Configuring IP Reachability Detection in Gaia Clish
|
Important - In a Cluster |
-
To see the available "
set
" commands for IP Reachability Detection, enter in Gaia ClishThe name of the default command line shell in Check Point Gaia operating system. This is a restricted shell (role-based administration controls the number of commands available in the shell).:
set ip-reachability-detection[Esc][Esc]
-
To see the available "
show
" commands for IP Reachability Detection, enter in GaiaCheck Point security operating system that combines the strengths of both SecurePlatform and IPSO operating systems. Clish:
show ip-reachability-detection[Esc][Esc]

|

Parameter |
Description |
||
---|---|---|---|
|
Configures the IP address range of the peer. Configuration in the address range applies to any BFD sessions, whose remote peer addresses are in the range. If ranges overlap, the narrowest range takes precedence (for example: 10.1.1.0/24 overrides 10.1.0.0/16). ![]() Specify the applicable IPv4 address and optionally the IPv4 subnet mask. If the subnet mask is not specified explicitly, it defaults to the maximum of 32. Examples:
![]() Specify the applicable IPv6 address and optionally the Mask Length. If the Mask Length is not specified explicitly, it defaults to the maximum of 128. Examples:
|
||
|
Deletes the BFD authentication settings, including keys and authentication type. In this case, if a greater, overlapping range is configured for authentication, that range's settings are used. |
||
|
No BFD authentication is used. If you switch from another authentication type to this type, all keys are removed and authentication is disabled for this range of peer addresses (even if a greater, overlapping range is configured for authentication). |
||
|
Configures the BFD Authentication type and key. ![]() BFD can be authenticated on a given address range, with specified Authentication Type, Key ID, and Shared Secret. BFD authentication is disabled by default. If BFD authentication is already enabled on the address range, you can add another Key (up to ten) with a unique Key ID, or replace the configured Key. For BFD authentication to work properly, you must configure the local and remote BFD peers to:
|
||
|
![]()
|
||
|
![]() This number uniquely identifies the key, if more than one key is used. BFD supports the use of multiple keys (up to ten). Make sure that the Configures of keys (Key IDs and Shared Secrets) are identical to those on the remote peer.
Range: 0-255 Default: None |
||
|
Specifies the shared secret in hexadecimal notation, with two hex digits to represent each byte.
|
||
|
Removes a BFD authentication key from the configuration. Leaves other keys alone. When you remove the last BFD authentication key from an address range, then BFD uses the settings from a broader overlapping address range (if any). If there is none, then BFD operates without authentication. This can disable BFD authentication if no more keys are left. |
||
|
Specifies the shared secret, in which each ASCII character represents one byte.
|
||
|
Enables multihop BFD for this IP address. Allows the remote address to be any number of hops away - even zero, although this is seldom useful (see RFC 5883). To support this extra versatility, with multihop BFD you must specify the Local Address of this Gaia. Multihop BFD only works if the remote and local IP addresses on the peers are configured correctly:
BFD Multihop Control packets use the UDP destination port 4784. |
||
|
Disables BFD completely for this IP address. |
||
|
Enables singlehop BFD for this IP address. Requires that the remote address be exactly one hop away (see RFC 5881). BFD Singlehop Control packets use the UDP destination port 3784. BFD Singlehop Control packets use the UDP source ports from 49152 to 65535. |
||
|
Configures the BFD detect multiplier that the system advertises. It determines the remote system timeout. Smaller values produce quicker detection. greater values produce better reliability. If the remote peer's Detect Multiplier is 1, the detection time on a Gaia gateway increases by 12.5% above the RFC 5880 specification, to improve reliability. This setting is global for all BFD sessions on a Security Gateway Range: 1-100 Default: 10 Recommended: At least 3 |
||
|
Configures the BFD minimal RX interval that the system advertises. It configures the local system timeout and the rate at which the remote system transmits packets. Smaller values produce quicker detection. greater values reduce network load. This setting is global for all BFD sessions on a Security Gateway or VSX Virtual System. Range: 50-1000 milliseconds Default: 300 milliseconds |
||
|
Configures the BFD minimal TX interval that this system advertises. It configures the remote system timeout and the rate at which the local system transmits packets. Smaller values produce quicker detection. greater values reduce network load. This setting is global for all BFD sessions on a Security Gateway or VSX Virtual System. Range: 50-1000 milliseconds Default: 300 milliseconds |
||
|
This feature detects whether various remote IP addresses are reachable using ICMP ping. Disables ( |
||
|
This feature detects whether various remote IP addresses are reachable using ICMP ping. Specifies the number of missed packets (no ICMP Echo Reply) to be tolerated in a row before the address is considered "not reachable." Range: 1-100 Default: 3 |
||
|
This feature detects whether various remote IP addresses are reachable using ICMP ping. Specifies the interval between ICMP Echo Request packets that are sent. This setting is global for all BFD sessions on a Security Gateway or VSX Virtual System. Range: 50-1000 seconds Default: 3 seconds |