> Source: [sk119934](https://support.checkpoint.com/results/sk/sk119934)

# sk119934 -  SmartProvisioning VPN with DAIP peer disconnected every time IP address changes

| Property | Value |
|----------|-------|
| Solution ID | sk119934 |
| Date Created | 2017-08-15 |
| Last Modified | 2017-08-16 |
| Technical Level | Advanced |
| Products | Security Management Server |
| Versions | R82.10, R82, R81.20, R82.x, R82.20 |
| OS | Gaia |

## Symptoms

- * IPSec VPN tunnel goes down when the IP address changes on the DAIP peer.
* SmartProvisioning shows the old IP address assigned and indicates that the tunnel is up, even if the tunnel is actually down.
* Push policy brings the IPSec VPN tunnel up until the remote peer is assigned to a different IP address.

## Cause

During phase 1, the gateway records the IP address of the DAIP gateway.

As the gateway is of type SmartProvisioning/LSM, the system updates the IP address in the kernel tables once it receives traffic (ESP / ISAKMP) from the DAIP peer, if the IP address has changed.

If the gateway does not receive any traffic from the DAIP peer, it will use the last IP address known to the gateway.

This is regardless of the "last known IP address" in Smart Provisioning.

Once the IP address changes, if there is no traffic from the DAIP peer, the gateway will not be able to know that the IP address has changed and the tunnel will go down.

A policy push causes the VPNs to restart, which should bring the tunnels back up until the IP address changes.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
