> Source: [sk126092](https://support.checkpoint.com/results/sk/sk126092)

# sk126092 - VPN tunnel cannot be established: IKE connection fails

| Property | Value |
|----------|-------|
| Solution ID | sk126092 |
| Date Created | 2018-05-04 |
| Last Modified | 2021-12-27 |
| Technical Level | Advanced |

## Symptoms

- * VPN tunnel cannot be established, the negotiation fails on Main Mode packet 5-6 with "`INVALID-COOKIE`" error message.  

* The `ike.elg` file shows "`Cert Certificate Revocation List (CRL)`" on packet 5-6:

  ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk126092/m11808160706.png)

## Cause

Some of the IKE packets are not reaching the destination, due to the fact that CRL over IKE is being used.

**CRL over IKE:** one of the payloads of the 5th and 6th packet is the actual CRL list with the revoked certificates, causing the packet to be large. The Gateway needs to fragment it. In environments with a loosy internet line, not all the packets arrive (could be ISP/MTU/routing issues) and the CRL validation will fail because not all the packets arrive.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
