> Source: [sk105566](https://support.checkpoint.com/results/sk/sk105566)

# sk105566 - Remote Access clients cannot connect to Security Gateway working in Hybrid Mode if it does not have an ICA and uses 3rd party certificate

| Property | Value |
|----------|-------|
| Solution ID | sk105566 |
| Date Created | 2015-04-06 |
| Last Modified | 2019-09-10 |
| Technical Level | Advanced |

## Symptoms

- * Remote Access clients that authenticate with username and password, cannot connect to Security Gateway working in Hybrid Mode if it does not have an ICA and uses 3rd party certificate.

* Debug of VPND daemon (per [sk89940](http://supportcontent.checkpoint.com/solutions?id=sk89940)) on Security Gateway shows:

  ```
  
  [vpnd PID ...]@HostName[Date Time] fwCert_FindCertListAndKey: Entering 
  [vpnd PID ...]@HostName[Date Time] Cert Reqeust got from peer: 
  [vpnd PID ...]@HostName[Date Time] type 4 
  [vpnd PID ...]@HostName[Date Time] CertListAndTypeForModule: cannot find certified key of ICA 
  [vpnd PID ...]@HostName[Date Time] fwisakmp_user_failed_with_auth: enter, reject category 0 
  [vpnd PID ...]@HostName[Date Time] getUserCertificate: fwCert_CertsAndCRLsFromCertInfoList failed 
  [vpnd PID ...]@HostName[Date Time] GetDAGIP: ID ... not in DAIP range 
  [vpnd PID ...]@HostName[Date Time] CFwdCommStreamLocal::Write called 
  [vpnd PID ...]@HostName[Date Time] CFwdCommStreamLocal::Write sent 264 bytes 
  [vpnd PID ...]@HostName[Date Time] RespMMPacketError: error in FWIKE_EXCH_MAIN_MODE - FWIKE_MM_PACKET_6_PROLOGUE
  ```

## Cause

When the Remote Access client does not send certificate request to Security Gateway during IKE Main Mode Packet 3, the Security Gateway tries to find the appropriate certificate for the client. If Security Gateway does not have an ICA, it fails to find the appropriate certificate for the client, and fails the IKE.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
