> Source: [sk154692](https://support.checkpoint.com/results/sk/sk154692)

# sk154692 - VPN Encryption Domain Routes are not added to kernel via RIM in VSX environment

| Property | Value |
|----------|-------|
| Solution ID | sk154692 |
| Date Created | 2019-06-07 |
| Last Modified | 2020-02-24 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * VPN Encryption Domain Routes are not added to kernel via RIM in VSX environment.

* When fwaccel and vpn accel off, ESP packets are being sent over a vpn tunnel are being sent to a destination that has a broadcast mac address.

* In Kernel debug (fw ctl debug -m VPN + policy; fw ctl debug -m fw + route drop) similiar errors can be seen:  
  `
  [vpnd] @Hostname[DATE TIME][tunnel] RIM_OS_Worker_handler: RIM Worker thread received 2 new routes to process from vpnd `  
  `
  [vpnd] @Hostname[DATE TIME][tunnel] rm_route_execute: Error adding route 123.123.123.123/255.255.255.255->0.0.0.0. cprti reason: OS API returned error 
  `  
  `[vpnd] @Hostname[DATE TIME][tunnel] rm_route_execute: Error adding route 21.21.21.0/255.255.255.0->0.0.0.0. cprti reason: OS API returned error `

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
