> Source: [sk185148](https://support.checkpoint.com/results/sk/sk185148)

# sk185148 - Remote Access VPN fails after Authentication on a Locally Managed Spark Firewall Appliance

| Property | Value |
|----------|-------|
| Solution ID | sk185148 |
| Date Created | 2026-07-13 |
| Last Modified | 2026-07-14 |
| Technical Level | Advanced |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 1570R, 1575R, 1500, 1900, 2000, 1600, 1800, 1595R, 2500, 15x5 |

## Symptoms

- * Remote Access VPN users cannot connect to the Spark Firewall appliance.

* Users authenticate successfully on the Security Gateway.

* The VPN tunnel does not establish successfully.

* The Endpoint Security VPN client stops at approximately 47%.

* The VPN connection times out and shows this error message: "*Negotiation with site failed."*

## Cause

A custom VoIP, service object, or server group configuration reserves one or more UDP ports required by Remote Access VPN:

* UDP 500

* UDP 4500

* UDP 30500

* UDP 34500

Remote Access VPN requires these ports to complete tunnel negotiation and establishment. When another configuration reserves these ports, the Security Gateway authenticates the user but cannot complete VPN tunnel establishment.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
