> Source: [sk120374](https://support.checkpoint.com/results/sk/sk120374)

# sk120374 - When establishing new VPN tunnel, SmartView Tracker  shows "Main Mode completion" message, but vpn tu does not show new IKE SAs

| Property | Value |
|----------|-------|
| Solution ID | sk120374 |
| Date Created | 2017-09-08 |
| Last Modified | 2017-09-10 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * When establishing new VPN tunnel, SmartView Tracker shows messages "Main Mode completion", but vpn tu does not show new IKE SAs
* *VPND* logs contain lines:  
  \[ PID\]\[Date Time\]\[\] find_sa_by_ike_peer: No IKE SA for this IKE peer found  
  .. \[ PID\]\[Date Time\]\[\] TalkToEngine: Engine RC is \<\< FWIKE_ERROR \>\>  
  \[ PID\]\[Date Time\]\[\] TalkToEngine: received Error reply from Engine
* Different VPN tunnels fail randomly.

## Cause

When checked kernel tables used for saving IKE SAs, **found them full**.

Verify as follows:

*#fw tab -t ike2esp -s*

*#fw tab -t ike2peer -s*

**Possible output:**

*localhost ike2esp **459**10200 10200 0*

*localhost ike2peer **461**10200 10200 0*

After kernel table name, there is the kernel table number (459 and 461).

The next column displays the current number of entries in the table, and the next column displays the peak reached value from last reboot.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
