> Source: [sk177425](https://support.checkpoint.com/results/sk/sk177425)

# sk177425 - When NAT traversal support is checked, IKE negotiations fail, and when disabled, negotiations are successful

| Property | Value |
|----------|-------|
| Solution ID | sk177425 |
| Date Created | 2022-02-07 |
| Last Modified | 2022-03-21 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * Site to site tunnel issues, after upgrading to R80.40 take 125/131.
* In debugs, gateway sends MM packet 5 to peer, but does not get any response.
* On peer side, MM5 packet does not arrive, and therefore peer is irresponsive after MM4 packet.
* Disabling Nat traversal support brings the tunnel up.

## Cause

When Phase 1 is initiated by the impacted device, and Nat traversal is enabled on the device, it switches traffic from port 500 to port 4500 for MM5 packet, even when there is not NAT device after the gateway. Therefore, peer does not receive MM5 packet, which renders the peer as irresponsive. In this case, the peer is unable to process traffic, and thus causes the issue.  

When NAT traversal is enabled:  
![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1642351659089/Support nat-t202201170033323.png)  

The same gateways send packet over 4500 port:  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1642351659089/Negotiations enabled nat-t202201170048015.png)  

When NAT-t is disabled, gateway sends the traffic over through port 500 and successfully negotiates with the peer:  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1642351659089/disabled NAt-t202201170049346.png)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
