> Source: [sk164861](https://support.checkpoint.com/results/sk/sk164861)

# sk164861 - Inbound connection fails to Endpoint Security VPN client

| Property | Value |
|----------|-------|
| Solution ID | sk164861 |
| Date Created | 2020-01-24 |
| Last Modified | 2020-02-25 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- * Inbound connection fails to Endpoint Security VPN client.
* Firewall logs show "encrypt" log for this traffic and it was accepted by the Remote Access gateway. "fw monitor" output shows the traffic is encrypted and sent out the link.
* *trac.log* on the client-side, shows that the packet was received on the Remote Access client and injected to the VNA.
* Services affected include, but are not limited to: remote desktop connection to Remote Access client, remote desktop support services such as Dameware MRC, or Avaya One-X VOIP H323 client software, when server is configured as "near end establishes tcp signaling socket = Y".
* Issue may occur following an upgrade, if "Desktop Security" policy is not installed post-upgrade.

## Cause

By default, Endpoint Security clients will drop incoming connections toward the Remote Access client.

Without a desktop security policy installed, Endpoint Security clients may show on the firewall tab, that the Firewall is "Off", but still the implicit drop for inbound connections will still apply.

Desktop Security policy must be configured and installed on the Remote Access gateway to allow these connections.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
