> Source: [sk31619](https://support.checkpoint.com/results/sk/sk31619)

# sk31619 - Troubleshooting "VPN tunnel is down" scenarios

| Property | Value |
|----------|-------|
| Solution ID | sk31619 |
| Date Created | 2006-03-19 |
| Last Modified | 2020-11-11 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81 (EOS) |

## Symptoms

- VPN tunnel is down.

## Solution

**Site-to-Site scenarios**   

1. Undo the last change made to your environment.   

2. Install the Security Policy, and see if this solves the issue (last change made can be viewed in the audit log).   

3. Verify configuration, i.e. verify that the VPN Domain is valid, and that the Rule Base and VPN community are configured correctly (source and destination machines are in the VPN Domain).   

4. Check for routing problems (for example, confirm traffic between two Security Gateways).   

5. Verify connectivity between the SmartCenter Server to the Gateway and vice versa.   

6. If the SmartCenter Server is behind the Gateway, try to exclude Check Point services.   

7. If the SmartCenter Server is behind an address-translated device, verify that Network Address Translation (NAT) is properly configured.   

8. Try switching to a pre-shared secret (although less secure, a pre-shared secret should bring up the tunnel, until the issue is resolved by Check Point Technical Support).   

9. Look at the SmartView Tracker, to see if Main mode and/or Quick mode are failing.   

10. Make sure any third-party device is properly configured.   

11. Make sure all machines participating in the tunnel (including the SmartCenter server) have the same time, and correct time zones configured.   

12. For VPN-1 Pro NGX, inspect the link-selection mechanism.   

13. Check Point recommends to always upgrade to a recent version, and to the most recent HFA (HotFix Accumulator) of this version.  

    To get the latest HFA for your product, version and Operating System, go to the [Support Center](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doHome) and visit our Products Pages.   

14. Check CPU/memory use. (For example, is a certain process consuming most of the CPU/memory?)

Related solution: [sk104760 - ATRG: VPN Core](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk104760).

<br />

**Client-to-Site scenarios**   

1. Undo the last change made to the environment.   

2. Install the Security Policy, and see if that solves the issue (The last change made can be viewed in the audit log).   

3. Verify configuration, i.e., verify that the VPN Domain is valid and that the Rule Base and VPN Community are properly configured. (source and destination machines are in the VPN Domain.)   

4. Check for routing problems and confirm traffic between two Security Gateways.   

5. Verify connectivity from the SmartCenter Server to the Gateway, and vice versa.   

6. Try using the latest available VPN client, which can be found on the [Remote Access (VPN) Clients page](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=overview&product=175).   

7. Try switching to a pre-shared secret (Although less secure, a pre-shared secret will bring up the tunnel, until the issue is resolved by Check Point Technical Support).   

8. Check SmartView Tracker, to see if Main mode and/or Quick mode are failing.   

9. Make sure all machines participating in the tunnel (including the SmartCenter server) have the same time, and correct time zones configured.   

10. If possible, disable Office Mode and try IP Pool NAT instead.   

11. If you are using Office Mode or IP Pool NAT, verify routing from the LAN to Office Mode addresses.   

12. For versions prior to VPN-1 Pro NGX, use dynamic-interface resolving (Select 'Policy \> Global Properties \> VPN \> Advanced' from the SmartDashboard menu).   

13. For VPN-1 Pro NGX, inspect the link-selection mechanism.   

14. Disable Secure Configuration Verification (SCV) checks.   

15. Check CPU/memory use, and verify whether a certain process is consuming most of the CPU/memory.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
