# Dynamic Routing and VRRP Features on Gaia OS

## Solution

## New Gaia Dynamic Routing features by release

|     |     |
| --- | --- |
| Version | New Dynamic Routing Features |
| R82 | Added support for new Dynamic Routing capabilities:<br>- BGP Extended Communities (RFC 4360).<br>- BGP Conditional Route Advertisement and Injection.<br>- Routing Table Monitor for EventClosed Triggers.<br>- IPv4 and IPv6 Router Discovery on cluster members.<br>- Router Preference and Route Information option.<br>- Route age information.<br>- IPv4 PIM-SSM with non-default prefixes.<br>- IPv4 PIM with BFD.<br>- IPv4 PIM neighbor filtering.<br>- IPv4 PIM RPT to SPT switchover control.<br>- IPv6 Protocol Independent Multicast (PIM) and Multicast Listener Discovery (MLD).<br>Added support for new Dynamic Routing API calls:<br>- REST API calls for BGP, PIM, Multicast Listener Discovery (MLD).<br>- REST API calls for Route Redistribution, Inbound Route Filters, and NAT Pools.<br>- REST API calls for IGMP.<br>See the [Check Point Gaia API Reference](https://sc1.checkpoint.com/documents/latest/GaiaAPIs/index.html) v1.8 (and higher) > section "Networking".
| R81.20 | - Support for Intermediate System (IS-IS) routing protocol.<br>- Support for DHCP Relay Agent Information Option 82 to address several scaling and security issues that arise in public DHCP use.<br>- Support for OSPFv3 NSSA.<br>- Support for IPv6 Static MFC Cache to enable forwarding of multicast data without PIM configuration.<br>- Support for Routing Event Triggers to allow ClusterXL failover, and tearing down of BGP connections through monitored BGP and BFD sessions.<br>- Routing Protocol History for BFD to improve troubleshooting capabilities.<br>- NetFlow Live connections and Firewall rule.
| R81.10 | - PIM Enhancements<br>- Ability to clear OSPF error counters<br>- OSPFv2 Graceful Restart in ClusterXL (RFC standard)<br>- Static IGMP source-group pairs<br>- ECMP support with different forwarding algorithms
| R81 | - OSPFv3 AH authentication - support authentication for OSPFv3 protocol security<br>- IPv6 route aggregation - support aggregating routes to reduce the number of prefixes advertised to neighbor routers, thus improving performance and scaling<br>- IPv4 NAT-pool routes - support NAT with routing by configuring and redistributing NAT-pool routes to routing protocols<br>- RIP route sync - re-implement RIP route sync in the standard way like the other routing protocols<br>- PIM restart - adds PIM to protocols that have user restarts<br>- BGP Support for VxLAN interfaces<br>- Dynamic Routing support for GRE interfaces
| R80.40 | - Protocol Restart for BGP and OSPF:<br>  - Protocols can be restarted in Gaia Portal or Gaia Clish<br>- PBR in VSX:<br>  - Enables users to configure PBR rules and tables in a VS Context<br>- BGP Enhanced Route Refresh:<br>  - Enables support for Enhanced Route Refresh as per RFC 7313<br>  - Gets enabled automatically when route-refresh is enabled
| R80.30 | - IP Reachability MultiHop detection with ICMP and BFD:<br>  - Multihop Ping and Multiple ISPs in Policy-Based Routing.<br>  - Multihop Ping in Static Routes.<br>  - BFD in Static Routes.<br>- VSX VSID in Netflow.
| R80.20 | - AllowAS-in-count<br>- OSPF v2/v3 Multiple Instances<br>- BGP IPv6 MD5<br>- OSPFv3 support in ClusterXL, including Link-Local VIP<br>- BFD support for BGP and OSPF (IPv4 and IPv6)
| R80.10 | - BGP 4-Byte AS Number<br>- Local AS Number<br>- AS Override<br>- IPv6 DHCP Relay<br>- IPv6 RIPng with VRRPv3<br>- Route Redistribution and inbound Route Filtering CLI<br>- OSPF Forced Hello<br>- ECMP for iBGP<br>- SNMP for RIP, OSPF, BGP, PIM, VRRPv2 (IPv4 only)<br>- Show Config for BGP and Route Redistribution<br>- BGP route filtering and AS range<br>- BGP communities regexp<br>The R80.10 Advanced Routing and Clustering Enhancement Hotfix includes these same R80.20 Dynamic Routing features (along with R80.20 ClusterXL features). For more information about this hotfix, see [sk122654.](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122654)
| R77.30 | - OSPF Graceful Restart (supported for IPv4 with VRRP-only). In R80.20, IPv6, VSX and ClusterXL have been added.<br>- OSPFv2 and ClusterXL inter-monitoring (supported for IPv4, single Security Gateway, VSX and ClusterXL. In R80.20, IPv6, VSX and ClusterXL have been added.<br>- Static Multicast Routes (supported for IPv4, single Security Gateway, VSX, VRRP cluster, and ClusterXL. (IPv6 is _not_ supported).<br>- Routing configuration support in Gaia Cloning Groups ( _cadmin_).<br>- PBR with Destination Port and Service - see [sk100500](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100500) (supported for IPv4, single Security Gateway, ClusterXL and VRRP. (IPv6 and VSX are _not_ supported).
| R77.20 | - New and improved handling of DHCP.<br>  <br>  See [sk98839](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98839) for more information on procedures for setting up DHCP on a Security Gateway, including:<br>  <br>  <br>  - DHCP Relay<br>  - DHCP Server<br>  - DHCP Relay + DHCP Server<br>_Legacy_ DHCP configuration (as supported in versions R77.10 and lower) can also be used on R77.20, if needed.<br>- BGP Graceful Restart (IPv4 and IPv6, Security Gateway mode and VSX mode)
| R77.10 | - BGP ECMP (IPv4 and EBGP only, Security Gateway mode and VSX mode)<br>- BGP Nexthop (Peer) monitoring (IPv4 and IPv6, Security Gateway mode and VSX mode)<br>- Netflow support for VSX<br>- ping6 for IPv6 Static Routes<br>- Configuration of VRRP SNMP traps<br>- Stability and Usability fixes<br>- OSPF Tag Matching<br>- Support for DNS option in IPv6 Router Advertisements
| R77 | - SNMP OIDs for VRRPv2<br>- Routing configuration support in Gaia Cloning Groups ( _cadmin_)

## Feature Support as of R80.20 Release

#### Routing:

Enter the string to filter this table:

|     |     |     |
| --- | --- | --- |
| Routing Protocol<br>or Feature | Support in<br>Gateway Mode | Support in<br>VSX Mode |
| **OSPF** | - OSPF v3 for IPv6: Supported on Security Gateway, ClusterXL and VRRPv3 Cluster<br>- OSPF v2 for IPv4 (RFC 2328): Supported on Security Gateway, ClusterXL and VRRPv3 Cluster<br>- Intermonitoring with ClusterXL from R77.30<br>- OSPF v2 / OSPF v3 with Multiple Instances<br>- BFD support (OSPF v2 / OSPF v3) | - OSPFv2 (IPv4) and OSPFv3 (IPv6)<br>- ClusterXL only (VRRP is not supported)<br>- Numbered warp interfaces: Not supported.<br>- Intermonitoring with VSX Cluster from R77.30<br>- OSPF v2 / OSPF v3 with Multiple Instances<br>- BFD Support (OSPF v2 / OSPF v3) |
| **BGP for IPv4** | - BGP for IPv4 (RFC 1771): Supported on Security Gateway, ClusterXL and VRRPv2 Cluster<br>- BGP IPv6: Multiprotocol Extension Capability on Security Gateway and VRRPv3 Cluster (ClusterXL is _not_ supported)<br>- BGP IPv6 MD5 authentication supports 4-byte AS Number, local-AS and AS-override, AllowAS-in-count,<br>- BFD support for IPv4 and IPv6 | - BGP IPv4 and IPv6: Supported on VSX Gateway and VSX Cluster<br>- BGP IPv6 MD5 authentication supports 4-byte AS Number, local-AS and AS-override, AllowAS-in-count.<br>- BFD support for IPv4 and IPv6 |
| **PIM (RFC 4601 and RFC 3973)** | - PIM for IPv4: Sparse Mode, Dense Mode, Source Specific Multicast, IGMPv2, IGMPv3 - on Security Gateway, ClusterXL and VRRPv2 Cluster<br>- PIM for IPv6: _Not_ supported | - PIM for IPv4: Sparse Mode, Dense Mode, Source Specific Multicast, IGMPv2, IGMPv3 - on VSX Gateway and VSX Cluster<br>- Numbered warp interfaces: Not supported.<br>- PIM for IPv6: Not supported |
| **RIP for IPv4** | - RIP for IPv4: Supported on Security Gateway, ClusterXL and VRRPv2 Cluster<br>- RIPng for IPv6: Supported from R80.10 | - RIP for IPv4: VSX Gateway and VSX Cluster<br>- Numbered warp interfaces: Not supported.<br>- RIPng for IPv6: Not supported |
| **Policy-Based Routing (PBR)** | - PBR for IPv4: Based on Source IP, Destination IP and Interface. ECMP is supported. ClusterXL and VRRPv2 Cluster and are supported.<br>- Destination Port and Protocol are supported as of R77.30<br>- PBR for IPv6: _Not_ supported<br>- ISP Redundancy: _Not_ supported | - PBR for IPv4: Based on Source IP, Destination IP and Interface. ECMP is supported. VSX Gateway and VSX Cluster are supported.<br>- PBR for IPv6: _Not_ supported<br>- PBR with Destination Port and Protocol are not supported in VSX mode due to configuration limitation<br>- ISP Redundancy: _Not_ supported |
| **IP Broadcast Helper** | For IPv4 only | For IPv4 only |
| **DHCP Relay** | For IPv4 and IPv6 | For IPv4 and IPv6 |
| **Router Discovery** | For IPv4 and IPv6<br>IPv6 Router Discovery works on Security Gateway and in ClusterXL.<br>IPv4 Router discovery is _not_ supported in ClusterXL (supported only on Security Gateway, or in VRRP cluster). | For IPv4 and IPv6<br>IPv6 Router Discovery is supported on VSX Gateway and VSX Cluster.<br>Note: IPv4 Router Discovery is _not_ supported in VSX Cluster (supported only on VSX Gateway) |
| **Inbound Route Filtering** | - IPv4: All protocols<br>- IPv6: All protocols | - IPv4: All protocols<br>- IPv6: All protocols |
| **Route Redistribution** | For IPv4 and IPv6 | For IPv4 and IPv6 |
| **Route Aggregation** | For IPv4 only | For IPv4 only |
| **ICMP** | For IPv4 and IPv6 | For IPv4 and IPv6 |
| **ECMP** | For IPv4 only<br>- OSPF<br>- BGP<br>  - eBGP from R77.10<br>  - iBGP from R80.10 | For IPv4 only<br>- OSPF<br>- BGP<br>  - eBGP from R77.10<br>  - iBGP from R80.10 |
| **Graceful Restart Helper** | For IPv4 and IPv6 - Supported:<br>- BGP for IPv4<br>- BGP for IPv6<br>- OSPF v2 for IPv4<br>- OSPF v3 for IPv6 | For IPv4 and IPv6 - Supported:<br>- BGP for IPv4<br>- BGP for IPv6<br>- OSPF v2 for IPv4<br>- OSPF v3 for IPv6 |
| **Graceful Restart Restarter** | - BGP for IPv4 and IPv6: Not supported<br>- OSPF v2 for IPv4 and OSPF v3 for IPv6: Not supported on Security Gateway and ClusterXL<br>- OSPF v2 for IPv4: Supported on VRRP cluster | - BGP for IPv4 and IPv6: Supported<br>- OSPF v3 for IPv6: Supported<br>- OSPF v2 for IPv4: Not supported |
| **Static Multicast Routes** | For IPv4 - from R77.30 on Security Gateway, ClusterXL, and VRRP Cluster | For IPv4 - from R77.30 on VSX Gateway and VSX Cluster |

#### VRRP

Refer to [sk105170 - Configuration requirements / considerations and limitations for VRRP cluster on Gaia OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105170)

|     |     |     |
| --- | --- | --- |
| Feature | Gateway Mode | VSX Mode |
| IPv4 | - VRRPv2 - Supports Monitored Circuits, Non-preempt, Auto-deactivation, Simplified VRRP Configurations (MCVR)<br>- RIP<br>- OSPF v2 and OSPF v2 Graceful Restart<br>- BGP<br>- PIM | VRRP is not supported in VSX Mode.<br>VSX uses ClusterXL only. |
| IPv6 | - VRRPv3 - Supports Monitored Circuits, Non-preempt.<br>- OSPFv3<br>- BGP with multiprotocol support<br>- RIPng from R80.10 |
| VRRPv3 | - PIM, Simplified VRRP Configuration and Auto-deactivation are not yet supported. |

## Administration Guides:

- [Gaia Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=428)
- [Gaia Advanced Routing Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=428)

## How-To Documents:

OSPF

- [sk98968 - OSPF on Gaia](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk95968)
- [sk100502 - How to configure Equal Cost Multipath (ECMP) over OSPF on Gaia OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100502)

BGP

- [sk95967 - BGP on Gaia OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk95967)
- [sk100499 - BGP on Gaia OS - configuring Graceful Restart](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100499)
- [sk100504 - How to configure Equal Cost Multipath (ECMP) over eBGP on Gaia](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100504)

PIM

- [sk100239 - How to configure PIM on Gaia OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100239)

DHCP / DHCP Relay

- [sk98839 - Configuration of IPv4 BOOTP/DHCP Relay using legacy services](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98839)
- [sk104114 - Configuration of IPv4 BOOTP/DHCP Relay using new services](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104114)

IP Broadcast Helper

- [sk98810 - How to configure IP Broadcast Helper on Gaia OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98810)

Routing Policy Configuration

- [sk98936 - How to configure route redistribution and inbound route filters in Gaia Portal](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98936)
- [sk100501 - How to configure Routemaps in Gaia Clish](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100501)

Policy Based Routing

- [sk167135 - Policy-Based Routing and Application-Based Routing in Gaia](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk167135)

## General Limitations and Notes regarding Dynamic Routing and VRRP (also see the Release Notes for your version)

- Use of Advanced VRRP Configuration in cases of multiple VRRP interfaces: Use of Advanced VRRP configuration is recommended when there are many VRRP interfaces (> 10). Use of VRRP (a.k.a. "mcvr") may result in very slow response in configuring due to the large number of VRRP configuration bindings.
- Route Redistribution and Inbound Router Filters vs. Routemaps:

There are two ways to configure routing policy
  - Route Redistribution and Inbound Router Filters (available in Gaia Portal only in versions R77.30 and lower, and in Gaia Clish from R80.10)
  - Routemaps (available in Gaia Clish only)

The two methods have different capabilities and different levels of integration with protocol-specific features. Routemaps are generally more capable but require all granularity to be configured within them. Also, if a Routemap is associated with a protocol (RIP/OSPF/BGP), it will take precedence over any Route Redistribution/Inbound Route Filters/protocol-specific features.

For example:

> Route Redistribution can be used to advertise certain routes with a specific MED to all BGP peers belonging to the same AS. Peer-specific configuration (med-out) can be used to advertise a different MED to one or more peers within the same AS. For those peers, med-out replaces the MED configured via Route Redistribution.
>
> If a Routemap is also configured to advertise routes to BGP peers within the same AS, all Route Redistribution and peer-specific configuration is ignored. The Routemap must be configured completely to ensure that the required routes are advertised to all the peers with the MED desired. A peer-specific Routemap would need to be configured to advertise a different MED to a specific peer (see [sk110477](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk110477)).

## Article Properties

Access Level: General

Status: Approved

Date Created: 2014-01-17

Last Modified: 2026-07-08

Was this page helpful? Yes / No
