> Source: [sk156172](https://support.checkpoint.com/results/sk/sk156172)

# sk156172 - Remote Access client fails to connect with "Negotiation with site failed" error message

| Property | Value |
|----------|-------|
| Solution ID | sk156172 |
| Date Created | 2019-06-18 |
| Last Modified | 2019-10-24 |
| Technical Level | Advanced |

## Symptoms

- * Remote Access client fails to connect with the error in the GUI showing:   
  "Negotiation with site failed"
* The following error will appear in the *client trac.log* :   
  "\[tunnel\] IkeTunnel::connection_failed: IKE connection failed, error code=-1000. Reason: Negotiation with site failed."
* vpnd.elg will show the following error:   
  "send_data_to_client: sending CCC show_message_text to client: There is no Mobile Access license, please contact you administrator for more info"
* *IKE.elg* shows that the client is trying to connect using TCPT ("Transport: TCPT")
* All of the above symptoms should appear together for the solution in this sk to be relevant.

## Cause

NAT-T is not enabled. NAT-T is necessary for Remote Access Clients to function properly.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
