> Source: [sk107155](https://support.checkpoint.com/results/sk/sk107155)

# sk107155 - Identity Awareness Agent disconnects with no apparent reason after some time of operation when Kerberos SSO is defined

| Property | Value |
|----------|-------|
| Solution ID | sk107155 |
| Date Created | 2015-08-02 |
| Last Modified | 2017-05-18 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Identity Awareness Agent disconnects with no apparent reason after some time of operation when Kerberos SSO is defined, but Kerberos authentication fails (or not working).

* SmartView Tracker logs show:  

  "*A secondary session request was received from the same IP. This caused logout of the current session* "  

  However, there are no duplicate IP addresses.

* Enabling "*Assume that only one user is connected per computer* " does not resolve issue (Identity Awareness gateway properties - go to "*Identity Awareness* " pane - check the box "*Active Directory Query* " - click on "*Settings...*" button).

* Connection status shows on the Identity Agent:  

  *Machine Identity: Not Detected*

* Debug of PDPD daemon on the Identity Awareness gateway ('`pdp debug set all all`') shows Kerberos errors:

  ```
  
  [ PID ...]@HostName[Date Time]  [AUTH (TD::Events)] pdp::AuthMngr::GetAuthenticator: Get Kerberos Authenticator.
  [ PID ...]@HostName[Date Time]  [AUTH (TD::Events)] pdp::KerberosAuthenticator::BuildAuthData: KerberosAuthenticator::BuildAuthData: (
  	:accountName (<UserName>)
  	:Type (1)
  	:kerberosMessage ("(KerberosMessage
  	:token (...)
  	:principal ('ckp_pdp/<domain_name>@<DOMAIN_NAME>')
  	:flag (2)
  )
  ")
  	:principleName ("ckp_pdp/<domain_name>@<DOMAIN_NAME>")
  	:AdditionalInformation (...)
  )
  
  [ PID ...]@HostName[Date Time] SpNegoToken::BDecContent ERROR - SEQUENCE is missing non-optional elmt. offset = 16
  [ PID ...]@HostName[Date Time] SpNegoToken::BDec: attempt to decoded Content failed
  ```

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
