> Source: [sk172603](https://support.checkpoint.com/results/sk/sk172603)

# sk172603 - BGP does not work after you enable MD5

| Property | Value |
|----------|-------|
| Solution ID | sk172603 |
| Date Created | 2021-03-18 |
| Last Modified | 2021-03-21 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When users do not enable MDS Authentication, BGP peering in "Establish state" functions with no issues.
* After users enable MD5 Authentication, the BGP peer alternates between "Connect" and "Active State."
* When users enable BGP traces, they see the following messages under /var/log/routed.log:   
  bgp_set_nexthop_addresses(9876): DEST_IP \[eBGP AS 65011\] Local IPv4 Address Cluster_IP  
  bgp_set_peer_ifaps(5445): 10.192.1.21 \[eBGP AS 65011\] using interface eth0 address Local_GW_IP  
  Refer to [sk101399](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk101399).

## Cause

The BGP neighbor on the other side of the peer uses the local gateway's IP instead of the VIP.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
