> Source: [sk103269](https://support.checkpoint.com/results/sk/sk103269)

# sk103269 - Remote Access VPN clients fail to connect with "IKE Negotiation with gateway has failed. Make sure the user is properly defined on the firewall"

| Property | Value |
|----------|-------|
| Solution ID | sk103269 |
| Date Created | 2014-11-06 |
| Last Modified | 2025-04-24 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Remote Access VPN clients fail to connect with "`IKE Negotiation with gateway has failed. Make sure the user is properly defined on the firewall`"

  .
* The IKE and VPN debugs show the following lines:

  * VPND: Failed to match proposal. Transform: AES-256, SHA1, Pre-shared secret, Group 2 (1024 bit); Reason: Wrong value for: Authentication Method
  * VPND: Failed to match in strict mode. Will try matching all supported DH
  * Ike: Not chosen because: Wrong value for: Authentication Method
  * Ike: Authentication Method: HybridInitRSA

## Cause

Misconfiguration in SmartConsole in Global Properties.

As long as the client attempts to connect in HybridInitRSA, the Hybrid Mode must be enabled.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
