> Source: [sk112141](https://support.checkpoint.com/results/sk/sk112141)

# sk112141 - Site-to-Site VPN fails between Check Point Security Gateway and Check Point Virtual Appliance for Amazon Web Services (AWS)

| Property | Value |
|----------|-------|
| Solution ID | sk112141 |
| Date Created | 2016-06-26 |
| Last Modified | 2020-11-01 |
| Technical Level | Advanced |
| OS | Gaia |
| Platform | AWS |

## Symptoms

- * Site-to-Site VPN fails between Check Point Security Gateway and Check Point Virtual Appliance for Amazon Web Services (AWS).

* Traffic capture shows:

  1. Tunnel is initiated from Check Point Security Gateway to Check Point Virtual Appliance for AWS
  2. The IKEv1 Quick Mode is completed
  3. Immediately, Check Point Virtual Appliance for AWS sends a "Delete" message
* Output of "*fw tab -t TABLE_NAME -s*" command on Check Point Virtual Appliance for AWS shows that the relevant kernel tables are not full:

  * `ike2esp`
  * `vpn_queues`
  * `peer2ike`
  * `ike2peer`
  * `ikev2_sas`
* Kernel debug ('`fw ctl debug -m VPN + warn mspi`') on Check Point Virtual Appliance for AWS repeatedly shows:

  `
  ;store_outbound_spi_in_msa: allocating esp sa in meta sa of mspi = ...;`  
  `
  ;store_outbound_spi_in_msa: re-aligning processed key;`  
  `
  ;store_outbound_spi_in_msa: ERROR: could not get kbuf;`  
  `
  ;store_spi_in_table_ex: failed to store outbound esp SA;
  `

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
