> Source: [sk170137](https://support.checkpoint.com/results/sk/sk170137)

# sk170137 - Endpoint Security VPN fails to connect with "negotiation with site failed" when "Visitor Mode" is disabled via GuiDBedit 

| Property | Value |
|----------|-------|
| Solution ID | sk170137 |
| Date Created | 2020-10-19 |
| Last Modified | 2022-12-26 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Endpoint Security VPN fails to connect with "negotiation with site failed" when "Visitor Mode" is disabled via GuiDBedit (as per [sk107433](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk107433))  
  Note: When the site was originally created, Visitor Mode was enabled.
* `C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Connect\trac.log` from the client shows:  
  **\[tunnel\] CreateNewIkeEvent: I/E: ParseFailed: BadReserved: Bad "Payload Header RESERVED" field value**
* Users are unable to re-create the site, if they delete the current one.

## Cause

Visitor Mode must be enabled. if Visitor Mode is disabled in GuiDBedit, this allows only NAT-T. In such a case, the initial negotiation for creating the site over port 443 (Visitor) Mode is not available. Once you enable Visitor Mode, the clients are able to create the site, as expected. Now they can choose the option to use NAT-T or Visitor Mode. in this order.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
