> Source: [sk167655](https://support.checkpoint.com/results/sk/sk167655)

# sk167655 - NATted VPN traffic dropped for: "According to the policy that packet should not have been decrypted"

| Property | Value |
|----------|-------|
| Solution ID | sk167655 |
| Date Created | 2020-06-29 |
| Last Modified | 2022-05-26 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- NATted VPN traffic is dropped for: "According to the policy that packet should not have been decrypted"

## Cause

**Environment:** Gateway VPN Domain is set to "All IP Addresses behind Gateway are based on Topology information"  

When the VPN domain (encryption domain) is set to "All IP Addresses behind Gateway are based on Topology information", the NAT IP address is not part of the topology, and thus not included in the domain.

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk167655/Capture202007020816062.png)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
