> Source: [sk180661](https://support.checkpoint.com/results/sk/sk180661)

# sk180661 - Capsule VPN for Android / Capsule Connect for iOS / Capsule VPN Plugin for Windows loses access to internal resources

| Property | Value |
|----------|-------|
| Solution ID | sk180661 |
| Date Created | 2023-02-24 |
| Last Modified | 2026-02-18 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * Remote Access user loses access to internal resources after some time, but stays connected to the VPN.
* Capsule VPN for Android / Capsule Connect for iOS / Capsule VPN Plugin for Windows uses SSL to connect to the gateway.
* The realm used for authentication is different from the realm set for the user in the legacy authentication.
* Drops are seen on the gateway for *vpn_inbound_tagging_ex: check_userc_tables returns -1;*   
  If SSL is the method of connection the drop will be *dropped by vpnktcpt_genpacket Reason: failed to write SSL decrypted message;"*

## Cause

When a Remote Access user authenticates the gateway (VPN) on the first connection, the user information is stored in the cache.  

When the user information is removed from the cache, the gateway tries to lookup the user using the default realm (*vpn*) instead of the realm used for authentication. This causes the gateway to drop the traffic for the user.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 126

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

This **workaround**is available:
Configure the default realm (*vpn* ) to use several fetching methods. You can use this for both Remote Access and Identity Awareness blades.  

For more information, see the *"My Identity Source is using both sAMAccountName and UserPrincipleName - what should I do?"* section in [sk149854](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk149854&partition=Advanced&product=Identity).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
