sk184923 - Wrong Route Selection with ISP Redundancy on ClusterXL

Wrong Route Selection with ISP Redundancy on ClusterXL

Product: ClusterXL
Version: R81.20, R82, R82.10
OS: Gaia
Last Modified: 2026-07-23

Symptoms

This behavior typically appears after an ISP priority change or failover.
Disabling SecureXL acceleration (fwaccel off) temporarily resolves the issue until the next ISP priority change or failover event.

Cause

This behavior is observed in R81.20 and R82 due to a specific interaction between ISP Redundancy routing updates and SecureXL routing and connection caching.

Under certain conditions:

As a result, reply packets may exit through an interface associated with the previously active ISP, leading to asymmetric routing and connection failures until routing information is refreshed.

Solution

This problem was fixed. The fix is included in:

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.

Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.

Workaround

Use this workaround to resynchronize SecureXL and ISP Redundancy routing information. This workaround is temporary and must be re‑applied after each ISP priority change.
On each affected Security Gateway or Cluster Member, in Expert mode, run:

fw rtupdate

NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Article Properties

Access Level: General
Status: Approved by TAC
Date Created: 2026-05-22
Last Modified: 2026-07-23