> Source: [sk110260](https://support.checkpoint.com/results/sk/sk110260)

# sk110260 - Main mode fails when using Traditional Mode VPN with DAIP Peer 

| Property | Value |
|----------|-------|
| Solution ID | sk110260 |
| Date Created | 2016-03-07 |
| Last Modified | 2020-11-12 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * Main mode fails when using Traditional Mode VPN with DAIP Peer on R77.30 Security Gateway.
* R77.20 and earlier version Security Gateways can establish VPN tunnel with DAIP peer.
* R77.30 Security Gateway cannot identify this peer as a DAIP device.  
  Error seen in *vpnd.elg* :   
  \[ 11825\]\[21 Jan 2:23:13\]\[\] FwIkeGetUserDNFromCerts: called   
  \[ 11825\]\[21 Jan 2:23:13\]\[\] canonize_gw_legacy: enter X.X.X.X   
  \[ 11825\]\[21 Jan 2:23:13\]\[\] GetEntryIsakmpObjectsHash: received ipaddr: X.X.X.X as key, found fwobj: NULL   
  \[ 11825\]\[21 Jan 2:23:13\]\[\] canonize_gw: Can''t get peer obj for ip ac1af9f8. Peer is unknown or mobile   
  \[ 11825\]\[21 Jan 2:23:13\]\[\] FwIkeGetUserDNFromCerts: Peer is not DAG, mobile user should be checked   
  \[ 11825\]\[21 Jan 2:23:13\]\[\] MMProcess5Epilogue1: IKEv1 is not supported for this peer   
  \[ 11825\]\[21 Jan 2:23:13\]\[\] RespMMPacketError: error in FWIKE_EXCH_MAIN_MODE- FWIKE_MM_PACKET_5_EPILOGUE1

## Cause

**R77.30 assumes that all dynamically assigned gateways belong to a community.**

When using Traditional Mode VPN with a DAIP peer, the R77.30 gateway looks for a community setting and cannot find it.

Consequently, main mode fails.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
