> Source: [sk180270](https://support.checkpoint.com/results/sk/sk180270)

# sk180270 - Scalable Platform Gateway drops VPN traffic for "decryption failure"

| Property | Value |
|----------|-------|
| Solution ID | sk180270 |
| Date Created | 2022-11-13 |
| Last Modified | 2026-01-25 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R81.20, R81.10 (EOS), R81.20, R81.10 (EOS) |
| Platform | 6, 41000 (EOL), 44000, 64000, Maestro Orchestrator |

## Symptoms

- * Scalable Platform Gateway drops VPN traffic. Site-to-Site VPN sees the returned encrypted traffic dropped for the reason "`Decryption Failed`".

* Remote Access VPN client disconnects after 20 seconds.

* Phase 1 / Parent negotiation is completed on one Security Gateway Member (SGM), but then phase 2 / Child SA is corrected to another SGM. Then the first SGM drops the encrypted traffic.

## Cause

The Remote Access client disconnects because all encrypted traffic is dropped on the Security Gateway while encrypted for "`Decryption Failed. : Could not get SAs from packet`". This causes the tunnel test traffic to fail, which in turn causes the client to disconnect.  

The Site-to-Site VPN establishes the tunnel correctly. Then traffic is encrypted across the VPN. The peer decrypts the traffic, and they reply with the encrypted traffic. The encrypted traffic arrives at the Security Gateway, but is dropped for "`Decryption Failed`".  

When debugging the issue, you see that Phase 1 / Parent SA is comple on one SGM. Then when Phase 2 / Child SA is sent to the Security Gateway, the negotiation is corrected to a different SGM. This is caused by the negotiation switching to NAT-T, and then seen as a new connection and corrected to another SGM. Then when the encrypted NAT-T packets arrive on the original SGM, they are dropped.

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
