R81.20 VPN wrong peer id

Had an odd one today, upgraded checkpoint cluster from R81.10 > R81.20, no issues cluster was functional and all was working as expected
Received an alert 3 hrs after the cluster upgrade work had finished , vpn was down, in the logs i could see the R81.20 cluster was sending the internal cluster IP

I went into the cluster config> IPSec VPN > Link Selection , and set Always use this address to the incorrect address it was sending , clicked ok then went back it and set it to the address it should be clicked ok and then installed policy

No changes have been made , on R81.10 this was all working fine. before?
Worried now there might be more issues like this that crop up…

This is why, when I do a cluster upgrade from one major version to another, I’ll do one node, wait 2 weeks and then do the other node.

This process has served me well over the years. Though I tell my TAC agent to cover his ears when we talk about it.

See if https://support.checkpoint.com/results/sk/sk172805 applies. From a recent similar experience, a packet capture may show the initial phase 1 using the correct Link Selection IP address, but then attempting to use the cluster IP for phase 2. Look for UDP 500 and 4500 (NAT-T) traffic in the capture.