> Source: [sk116157](https://support.checkpoint.com/results/sk/sk116157)

# sk116157 - Instability issues between Check Point Security Gateway and Microsoft Azure in IKEv2 Site to Site VPN

| Property | Value |
|----------|-------|
| Solution ID | sk116157 |
| Date Created | 2017-03-02 |
| Last Modified | 2021-04-15 |
| Technical Level | General |
| OS | Gaia |
| Platform | Azure |

## Symptoms

- * Microsoft Azure gateways may not allow VPN renegotiation, if keys already exist for tunnel.
* In some circumstances, a renegotiation request may be received, if the Microsoft Azure gateway believes that the tunnel should still be up and running.
* In case of SMB Appliance, such as Check Point 1490, the following error is shown in *SFWD.elg*: "\[ikev2\] ikeAuthExchange_r::createIDrPayload: invalid ID-r payload"

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R77.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk106162) - since *Take_338*

Check Point recommends to always [upgrade to the most recent version](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184)

For **other [supported](http://www.checkpoint.com/support-services/support-life-cycle-policy/index.html) versions** , [Check Point Support](http://www.checkpoint.com/support-services/contact-support/index.html) can supply a **Hotfix** .  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

**Hotfix installation instructions:**

1. Hotfix has to be installed on ***Security Gateway***.

   **Note:** In cluster environment, this procedure must be performed on *all* members of the cluster.
2. Procedure:

   * Using CPUSE on Gaia OS:

     Refer to [sk92449: CPUSE - Gaia Software Updates (including Gaia Software Updates Agent)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE):
     * Section "[(4-A-c)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Portal)" / "[(4-A-d)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to download and import a CPUSE package - Import instructions for Offline procedure - Gaia Clish)" - refer to import instructions for *Offline procedure*
     * Section "[(4-B-a)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92449#How to work with CPUSE - How to install a CPUSE package - Installing a Hotfix package / Minor Version package)" - refer to installation instructions for *Hotfixes*

     **Note:** Machine will be rebooted automatically.
   * Using Legacy CLI on Gaia/SecurePlatform/IPSO OS:

     1. Transfer the hotfix package to the machine (into some directory, e.g., */some_path_to_fix/*).

     2. Unpack and install the hotfix package:

        ***\[Expert@HostName:0\]# cd /some_path_to_fix/***   
        ***\[Expert@HostName:0\]# tar -zxvf fw1_wrapper_\<HOTFIX_NAME\>.tgz***   
        ***\[Expert@HostName:0\]# ./fw1_wrapper_\<HOTFIX_NAME\>***
        **Note:** The script will stop all of Check Point services (*cpstop*) - read the output on the screen.
     3. Reboot the machine.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
