> Source: [sk185253](https://support.checkpoint.com/results/sk/sk185253)

# sk185253 - Remote Access VPN Disconnects in Visitor Mode After Migration to IKEv2

| Property | Value |
|----------|-------|
| Solution ID | sk185253 |
| Date Created | 2026-08-17 |
| Last Modified | 2026-08-26 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82 |
| OS | Gaia |
| Platform | Intel/PC, Smart-1 |

## Symptoms

- * After migrating a Remote Access VPN deployment to [IKEv2](https://support.checkpoint.com/results/sk/sk166415), the VPN client successfully establishes a Visitor Mode connection but typically disconnects approximately 20 seconds later.
* The VPN Client `helpdesk.log` shows that the Office Mode IP is assigned successfully, followed by repeated tunnel test failures:  
  `[DATETIME] Office mode IP was set successfully`  
  `[DATETIME] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=yy.yy.yy.yy, source port=18001.`  
  `[DATETIME] Client state is connecting`  
  `[DATETIME] Connection was successfully established (1)`  
  `[DATETIME] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=yy.yy.yy.yy, source port=18002.`  
  `...`  
  `[DATETIME] No reply from the gw ip=xx.xx.xx.xx for tunnel test packet. Office Mode IP=yy.yy.yy.yy, source port=18008.`  
  `[DATETIME IKE tunnel disconnected, error code=-1000. Reason: Site is not responding.`  
* On the affected Security Gateway, the following drop messages may appear while reproducing the issue using this command in Expert mode:`fw ctl zdebug + drop | grep client_om_ip`  

  `[kern];[tid_1];[SIM4];handle_vpn_encryption: ipsec_encrypt failed: encrypted packet too big. Dropping packet... `  
  `conn: <xx.xx.xx.xx,18234,yy.yy.yy.yy,18001,17>;`  
* The issue occurs more frequently when:
  * A DHCP server assigns Office Mode IP addresses.
  * Custom Office Mode assignments are configured through *ipassignment.conf*.

## Cause

Under specific conditions, the SecureXL Acceleration Module (SIM) cannot correctly process encrypted traffic for a Remote Access VPN client when route resolution for the assigned Office Mode IP address is incomplete. As a result, tunnel test packets fail, and the VPN client disconnects.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
