> Source: [sk97612](https://support.checkpoint.com/results/sk/sk97612)

# sk97612 - Site to Site VPN going down frequently with error "encryption failure: According to the policy the packet should not have been decrypted."

| Property | Value |
|----------|-------|
| Solution ID | sk97612 |
| Date Created | 2014-01-19 |
| Last Modified | 2019-05-21 |
| Technical Level | Advanced |
| OS | Gaia |

## Symptoms

- * Packet Drops in SmartView Tracker: "encryption failure: According to the policy the packet should not have been decrypted."
* Third Party firewall (Dell Sonic) shows following error:   
  Received notify: ISAKMP_AUTH_FAILED  
  Received unencrypted packet in crypto active state

## Cause

Site-to-Site VPN Troubleshooting on SonicWALL Security Appliances Tech Note (p.15) states:

Received notify: ISAKMP_AUTH_FAILED = Responder is reporting that preshared key is mismatched. Check settings on both peers.

There are other Check Point Firewall or Interoperable (Non-Check Point Firewall) objects with the same external IP address and encryption domain as the peer. Packets from the peer firewall are accepted, decrypted, and then dropped because the Check Point Firewall receiving the traffic cannot determine which firewall sent the packet.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
