> Source: [sk118792](https://support.checkpoint.com/results/sk/sk118792)

# sk118792 - VPN IKE SA's are deleted after 2 minutes

| Property | Value |
|----------|-------|
| Solution ID | sk118792 |
| Date Created | 2017-07-08 |
| Last Modified | 2021-08-03 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- Security gateway deletes IKE_SA's after 2 minutes since no IPsec SA's were established using the IKE_SA that was created after upgrading to R77.30 Jumbo Hotfix Take 184 and higher or R80.10

## Cause

Code was changed in R80.10 and R77.30 JHF 184: when an entry for the SA is saved for the first time in the kernel table IKE_SA_table, the expiration field is set to 2 minutes instead of using the expiration time for the SA.

Only after the SA has been used, the entry is saved with the SA's expiration time.

**That means if an IKE SA was created but no subsequent IPsec SA was created using it within 2 minutes since the IKE SA creation (e.g. no traffic was conducted between the VPN peers) -, the IKE SA will be deleted.**   

This change was made to solve a problem that can occur where a malfunctioning VPN peer initiates IKE SAs repeatedly thus overwhelming the local VPN gateway with IKE SAs.

However, it was discovered that this can cause an issue for some third party peers that need to create an IKE SA without a subsequent IPsec SA for the purposes of DPD which uses IKE SA only for traffic encryption (UDP Port 500) or for peers authentication purpose only etc.  

**Important: Since R80.40 a new infrastructure has been introduced for handling VPN IKE queues.**

## Solution

[Contact Check Point Support](http://www.checkpoint.com/services/contact/index.html) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

This fix eliminates the 2 minute timeout completely, and solves an issue where the IKE DOS protection was not working correctly.

For more information see: **[Protection After Successful Authentication](https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_SitetoSiteVPN_AdminGuide/13847.htm#o162304)**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
