> Source: [sk1000010](https://support.checkpoint.com/results/sk/sk1000010)

# sk1000010 - Open Shortest Path First Does Not Start on ClusterXL High Availability Members After Central Deployment Upgrade

| Property | Value |
|----------|-------|
| Solution ID | sk1000010 |
| Date Created | 2026-08-20 |
| Last Modified | 2026-08-28 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20 |
| OS | Gaia |

## Symptoms

- * After you upgrade a ClusterXL High Availability (HA) cluster with the SmartConsole Central Deployment Tool, Open Shortest Path First (OSPF) does not start on either cluster member in a dual-stack IPv4 and IPv6 environment. You may experience the following symptoms:
* OSPF adjacencies do not form after the upgrade.  
* OSPF routes are unavailable.  
* A routing outage occurs because OSPF-learned routes are missing.  
* Multiple ClusterXL HA clusters can experience the same behavior if the same upgrade procedure is used during the same maintenance window.
* On the affected Security Gateway cluster members, the Gaia Clish command below returns an empty table although OSPF interfaces are configured:   
  `show ospf interfaces`

  Example output:  
  \<empty OSPF interface table\>
* On the affected Security Gateway cluster members, the /var/log/routed.log file contains messages similar to:  
  `OSPF2 instance default OspfInterfaceUp(4632):`  
  `not starting protocol on interface`
* Similar OSPFv3 messages can appear for IPv6 interfaces.  
* During the affected boot sequence, the routed process does not detect the configured IPv4 cluster Virtual IP (VIP) addresses. The cluster later installs both IPv4 and IPv6 VIP addresses successfully.

## Cause

In a dual-stack IPv4 and IPv6 ClusterXL HA environment, a timing condition can occur during the upgrade boot sequence.

The routed process restarts and initializes before ClusterXL completes the installation of all cluster interfaces and Virtual IP (VIP) addresses. IPv6 VIP information becomes available to routed before IPv4 VIP information.

As a result, routed identifies the cluster as ready before all cluster VIP information is available. The process completes its initialization with only partial VIP information and does not refresh the IPv4 cluster VIP list after ClusterXL installation completes.

When ClusterXL later installs the IPv4 VIP addresses, routed does not update its internal cluster VIP information. Because routed does not recognize the IPv4 cluster VIP addresses, OSPF cannot associate with the configured IPv4 OSPF interfaces and does not start.

This behavior results in:

* Empty show ospf interfaces output
* Missing OSPF adjacencies
* Missing OSPF routes
* Routing disruption following the upgrade

This issue is resolved by a software update that synchronizes cluster readiness processing for IPv4 and IPv6 VIP information.

## Solution

<br />

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member / Security Group involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
