> Source: [sk98604](https://support.checkpoint.com/results/sk/sk98604)

# sk98604 - No valid SA when creating VPN tunnel between locally managed SMB appliance and 3rd party gateway 

| Property | Value |
|----------|-------|
| Solution ID | sk98604 |
| Date Created | 2014-02-17 |
| Last Modified | 2022-07-26 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |
| Platform | 1570R, 1500, 1600, 910 |

## Symptoms

- Clients behind the locally managed SMB appliance cannot use Site-to-Site VPN to access internal resources located behind the remote gateway.

## Cause

The nature of this problem is due to the ability of the Check Point Security Gateways to dynamically supernet subnets to reduce the amount of SA overhead normally generated by VPN traffic.

For example:

If the remote encryption domain includes 192.168.12.x/24 and 192.168.13.x/24, the Check Point gateway will group them as one network: 192.168.12.x/23, with subnet 255.255.254.0.

Most 3rd party vendors are inherently static and therefore do not have the ability to understand this dynamic behavior and therefore drop the traffic.

## Solution

To disable subnet summary in the VPN module:

Go to "Device \> Advanced Settings \> uncheck the option "Join adjacent subnets in IKE Quick Mode"".  

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98604/join202103031115442.png)

**Note: This option is available only on locally managed appliances from firmware version R75.20 HFA_42 and above.** Another setting would be to exclude the WAN IP from the encryption domain.   
This was only available after R77.20.75 [sk121758:](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk121758&partition=Basic&product=Quantum)**![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk98604/exclude202103031118581.png)**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
