> Source: [sk112933](https://support.checkpoint.com/results/sk/sk112933)

# sk112933 - Endpoint Security VPN client timeout reached during the time that a third-party server is handling Multifactor Authentication (MFA)

| Property | Value |
|----------|-------|
| Solution ID | sk112933 |
| Date Created | 2016-08-17 |
| Last Modified | 2024-03-13 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |

## Symptoms

- * Endpoint Security VPN client timeout reached while Multifactor Authentication (MFA) handled by 3rd party server.
* OTP window in Remote Access VPN client to wait for more than 5 minutes.
* Login stuck on 41% if entering the OTP after approximately a minute

## Cause

**Environment:**

1. The User provides user name and password.
2. An LDAP server looks up the credentials. The credentials are authenticated by a Microsoft RADIUS server.
3. The Check Point Security Gateway sends a RADIUS Access Request to the RADIUS server and "waits" for the reply (RADIUS Access Reject / Accept).
4. While the Gateway is waiting for the RADIUS Access accept/reject, the RADIUS server (not the Gateway) implements a two factor authentication "MFA". It does this by sending a challenge to the User's mobile device (not through the Check Point Security Gateway).
5. The User replies to this challenge, from the mobile device to the RADIUS server.
6. The RADIUS sends a RADIUS Access Accept message to the Security Gateway. This allows the client to connect.

**If the User replies to the Challenge received on his mobile device in a few seconds, the connection is established without any problem.**

If the User replies 90 or more seconds after receiving the challenge to his mobile device, the connection fails for "Access denied - wrong user name or password".

The Check Point Security Gateway handles the Endpoint connection's timeout as expected, without waiting for the multifactor authentication handled by the RADIUS server.

Therefore, the "actual" timeout used by the Endpoint Security VPN Client and by the Security Gateway is reached before the desired time.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
