sk184923 - Wrong Route Selection with ISP Redundancy on ClusterXL
Wrong Route Selection with ISP Redundancy on ClusterXL
Product: ClusterXL
Version: R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-07-23
Symptoms
- When ISP Redundancy is enabled on a ClusterXL Security Gateway, return traffic may exit through the wrong interface, causing asymmetric routing.
For example:- TCP SYN packets arrive through the backup ISP.
- TCP SYN‑ACK replies leave through the primary ISP.
This behavior typically appears after an ISP priority change or failover.
Disabling SecureXL acceleration (fwaccel off) temporarily resolves the issue until the next ISP priority change or failover event.
Cause
This behavior is observed in R81.20 and R82 due to a specific interaction between ISP Redundancy routing updates and SecureXL routing and connection caching.
Under certain conditions:
- The Linux routing table updates correctly after an ISP priority change.
- Internal ISP Redundancy and SecureXL routing structures retain information about the previously active ISP.
- SecureXL continues to accelerate existing connections using outdated routing data.
As a result, reply packets may exit through an interface associated with the previously active ISP, leading to asymmetric routing and connection failures until routing information is refreshed.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 36
- Jumbo Hotfix Accumulator for R82 starting from Take 118
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
Workaround
Use this workaround to resynchronize SecureXL and ISP Redundancy routing information. This workaround is temporary and must be re‑applied after each ISP priority change.
On each affected Security Gateway or Cluster Member, in Expert mode, run:
fw rtupdate
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2026-05-22
Last Modified: 2026-07-23