> Source: [sk97968](https://support.checkpoint.com/results/sk/sk97968)

# sk97968 - 3rd party Client to Site VPN fails when using ISP redundancy in Load Sharing mode 

| Property | Value |
|----------|-------|
| Solution ID | sk97968 |
| Date Created | 2014-01-01 |
| Last Modified | 2017-07-25 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * 3rd party VPN clients cannot connect to server behind ISP redundancy in Load Sharing mode.
* Key exchange packets are going out through one link while the ESP packets going through another link IP.
* The gateway is not dropping any packet.

## Cause

The gateway cannot associate between the key exchange traffic and the encrypted packets.

The VPN server expects that all of the traffic will come from the same source so he could associate the keys for each packet.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
