> Source: [sk182942](https://support.checkpoint.com/results/sk/sk182942)

# sk182942 - Site-to-Site VPN with a Dynamically Assigned IP (DAIP) Security Gateway fails to connect

| Property | Value |
|----------|-------|
| Solution ID | sk182942 |
| Date Created | 2024-12-19 |
| Last Modified | 2026-01-21 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * VPN Site-to-Site with a certificate works fine with a peer Gateway when it has a fixed IP address. The VPN fails after changing the peer Gateway fixed IP address to DAIP.

* The IPSec VPN Link Selection is set to use DNS to resolve the peer Gateway.

* In the *$FWDIR/log/legacy_ike.elg* file, you can see only the first Main Mode negotiation packet sent to the DAIP peer.  

  In the *$FWDIR/log/ike.elg* file, you can only see an IKE packet that is received from the DAIP VPN peer.  

  In the *$FWDIR/log/vpnd.elg* file, you can see that the Security Gateway sent the first outbound main mode negotiation packet.

* In the *$FWDIR/log/vpnd.elg* file, you can see this log:  

  `
  [vpnd PID]@Hostname[DATE TIME][tunnel] Transmitter::ResolvePeer: resolve - <real peer Gateway IP address>, peer - <0.0.0.X IP Address>`

## Cause

When the Check Point Security Gateway initiates a VPN tunnel to the DAIP peer Gateway, the VPND process initiates the negotiation because the peer is identified with an Unusual ID Type (0.0.0.X) instead of the regular IPv4 address. The IKED process handles the incoming packet from the VPN peer, and the negotiation fails.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
