> Source: [sk165492](https://support.checkpoint.com/results/sk/sk165492)

# sk165492 - Mobile Access SSL Client takes long time to access portal after authentication

| Property | Value |
|----------|-------|
| Solution ID | sk165492 |
| Date Created | 2020-03-02 |
| Last Modified | 2020-11-02 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * Mobile Access SSL client takes a long time to access portal after authentication (i.e. approximately 40 seconds).
* *$CVPNDIR/log/cvpnd.elg* from Mobile Access gateway shows the following errors:  
  `Retry User By Name`  
  All servers are down. Switch all to up  
  Set to up

## Cause

Mobile Access gateway is attempting to contact LDAP server, but fails due to one of the following reasons:  

* The LDAP server is not accessible from the Mobile Access gateway.
* The Mobile Access gateway is having SSL validation issues with the LDAP server.
* An LDAP Account Unit with the LDAP server is configured, but is not used any more.

<br />

## Solution

**Scenario 1: LDAP server is not accessible from Mobile Access gateway**   

Check and resolve network connectivity issue between Mobile Access gateway and LDAP server.  

**Scenario 2: Mobile Access gateway is having SSL validation issues with the LDAP server**   

Check the configuration on the following page of the LDAP Account Unit Properties of the LDAP Account Unit object in SmartDashboard:  

1. Select 'Manage \> Servers \& OPSEC Applications'.
2. In the Servers and OPSEC Applications dialog box, select the LDAP Account Unit.
3. Click on "Edit".
4. Select the Servers tab.
5. In the Servers tab, select the LDAP server.
6. Click on "Edit".
7. In the LDAP Server Properties dialog box, select the Encryption tab.

**Scenario 3: LDAP Account Unit with LDAP server is configured, but is not used any more**   

If the LDAP Account Unit is not used any more, remove both the LDAP Account Unit object and the LDAP server host object(s) from the SmartDashboard configuration, and reinstall the policy on the Mobile Access gateway.  

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
