> Source: [sk172926](https://support.checkpoint.com/results/sk/sk172926)

# sk172926 - Traffic stops passing at certain times over the Site to Site VPN between the Check Point Cluster in the High Availability mode and a 3rd party VPN peer

| Property | Value |
|----------|-------|
| Solution ID | sk172926 |
| Date Created | 2021-04-11 |
| Last Modified | 2021-09-12 |
| Technical Level | General |

## Symptoms

- * Traffic stops passing at certain times over the Site to Site VPN between the Check Point Cluster in the High Availability mode and a 3rd party VPN peer

* Site to Site VPN tunnel disconnects during IKEv2 renegotiation between the Check Point ClusterXL in the High Availability mode and a 3rd party VPN peer.

* Traffic capture (or IKE debug) shows that when the 3rd party VPN peer sends the IKE "Child SA" packet, the Check Point ClusterXL responds with the "Invalid SPI" packet.

* Traffic capture (or IKE debug) shows that the Check Point ClusterXL keeps sending the IKE Phase 2 "Child SA" packets with the SPI from the previous IKE negotiation.

* The Site to Site VPN tunnel starts passing traffic again in these cases:

  * After deleting all IPsec+IKE SAs for a given peer on the Check Point ClusterXL in the "`vpn tu`" CLI menu.
  * After waiting for 20-30 minutes (depends on the VPN configuration).

## Cause

The cluster does not delete the IKE SA correctly during the cluster synchronization.

<br />

## Solution

This problem was fixed. The fix is included in:

* [Check Point R81.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170416&partition=Basic&product=All)
* [Check Point R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 119
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 235 (for Gaia 3.10)
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 232 (for Gaia 2.6.18)
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 190

Check Point recommends to always upgrade to the most recent version.  

<br />

<br />

<br />

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
