> Source: [sk184211](https://support.checkpoint.com/results/sk/sk184211)

# sk184211 - VPN MEP failover does not work with FortiGate firewalls

| Property | Value |
|----------|-------|
| Solution ID | sk184211 |
| Date Created | 2025-10-22 |
| Last Modified | 2025-10-26 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * The primary Site-to-Site VPN tunnel to FortiGate firewalls establishes successfully, but failover to the secondary tunnel does not work. Multiple Entry Point (MEP) does not recognize the standby tunnel after the primary tunnel fails.

* After failover, traffic does not switch to the secondary tunnel. Failback to the primary tunnel also fails.

* SmartConsole logs show:  

  `Failed to resolve VPN MEP gateway`

* Only one tunnel is visible and operational at a time.

* When using MEP, only a subset of networks work unless FortiGate encryption domains are set to "all/any".

## Cause

This issue is caused by interoperability limitations between Check Point's Multiple Entry Point (MEP) and FortiGate's restrictive Phase 2 selectors. When FortiGate defines specific networks in its encryption domain, MEP cannot resolve and failover between tunnels. Using both IKEv1 and IKEv2 may lead to inconsistencies if peer devices do not support fallback negotiation.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
