
The problem can be resolved following scenario 2 in sk108600 (https://support.checkpoint.com/results/sk/sk108600) :
To enable IKE MM-ID based on routing on the Security Gateway:
It is currently unknown why this behavior has changed in this version. The documentation still indicates that the default setting is the IP address, not the FQDN.
It is now documented : https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Conf...
In the R81.10.X releases, this feature is available starting from the R81.10.10
version.
Quantum Spark Spark gateways can configure IKEv2 ID Type to one of these:
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 2 | |
| 2 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Thu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY