> Source: [sk119596](https://support.checkpoint.com/results/sk/sk119596)

# sk119596 - "Dynamic ID authentication failed" error after upgrading from R77.30 to R80.XX

| Property | Value |
|----------|-------|
| Solution ID | sk119596 |
| Date Created | 2017-08-07 |
| Last Modified | 2020-11-17 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * After upgrading from R77.30 to R80.10, user cannot connect to Mobile Access portal with the error "Dynamic ID authentication failed".
* In *cvpnd.elg* , can see the following:

  \[7128\]\[20 Jul 9:38:56\]\[AU\] DynamicIDManager::loadGlobalConfigFromFile: initial challenge_matcher_list /conf/dynamic_id_matcher.lst

  \[7128\]\[20 Jul 9:38:56\]\[AU\] DynamicIDManager::loadGlobalConfigFromFile: challenge_matcher_list /opt/CPshrd-R80/conf/dynamic_id_matcher.lst

  \[7128\]\[20 Jul 9:38:56\]\[AU\] ..\<-- DynamicIDManager::loadGlobalConfigFromFile

  \[7128\]\[20 Jul 9:38:56\]\[AU\] ..--\> DynamicIDManager::reloadLocalTargets

  \[7128\]\[20 Jul 9:38:56\]\[AU\] DynamicIDManager::reloadLocalTargets: about to open file = '/opt/CPshrd-R80/conf/dynamic_id_users_info.lst'

  \[7128\]\[20 Jul 9:38:56\]\[AU\] DynamicIDManager::reloadLocalTargets: **failed to open file = '/opt/CPshrd-R80/conf/dynamic_id_users_info.lst' - abort**

  \[7128\]\[20 Jul 9:38:56\]\[AU\] ..\<-- DynamicIDManager::reloadLocalTargets

  \[7128\]\[20 Jul 9:38:56\]\[AU\] DynamicIDManager::init: failed to load local targerts - continue without

  \[7128\]\[20 Jul 9:38:56\]\[AU\] ..--\> DynamicIDManager::reconfAllDynamicIDs

  \[7128\]\[20 Jul 9:38:56\]\[AU\] DynamicIDManager::reconfAllDynamicIDs: start

  \[7128\]\[20 Jul 9:38:56\]\[AU\] DynamicIDManager::reconfAllDynamicIDs: failed to get data from servers database - will reconf with no obj (LEGACY)

## Cause

The relevant information for the Dynamic ID was not added correctly to *$CPDIR/conf/dynamic_id_users_info.lst*

SmsPhones.lst, is a Phone Directory on the local gateway, saving Phone numbers and / or emails address, used to send One Time Password (OTP) via SMS / Email as a 2nd challenge to user during Mobile Access authentication. In case you configured such a file on your R77.30 gateway, you will have to copy this file to your upgraded R80.10 gateway under the path *$CPDIR/conf/dynamic_id_users_info.lst*.

Note that although both the name of the files and the directories in which the file is placed were changed, the format of the file remains the same. **A simple copy \& rename is needed.**

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
