> Source: [sk109586](https://support.checkpoint.com/results/sk/sk109586)

# sk109586 - VPN negotiation between Avaya VPN phone and Check Point Gateway fails due to Invalid MM ID

| Property | Value |
|----------|-------|
| Solution ID | sk109586 |
| Date Created | 2016-01-13 |
| Last Modified | 2018-04-17 |
| Technical Level | Advanced |

## Symptoms

- * VPN is not established between Avaya VPN phone and Check Point Security Gateway.

* Check Point Security Gateway denies the Main Mode ID that is proposed by the Avaya phone, despite it being a regular IPv4 Main Mode ID type.

* Debug of VPND daemon on Security Gateway (per [sk89940](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk89940)) shows that "`Wrong length 14 for ID`" is presented for the proposed Main Mode ID by Avaya phone.

## Cause

The Avaya MM ID is presented by IPv4 with wrong key length.

In regular IPv4 ID translation, Main Mode ID is presented in Hexadecimal format, which is translated into IPv4 address.

Avaya IPv4 Main Mode ID is presented in Hexadecimal format, which is translated into ASCII code. As a result, the generated Main Mode ID contains 14 characters, instead of a shorter ID, which can be observed in any successful IKE negotiation with Check Point Security Gateway.

Note: The proposed Avaya Main Mode ID (as see in the debug of VPND daemon) is translated to a different IP address, than the IP address seen in the *$FWDIR/log/ike.elg*. This difference is not related to any problem. Moreover, it is officially supported for IKEV2 as per the relevant RFC.

Note: in case of ikev2 tunnel the log file is $FWDIR/log/ikev2.xmll.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
