> Source: [sk179518](https://support.checkpoint.com/results/sk/sk179518)

# sk179518 - "Negotiation with site failed" VSX Private Authentication Fails for VPN Clients 

| Property | Value |
|----------|-------|
| Solution ID | sk179518 |
| Date Created | 2022-06-09 |
| Last Modified | 2022-06-15 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * Authentication in a Remote Access VPN Client fails with the error message "*Negotiation with site failed*".

* The VSX Virtual System is configured to use private authentication with RADIUS (in SmartConsole, *General Properties* \> *Other* \> *Legacy Authentication* \> *Authentication Servers Accessibility (Including LDAP)*).

* Traffic capture on the VSX Gateway shows no authentication requests from the VSX Gateway to the RADIUS server.

* There is an LDAP Account Unit configured in the same Domain or Management Station.

* Configuring the timeout for LDAP Requests to one (1) second does not help (in SmartConsole, *General Properties* \> *Other* \> *User Directory* \> *Timeout on LDAP requests*).

## Cause

By default, the legacy VPN realm fetches users from LDAP. The Virtual System fails to connect to the LDAP Server in the account unit when this LDAP server is configured to Private Authentication. After the Virtual System fails to connect, there is a 60 second timeout until the next retry to reach the LDAP. This 60 second timeout is longer than the VPN timeout.

## Solution

If you do not need the Account Unit, remove it.  

If you do not want to remove the Account Unit, follow this procedure in SmartConsole to remove the legacy VPN authentication realm and configure the required login options in a new realm:   

1. Configure the Virtual System object:
   1. Open the Virtual System object.
   2. From the left tree, click **VPN Clients** \> **Authentication**.
   3. If you do not use legacy VPN clients, then disable the legacy VPN authentication for older clients.  
      In the section **Compatibility with Older clients** , clear the checkbox "**Allow older clients to connect to this gateway"**.
   4. In the section **Multiple Authentication Clients Settings**, configure the applicable new multi-realm authentication settings.
   5. Click OK.
   6. Install the applicable Access Control policy on the Virtual System object.
2. Configure the VSX Gateway / VSX Cluster object:
   1. Open the VSX Gateway / VSX Cluster object.
   2. From the left tree, click **General Properties** .  
      Make sure the **IPSec VPN** Software Blade is enabled.
   3. From the left tree, click **VPN Clients** \> **Authentication**.
   4. In the section **Multiple Authentication Clients Settings**, configure which identity sources are queried by the VSX Gateway / VSX Cluster:
   5. Click OK.
   6. Install the applicable Access Control policy on the VSX Gateway / VSX Cluster object.

For more information, see the [Mobile Access Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=175) for the relevant version.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
