> Source: [sk102192](https://support.checkpoint.com/results/sk/sk102192)

# sk102192 - RIM creates many separate routes for the remote encryption domain

| Property | Value |
|----------|-------|
| Solution ID | sk102192 |
| Date Created | 2014-08-26 |
| Last Modified | 2015-07-12 |
| Technical Level | General |

## Symptoms

- * The RIM mechanism adds many routes for the peer's encryption domain - it subnets the network behind the peer to many subnets and adds a route for each.
* Specifically, the subnetting is done to exclude peer's internal interface, so the end result is that there is no route to it.

## Cause

The RIM_inject_peer-interfaces attribute controls this behavior and can be configured as follows:

* When selected, adds one route per network in the peer's domain and, in addition, one route for each of the peer's interfaces.
* When not selected, adds only routes to networks inside the peer's encryption domain, and if a peer's interface is included in one of those networks, subnets it as needed in order to exclude the interface and add routes to the subnets created by this division.

## Solution

1. Select the attribute in SmartDashboard: 'Policy \> Global Properties \> SmartDashboard customization \> Configure... \> VPN advanced properties \> Tunnel Management \> RIM_inject_peer-interfaces'

2. Install policy

**Notes:**

1. This is global parameter that will be enforced by all RIM-performing gateways managed by the same SmartCenter.
2. Pay attention to define the full subnet in encryption domain, e.g. range 10.60.4.**1** -10.60.4.7 is not subnet, while 10.60.4.**0**-10.60.4.7 is

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
