> Source: [sk118855](https://support.checkpoint.com/results/sk/sk118855)

# sk118855 - Problems with supernetting during IKE negotiation with Large Scale VPN (LSV) peer

| Property | Value |
|----------|-------|
| Solution ID | sk118855 |
| Date Created | 2017-07-11 |
| Last Modified | 2017-07-11 |
| Technical Level | Advanced |

## Symptoms

- Problems with supernetting during IKE negotiation with Large Scale VPN (LSV) peer.  

When phase 1 (initiated from LSV peer) (satellite) is already up, phase 2 (initiated from behind central gateway) fails on "invalid ID information".  

QM_PACKET_1 is sent from central gateway to satellite, and satellite replies with QM_PACKET_2 with same IDs, but is rejected by central gateway on "invalid ID information".

## Cause

The system did not receive the expected IDs from the peer (First connection was made by the Central Gateway ...). It had to "guess" which encryption domain is expected by the peer, therefore it used the *vpn_routing* configuration.

As the peer is not a "normal" peer, the system cannot properly calculate the network range and this VPN issue occurs.

The currently implemented changes (provided in the hotfix) constitute a design change on how you obtain the network ranges (IDs) for P2 to an LSV peer that has not initiated a P2 previously for the required ranges (IDs).

The current workaround hotfix, instead of guessing according to the *vpn_routing*, just uses a single IP address (the one trying to communicate), which is what you now see at this moment in the environment.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
