> Source: [sk168493](https://support.checkpoint.com/results/sk/sk168493)

# sk168493 - Remote Access clients cannot connect to Security Gateway when Multi Factor Authentication (MFA) is enabled

| Property | Value |
|----------|-------|
| Solution ID | sk168493 |
| Date Created | 2020-08-05 |
| Last Modified | 2022-01-03 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * VPN Remote Access clients that do not support Multi Factor Authentication (MFA), such as Mac OS and iOS, cannot connect as Remote Access clients, if Multiple login options (MFA) is enabled (while older clients can connect without MFA) after an upgrade to:  

  * R80.40 Jumbo Hotfix Take 48
  * R80.30 Jumbo Hotfix Take 210
  * R80.20 Jumbo Hotfix Take 156
  * R80.10 Jumbo Hotfix Take 275

  <br />

  Same issue occurs on base install of R80.30 for [Quantum appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166572).   

* The *vpnd.elg* file shows:  

  `[vpnd ...]@GW[DATE TIME][CLIENT_CONFIG] CCCMultiLoginOption::getRealmById: login option = vpn`  
  `
  [vpnd ...]@GW[DATE TIME][CLIENT_CONFIG] CCCMultiLoginOption::isLoginOptionIDAllowed: vpn this realm is not allowed for the client`  
  `
  [vpnd ...]@GW[DATE TIME][CLIENT_CONFIG][tunnel] InitXAuthConnectAuAuth Invalid realm. Aborting`  

  OR  

  `

  [vpnd ...]@GW[DATE TIME][CLIENT_CONFIG][CLIENT_CONFIG] CCCMultiLoginOption::isLoginOptionIDAllowed`  
  `
  [vpnd ...]@GW[DATE TIME][CLIENT_CONFIG][CLIENT_CONFIG] CCCMultiLoginOption::getRealmById: login option =`  
  `
  [vpnd ...]@GW[DATE TIME][CLIENT_CONFIG][CLIENT_CONFIG] CCCMultiLoginOption::isLoginOptionIDAllowed: does not exist`  
  `
  [vpnd ...]@GW[DATE TIME][CLIENT_CONFIG][tunnel] FwIkeP1FetchUser Invalid realm. aborting`  

* For Site-to-Site tunnels with Dynamically Assigned IP (DAIP) gateway, *vpnd.elg* shows:   

  `
  [vpnd ...]@GW[DATE TIME][tunnel] < FWIKE_EXCH_MAIN_MODE > Id = XXXXX `  
  `
  [vpnd ...]@GW[DATE TIME][tunnel] < FWIKE_MM_PACKET_5_FETCH_PEER > Id = XXXXX `  
  `
  [vpnd ...]@GW[DATE TIME][tunnel] MMProcess5FetchPeer: stage=0; idType=9; `  
  `
  {{ peer_cannot_be_user=1; peer_cannot_be_dag=0;}} `  
  `
  {{ peer_is_mobile_ip=0; peer_is_dag=0; peer_cannot_be_lsv=1; peer_is_lsv=0}} `  
  `
  [vpnd ...]@GW[DATE TIME][tunnel] FwIkeP1FetchDaip: entering`  
  `
  `  
  `
  ...`  
  `
  `  
  `
  [vpnd ...]@GW[DATE TIME][tunnel] FwIkeP1FetchUser Invalid realm. aborting`  
  `
  [vpnd ...]@GW[DATE TIME][tunnel] RespMMPacketError: error in FWIKE_EXCH_MAIN_MODE - FWIKE_MM_PACKET_5_FETCH_PEER`  
  `
  [vpnd ...]@GW[DATE TIME][tunnel] TalkToEngine: Engine RC is << FWIKE_ERROR >>`  
  `
  [vpnd ...]@GW[DATE TIME][tunnel] TalkToEngine: received Error reply from Engine`

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 74
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 217
* [Jumbo Hotfix Accumulator for R80.20](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592) starting from Take 183
* [Jumbo Hotfix Accumulator for R80.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116380) starting from Take 283

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

<br />

For the list of clients that support MFA, refer to [sk111583 - Mobile Access and VPN clients supporting Multiple Login Options](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk111583).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
