> Source: [sk106676](https://support.checkpoint.com/results/sk/sk106676)

# sk106676 - Capsule VPN fails to connect to site with error "Internal error - policy callback failed"

| Property | Value |
|----------|-------|
| Solution ID | sk106676 |
| Date Created | 2015-06-30 |
| Last Modified | 2017-09-26 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Android |
| Platform | Mobile Devices |

## Symptoms

- "`Failed to connect: internal error - policy callback failed`" error in the client logs when Capsule VPN client cannot connect to the site.   

The issue is limited to devices of specific Vendors and Android versions. The same user can connect from other devices with Capsule VPN.  
**The issue was reported on some models of General Mobile and Lenovo phones after upgrade of Android version to 4.4.2.**

## Cause

Android Java API is implemented incorrectly.

The Capsule VPN application receives the encryption domain topology from the VPN Gateway and then makes API calls to add to the device's routing table specific routes to the encryption domain via a tunnel interface.

However, on the affected devices, instead of adding the specific routes, the routes that are added cause almost all traffic to be routed via the tunnel interface instead of out of the physical network interfaces, thus breaking connectivity.

## Solution

Contact the device / ROM vendor for possible fix for this issue.

**Important Note**: The Capsule VPN client may generate the error "Internal error - policy callback failed" because of other reasons as well.

[Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a procedure that verifies whether a mobile device is affected by the issue described in this article.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
