> Source: [sk103565](https://support.checkpoint.com/results/sk/sk103565)

# sk103565 - Permanent VPN Tunnel between DAIP SMB appliance and Check Point Security Gateway is reported as 'Down'

| Property | Value |
|----------|-------|
| Solution ID | sk103565 |
| Date Created | 2014-12-01 |
| Last Modified | 2022-07-25 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1500, 1600, 1800, 910 |

## Symptoms

- * VPN Tunnel with 600 / 1100 appliance and another Check Point Security Gateway is configured to use Permanent Tunnels feature. The VPN Tunnel is passing traffic correctly, but the tunnel is marked as '`Down`' when 600 / 1100 appliance is configured as DAIP (behind some NATing device, such as ISP router) and is Centrally Managed.  

* DHCP Relay functionality over VPN on 600 / 1100 appliance stops working after fail-over from ADSL to Cellular Modem (3G).  

* SmartView Tracker shows that Tunnel Test packets between the gateways are dropped with reason "`According to the policy the packet should not have been decrypted`".  

* sfwd_tnlmon_test tries to send tunnel test to the DAIP ID (which is an illegal address):  

  `...[DATE TIME] sfwd_tnlmon_test: Peer cp-ohbl, IP address 0.0.0.17 (11)`  
  `
  ...[DATE TIME] get_resolved_link: can't find resolved link for peer 0.0.0.17`  
  `
  ...[DATE TIME] tunnel_test_generic : entering - gateway = 0.0.0.17, maxRetryCounter = 15, mode = 0, flags = 7`  
  `
  ...[DATE TIME] openTunnelTestSocket: binding socket 132 to ip 0 (0 for all), port 0`  
  `
  ...[DATE TIME] openTunnelTestSocket: socket 132 initialized successfully`  
  `
  ...[DATE TIME] send_packet : could not send tunnel test packet, error = 22`

## Cause

The peer gateway's external IP address (the interface that is connected to the NAT device) is not recognized as a part of the 600 / 1100 appliance's encryption domain.

## Solution

This problem was fixed. The fix is included in:

* [Check Point R75.20 HFA 70 (R75.20.70) for 600 / 1100 Appliance and Security Gateway 80](http://supportcontent.checkpoint.com/solutions?id=sk106669)

Check Point recommends to always upgrade to the most recent version ([Check Point 1100 appliance](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=420) / [Check Point 600 appliance](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=421) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=184) / [upgrade Multi-Domain Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=166)).

For **lower versions** , Check Point can supply a **Hotfix** .[Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a Hotfix (improved firmware image) that needs to be installed instead of the already installed. The fix causes the 600 / 1100 appliance to send Tunnel Test packets with its internal IP address as Source IP address. Therefore, this internal IP address needs to be added to the appliance's encryption domain.

<br />

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and 600 / 1100 appliances involved in the case.

Also, the following **workaround** is available: add the IP address of the external interface (that is connected to the NAT device) to the appliance's encryption domain and install policy.

<br />

If the peer gateway of the DAIP is a R80.20 or above please also install the fix from [sk164933](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk164933)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
