> Source: [sk180917](https://support.checkpoint.com/results/sk/sk180917)

# sk180917 - Site to Site VPN forms on port 30500 instead of 500/4500

| Property | Value |
|----------|-------|
| Solution ID | sk180917 |
| Date Created | 2023-04-26 |
| Last Modified | 2024-05-16 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Site to Site VPN forms on port 30500 instead of 500/4500
* Cluster gateway involved with the VPN tunnel

## Cause

Due to an object look up issue when referencing the Peer in vpn_routing kernel table,  
The cluster may believe the cluster is a DIAP or a mobile device when referencing the Management interface of the cluster if the interface was defined as "private" instead of a Cluster Interface without a VIP IP address.   

When this happens, The VPN tunnel is handled by IKED instead of VPND, causing the source port to be 30500.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
