> Source: [sk115352](https://support.checkpoint.com/results/sk/sk115352)

# sk115352 - "Wrong username or password"  error message when LDAP users cannot access Remote Access VPN to gateway 

| Property | Value |
|----------|-------|
| Solution ID | sk115352 |
| Date Created | 2017-01-07 |
| Last Modified | 2020-11-04 |
| Technical Level | General |
| Products | Security Gateway, Endpoint Security |
| Versions | R82.10, R82, R81.20, Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * Some LDAP users cannot access Remote Access VPN to gateway with their LDAP credentials, or log into Mobile Access portal. Error message states: "wrong username or password"
* No LDAP traffic for those problematic LDAP users between AD server and gateway, when trying to use Remote Access VPN with gateway.
* *Vpnd* debug log shows gateway cannot get authenticating group for the user:  
  \[vpnd 5997 4126250688\]@CPFW-R77.20\[26 Dec 13:40:22\] check_uint_attribute_value: failed to get attribute \[sr_info_auth_grps_fetched\] from userobject  
  \[vpnd 5997 4126250688\]@CPFW-R77.20\[26 Dec 13:40:22\] check_uint_attribute_value: read attribute \[sr_info_auth_grps_fetched\] on user object, value is 0

## Cause

**Environment:** Customer has enabled Remote Access and Mobile Access VPN blades on the gateway. Internal users were created on both gateway and AD server.

There are some internal users on the gateway with the same user name as users on the AD server.

**The gateway will first check internal users before trying LDAP authentication.**

## Solution

Remove those internal users with the same user name as the LDAP users, or change internal user's authentication method to "Check Point Password".

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
