> Source: [sk170935](https://support.checkpoint.com/results/sk/sk170935)

# sk170935 - Remote Access clients with certificate authentication using UPN/EMAIL/CN/ or any custom field get disconnected during phase 2 re-key or after policy install

| Property | Value |
|----------|-------|
| Solution ID | sk170935 |
| Date Created | 2020-12-13 |
| Last Modified | 2021-12-29 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * Remote Access clients with certificate authentication using UPN get disconnected during phase 2 re-key or after policy install
* From `$FWDIR/log/ike.elg` file you will find "Unknown user" as a response from the Security Gateway after packet 1 of phase 2 renegotiation.
* The following error will appear in the client `C:\Program Files (x86)\CheckPoint\Endpoint Security\Endpoint Connect\trac.log`:  
  InformationalPktEventHandler: msg from notify payload = \[0023\] Unknown user.   
  IkeTunnel::disconnected: IKE tunnel disconnected, error code=-1000. Reason: Unknown user..
* The following error will appear in `$FWDIR/log/vpnd.elg`   
  \[vpnd 3511 4082542528\]\] Passing response for Lookup 2615   
  \[vpnd 3511 4082542528\] User not found: Email=xxxx@xxxx.com,CN=xxxx\\, xxxx,OU=xxxx ,OU=xxxx,OU=xxxx,OU=xxxx,DC=xxxx   
  \[vpnd 3511 4082542528\] Statistics are off - return timestamp 0   
  \[vpnd 3511 4082542528\] CLdapResponse::CLdapResponse (0xb533f18): new Response object   
  \[vpnd 3511 4082542528\] EntryId = 2615 found   
  \[vpnd 3511 4082542528\] Lookup 2615 was found in repository   
  \[vpnd 3511 4082542528\] Entry number 2615 was found

## Cause

The customer uses a certificate (username includes email) for authentication.   
When "vpn_update_isakmp_user" trap is done in re-auth, wrong user name from SA (full subject from cert, instead of the email itself (the real username)) is being used, resulting in failed authentication.

<br />

## Solution

This problem was fixed. The fix is included in:  

[Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 34  
[Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 119  
[Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152)starting from Take 237  

If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.  

Hotfix installation instructions:  
Refer to [sk168597](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597)- How to install a Hotfix.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
