> Source: [sk147212](https://support.checkpoint.com/results/sk/sk147212)

# sk147212 - "SIC ERROR 111 - SIC Error for lea: Peer sent wrong DN" on Opsec lea connection to SPLUNK

| Property | Value |
|----------|-------|
| Solution ID | sk147212 |
| Date Created | 2019-02-15 |
| Last Modified | 2023-11-14 |
| Technical Level | Advanced |
| Products | Multi-Domain Security Management Server |
| Versions | R81 (EOS), R81.10 (EOS), R81.20 |
| OS | Gaia |

## Symptoms

- * Trying to configure the OPSEC lea connection with Secondary CMAs, the following error is received in the SPLUNK logs:  
  ` "Session end reason: SIC ERROR 111 - SIC Error for lea: Peer sent wrong DN: CN=cp_mgmt.."`
* trace-route from the Checkpoint machine to SPLUNK is successful .
* Packet capture is showing the OPSEC is sending the RESETs.
* Same also applies when monitoring through another 3rd party like Algosec.

## Cause

Wrong DN name selected under SPLUNK configuration file ''opseclea_connection.conf'' - parameter (opsec_entity_sic_name)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
