> Source: [sk177646](https://support.checkpoint.com/results/sk/sk177646)

# sk177646 - "malformed reply from site"  error on Capsule VPN connection with SAML authentication

| Property | Value |
|----------|-------|
| Solution ID | sk177646 |
| Date Created | 2022-01-29 |
| Last Modified | 2024-01-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | iOS, Gaia |

## Symptoms

- * Users connecting from iPhone or Ipad using Capsule VPN client receive error "malformed reply from site" during the VPN connection, when the authentication method under Remote Access VPN for the Security Gateway is set to Identity Provider.

* These logs are found in the $FWDIR/log/vpnd.elg file:  

  `
  [vpnd PID]@Gateway[DATE TIME][ccc_core] CPRAS_Dispatcher_CallService: Service 'Signout' failed flag verifications`  
  `
  [vpnd PID]@Gateway[DATE TIME][ccc_core] setReturnCode: Re/setting response return code... (500 + 3 = 503)`  
  `
  [vpnd PID]@Gateway[DATE TIME][ccc_core] CccMain::CCCRequest: CPRAS_SRVC_Interface_CallService() failed`

## Cause

Capsule VPN does not support SAML authentication

## Solution

Capsule support SAML, See [SK181494](https://support.checkpoint.com/results/sk/sk181494)  

This problem was fixed. The fix is included starting from:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 43
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 113

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

<br />

<br />

<br />

If you choose not to upgrade you environment.

As a workaround you can use Legacy Authentication:

1. In SmartConsole. go to the Security Gateway object \> VPN Clients \> Authentication
2. Select "Allow older clients to connect to this gateway"
3. Click "Settings..." -\> Select Authentication method as "Defined On User Record (Legacy)". ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk177646/Capture2202202061222301.png)  

4. Save and install the Security policy.  

<br />

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
