> Source: [sk44978](https://support.checkpoint.com/results/sk/sk44978)

# sk44978 - Check Point gateways always send main IP address as IKE Main Mode ID

| Property | Value |
|----------|-------|
| Solution ID | sk44978 |
| Date Created | 2010-06-15 |
| Last Modified | 2021-11-09 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |

## Symptoms

- For IKEv2 Only:  
Authentication response (Sent from the Check Point gateway) contains IKE ID information of the Main IP address of the cluster instead of what is configured in link selection.  
\*\*NOTE\*\* For IKEv1, the IKE ID sent in Main Mode Packet 5 is based on what is configured in link selection, in the following thumb rules:  
Link selection: Selected address from topology -IKEV1 MM ID: Link selection  
Link selection: Probing HA - IKEV1 MM ID: Main Address  
Link selection: Calculated IP based on network topology - IKEV1 MM ID: Main Address

## Solution

**For IKEv2,**this behavior is by design.

Check Point gateways always send the main IP address of the gateway as the IKE ID.

**Note:**By default IKEv2 uses the main IP as ID, but since R80.10 it can be changed to FQDN/DN as well (important for Azure integration).

<br />

Some third party VPN peers will not allow an IKE ID that is an IP address to differ from the IP address that the VPN terminates on.   

See [sk33822 - Site-to-Site VPN connection between Check Point VPN-1 and third-party gateways fails with (AUTHENTICATION-FAILED) error](http://supportcontent.checkpoint.com/solutions?id=sk33822) for a possible work-around when this is encountered.

**For IKEv1:**

In SmartConsole, open the Security Gateway object -\> IPSec VPN \> Link Selection.

Selecting the "Selected address from topology table:" or "Statically NATed IP:" option will affect the IPv4 address used as the IKE ID in Main Mode Packet 5.

**Note: Starting from R80.30**, Check Point gateways no longer use the main IP address of the gateway as IKE ID. This is true when using IKEV2, and when link selection is configured to use another interface than the main IP (which is the default).

Using "DNS Resolving" or "Link probing" in "Link selection" with IKEv2, will result in the gateway using its main IP as IKE ID."  

[sk173048](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk173048) describes a hotfix for an issue that was found in the new mechanism.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
