# The "asg diag verify" command reports inconsistent OSPFv3 routes for Security Gateway Modules in Quantum Maestro

## Product
Maestro HyperScale Firewall

## Version
R81 (EOS), R81.10 (EOS), R81.20

## OS
Gaia

## Last Modified
2025-12-18

## Cause
This article describes scenarios when the "`asg diag verify`" command reports inconsistent OSPFv3 routes for different Security Gateway Modules (SGMs).

### Scenario 1 - Dynamic Routing does not sync "tag" and "cost" with Software Blades

**Symptoms:**

> `1_01:`  
> `O E             xxxx:8b00:1200:xxxx::/115     via xxxx::3e57:31ff:fe36:xxxx, eth1-07, <b>cost 9:20</b>, age 1287632, <b>tag 0xffffffff</b>, instance default`  
> `1_02:`  
> `O E             xxxx:8b00:1200:xxxx::/115     via xxxx::3e57:31ff:fe36:xxxx, eth1-07, <b>cost 0:0</b>, age 1287632, <b>tag 0x00000000</b>, instance default`

**Cause:**  
By design, Dynamic Routing does not sync the OSPFv3 routes' "cost" and "tag."

**Solution:**  
This problem was fixed. The fix is included starting from:  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 8  
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 82  
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 79

### Scenario 2 - When Graceful Restart (GR) is enabled, the SMO does not synchronize the "IA (Inter-Area)" flag with the other SGMs.

**Symptoms:**

```
------------------------------------------------------------------------------  
| Tests Status                                                              |
------------------------------------------------------------------------------  
| ID | Title              | Result     | Reason                               |
------------------------------------------------------------------------------  
| Networking                                                              |
------------------------------------------------------------------------------  
| 13 | IPv4 Route        | Failed (!) | (1)Inconsistent routes               |
------------------------------------------------------------------------------
```

> [Global] SG_01-ch01-01> show route all  
> 1_01:  
> Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),  
>        O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),  
>        IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),  
>        A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,  
>        NP - NAT Pool, U - Unreachable, i - Inactive  
> **O IA            x.x.x.x/x        via x.x.x.x, eth1-05, cost 2, age 386075, instance default**  
> 1_02:  
> Codes: C - Connected, S - Static, R - RIP, B - BGP (D - Default),  
>        O - OSPF IntraArea (IA - InterArea, E - External, N - NSSA),  
>        IS - IS-IS (L1 - Level 1, L2 - Level 2, IA - InterArea, E - External),  
>        A - Aggregate, K - Kernel Remnant, H - Hidden, P - Suppressed,  
>        NP - NAT Pool, U - Unreachable, i - Inactive  
> **O               x.x.x.x/x        via x.x.x.x, eth1-05, cost 0, age 3016, instance default**

**Cause:**  
This behavior is expected and has no functional impact.  
When Graceful Restart (GR) is enabled, only OSPF routes are synchronized — the LSAs, database, and neighbor states are not synced between members.  
When Graceful Restart (GR) is disabled, cluster members synchronize OSPF LSAs, database, and neighbor states.

**Solution:**  
This problem was fixed. The fix is included in:  
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 41  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 115  
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 183

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**  
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties
**Access Level:** General  
**Status:** Approved by TAC  
**Date Created:** 2022-09-25  
**Last Modified:** 2025-12-18
