> Source: [sk102411](https://support.checkpoint.com/results/sk/sk102411)

# sk102411 - VPN tunnel is down after upgrade with error message:  "Received encrypted packet on non encryption connection"

| Property | Value |
|----------|-------|
| Solution ID | sk102411 |
| Date Created | 2014-09-09 |
| Last Modified | 2016-02-18 |
| Technical Level | Advanced |
| Products | Licensing |
| Versions | Not Version-Specific |
| OS | Gaia |

## Symptoms

- * After an upgrade from R6X to R7X, could not establish a VPN tunnel with any peer gateway. Could not see any information in the IKE/VPND debugs. The configuration was set correctly.
* Traffic from encryption domain to the peer gateway encryption domain - " fw monitor -p all" shows that the packet arrives until the last chain of the (i) then after the first chain of the (I) drops.
* "fw ctl zdebug drop" - "Received encrypted packet on non encryption connection"

## Cause

The license is no longer valid.

\*A blade license is required in R7X versions, unlike in R6X versions.

\*In User Center, see that a valid license was submitted, however "cplic print" shows otherwise.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
