# Tunnel Testing fails after an upgrade

## Product
IPSec VPN

## Version
R81 (EOS), R81.10 (EOS), R81.20

## OS
Gaia

## Last Modified
2024-10-22

## Symptoms
- Tunnel Testing traffic fails on R81.20 ClusterXL HA gateways.
- Packet captures show that the peer responds with "ICMP Port Unreachable" messages after Cluster gateway responds to Tunnel Testing packet initiated from the peer Security Gateway.

## Cause
The Security Gateway treats a tunnel testing reply source 18234 as a new connection, and performs Hide NAT.

## Solution
This problem was fixed. The fix is included in:
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 79
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 158
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 106

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

#### NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
