> Source: [sk115213](https://support.checkpoint.com/results/sk/sk115213)

# sk115213 - LDAP or RADIUS user randomly cannot access internal resources after successful login

| Property | Value |
|----------|-------|
| Solution ID | sk115213 |
| Date Created | 2017-01-01 |
| Last Modified | 2018-05-29 |
| Technical Level | Advanced |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, E89.X, E88.X |

## Symptoms

- * LDAP or RADIUS user randomly cannot access internal resources after a successful login.
* SmartView Tracker shows that the traffic from the client Office Mode IP address toward the internal resource is not being matched to the relevant rule, and therefore is being dropped by the clean-up or other rule. **The rule that allows this traffic contains only one of the possible user groups.** Therefore, if the user is associated with the "wrong" group, the traffic from the client will not be matched by this rule.
* In SmartView Tracker, under the login session of the Mobile Access section, you can see that the same user is associated with different groups ("Identity\> User Groups") and therefore is matched against different rules.
* The following error appears in *helpdesk.log* and *trac.log* when reviewing VPN Client logs:  
  "IKE tunnel disconnected, error code=-1000. Reason: Access denied - wrong user name or password"
* The following error may appear in *vpnd.elg* , when running VPN debug on the Remote Access VPN Gateway:  
  "Access denied - wrong user name or password"
* Similar symptoms may occur for LDAP Computer Objects when utilizing Machine Authentication. The following solution may be valid for such issues, as well.

## Cause

The same user name exists in more than one Account Unit or LDAP server.

**A duplicated user, i.e. one that exists in more than one LDAP server is not supported.**

Upon a connection, the Check Point gateway addresses all the Account Units **with the same priority** for the user lookup process.

**The gateway uses the answer from the first LDAP server to respond and builds the user group membership accordingly.**

From the gateway's perspective, the relevant SmartDashboard LDAP group associated with the user depends on the LDAP group criteria:

* Under which LDAP branch (Account Unit) the user is located.
* Whether the user belongs to the relevant group, as per the LDAP server response.

**Once the SmartDashboard LDAP group is chosen, it is used for the rule base match. (Once the user is assigned the LDAP group membership, the Security Gateway looks into the rule base and tries to find a rule that contains that LDAP group membership in the Source column.)**

Based on the information listed above, if the "wrong" LDAP server answers first for the user lookup request, the user is matched against an LDAP group that is not allowed by the relevant rule.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
