> Source: [sk161992](https://support.checkpoint.com/results/sk/sk161992)

# sk161992 - Site to site VPN fails on Main Mode packet 1 with the error "IKE (INVALID-EXCHANGE-TYPE)"

| Property | Value |
|----------|-------|
| Solution ID | sk161992 |
| Date Created | 2019-09-03 |
| Last Modified | 2019-09-09 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * Site to site VPN fails on Main Mode packet 1 with the error "IKE (INVALID-EXCHANGE-TYPE)"
* *Ike.elg* shows:   
  Notify Type: 7 (INVALID-EXCHANGE-TYPE)
* *vpnd.elg* shows:   
  \[CPLOG_BIN_OBJ\] CBinObjCommon::PackLogData: Field number:6, Data offset:23, Type:eFtCstring, Value:Main Mode Sent Notification to Peer: Aggressive Mode is not supported

## Cause

Peer gateway configured to use Aggressive mode in phase1, but Check Point Security Gateway is not configured to use Aggressive mode in phase1.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
