> Source: [sk178891](https://support.checkpoint.com/results/sk/sk178891)

# sk178891 - Endpoint Security users are disconnected from the Remote Access VPN when the VPN tunnel timeout is reached - "dropped by vpn_inbound_tagging_ex Reason: check_userc_tables returns -1" 

| Property | Value |
|----------|-------|
| Solution ID | sk178891 |
| Date Created | 2022-04-26 |
| Last Modified | 2022-10-24 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * After installing R80.40 Jumbo Hotfix Accumulator Take 156, Endpoint Security users are disconnected from the Remote Access VPN when the VPN tunnel timeout is reached and users need to authenticate again.

* During the issue, SmartConsole log shows:

  *Packet is dropped because user information could not be retrieved*
* If the Remote Access VPN user disconnects and connects again, the VPN session works until the next reauthentication.

* During the issue, kernel debug on the VPN Security Gateway shows after reauthentication:

  *fw_log_drop_ex: Packet proto=\<N\> \<Source\> -\> \<Destination\> dropped by vpn_inbound_tagging_ex Reason: check_userc_tables returns -1*
* During the issue, the output of the "`fw tab -t userc_users -f -u | grep userid`" command on the VPN Security Gateway does not show anything.

## Cause

ICS compliance check failure in a new handling mechanism for the "`ccc_sessions`" kernel table when Endpoint Security clients connect to the VPN Gateway.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 79
* [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 72
* [Jumbo Hotfix Accumulator for R80.40](https://sc1.checkpoint.com/documents/Jumbo_HFA/R80.40/Default.htm) starting from Take 180

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
