> Source: [sk180985](https://support.checkpoint.com/results/sk/sk180985)

# sk180985 - "You cannot receive an Office Mode IP at this time" when connecting to Maestro Security Gateway Module with Remote Access VPN

| Property | Value |
|----------|-------|
| Solution ID | sk180985 |
| Date Created | 2023-06-13 |
| Last Modified | 2023-06-18 |
| Technical Level | Advanced |
| Products | Security Gateway, Scalable Platforms |
| Versions | R81.10 (EOS), R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * End users fail to connect to resources located behind a Maestro Security Gateway Modeule with Remote Access VPN.
* End users see this error message in the Remote Access VPN Client: "*You cannot receive an Office Mode IP address because the security gateway does not have a license for Office Mode. Contact your administrator.*"
* Maestro Gateway logs show "*IP pool is full. Addresses cannot be allocated.*"

## Cause

When you use the internal pool for Office Mode allocation in Maestro, the Maestro Orchestrator recalculates the original range based on the number of active members. Then, it distributes the IP addressess equally to the members.  

**Example**   
The Office Mode range is *172.16.10.0/24* , so there are 254 valid IP address.  
The Maestro Orchestrator has 2 Security Gateway Modules (SGMs).  
Each SGM receives 127 IP addresses:  

* SGM1 has IP addresses in the range 1*72.16.10.1* -1*72.16.10.127*
* SGM2 has IP addresses in the range *172.16.10.128* -*172.16.10.254*
In this scenario, the first 127 users can connect to SGM1, but the 128th user cannot connect (even though SGM2 has 127 available IP addresses).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
