> Source: [sk36973](https://support.checkpoint.com/results/sk/sk36973)

# sk36973 - VPN tunnels cannot be established due to IKE_SA_table overflow

| Property | Value |
|----------|-------|
| Solution ID | sk36973 |
| Date Created | 2009-01-26 |
| Last Modified | 2025-11-27 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * A VPN client (SecureClient, SecuRemote), or a VPN peer, does not succeed in making a VPN connection.
* SecureClient shows the error message "Gateway not responding".
* There is no error message in the standard Security Gateway log.
* Debugging with "fw monitor" show packets flowing in IKE phase 1 and 2, but the client repeating the first packet in phase 2 over and over again.
* When vpn debugging is run on the Security Gateway, `vpnd.elg` shows:  

  \[vpnd 3264 2002657952\]@vpn\[22 Jan 13:39:24\] WriteSA: called - me:0x00000000 cookieI:\*\*\*\*\*\*\* \*\*\*\*\*\*\*\* cookieR:\*\*\*\*\*\*\*\* \*\*\*\*\*\*\*\* newsa:1  
  \[vpnd 3264 2002657952\]@vpn\[22 Jan 13:39:24\] WriteSA: failed to set IKE_SA_table (1)  
  \[vpnd 3264 2002657952\]@vpn\[22 Jan 13:39:24\] RespMMPacketError: error in FWIKE_EXCH_MAIN_MODE - FWIKE_MM_PACKET_6  
  \[vpnd 3264 2002657952\]@vpn\[22 Jan 13:39:24\] Ta  

  You may also see the following lines in vpnd.elg  
  chooseProposalFromList: Failed to match proposal. Transform: AES-256, SHA1, Pre-shared secret, Group 2 (1024 bit); Reason: Wrong value for: Hash Algorithm  
  chooseProposalFromList: Failed to match in strict mode. Will try matching all supported DH groups  
* When you examine the table on the Security Gateway via `fw tab -t IKE_SA_table -c` you see that the table is nearly, or completely full.  

  <br />

  **Note:** Be sure to examine the active cluster member, when you have a HA/LS configuration. The IKE_SA_table is synched between cluster members, `vpnd.elg` is not.
* fwk.elg contains the following error messages: \[27 Nov 15:15:32\]\[fw4_1\];\[vs_18\];vpn_route_info_from_orig_route_vals: ERROR: my address (XX.YYY.ZZZZ.102) is not a cluster's address. Address on kbuf: (XX.YYY.ZZZZ.102). Called by: record_tunnel_route_parameters. Keeping current address \[27 Nov 15:15:39\]\[fw4_0\];\[vs_18\];write_ikev1_sa: Failed to set SA table \[27 Nov 15:15:57\]\[fw4_0\];\[vs_18\];write_ikev1_sa: Failed to set SA table \[27 Nov 15:16:02\]\[fw4_0\];\[vs_18\];write_ikev1_sa: Failed to set SA table \[27 Nov 15:17:27\]\[fw4_0\];\[vs_18\];write_ikev1_sa: Failed to set SA table \[27 Nov 15:17:38\]\[fw4_0\];\[vs_18\];write_ikev1_sa: Failed to set SA table

## Cause

When the IKE_SA_table is full, no SAs can be generated and IKE negotiations will fail for site-2-site and client-2-site VPN.   
When there are many Remote Access users, the problem may be intermittent, as users log in/out.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
