> Source: [sk172184](https://support.checkpoint.com/results/sk/sk172184)

# sk172184 - Remote Access client behind NAT disconnects after 20 seconds in Visitor Mode

| Property | Value |
|----------|-------|
| Solution ID | sk172184 |
| Date Created | 2021-02-22 |
| Last Modified | 2021-02-24 |
| Technical Level | General |

## Symptoms

- * Remote Client connections in Visitor Mode disconnect after twenty seconds while connections with NAT-T remain connected.
* The user's local network overlaps with a network within the Encryption Domain.

## Cause

When a new Remote Access Visitor Mode tunnel establishes, we offload the SA to PPAK.  

In the SA offload procedure, we look for routing information from the kernel table orig_route_params.  

At this point, we do not have the routing information so we set default values on the SA to offload to PPAK. One of these default fields is localnet.  

When we decrypt the first packet, we send the udp update notification. When FW receives this notification, we update the orig_route_params with the correct information. We don't update the localnet field with the gateway's correct IP.  

When PPAK encrypts the reply, an incorrect IP of the gateway is set as the source of the packet. The packet sent to the Client (after VM encapsulation) drops with the incorrect source IP.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).  

This problem was fixed. The fix is included in:

* **[R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk160736&partition=Basic&product=All) Take 78**

Check Point recommends to always upgrade to the most recent version ([upgrade Security Gateway](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=435) / [upgrade Security Management Server](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=184) / [upgrade Multi-Domain Security Management](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=166)).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
