> Source: [sk174084](https://support.checkpoint.com/results/sk/sk174084)

# sk174084 - Remote Access / Endpoint VPN LDAP users do not match their Access Roles in certain scenarios

| Property | Value |
|----------|-------|
| Solution ID | sk174084 |
| Date Created | 2021-06-17 |
| Last Modified | 2022-09-21 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- LDAP users connect successfully to Endpoint VPN, receive Office Mode, but do not match their assigned Access Roles - causing traffic to miss the rule it was placed in (and the traffic is usually dropped by the Cleanup rule).

## Cause

**Background**   

The authentication method used for the clients to connect is configured in the Multi Login Option checkbox under "VPN Clients \> Authentication" in the Gateway object itself.  

That same Login Option (AKA Realm) has one or both of the following conditions:

* The LDAP Lookup Type under User Directories was changed to any non-default value.
* The authentication factor is Certificate, and the Parsing Rules were changed.

*** ** * ** ***

\* A most common scenario for a change in the Parsing Rules is to fetch a UPN of a user from the Alternative Subject Field.  

PDP (identity awareness blade) uses the default legacy "vpn" realm. Consequently, changes made to the Lookup Type or Certificate Parsing Rules in the custom Login Option do not apply to PDP's own authentication flow.

<br />

## Solution

This problem was fixed. The fix is included in:  

* **[Jumbo Hotfix Accumulator for R80.30](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.30/Default.htm) starting from Take 241**
* **[Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 126**

<br />

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.   
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.   
For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
