> Source: [sk185144](https://support.checkpoint.com/results/sk/sk185144)

# sk185144 - Capsule Connect Remote Access VPN Traffic Drops with Secure Configuration Verification Error

| Property | Value |
|----------|-------|
| Solution ID | sk185144 |
| Date Created | 2026-08-03 |
| Last Modified | 2026-09-10 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * Users connect with Capsule Connect on iOS and Android through Remote Access Virtual Private Network (VPN) over Internet Protocol Security (IPsec).
* Users cannot access internal resources after the VPN connection is established.
* Users receive the error message: `Client's configuration is not verified`
* The deployment uses Remote Access VPN over IPsec only. The Mobile Access blade is not enabled.
* In SmartConsole, the **Do not apply SCV for Capsule VPN/Connect** option is selected.
* The $FWDIR/conf/local.scv file contains:  
  `:allow_non_scv_clients (true)` `Despite this configuration, VPN traffic is dropped with SCV-related messages.`
* VPN traffic is dropped although the SCV bypass is configured.  
  Example kernel debug output:  

  ```
  fwscv_check_client_verification:
  state is VERIFIED
  state is UNVERIFIED
  ```

## Cause

Capsule Connect mobile clients on Apple iOS and Android do not use the desktop Secure Configuration Verification (SCV) agent.

When the following conditions are configured, the Security Gateway should allow these clients without SCV verification:

1. The Do not apply SCV for Capsule VPN/Connect option is selected in SmartConsole.
2. The file $FWDIR/conf/local.scv contains:  
   `:allow_non_scv_clients (true)`

Under specific conditions, the Security Gateway does not correctly apply the configured SCV bypass for Capsule Connect mobile clients. As a result, the Security Gateway identifies the clients as unverified and drops Remote Access VPN traffic.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
