> Source: [sk177823](https://support.checkpoint.com/results/sk/sk177823)

# sk177823 - VPN uses NAT-T after installing a Jumbo Hotfix Accumulator or an upgrade to R81.10 or higher

| Property | Value |
|----------|-------|
| Solution ID | sk177823 |
| Date Created | 2022-02-16 |
| Last Modified | 2025-08-26 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * VPN Tunnel uses NAT-T traffic on the UDP port 4500 when the Security Gateway is the initiator and NAT is detected.

* This change started automatically after installing a Jumbo Hotfix Accumulator or after an upgrade to R81.10 or higher.

* Before installing a Jumbo Hotfix Accumulator or upgrade to R81.10 or higher, VPN Tunnel used the UDP port 500.

## Cause

A behavior change was introduced in the Jumbo Hotfix Accumulators. It changed how the VPN is established if there is a NAT device between a Check Point Security Gateway and its VPN peer.

This new behavior is enabled by default. For more information about the parameter "*offer_nat_t_initator* ", refer to [sk32664](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk32664).

Versions and the Jumbo Hotfix Accumulators that include this change:

* R81.10 and higher
* [R81 Jumbo Hotfix](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) - from Take 34
* [R80.40 Jumbo Hotfix](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) - from Take 119
* [R80.30 Jumbo Hotfix](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm) - from Take 237

Behavior of a Check Point Security Gateway:

|--------------------------------------------------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------|------------------------------------------------------------------------------------------------------------------|
|                                                                                            | Check Point Security Gateway is the initiator of a VPN tunnel                                                                 | Check Point Security Gateway is the responder to a VPN tunnel                                                    |
| Before installing the Version / Jumbo Hotfix Accumulator that contains the behavior change | Check Point Security Gateway does **not** report that it supports NAT-T. Therefore, the NAT-T UDP on port 4500 is never used. | If a VPN peer indicates it supports NAT-T, then the Check Point Security Gateway reports that it supports NAT-T. |
| After installing the Version / Jumbo Hotfix Accumulator that contains the behavior change  | Check Point Security Gateway **reports** that it supports NAT-T.                                                              | If a VPN peer indicates it supports NAT-T, then the Check Point Security Gateway reports that it supports NAT-T. |

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
