> Source: [sk167902](https://support.checkpoint.com/results/sk/sk167902)

# sk167902 - VPN Tunnel using IKEv2 does not establish when 'NULL' encryption algorithm is used

| Property | Value |
|----------|-------|
| Solution ID | sk167902 |
| Date Created | 2020-07-21 |
| Last Modified | 2021-02-03 |
| Technical Level | General |

## Symptoms

- * VPN Tunnel does not establish when using IKEv2 and NULL as encryption algorithm.  

* 3rd party peers respond with "No proposal chosen" during Child SA creation, NULL is used in the proposal.  

* In *VPND* debugs, see the following when attempting to establish VPN between Check Point Security Gateways:  

  `

  [vpnd ...]@gw1[DATE TIME][ikev2] ikeAuthExchange_r::updateSA: Updating esp sa.`  
  `
  [vpnd ...]@gw1[DATE TIME][ikev2] dbCommunityHandle::getChildSARekey: entering`  
  `
  [vpnd ...]@gw1[DATE TIME][ikev2] childsaKeyingMaterialHandler::updateSa: Sanity check failure. Encryption and decryption keys are identical`  
  `
  [vpnd ...]@gw1[DATE TIME][ikev2] ikeEvent::handled: Event Diffie-Hellman Event could not be handled by exchange 8`  
  `
  [vpnd ...]@gw1[DATE TIME][ikev2] ikeAuthExchange_r::eventTerminated: entering. event: Diffie-Hellman Event.`  
  `
  [vpnd ...]@gw1[DATE TIME][ikev2] ikeDHEvent::~ikeDHEvent: entering. (exchange 8)`  
  `
  [vpnd ...]@gw1[DATE TIME][ikev2] Exchange::setStatus: Changing status from: initial to: failure (final)..`  
  `
  [vpnd ...]@gw1[DATE TIME][ikev2] Exchange::setStatus: Status is already final (failure (final)) and cannot be changed to failure (final)..`

## Cause

There was a code change for FIPS Certification. Check to make sure that encryption and decryption keys are not the same and edge case for when NULL is used as encryption algorithm was left out. Because there are technically no keys to check, the check will fail.

## Solution

This problem was fixed. The fix is included in:

* **[Check Point R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)**
* **[Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 69**
* [**Jumbo Hotfix Accumulator for R80.30**](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152)**starting from Take 228 (for Gaia 3.10)**
* **[Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 215 (for Gaia 2.6.18)**
* **[Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 173**   

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
