> Source: [sk182849](https://support.checkpoint.com/results/sk/sk182849)

# sk182849 - No RIM routes available after SMB failover to second link

| Property | Value |
|----------|-------|
| Solution ID | sk182849 |
| Date Created | 2024-12-02 |
| Last Modified | 2024-12-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * No RIM (Route Injection Mechanism) routes available after SMB failover to second link.
* After a link failover on the SMB from static IP to DHCP, the center Security Gateway detects the tunnel as down.
* The `vpnd.elg `debug logs ([sk180488](https://support.checkpoint.com/results/sk/sk180488)) show that, following the link failover, IKE and IPsec SA (Security Association) negotiations are successful, and encrypted traffic is sent and received. Tunnel tests also pass.
* The vpnd.elg logs indicate that the new IP address is not associated with the SMB. The following entries show the failure to recognize the new IP address:

  > `[vpnd 13169 4071578240]@FW[19 Aug 13:55:09] canonize_gw_legacy: enter 8.8.8.8 
  > [vpnd 13169 4071578240]@FW[19 Aug 13:55:09] GetEntryIsakmpObjectsHash: received ipaddr: 8.8.8.8 as key, found fwobj: NULL 
  > [vpnd 13169 4071578240]@FW[19 Aug 13:55:09] canonize_gw: Can't get peer obj for ip 5e45025. Peer is unknown or mobile 
  > [vpnd 13169 4071578240]@FW[19 Aug 13:55:09][tunnel] tnlmon_db_get: Failed to get gateway = 8.8.8.8, type = 257 values 
  > [vpnd 13169 4071578240]@FW[19 Aug 13:55:09][tunnel] tnlmon_life_sign_trigger: <8.8.8.8;0101>; does not exist in database. 
  > [vpnd 13169 4071578240]@FW[19 Aug 13:55:09][tunnel] tnlmon_life_sign_trigger: Trying <8.8.8.8;0001>; 
  > [vpnd 13169 4071578240]@FW[19 Aug 13:55:09][tunnel] tnlmon_db_get: Failed to get gateway = 8.8.8.8, type = 1 values 
  > [vpnd 13169 4071578240]@[19 Aug 13:55:09][tunnel] tnlmon_life_sign_trigger: object IP 8.8.8.8 does not exist in database, ignoring peer`

  These logs show that the system cannot associate the new IP address (8.8.8.8) with the gateway object. Attempts to retrieve the object for this IP result in failure, indicating that the peer is unknown or mobile, and the IP is not present in the database.

## Cause

The DAIP (Dynamic IP Address) detection mechanism failed to associate the SMB with the new IP address after the link failover.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
