> Source: [sk171966](https://support.checkpoint.com/results/sk/sk171966)

# sk171966 - Remote Access users, when authenticated by UPN, are disconnected after a policy push 

| Property | Value |
|----------|-------|
| Solution ID | sk171966 |
| Date Created | 2021-02-21 |
| Last Modified | 2021-07-11 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Gaia |

## Symptoms

- * Remote Access users, when authenticated by UPN, are disconnected after a policy push. This occurs when authenticating the user with a User Principal Name (UPN) field that is different from the email.
* In `$FWDIR/log/vpnd.elg`, the user sees:   

  **When the User successfully logs in using the UPN field**   

  vpnd 19376 4082440128\]\[24 Jan 16:27:12\]\[tunnel\]: Activating XAUTH for certificate   
  \[vpnd 19376 4082440128\]\[24 Jan 16:27:12\]\[tunnel\] Certs for validation:   
  \[vpnd 19376 4082440128\]\[24 Jan 16:27:12\]\[tunnel\] cert DN: **Email=Bob.Junior@xyz.com,** CN=Junior\\, Bob,OU=Internal Users,OU=Users,OU=ABC,DC=XYZ,DC=LOCAL **Other Name: principalName: juniorb@xyz.com**   

  **When User Update occurs, or after pushing the policy:**   

  vpnd 19376 4082440128\]\[24 Jan 15:22:45\]\[VPNIO\] vpn_trap_multik: **received UPDATE_ISAKMP_USER**   
  \[vpnd 19358 4081756096\]\[24 Jan 11:26:23\]\[vpnd\] vpn_update_isakmp_user: Check if realm was received from sa: vpn_POC-Login   
  \[vpnd 19358 4081756096\]\[24 Jan 11:26:23\]\[ucache\] UCMem_get_by_name: Searching for **++\*Email=Bob.Junior@xyz.com++** ++,CN=Junior\\, Bob,\*OU=Internal Users,OU=Users,OU=ABC,DC=XYZ,DC=LOCAL++   
  \[vpnd 19358 4081756096\]\[24 Jan 11:26:23\]\[ucache\] UCMem_get_by_name: Entry not found.   
  \[vpnd 19358 4081756096\]\[24 Jan 11:26:23\] fetch_user_with_sr_info: requesting au_realm_fetchuser with groups   

  Or   

  \[vpnd 19353 4082116544\]\[5 Jan 23:47:07\]\[CPLDAPCL\] escaping needed   
  \[vpnd 19353 4082116544\]\[5 Jan 23:47:07\]\[CPLDAPCL\] Realm: vpn_POC-Login, UserLoginAttr from Realm: userPrincipalName   
  \[vpnd 19353 4082116544\]\[5 Jan 23:47:07\]\[CPLDAPCL\] Query Filter: (\&(objectclass=user)**(userPrincipalName=Bob.Junior@xyz.com) )** (\*\*Considering Email as UPN Field)   
  \[vpnd 19353 4082116544\]\[5 Jan 23:47:07\]\[vpnd\] fwuserc_update_isakmp_user_S: user : **++Email=Bob.Junior@xyz.com,++** ++CN=Junior\\, Bob,OU=Internal Users,OU=Users,OU=ABC,DC=XYZ,DC=LOCAL not found++   

* Sometime although VPN shows in connected state, users are unable to access it. While applying a Zdebug, the following drops are captured:   

  @;61687;\[vs_0\];\[tid_2\];\[fw4_2\];fw_log_drop_ex: Packet proto=17 10.111.64.1:61000 -\> 10.9.1.115:53 dropped by vpn_inbound_tagging_ex Reason: check_userc_tables returns -1;   
  @;61761;\[vs_0\];\[tid_2\];\[fw4_2\];fw_log_drop_ex: Packet proto=17 10.111.64.1:61000 -\> 10.9.1.115:53 dropped by vpn_inbound_tagging_ex Reason: check_userc_tables returns -1;

## Cause

When a user update occurs, Check Point fetches the user details "fwuserc_update_isakmp_user" from the email field. It should fetch the user details from the UPN, because the authentication method used for login was UPN  

**Note:** Where the email and UPN field values are the same, there should not be issues.

<br />

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk170114) starting from Take 34
* [Jumbo Hotfix Accumulator for R80.40](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456) starting from Take 119
* [Jumbo Hotfix Accumulator for R80.30](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152) starting from Take 237

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
