> Source: [sk170873](https://support.checkpoint.com/results/sk/sk170873)

# sk170873 - S2S VPN traffic from Standby  Cluster member to a server does not work after R80.40 upgrade

| Property | Value |
|----------|-------|
| Solution ID | sk170873 |
| Date Created | 2020-12-16 |
| Last Modified | 2021-04-05 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * S2S VPN traffic from Standby Cluster member to a server does not work after R80.40 upgrade.
* Drop logs observed on Active Cluster member:  
  dropped by vpn_encrypt_chain Reason: illegal interface group;

## Cause

Standby Cluster member originates the traffic with the Physical IP address and not with the VIP address as was done in previous versions and this caused the VPN drop.  
The problem occurs with local connections over S2S VPN. With clear traffic, it works OK.

<br />

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).  

This problem was fixed. The fix is included since:

* **R80.40 JHA take 91**

Check Point recommends to always upgrade to the [most recent version.](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456&partition=Basic&product=All)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
