> Source: [sk160172](https://support.checkpoint.com/results/sk/sk160172)

# sk160172 - Endpoint Security VPN displays "Connection to Check Point Server lost" when using "Youku"  (AliProtect) Application

| Property | Value |
|----------|-------|
| Solution ID | sk160172 |
| Date Created | 2019-08-11 |
| Last Modified | 2021-02-18 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * Endpoint Security VPN Client displays: **"Connection to Check Point Server lost"**
* Endpoint Security VPN Client displays: **"Connectivity with the VPN services is lost"**
* The following error is found in *Trac.log* :  
  \[ 4240 9132\]\[7 May 12:20:11\]\[TR_FEATURE_MANAGER\] TrFeatureManager::Init: mOfficeModeEnable=true,mSplitDnsEnable=false,mLocationAwarenessEnable=true,mAlwaysConnectEnable=true,mRoamingEnable=true,mHotspotDetectionEnable=true,mFirewallEnable=true,mScvEnable=true  
  \[ 4240 9132\]\[7 May 12:20:11\]\[TR_FIREWALL\] CFirewallWrapper::InitFirewallMonitor: entering...  
  \[ 4240 9132\]\[7 May 12:20:11\]\[TR_FIREWALL\] CFirewallWrapper::InitFirewallMonitor: loading library: C:\\WINDOWS\\system32\\FirewallMonitor.dll  
  \[ 4240 9132\]\[7 May 12:20:12\]\[TR_FIREWALL\] CFirewallWrapper::InitFirewallMonitor: lpFwMonitor_initLibrary returned true  
  \[ 4240 9132\]\[7 May 12:20:12\]\[TR_FIREWALL\] CFirewallWrapper::InitFirewallMonitor: **ERROR - lpFwMonitor_Start failed**   
  \[ 4240 9132\]\[7 May 12:20:12\]\[TR_FIREWALL\] CFirewallWrapper::FreeFirewallMonitor: entering...  
  \[ 4240 9132\]\[7 May 12:20:12\]\[TR_FIREWALL\] CFirewallWrapper::FreeFirewallMonitor: calling lpFwMonitor_Stop  
  \[ 4240 9132\]\[7 May 12:20:12\]\[TR_OVERSITE\] critical error: fail to InitFirewallMonitor, going down  
* Application is not able to recover. Even if the application is repaired, the services are stopped and restarted. You can see the below log message on the client machine:  
  \[ 13084 1408\]\[7 May 12:21:10\]\[tcpserver\] TcpMultiPipe::pipe_socket_connect: \[SEVERE\]: Failed to connect to 0x0100007f on **tcp port 7778: Connection refused**

## Cause

The Endpoint Security VPN is unable to load *FirewallMonitor.dll* , which causes the VPN service to shutdown. *FirewallMonitor.dll* is needed to communicate with the FW feature of the VPN client.

In the client machine, under *C:\\Windows\\INF\\ location* file "setupapi.dev.log" logs:

*\>\>\> \[Device Install (UpdateDriverForPlugAndPlayDevices) - cp_apvna\]*

*\>\>\> Section start 2018/12/21 12:06:54.720 cmd: vna_install64.exe install "C:\\Program Files (x86)\\CheckPoint\\Endpoint Connect\\netvna.inf" cp_apvna*

*vi: {DIF_REGISTER_COINSTALLERS - exit(0x00000000)} 12:06:55.239*   
*dvi: {DIF_INSTALLINTERFACES} 12:06:55.241*   
*!!! dvi: Loading module 'C:\\Windows\\system32\\vnaap_coinstall.dll' failed.*   
*!!! dvi: Error 193: %1 is not a valid Win32 application.*   
*!!! dvi: Error 193 loading CoInstaller(vnaap_coinstall.dll, _vna_co_installer@16)*   
*!!! dvi: Error 193: %1 is not a valid Win32 application.*   
*dvi: Default installer: Enter 12:06:55.251*   
*dvi: Default installer: Exit*

## Solution

**This is an expected behavior with Endpoint Security VPN when "Youku" Application is also installed on the same machine.**

The Endpoint Security Client can be installed in 3 different flavors:

* Basic (SecuRemote) that has only VPN capabilities.
* Mobile Client that also has Compliance.
* Endpoint Security VPN that also has a Firewall driver and other FW-related components.

During installation, you can choose one of these three flavors.

After testing the above clients, only Endpoint Security VPN is affected.

**As a workaround, either "SecuRemote" or "Check Point Mobile for Windows" can be used.**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
