> Source: [sk183037](https://support.checkpoint.com/results/sk/sk183037)

# sk183037 - Remote Access VPN randomly disconnects after successful authentication in Spark Firewall

| Property | Value |
|----------|-------|
| Solution ID | sk183037 |
| Date Created | 2025-02-09 |
| Last Modified | 2025-02-19 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1575R, 1500, 1900, 2000, 1600, 1800, 1595R |

## Symptoms

- * The Remote Access VPN client disconnects randomly 10 seconds after successful authentication.

* SmartLog displays tunnel_testing traffic dropped with the message "*Rulebase Internal Error.*"

* Kernel debug logs show the following entry:

  ```
  
  @;147606591;24Oct2024 18:15:47.100473;[cpu_2];[fw4_2];fw_log_drop_ex: Packet proto=17 : -> :18234 dropped by fw_send_log_drop Reason: Rulebase drop - NO MATCH;
  ```

## Cause

* Starting from R81.10.10, the Identity Awareness Nested Groups search feature (Auto-Tune) is disabled by default.

* This change prevents issues described in [sk180664 - Remote Access users unable to connect and high IKED daemon CPU utilization](https://support.checkpoint.com/results/sk/sk180664).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
