> Source: [sk64060](https://support.checkpoint.com/results/sk/sk64060)

# sk64060 - 'Encryption Failure: according to the policy the packet should not have been decrypted' log in SmartView Tracker for VPN Tunnel Test packet

| Property | Value |
|----------|-------|
| Solution ID | sk64060 |
| Date Created | 2011-07-01 |
| Last Modified | 2022-05-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Remote Access VPN user successfully connects to the VPN Gateway. However, after a short period of time (20 seconds or so) VPN user gets disconnected.  

* "`Encryption Failure: according to the policy the packet should not have been decrypted`" log in SmartView Tracker.  

* Traffic is dropped inside the VPN tunnel.

## Cause

The Remote Access VPN user has a private IP address on his local computer that is on the same subnet as one of the subnets in the encryption domain, AND the Gateway is not configured to assign an Office Mode IP address to the user.

Excluded services are configured in the VPN Community settings on one of the connecting Gateways, but are being encrypted on the other Gateway.

*Example*:

* User A is hiding behind a router on the Internet with private IP address 172.16.1.32/24.
* User A successfully connects to a Gateway somewhere on the Internet.
* Gateway has the following subnets defined in the encryption domain: 192.168.1.0/24 and 172.16.1.0/24.
* Gateway is not configured to assign an Office Mode IP address to user A.

Thus, when the encrypted Tunnel Test packet arrives at the Gateway, the Gateway decrypts the packet (strips the outer IP layer of the packet and maintains the inner IP layer, which contains the user's private IP address).   
When Gateway attempts to reply to the Tunnel Test packet, it detects that the Source IP address of the packet is on the Gateway's inner/local network, and therefore, the packet should not have been decrypted in the first place, since there is no matching rule in the policy that would encrypt it. This causes the Gateway to drop the packet with the above-mentioned error.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
