> Source: [sk166656](https://support.checkpoint.com/results/sk/sk166656)

# sk166656 - VPN traffic fails when SecureXL is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk166656 |
| Date Created | 2020-05-04 |
| Last Modified | 2020-05-05 |
| Technical Level | Advanced |

## Symptoms

- * VPN traffic fails when SecureXL is enabled

* Running Kernel + fwaccel debug is showing valid VPN traffic address spoofing drops;  
  `
  [SIM-204807847];do_inbound: possible spoof violation for `(in_ifn 4 cdir 1 *vti_ifn -1 crypto_flags 0x2);  
  [SIM-204807847];sim_validate_address: ifn: 4, conn: , ttl: 63;  
  [SIM-204807847];sim_validate_address: vsid=0, valid_addrs_table_id=20;  
  [SIM-204807847];sim_validate_address: Matching range wasn't found, IP address is invalid for eth6;  
  [SIM-204807847];handle_spoofed_suspect: IP address x.x.x.x is invalid for interface eth6 -> DROP;  
  [SIM-204807847];sim_pkt_send_drop_notification: (0,0) received drop, reason: spoofed address, conn: ;

## Cause

A Security Gateway managed by the Security Management Server has the source IP of the packet in an interface's topology.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
