> Source: [sk109740](https://support.checkpoint.com/results/sk/sk109740)

# sk109740 - Incoming VPN Traffic not matched by correct firewall rule

| Property | Value |
|----------|-------|
| Solution ID | sk109740 |
| Date Created | 2016-01-25 |
| Last Modified | 2021-07-19 |
| Technical Level | Advanced |

## Symptoms

- * Incoming VPN Traffic is not being matched by the relevant firewall rule. Instead the traffic is either dropped or sent in the clear unencrypted, depending on other rules than the expected relevant firewall rule (designated for the specific VPN community (with correct source and destination) and configured earlier in the rule base).
* After running kernel debug, the following output is seen in *kern.ctl* :  
  "vpn_inbound_tagging_ex: incoming packet from : +++ to : +++ non-decrypted client location : **My** encdom server location My encdom client_ifs_grp : 0 server_ifs_grp : 0 ;"

## Cause

This issue is caused by IP Addresses from the Peer Gateway that are configured on the local Check Point Gateway object in its Encryption Domain.

The local gateway identifies the traffic as being internal to it. Consequently, it does not allow the VPN traffic to be matched with the correct rule that is set to the relevant VPN Community and instead skips the rule.

The rule that is finally enforced is located later in the rule base than the designated rule (for example, the later rule could be the cleanup rule).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
