sk183147 - Remote Access VPN users repeatedly lose connection to resources behind gateway, "IKE Negotiation with the gateway has failed" message in Remote Access VPN Client
Remote Access VPN users repeatedly lose connection to resources behind gateway, "IKE Negotiation with the gateway has failed" message in Remote Access VPN Client
Product: Remote Access VPN
Version: R81.10 (EOS), R81.20
Last Modified: 2025-04-28
Symptoms
- Users of a Remote Access VPN client cannot access resources located behind a Remote Access VPN Gateway. The Remote Access VPN client shows: " IKE Negotiation with the gateway has failed. Make sure the user is properly defined on the firewall."
- The Remote Access VPN Gateway has installed R81.20 Jumbo Hotfix Accumulator Take 96 or higher / R81.10 Jumbo Hotfix Accumulator Take 173.
- In the CLI Expert Mode of the Remote Access VPN Gateway / Cluster Member, output of
hcp -r all HCP Reportsshows core dumps related to problems withikedandvpnd. - In the CLI of the Remote Access VPN Gateway, / var/log/messages shows errors that are similar to this:
kernel:iked[-]: segfault at 19 ip - sp - error 4 in ike[-] - IKED debugs (or VPND debugs if IKED is disabled) show
__MsgObj_internal_error:_NULL_obj__ error can be seen on IKED debugs
Cause
There is a problem with the iked and vpnd processes on the Remote Access VPN Gateway due to aggressive DDOS protection.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 99
- Jumbo Hotfix Accumulator for R81.10 starting from Take 174
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions: Refer to sk168597 - How to install a Hotfix.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-02-24
Last Modified: 2025-04-28