> Source: [sk165176](https://support.checkpoint.com/results/sk/sk165176)

# sk165176 - Implied rules are not enforced on DAIP gateway after an IP address change or a reboot 

| Property | Value |
|----------|-------|
| Solution ID | sk165176 |
| Date Created | 2020-02-13 |
| Last Modified | 2020-11-11 |
| Technical Level | Advanced |

## Symptoms

- * Implied rules are not enforced on DAIP gateway after an IP address change, or a reboot.  
* VPN Kernel debugs will show the lines:  
  **fw_match_implied_rules: Match implied rules returned NO MATCH;**   
  and  
  **vpn_inbound_tagging_ex: fw_match_implied_rules returned 0;**   
* IKE (port 500) traffic will be dropped with the error:  
  **dropped by vpn_drop_and_log Reason: Clear text packet should be encrypted;**   
* If DPD is configured, the following lines will be seen in the *vpnd.elg* debug from the DAIP side.  
  **fw_kbuf_get_multik(instance: 0): ioctl(FWKBUF): Bad address**   
  **find_sa_by_ike_peer: Error fetching IKE SA from kbuf**   
  **\[tunnel\] send_dpd_notification_IKEv1: no IKE phase1 SA**   
  **\[tunnel\] send_dpd_notification_IKEv1: deleting outbound SAs for 3rd party gw**   
* The issue is not relevant if the DAIP gateway is an SMB device.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
