> Source: [sk184923](https://support.checkpoint.com/results/sk/sk184923)

# sk184923 - Wrong Route Selection with ISP Redundancy on ClusterXL

| Property | Value |
|----------|-------|
| Solution ID | sk184923 |
| Date Created | 2026-05-22 |
| Last Modified | 2026-07-23 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- When ISP Redundancy is enabled on a ClusterXL Security Gateway, return traffic may exit through the wrong interface, causing asymmetric routing. For example:

* TCP SYN packets arrive through the backup ISP.
* TCP SYN?ACK replies leave through the primary ISP.
This behavior typically appears after an ISP priority change or failover. Disabling SecureXL acceleration (fwaccel off) temporarily resolves the issue until the next ISP priority change or failover event.

## Cause

This behavior is observed in R81.20 and R82 due to a specific interaction between ISP Redundancy routing updates and SecureXL routing and connection caching.

Under certain conditions:

* The Linux routing table updates correctly after an ISP priority change.
* Internal ISP Redundancy and SecureXL routing structures retain information about the previously active ISP.
* SecureXL continues to accelerate existing connections using outdated routing data.
As a result, reply packets may exit through an interface associated with the previously active ISP, leading to asymmetric routing and connection failures until routing information is refreshed.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 36
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

### Workaround

Use this workaround to resynchronize SecureXL and ISP Redundancy routing information. This workaround is temporary and must be re?applied after each ISP priority change.

On each affected Security Gateway or Cluster Member, in Expert mode, run:

`fw rtupdate`

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
