> Source: [sk111792](https://support.checkpoint.com/results/sk/sk111792)

# sk111792 - Error: "A secondary session request was received from the same IP. This caused logout of the current session." 

| Property | Value |
|----------|-------|
| Solution ID | sk111792 |
| Date Created | 2016-06-14 |
| Last Modified | 2020-03-05 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * "`A secondary session request was received from the same IP. This caused logout of the current session.`" log in SmartView Tracker from Identity Awareness Gateway when client disconnects:

  1. Client is connected to the Identity Awareness Gateway (PDP)
  2. After some time, the client is disconnected
  3. SmartView Tracker shows the above log.
  4. Client reconnects.
* Issue occurs when using Proxy / Terminal Server / Citrix with Identity Awareness.

## Cause

When clients connect from behind a Proxy / Terminal Server / Citrix, the Identity Awareness Gateway (PDP) detects the IP address of the Proxy / Terminal Server / Citrix server, instead of the real client's IP address.

As a result, all connections from the clients appear with the same source IP address. Therefore, the current incoming client will cause the last client to being disconnected.

## Solution

Follow these steps in SmartDashboard:

1. Open the Identity Awareness Gateway (PDP) object.

2. In the left tree, click on ***General Properties*** - enable the ***Application Control*** blade.

3. In the left tree, click on ***Identity Awareness***.

4. Check the box ***Detect users located behind HTTP proxy using X-Forward-For header***.

   Additional information:
   * If your organization uses an HTTP proxy server behind the Security Gateway, the Rule Base cannot match taking into account identities. Therefore, you cannot see identities of users behind the proxy. Application Control and URL Filtering logs show the proxy as their source IP address and not the user identity. Application Control, URL Filtering and Identity Awareness Security Gateways can use X-Forward-For HTTP header, which is added by the proxy server, to resolve this issue. When you configure the proxy server to add X-Forward-For HTTP header and the Check Point gateways to use it, you will see the correct source identities for traffic that goes through the proxy.  
     You can also configure the gateways to hide and strip the X-Forward-For header in outgoing traffic so that internal IP addresses will not be seen in requests to the internet.

   * **Important Note:** Configure your proxy server to use X-Forward-For HTTP Header.

5. Click on OK.

6. Install policy.

Note: The same behavior might be observed when there are two Identity Awareness Gateways (PDP) configured on the same network.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
