> Source: [sk104441](https://support.checkpoint.com/results/sk/sk104441)

# sk104441 - OSPF Graceful Restart with VRRP in R77.30 and above

| Property | Value |
|----------|-------|
| Solution ID | sk104441 |
| Date Created | 2015-02-16 |
| Last Modified | 2017-01-27 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Solution

OSPF Graceful Restart with VRRP is the new feature added in R77.30.

OSPF Graceful Restart works in two modes:

* restarter
* helper

This article describes only the *restarter* functionality.  
The *helper* mode is supported in both VRRP and ClusterXL solutions.

*Restarter* functionality is needed to signal neighboring routers that Check Point Security Gateway / cluster member is restarting and that it can still forward data packets. This helps neighboring routers to keep Check Point Security Gateway / cluster member in forwarding path.

**Important Notes:**

1. When configuring OSPF Graceful Restart with VRRP, fast cluster failovers/failbacks can still lead to traffic outage. Therefore, it is recommended to use *non-prempt* mode in VRRP. This happens because the VRRP Backup members have no information about OSPF routes as VRRP Master member has not completed the restart operations yet.   

2. Users must wait for all OSPF routes to synchronize to VRRP Backup members before performing a cluster failover/failback.   

3. *VRRP prempt (default) mode* : When using VRRP with preempt (default) mode, users must make sure to not failback before OSPF Graceful Restart is finished on the VRRP Master member.  
   For example:

   If users perform a failover by disconnecting a network cable from a VRRP interface, then user must *not* reconnect the cable before OSPF Graceful Restart is finished. Otherwise, traffic outages are expected because an immediate failback will happen to a VRRP Backup member, which does not have any OSPF routing state.
   To avoid this situation, use the *non-prempt* mode in VRRP.   

4. OSPF Graceful Restart with VRRP is supported *only* for complete failovers. Meaning, user must avoid Active/Active state on VRRP interfaces.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
