> Source: [sk116054](https://support.checkpoint.com/results/sk/sk116054)

# sk116054 - Traffic does not pass over a VPN tunnel between a VPN device managed by SmartProvisioning and Central VPN Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk116054 |
| Date Created | 2017-02-22 |
| Last Modified | 2017-02-23 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Traffic does not pass over a VPN tunnel between a VPN device managed by SmartProvisioning and Central VPN Gateway.

* Kernel debug ('`fw ctl debug -m fw + drop`') on the Central VPN Gateway shows that it drops decrypted traffic that was received from a VPN peer that is managed by SmartProvisioning:  

  `;fw_log_drop: Packet proto= ... dropped by vpn_drop_and_log Reason: Wrong peer gateway for decrypted packet (VPN Error code 01);`

* Output of the '`vpn overlap_encdom communities -s`' command on the Central VPN Gateway does not show any overlaps.

* VPN kernel debug ('`fw ctl debug -m VPN all`') on the Central VPN Gateway shows the following for the dropped decrypted traffic:  

  `;check_valid_peer_cpip: peer 0.0.XX.XXX is not valid:`  
  `
  valid peer 0.0.YY.YYY, allowed peers table id is0;`  
  `
  ;check_encryption_props: The decrypted peer 0.0.XX.XXX is not valid;`

## Cause

There are two gateways managed by SmartProvisioning that have the same/overlapping encryption domains.

Overlapping encryption domains for SmartLSM gateways do not appear in the kernel table `vpn_routing`, and SmartLSM gateways are identified by their dynamic IP addresses of format `0.0.XX.XXX`.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
