> Source: [sk183130](https://support.checkpoint.com/results/sk/sk183130)

# sk183130 - Site to Site VPN between SMB Appliance and Cisco drops when permanent VPN Tunnel is configured

| Property | Value |
|----------|-------|
| Solution ID | sk183130 |
| Date Created | 2025-02-23 |
| Last Modified | 2025-03-11 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 1500, 1900, 2000, 1600 |

## Symptoms

- A Site to Site VPN tunnel between a Quantum Spark gateway and Cisco fails to establish when permanent VPN Tunnel is enabled on the Quantum Spark gateway.

## Cause

The Quantum Spark gateway uses DPD to check Tunnel health for site to site VPN between SMB and 3rd Party Gateway.  

DPD in IKEv2 goes through Phase2 and it uses the external IP address of the Quantum Spark Gateway. The Cisco gateway does not have the SMB device's external IP address in its encryption domain, so it rejects the negotiation and the tunnel does not establish.

## Solution

There are two possible solutions. The first solution requires cooperation with the administrator of the third-party gateway. The second solution can be implemented by a Quantum Spark administrator independently.  

**Solution 1: Add the Quantum Spark Gateway's External IP Address to the Encryption Domain of the Third Party Gateway** Ask the administrator of the third-party gateway to add the Spark Gateway's External IP address to third-party gateway's encryption domain.  

**Solution 2: On the Quantum Spark Gateway, Disable the Permanent VPN Tunnel with the Third Party Gateway**   

1. Enter the UI of the Quantum Spark Gateway.
2. Open the **VPN**tab.
3. In the **Site to Site** section, go to **VPN Sites**.
4. Edit the VPN site.
5. In the **Advanced** tab, clear the checkbox "**Enable permanent VPN tunnels**".

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
