> Source: [sk175092](https://support.checkpoint.com/results/sk/sk175092)

# sk175092 - Packets dropped in Site to Site VPN tunnel with "Failed to resolve VPN MEP gateway" error message

| Property | Value |
|----------|-------|
| Solution ID | sk175092 |
| Date Created | 2021-08-17 |
| Last Modified | 2025-01-06 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Packets are dropped in a Site to Site VPN tunnel with two Multiple Entry Point central Security Gateways. The VPN community includes at least one third-party peer with a fully overlapping encryption domain.
* This error message appears in logs: "`Failed to resolve VPN MEP gateway`".
* The *$FWDIR/log/ikev2.xmll* output file shows many Authentication Exchange failures with "`Authentication Failed`" messages.

## Cause

When the Security Gateway sends dead peer detection messages for Multiple Entry Point resolution, it uses public IP addresses as Traffic Selectors instead of using Universal Traffic Selectors.  
If the Security Gateway sends DPD messages every 10 seconds, the problem may be related to dead peer detection exchanges that were initiated for Multiple Entry Point resolution.  

The error notification is caused by one of these problems:  

Wrong ID payload IP address   
Wrong Traffic Selectors

## Solution

This problem was fixed. The fix is included in:

* [Check point R81.10](https://support.checkpoint.com/results/sk/sk170416) / [Quantum Spark Appliances - Releases R81.10.X](https://support.checkpoint.com/results/sk/sk179615)
* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 51
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 126
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 241

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
