> Source: [sk121736](https://support.checkpoint.com/results/sk/sk121736)

# sk121736 - Gateway sends DPD to client during phase 1 negotiation, resulting in "Negotiation with site failed" error for Remote Access Client trying to connect to an R80.xx Security Gateway

| Property | Value |
|----------|-------|
| Solution ID | sk121736 |
| Date Created | 2017-12-08 |
| Last Modified | 2020-05-26 |
| Technical Level | Advanced |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * Remote access clients are unable to connect to an R80.10 Security Gateway.
* "`Negotiation with site failed`" error message when trying to create a site.
* The following lines appear in the client logs:   
  `"payloads_count: FAILED: Extra payloads left in packet (found 1 Vendor ID's)"`  
  `
  [PID][DATE TIME][IKE] payloads_count: A Identification payload (total 1)`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: A Certificate payload (total 1)`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: A Certificate payload (total 2)`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: A Signature payload (total 1)`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: A Vendor ID payload (total 1)`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: Found 1 payloads of type Identification, need one exactly`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: Found 2 payloads of type Certificate, need one or more`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: Found 1 payloads of type Signature, need one exactly`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: Found 0 payloads of type Notification, need zero or one exactly`  
  `
  [PID][DATE TIME][IKE][IKE] payloads_count: FAILED: Extra payloads left in packet (found 1 Vendor ID's)`  
  `
  [PID][DATE TIME][IKE][IKE] MM6PacketHandler: Packet parse failed (expecting 1 ID, 1-2 certs, 1 sig)`  
  `
  [PID][DATE TIME][IKE][IKE] send_notification: NOT IMPLEMENTED YET`  
  `
  [PID][DATE TIME][IKE][negs] [WARNING] [Negotiation::process_event] (0x04967710): *** Negotiation failed! ***`
* On the Security Gateway's *$FWDIR/log/vpnd.elg* file, in the relevant negotiation, the following line appears:  
  `MMCreate6: send_dpd_vendor_id=1, force_send_dpd_payload=1, received_dpd_vendor_id=0, sent_dpd_vendor_id=0`
* ***forceSendDPDPayload*** is enabled on the Security Gateway. This can be checked by running the command:  
  *ckp_regedit -p SOFTWARE\\\\CheckPoint\\\\VPN1 \| grep forceSendDPDPayload*

## Cause

When ***forceSendDPDPayload*** is configured in the registry, the Security Gateway sends an extra payload inside the negotiation. The client does not expect this payload and the negotiation fails.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
