- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello mates!
CP recommends when configuring OSPF, set a loopback interface different from 127.0.0.1 ... If we have a ClusterXL, we can set the same @ip in a new loopback interface on both firewalls and set this ip as Router ID or we must maintain the default configuration? Thanks in advance!
The Router ID should be configured to one of the cluster IP addresses.
It should be configured this way on all cluster members.
This is explicitly stated here: OSPF on Gaia
Hello Phoneboy,
starting from 81.10 it seems that is possible to configure loopback: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
that procedure looks very bad to me because of any new "Get interfaces with/without topology" will invalidate/delete the manually added Loopback interface in Cluster object under network management.
i've submitted a feedback to sk.
any idea on your side?
Why would you make a loopback for this? The router ID is not an IP address. It's just a number. All members of a cluster must use the same number, but it doesn't need to have any relation to any interface. You can use router IDs like 0.0.0.1 which are not valid IP addresses.
I agree with you but i've simply followed admin guide.... https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_Advanced_Routing_AdminG...
Use an address on a loopback interface that is not the loopback IPv4 address 127.0.0.1
Important:
In a cluster, you must configure the Router ID to one of the Cluster Virtual IP addresses.
So where is the truth?
"but it doesn't need to have any relation to any interface."
This statement seems to be very far compared to documentation/admin guide/SKs
I have customers that do each method successfully (Loopbacks or bonds - not VSX).
Traditional network folk like Loopbacks because they should never go down, historically differing vendor implementations could do odd things when ID values are tied to physical interfaces so habits were formed to avoid gotchas.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY