> Source: [sk173048](https://support.checkpoint.com/results/sk/sk173048)

# sk173048 - IKEv2 to a 3rd party uses the main IP address of the VPN Gateway object as its IKEID when BestRoutingSenderIP is set to true

| Property | Value |
|----------|-------|
| Solution ID | sk173048 |
| Date Created | 2021-04-15 |
| Last Modified | 2021-10-05 |
| Technical Level | General |
| OS | Gaia |

## Symptoms

- * The VPN gateway uses the main IP address of the gateway object as its IKE ID.
* Link selection is configured to use an interface *x.x.x.x* that is not the main default IP *y.y.y.y*.
* The vpnd logs show that the gateway used the main IP address as an ID:  

      
      [vpnd][ikev2] ikeAuthExchange_i::createIDiPayload: entering.
      
      
      [vpnd][ikev2] ikeAuthExchange_i::createIDiPayload: entering. authenticating via certificates: 0.
      
      
      [vpnd][tunnel] getIdFromEnvVars: enter. FullyDone 1. id-type 0, id-len 0.
      
      
      [vpnd][ikev2] ikeSimpOrder::getMainIPAddr: Enter
      
      
      [vpnd][ikev2] ikeSimpOrder::getMainIPAddr: ip addr is 4=x.x.x.x, 6=::
      
      
      [vpnd][ikev2] ikeOrder::getMyIDData: my ID data: x.x.x.x (order 10, ref count 2).
      
      
      [vpnd][ikev2] Message::addPayload: Added payload 1 (IDi)

## Cause

This is a known issue.  
The IKE-ID that Check Point sends as an IKE payload is not equal to the source IP address of the IKE transport.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736)
* [Jumbo Hotfix Accumulator for R80.30](upportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 235
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 202

Check Point recommends to always upgrade to the most recent version ([Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=435) / [VSX](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=359) / [Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=184) / [Multi-Domain Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=166) / [SmartConsole](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=191)).

If you do not wish to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).
Workaround - For Customers Who Do Not Upgrade  

As a workaround, customers who do not upgrade can perform the procedure in Scenario 2 of [sk108600 - VPN Site-to-Site with 3rd party](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108600).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
