> Source: [sk104578](https://support.checkpoint.com/results/sk/sk104578)

# sk104578 - VPN tunnel can not be established / no traffic passes when SHA-384 is configured for data integrity

| Property | Value |
|----------|-------|
| Solution ID | sk104578 |
| Date Created | 2015-02-09 |
| Last Modified | 2020-07-09 |
| Technical Level | Advanced |

## Symptoms

- * VPN tunnel can not be established / no traffic passes over VPN tunnel when SHA-384 is configured for data integrity.

* IPsec VPN tunnel can not be established between peers in the following scenario:

  1. SHA-384 is selected for data integrity for IKE Phase 1 (IPSec VPN community properties - "*Encryption* " pane - in section "*Encryption Suite* ", select "*Custom* " - click on "*Custom Encryption...* " button - go to section "*IKE Security Association (Phase 1) Properties* " - in the field "*Perform data integrity with* ", select "*SHA-384*")
  2. one peer is R77.20 and lower
  3. the other peer is R77.30 and above (or a 3rd party device)

  The following logs might appear in SmartView Tracker:
  * `IKE: Phase1 Received Notification from Peer: payload malformed`
  * `IKE: Auth exchange: Peer's message is unacceptable`

* IPsec VPN tunnel is established between peers, but no traffic passes over the tunnel in the following scenario:

  1. SHA-384 is selected for data integrity for IKE Phase 2 (IPSec VPN community properties - "*Encryption* " pane - in section "*Encryption Suite* ", select "*Custom* " - click on "*Custom Encryption...* " button - go to section "*IPsec Security Association (Phase 2) Properties* " - in the field "*Perform data integrity with* ", select "*SHA-384*")
  2. one peer is R77.20 and lower
  3. the other peer is R77.30 and above (or a 3rd party device)

  The following log might appear in SmartView Tracker:
  * `encryption failure: Authentication failure. Sequence Number 1 (Expected 0)`

## Cause

Starting in R77.30, the HMAC-SHA384 algorithm used by the Security Gateway was updated to conform to [RFC 2104](http://www.rfc-editor.org/info/rfc2104).

Security Gateways using different versions of the HMAC-SHA384 algorithm are not able to interoperate.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
