> Source: [sk167115](https://support.checkpoint.com/results/sk/sk167115)

# sk167115 - Site-2-Site VPN is not working when using Wire Mode (in at least one community) with SecureXL enabled

| Property | Value |
|----------|-------|
| Solution ID | sk167115 |
| Date Created | 2020-05-28 |
| Last Modified | 2026-07-06 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Site-2-Site VPN is not working when using Wire Mode (in at least one community) with SecureXL enabled.
* Running   
  # fw ctl zdebug + drop   
  on the Security Gateway will show:  
  vpn_route_change_sxl_notification_handler Reason: dynamic VPN routing is not supported
* Kernel debugs show:   
  \[SIM-206054816\];do_routing: do routing calc (last routing calc done 8201 msec ago, dir=s2c);   
  \[SIM-206054816\];do_routing: returning out_ifn eth3;   
  \[SIM-206054816\];prepare_cut_through: route ifn change requires F2F (curr_ifn=10, out_ifn=5, ci_flags=0x2028088), conn: ;   
  \[SIM-206054816\];sim_pkt_send_drop_notification: (0,1) received drop, reason: general reason, conn: ;   
  \[SIM-206054816\];sim_pkt_send_drop_notification: no track is needed for this drop - not sending a notificaion, conn: ;   
  \[SIM-206054816\];sim_mgr_nt_start_ex: type=ntVPNEncRouteChange conn=Empty nt_params_sz=104;   
  \[SIM-206054816\];sim_mgr_host_send_message_start_cb: opcode=37 data_sz=104 hdr_sz=20 total_sz=132 packet=ffff8107bd57a980 t_params=ffffffff80639928 (1,0) target sxl_dev_id=0;   
  \[SIM-206054816\];sim_mgr_host_send_message_start_cb: data=ffff810704c506ec;   
  \[SIM-206054816\];sim_mgr_host_send_message_end_cb: thead=ffff810704c506d0 data=ffff810704c506ec total_len=132 opcode=37 service_id=2;   
  \[fw4_0\];cphwd_multik_handle_message: Handling message asynchronously. packet=0000000000000000 thead=ffff810704c506d0 service=2 opcode=37 instance=1 vsid=0 total_len=132 sxl_dev_id=0;   
  \[SIM-206054816\];handle_cut_through: prepare_cut_through returned !SIMPKT_IN_FORWARD_TO_OUTBOUND (rc=3, valid=1);   
  \[SIM-206054816\];handle_packet_ci: do_cut_through_and_outbound returned !SIMPKT_IN_FORWARD_TO_OUTBOUND (action=3);   
  \[SIM-206054816\];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:;   
  \[fw4_1\];cphwd_handle_vpn_f2f: ffff8107bd57a980;   
  \[fw4_1\];fw_log_drop_ex: Packet proto=6 xx.x.x.x:xx -\> xx.xxx.xx.xx:xxxxx dropped by vpn_route_change_sxl_notification_handler Reason: dynamic VPN routing is not supported;
* This issue may affect gateways that have VPN disabled, as long as they are managed by a management server which has wire mode configured on any of the VPN communities.
* @;748881399.115317;\[kern\];\[tid_0\];\[SIM4\];prepare_cut_through: route ifn change requires P2F (curr_ifn=3, out_ifn=2, ci_flags=0x2018048), conn: \<10.175.134.12,50942,52.112.127.101,443,6\>; @;748881399.115327;\[kern\];\[tid_0\];\[SIM4\];sim_pkt_send_drop_notification: (0,0) received drop, reason: Route ifn changed (6u), conn: \<10.175.134.12,50942,52.112.127.101,443,6\>; @;748881399.115333;\[kern\];\[tid_0\];\[SIM4\];sim_pkt_send_drop_notification: no track is needed for this drop - not sending a notification, conn: \<10.175.134.12,50942,52.112.127.101,443,6\>; @;748881403.115347;\[kern\];\[tid_0\];\[SIM4\];do_packet_finish: SIMPKT_IN_DROP vsid=0, conn:\<10.175.134.12,50942,52.112.127.101,443,6\>; @;731676502.11535;\[vs_0\];\[tid_0\];\[fw4_0\];fw_log_drop_ex: Packet proto=6 10.175.134.12:50942 -\> 52.112.127.101:443 dropped by vpn_route_change_sxl_notification_handler Reason: dynamic VPN routing is not supported;

## Cause

Since Wire Mode is being used in at least one VPN community, re-routing SecureXL is not supported (There is no F2F since R80.20)

## Solution

This problem was fixed. The fix is included in:

* [Check Point R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) - since *Take_87*
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) - since Take_221
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) - since Take_187

Check Point recommends to always upgrade to the most recent version ([Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=downloads&product=435)).

**Related solutions:**

* [sk170133 - Acceleration does not work when using wire mode with SecureXL enabled](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170133)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
