sk179931 - The "asg diag verify" command reports inconsistent OSPFv3 routes for Security Gateway Modules in Quantum Maestro
The "asg diag verify" command reports inconsistent OSPFv3 routes for Security Gateway Modules in Quantum Maestro
Product
Maestro HyperScale Firewall
Version
R81 (EOS), R81.10 (EOS), R81.20
OS
Gaia
Last Modified
2025-12-18
Cause
This article describes scenarios when the "asg diag verify" command reports inconsistent OSPFv3 routes for different Security Gateway Modules (SGMs).
Scenario 1 - Dynamic Routing does not sync "tag" and "cost" with Software Blades
Symptoms:
1_01:O E xxxx:8b00:1200:xxxx::/115 via xxxx::3e57:31ff:fe36:xxxx, eth1-07, <b>cost 9:20</b>, age 1287632, <b>tag 0xffffffff</b>, instance default1_02:O E xxxx:8b00:1200:xxxx::/115 via xxxx::3e57:31ff:fe36:xxxx, eth1-07, <b>cost 0:0</b>, age 1287632, <b>tag 0x00000000</b>, instance default
Cause:
By design, Dynamic Routing does not sync the OSPFv3 routes' "cost" and "tag."
Solution:
This problem was fixed. The fix is included starting from:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 8
- Jumbo Hotfix Accumulator for R81.10 starting from Take 82
- Jumbo Hotfix Accumulator for R81 starting from Take 79
Scenario 2 - When Graceful Restart (GR) is enabled, the SMO does not synchronize the "IA (Inter-Area)" flag with the other SGMs.
Symptoms:
------------------------------------------------------------------------------
| Tests Status |
------------------------------------------------------------------------------
| ID | Title | Result | Reason |
------------------------------------------------------------------------------
| Networking |
------------------------------------------------------------------------------
| 13 | IPv4 Route | Failed (!) | (1)Inconsistent routes |
------------------------------------------------------------------------------
[Global] SG_01-ch01-01> show route all
1_01:
Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),
O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),
IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),
A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,
NP - NAT Pool, U - Unreachable, i - Inactive
O IA x.x.x.x/x via x.x.x.x, eth1-05, cost 2, age 386075, instance default
1_02:
Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),
O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),
IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),
A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,
NP - NAT Pool, U - Unreachable, i - Inactive
O x.x.x.x/x via x.x.x.x, eth1-05, cost 0, age 3016, instance default
Cause:
This behavior is expected and has no functional impact.
When Graceful Restart (GR) is enabled, only OSPF routes are synchronized — the LSAs, database, and neighbor states are not synced between members.
When Graceful Restart (GR) is disabled, cluster members synchronize OSPF LSAs, database, and neighbor states.
Solution:
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 41
- Jumbo Hotfix Accumulator for R81.20 starting from Take 115
- Jumbo Hotfix Accumulator for R81.10 starting from Take 183
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2022-09-25
Last Modified: 2025-12-18