> Source: [sk164933](https://support.checkpoint.com/results/sk/sk164933)

# sk164933 - Permanent VPN Tunnel between DAIP Gateway and Check Point Security Gateway reported as 'Down' although it is really 'Up'

| Property | Value |
|----------|-------|
| Solution ID | sk164933 |
| Date Created | 2020-01-29 |
| Last Modified | 2021-11-29 |
| Technical Level | General |
| OS | Gaia |

## Symptoms

- * Permanent VPN Tunnel between DAIP Gateway and Check Point Security Gateway R80.20 /R80.30 reported as 'Down', although it is really 'Up'
* Working Tunnel test packet's Source and Destination addresses change as they go through the kernel chains, but they are changed back to the original addresses when they leave the gateway.  

  Non-working Tunnel test packets do not switch back to the original addresses.
* When the Source and Destination addresses are not switched back to the original addresses, the request and response are handled in different cores.
* Drop is seen as due to "According to the policy the packet should not have been decrypted".

## Cause

Tunnel test requests and replies handled in different instances.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 48 **- additional fixes**
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 38
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 215
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 173

<br />

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Note:** If the peer gateway of the DAIP is R80.10 or below, the cause is due to the external interface not being included in the encryption domain. Refer to [sk103565](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk103565&partition=Advanced&product=IPSec)

[](https://www.checkpoint.com/support-services/contact-support/)  
As a workaround, run the following commands to move the tunnel test to kernel:  
*#fw ctl set int tunnel_test_do_in_kernel 1*   
*#fw fetch local
\*If it's a cluster, make sure to execute the commands on both cluster members.*

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
