> Source: [sk106258](https://support.checkpoint.com/results/sk/sk106258)

# sk106258 - Authentication traffic does not originate from VSX Gateway (VS0) when using Shared LDAP Authentication

| Property | Value |
|----------|-------|
| Solution ID | sk106258 |
| Date Created | 2015-06-05 |
| Last Modified | 2020-03-30 |
| Technical Level | Advanced |
| Products | Security Gateway, Hardware |
| Versions | R82.10, R82, R81.20, Not Version-Specific |
| OS | Gaia |

## Symptoms

- LDAP authentication traffic is *not* shared through VSX Gateway itself (context of VS0) after configuration of "Shared" LDAP Authentication in SmartDashboard per VSX Admin Guide (Virtual System object - Properties - Other - Legacy Authentication - section Authentication Servers Accessibility (including LDAP) - select "Shared (servers are accessible from the VSX gateway/cluster)"):

* LDAP traffic originates from VSX Gateway itself (context of VS0)
* WMI (MS-RPC) traffic originates from the relevant Virtual System

## Cause

LDAP is a part of the Authentication mechanism, it is implemented in Check Point Authentication infrastructure and used by multiple Software Blades (e.g., Identity Awareness, IPSec VPN, DLP, etc.).

WMI is used only by the Identity Awareness blade to query domain events from domain controllers. An external tool called *WMIC* is used for these queries.

This was not designed to work across different Virtual Systems.

WMI queries to the domain controller generated from that specific Virtual System (e.g., a subscription for security events) are *not* handled by VSX Gateway itself (context of VS0).

There must be connectivity between the relevant Virtual System initiating traffic and the Domain Controller responsible for Authentication requests.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
