sk182742 - 0.0.0.0 static route does not show in VSX Security Gateway's routing table
0.0.0.0 static route does not show in VSX Security Gateway's routing table
Product: VSX (Traditional)
Version: R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-08-04
Symptoms
A static route to 0.0.0.0, regardless of the subnet mask, is not installed in the VSX Gateway's routing table.
The route is added to the $FWDIR/state/local/VSX/local.vsall file but does not show in the output of the
"ip route"or"show route"commands.If you delete the 0.0.0.0/1 route, the default route that is added from SmartConsole is also deleted.
Cause
There is an issue with verification in the route installation flow.
When adding a route, if the destination address is 0.0.0.0, the VSX Gateway adds the route as a default route regardless of the subnet mask.
If you delete the route there is a mismatch between the Management Server, which in its database the VSX Gateway has a default route, and the VSX itself, which does not have a default route.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 36
- Jumbo Hotfix Accumulator for R81.20 starting from Take 111
- Jumbo Hotfix Accumulator for R81.10 starting from Take 177
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.