> Source: [sk141112](https://support.checkpoint.com/results/sk/sk141112)

# sk141112 - When using IKEv2 Branch Office/Ruggedized appliance initiates tunnel with KEY_ID instead of IPv4_ADDR with 3rd party peers

| Property | Value |
|----------|-------|
| Solution ID | sk141112 |
| Date Created | 2018-11-26 |
| Last Modified | 2019-09-24 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 20, 400, 110 |

## Symptoms

- * Negotiations of Branch Office/Ruggedized appliances with 3rd party devices fail for "Authentication Failed" response from the peer when using PSK authentication method.
* During the IKEv2 negotiation , it is visible that the appliance is using Type of KEY_ID rather than IPV4_ADDR under Authentication phase over the ikev2.xmll file.

## Cause

As a new feature from R77.20.60 and above, is when Gaia embedded appliance initiate the connection using IKEv2 with 3rd party device using PSK authentication method, during the authentication phase the Gateway will send ID of type "KEY_ID" (which can be a string of the Gateway name or IP address) rather than "IPV4_ADDR" which was used in the past.

Existing tunnels with 3rd party vendors may fail due to authentication failure between the peers, as the peer expects IPv4 as data, however it receives the KEY_ID and does not recognize it.

The new behavior could be observed over the IKEv2.xmll file -\> Authentication phase -\> IDi:

**New Behavior:**

Critical: No

Data: fw-test-conn

Length: 21

Next payload: Auth

Type: KEY_ID

**Old Behavior:**

Critical: No

Data: 172.30.38.14

Length: 12

Next payload: Auth

Type: IPV4_ADDR

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
