> Source: [sk143372](https://support.checkpoint.com/results/sk/sk143372)

# sk143372 - R80.20 Security gateway drops IKE traffic when NAT-T enforced

| Property | Value |
|----------|-------|
| Solution ID | sk143372 |
| Date Created | 2018-12-25 |
| Last Modified | 2019-12-15 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * Security Gateway drops IKE traffic when NAT-T is enforced.
* VPN debugs on the Central Gateway shows that VPN tunnel negotiation stopped on Main Mode packet 4 (waiting on packet 5 to be sent by the Remote Gateway).
* On the other hand, VPN debugs from the remote peer show Main Mode packet 5 has been sent to the Central Gateway.
* Central Gateway drops the traffic sent by the Remote Gateway due to: "dropped by fwfrag_expires Reason: timeout has expired for fragment;"
* *tcpdump* on the Central Gateway shows that the Central Gateway received all fragmented packets.

## Cause

The remote peer sent the Main Mode packet 5 with a large certificate, so it has to fragment the packet. The R80.20 peer received the packets. However, it does not proccess any packet that is smaller than 240 KB.

The gateway action was to drop fragments smaller than 240 KB (which were not the last fragment).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
