> Source: [sk179129](https://support.checkpoint.com/results/sk/sk179129)

# sk179129 - LDAP authentication fails and TCPDump capture shows "LDAPMessage searchResDone(261) referral (0000202B: RefErr: DSID-0310074A, ...)"

| Property | Value |
|----------|-------|
| Solution ID | sk179129 |
| Date Created | 2022-05-10 |
| Last Modified | 2025-10-17 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * LDAP authentication fails, although the connectivity is stable.

* SmartView / SmartConsole show the log "`Authentication failure reason: Unknown User`".

* $FWDIR/log/vpnd.elg on the VPN Security Gateway shows:

  `[vpnd PID]@Host[DATE TIME][CPLDAPCL] Returning result. ErrCode=1 ErrMessage=Internal lookup error`  

  `[vpnd PID]@Host[DATE TIME][AU] au_fetchuser_callback(o=0xa494428 user=0x0): start ldap_err=1`  
  `[vpnd PID]@Host[DATE TIME][AU] au_fetchuser_callback(o=0xa494428): user obj: null`  

  `[vpnd PID]@Host[DATE TIME] fetch_user_wrapper_cb: Error occurred -> user = 0, err = 1, err_msg = Internal lookup error`
* The *$FWDIR/log/test_ad_connectivity.elg* file on the VPN Security Gateway shows:

  `:status (SUCCESS_LDAP)`  

  ` :err_msg ("ADLOG_ERROR_BAD_CREDS;LDAP_SUCCESS")`  

  ` :ldap_status (LDAP_SUCCESS)`  

  ` :wmi_status (ADLOG_ERROR_BAD_CREDS)`  

  <br />


  `[...]@Host[DATE TIME] [ADLOG_DCOM (TD::All)] ADLOG::DcomWmiLogicLayer::analyze: analyzing data: error: ntstatus = 0xc0000022`
* TCPDump capture on the VPN Security Gateway of the LDAP traffic shows:

  `Lightweight Directory Access Protocol`  
  ` LDAPMessage searchResDone(261) referral (0000202B: RefErr: DSID-0310074A, data 0, 1 access points`  
  `ref 1: 'domain_name.com'`  
  `) [0 results]`

  <br />

## Cause

There are two domains configured on the LDAP/AD server in the same root domain.

For example:

* Parent.AD.ABC
* Child.AD.ABC

Users are part of one of these domain or two domains.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
