> Source: [sk151052](https://support.checkpoint.com/results/sk/sk151052)

# sk151052 - Configuring VPN S2S with Encryption Domain based routing table, causes various issues on SMB appliances

| Property | Value |
|----------|-------|
| Solution ID | sk151052 |
| Date Created | 2019-04-16 |
| Last Modified | 2021-08-11 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 910 |

## Symptoms

- Configuring VPN S2S with Encryption Domain based routing table, causes the following issues:

* Tunnel is up in VPN S2S but, traffic does not pass over the VPN tunnel
* "vpn_inbound_tagging_ex Reason: Dynamic VTI configuration is not ready or bad.;" output for \<code\>fw ctl zdebug + drop\</code\> command, when initiating traffic from the site or when receiving traffic from other site over VPN

**Notes:**

1. The issue occurs only on the following firmware versions:

* All builds of R77.20.85
* All builds of R77.20.86 until build 990172852 (including)
* All builds of R77.20.87 until build 990172917 (including)

2. Regarding the first symptom, the tunnel is up only if the other side doesn't run on the mentioned firmware versions.

## Solution

This problem was fixed. The fix is included in:

* **[Check Point R77.20.87](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk151574&partition=General&product=Small "Check Point R77.20.87")**

Check Point recommends to always upgrade to the most recent version ([Check Point 700 appliance](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&product=460 "Check Point 700 appliance") / [Check Point 910 appliance](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&product=500 "Check Point 910 appliance") / [Check Point 1400 appliance](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&product=490 "Check Point 1400 appliance"))

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
