> Source: [sk111156](https://support.checkpoint.com/results/sk/sk111156)

# sk111156 - VPN traffic dropped with "Encryption failure: Warning: possible replay attack" log

| Property | Value |
|----------|-------|
| Solution ID | sk111156 |
| Date Created | 2016-04-29 |
| Last Modified | 2022-03-17 |
| Technical Level | Advanced |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82, R81.20, R82.20 |
| OS | Gaia |

## Symptoms

- * VPN traffic is dropped with the log message

  ```
  Encryption failure: Warning: possible replay attack.
  ```

* VPN traffic is dropped at random times, usually during peak hours. Traffic is usually dropped by a Security Gateway or Cluster in a Site-to-Site VPN tunnel with a Cluster.
* When the "disable_replay_attack" attribute is "true", the dropped traffic ceases.

## Cause

The purpose of a standby member is to send traffic after a failover.

Sometimes a standby member initiates traffic, or is accessed directly for maintenance or monitoring, while the active member is still sending traffic. When this happens, the Security Gateway or Cluster sometimes drops VPN traffic.  

This drop is directly related to traffic being directed to the physical IP addresses of the cluster members.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
