> Source: [sk166417](https://support.checkpoint.com/results/sk/sk166417)

# sk166417 - IKEv2 Site to Site VPN instability when the VPN tunnel is narrowed 

| Property | Value |
|----------|-------|
| Solution ID | sk166417 |
| Date Created | 2020-04-20 |
| Last Modified | 2025-04-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * IKEv2 Site-to-Site VPN traffic fails for specific ports between the same source and destination when SecureXL is enabled.

* IKEv2 negotiations are repeated for the same VPN peer.

* Kernel debug logs show that packets are dropped because no Security Association (SA) is found, despite the presence of a valid SA for the subnet.

  The valid SA is formed:  
  `[vs_4];[tid_0];[fw4_0];calc_tunnel_instance: Tunnel Params = peer: x.x.x.x, methods: (Tunnel 3DES MD5), IDs: [xxx.xxx.xxx.xxx/xx]<-->[xxx.xxx.xxx.xxx/xx];`  
  `[vs_4];[tid_0];[fw4_0];calc_tunnel_instance: hash 1628888145, instance 0/1;`  
  `[vs_4];[tid_0];[fw4_0];create_new_MSA: MSA for IPsec, will belong to instance 0;`  
  `[vs_4];[tid_0];[fw4_0];create_mspi: --- NEW MSPI === xxx (i: 0) (generated in 1 iteration(s));`  

  The SA is not found due to the narrowing of selectors. You will see the narrowed IP range/host IP:  
  `[kern];[tid_0];[SIM-204537923];vpn_ipsec_encrypt: packet needs to be encrypted with mspi xxx;`  
  `[kern];[tid_0];[SIM-204537923];sim_db_get_any_sa: searching sa xxx in table xx;`  
  `[kern];[tid_0];[SIM-204537923];sim_db_get_any_sa: failed to find SA, tab id xx, ret_val -1;`  
  `[kern];[tid_0];[SIM-204537923];vpn_send_outbound_sa_notification: no outbound SA found! mspi=xxx;`  
  `[kern];[tid_0];[SIM-204537923];sim_mgr_nt_start_ex: type=ntNoOutboundSA conn=Empty nt_params_sz=4;`  
  `...`  
  `[kern];[tid_0];[SIM-204537923];vpn_encrypt: vpn_ipsec_encrypt returns 3;`  
  `[kern];[tid_0];[SIM-204537923];sim (vpn_encrypt): drop due vpn_ipsec_encrypt returns `
* The output of "`vpn tu tlist`" command shows the following indication for narrowing:   

  * If there is narrowing and the local gateway is the initiator, you see the text: `* * * Eclipsed * * *`
  * If narrowing occurred and the local gateway is the responder, you see the text:` * * * Narrow * * *`

  <br />

* When the initiator of the negotiation requests Traffic Selectors (TS) that is wider than the one the responder is willing to accept, the responder replies with a narrowed range. The final TS is set to the narrowed range. In this case we can see in IKEView difference in TSi/TSr between the request and response messages.
  If the initiator offers a narrow TS than the one configured on the responder, the TS is also set to this narrowed range. In this case narrowing is not visible in IKEView.

## Cause

Tunnel narrowing is an IKEv2 feature where one side reduces the proposed Traffic Selectors (encryption domains) to a more limited range.  

The Firewall kernel instance responsible for the tunnel traps the VPN daemon to generate an IPsec SA. If narrowing occurs during IKE negotiation, the system may assign the SA to a different Firewall kernel instance. This change in instance can cause packet drops because the original instance does not recognize the SA.  

Additionally, SecureXL may fail to locate the required encryption keys due to the narrowed selectors, resulting in dropped packets. In such cases, the Firewall traps the VPN daemon to renegotiate the tunnel. The outbound SA message is sent by SecureXL.  

Common causes of tunnel narrowing include:

* Overlapping encryption domains between different Security Gateways managed by the same Security Management Server.
* Configuration mismatches between VPN peers.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
