sk184007 - GRE tunnels fail after upgrade to R82 when SecureXL is enabled on the Security Gateway
GRE tunnels fail after upgrade to R82 when SecureXL is enabled on the Security Gateway
Product: SecureXL
Version: R82
OS: Gaia
Last Modified: 2026-05-26
Symptoms
- After upgrading the Security Gateway to R82, Generic Routing Encapsulation (GRE) tunnels intermittently fail when SecureXL is enabled.
- Some DMZ-to-DMZ traffic also fails because of NAT inconsistencies.
- Packet captures on the Security Gateway show GRE traffic leaving the Gateway without NAT translation.
- Disabling SecureXL and restarting the Security Gateway restores tunnel connectivity.
Note: Disabling SecureXL can decrease performance and bypass acceleration features. Use only for temporary troubleshooting.
- Multiple locations are affected. The issue is not site-specific.
Cause
The Security Gateway does not use NAT for GRE traffic, even though NAT is configured for this traffic.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82 starting from Take 103
If you choose not to upgrade, Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
For faster resolution and verification, collect these files:
- CPinfo file from the Management Server involved in the case.
- CPinfo file from the Security Gateway / each Cluster Member / Security Group involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.