sk182848 - The routing daemon (routed) fails to start when a VTI is configured with a local IP address that matches the next-hop address used in the static route configuration
The routing daemon (routed) fails to start when a VTI is configured with a local IP address that matches the next-hop address used in the static route configuration
Product: Security Gateways
Version: R81.10 (EOS), R81.20, R82
OS: Gaia
Last Modified: 2025-04-20
Symptoms
- Running the command "
show ospf interfaces" in clish returns an error: "RTGRTG0019 Routing daemon is busy". - When running the "
ps aux | grep -v grep | grep routed" command, only oneroutedprocess appears, while there must be tworoutedprocesses in a non-VSX environment. - The "
show vpn tunnel" command shows a local IP address that matches the next-hop IP address in the static-route configuration.
Cause
The issue is caused by the configuration conflict where:
- A static route is configured with a specific next-hop IP address.
- A Virtual Tunnel Interface (VTI) is then created using that same IP address as its local IP address.
This creates a circular reference that prevents the routing service from starting correctly.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 14
- Jumbo Hotfix Accumulator for R81.20 starting from Take 99
- Jumbo Hotfix Accumulator for R81.10 starting from Take 173
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.