> Source: [sk180716](https://support.checkpoint.com/results/sk/sk180716)

# sk180716 - After enabling 'Exclude gateway's external IP addresses from the VPN Domain' VPN Tunnel is down

| Property | Value |
|----------|-------|
| Solution ID | sk180716 |
| Date Created | 2023-03-29 |
| Last Modified | 2023-03-29 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20 |

## Symptoms

- * In SmartConsole \> Security Gateway object \> **Network Management** \> **VPN Domain** , users enable **Exclude gateway's external IP addresses from the VPN Domain** . Then, SmartView Monitor shows Permanent Tunnel state is **Down**, but traffic passes over the VPN tunnel as expected.
* Firewall log shows that the VPN Peer Gateways send `tunnel_test` packets over UDP port `18234` in clear text, and not over the VPN tunnel.

## Cause

When the Permanent Tunnel feature is enabled for a VPN Community, a Security Gateway uses a Check Point proprietary protocol by default to test if VPN tunnels are active. The gateway periodically sends "tunnel test" packets over the VPN tunnel to monitor the status of the tunnel. If the gateway receives responses to the "tunnel test" packets, it keeps the VPN tunnel open. If the gateway does not receive a response within a given time period, it closes the VPN tunnel.

<br />

## Solution

If you create a Permanent Tunnel between Check Point Security Gateways, do not enable this feature **Exclude gateway's external IP addresses from the VPN Domain.** To use this feature for a VPN Tunnel between a Check Point Security Gateway and a third-party Gateway, see [sk108600](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108600 " VPN Site-to-Site with 3rd party").  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180716/exclude_gw_ip202303131100391.png)

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
