> Source: [sk66681](https://support.checkpoint.com/results/sk/sk66681)

# sk66681 - VPN tunnel down and kernel debug shows 'dropped by vpn_encrypt_chain Reason: no error'

| Property | Value |
|----------|-------|
| Solution ID | sk66681 |
| Date Created | 2012-02-06 |
| Last Modified | 2019-07-24 |
| Technical Level | Advanced |

## Symptoms

- * VPN tunnel does not establish.  

* SmartView Tracker logs show "no response from peer".  

* Kernel debug ('`fw ctl debug -m fw + drop`') on Security Gateway shows the following drops:  
  "dropped by vpn_encrypt_chain Reason: no error"

## Cause

**Probable Cause 1:**  

One possible reason for VPN tunnel not being established is that "Accept Control Connection" in the Global Properties has not been enabled, and the specific rules required to allow VPN traffic were not explicitly created.

**Probable Caues 2:**

Incorrect NAT rules. For example, if there was a NO NAT rule which encompasses the VPN Traffic is above a **Source HIDE NAT** rule for this VPN Traffic, this will cause a conflict.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
