> Source: [sk35741](https://support.checkpoint.com/results/sk/sk35741)

# sk35741 - Encryption Domain for L2TP Clients and iPhone

| Property | Value |
|----------|-------|
| Solution ID | sk35741 |
| Date Created | 2008-08-10 |
| Last Modified | 2020-09-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When working with L2TP clients, if the Remote Access encryption domain is too complex, not all of it will be transmitted to the client. In such a case, some of the traffic will not go through the tunnel.
* An alert is displayed in SmartView Tracker: "RA encryption domain includes xx subnets. Only first 28 will be used for L2TP clients". Similar alert also can be found in vpnd.elg.

## Cause

L2TP clients use the "classless static routes" option of the DHCP protocol to get the encryption domain from the Security Gateway. A limitation of the DHCP protocol caps each option at 255 bytes. This is enough for about 28 subnets.

<br />

## Solution

For Remote Access, the encryption domain should be changed so that it fits in 28 subnets.  

Note: The issue is similar to another issue that we have had before with too many routes in an LT2P connection. However it looks like DNS suffixes also get sent across in the same way, so if there is too much data in the L2TP setup, they get missed, as the setup is truncated.  

We fixed the issue by changing the VPN domain for Remote Access to just contain a much smaller set of more global routes (eg: 10.0.0.0/8, 192.168.0.0/16).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
