> Source: [sk113022](https://support.checkpoint.com/results/sk/sk113022)

# sk113022 - Site to Site VPN with 3rd party peer fails (when using pre-shared secret) if VPN community name contains spaces or special characters  

| Property | Value |
|----------|-------|
| Solution ID | sk113022 |
| Date Created | 2016-08-21 |
| Last Modified | 2023-12-18 |
| Technical Level | General |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Site to Site VPN with 3rd party peer fails (when using pre-shared secret) if VPN community name contains spaces or special characters.
* VPN with 3rd party peer fails with reason (AUTHENTICATION-FAILED).
* vpnd.elg may show:  

  ```
  [ 9882][8 Jun 10:38:36]fwisakmp_get_preshared: pre-shared secret nil or empty for host
  [ 9882][8 Jun 10:38:36][] InitMMPacketError: error in FWIKE_EXCH_MAIN_MODE - FWIKE_MM_PACKET_5_PROLOGUE 
  [ 9882][8 Jun 10:38:36][stat] vpn_inc_status_VPND_counter: increased counter 0 
  [ 9882][8 Jun 10:38:36][stat] vpn_inc_status_VPND_counter: increased counter 4 
  [ 9882][8 Jun 10:38:36][ikestate] < FWIKE_EXCH_INFORMATION > Id = 748150 
  [ 9882][8 Jun 10:38:36][ikestate] < FWIKE_PACKET_START > Id = 748150 [ 9882][8 Jun 10:38:36][] InitInfoStart: enter.
  ```

  <br />


  And:

  ```
  [ 9882][8 Jun 10:38:36][] find_sa_by_ike_peer: No IKE SA for this IKE peer found 
  [ 9882][8 Jun 10:38:36][] InitInfoStart: no sa for notification. Send without... 
  [ 9882][8 Jun 10:38:36][ikestate] < FWIKE_INFO_NOTIFY_CLEAR > Id = 748150 
  [ 9882][8 Jun 10:38:36][] CreateNotifyClear (24): entering 
  [ 9882][8 Jun 10:38:36][] Sent Notification to Peer 4fada412: authentication failed 
  [ 9882][8 Jun 10:38:36][] Sent Notification to Peer: authentication failed 
  ```

## Cause

This is a Security Management limitation.

## Solution

This problem was fixed. The fix is included in:

* [Check Point R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111841)

Check Point recommends to always upgrade to the most recent version ([Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=184)).

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , [Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) can supply a **Hotfix** .  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPInfo files](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) from the Security Management Server and Security Gateways involved in the case.

**If you choose not to get the Hotfix, you can use this workaround:**

Change the VPN community name to contain only English Characters and no spaces.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
