> Source: [sk180935](https://support.checkpoint.com/results/sk/sk180935)

# sk180935 - VPN failure in Centrally Managed Spark Firewall with Management a Server behind "Hide NAT"

| Property | Value |
|----------|-------|
| Solution ID | sk180935 |
| Date Created | 2023-05-02 |
| Last Modified | 2023-05-04 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Symptoms

- Under these conditions:

* There is a site to site VPN configured between a centrally managed Quantum Spark appliance and another internally managed Check Point gateway.

* The Management Server sits behind the peer gateway and has HIDE NAT behind its external interface.

* The Quantum Spark appliance has two ISP connections for redundancy.

When the ISP fails over on the Quantum Spark appliance, the VPN fails due to CRL fetch failure.

## Cause

The Quantum Spark appliance tries to fetch the CRL from the Management Server's "real" IP address instead of the HIDE NAT address.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
