> Source: [sk180877](https://support.checkpoint.com/results/sk/sk180877)

# sk180877 - Remote Access clients connecting using LDAP successfully authenticate and pass traffic but randomly some time after traffic fail to pass the relevant access role.

| Property | Value |
|----------|-------|
| Solution ID | sk180877 |
| Date Created | 2023-04-19 |
| Last Modified | 2025-08-28 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |

## Symptoms

- * Remote Access clients connecting using LDAP successfully authenticate and pass traffic but randomly some time after traffic fail to pass the relevant access role.
* When the issue begins, at the same time SmartLog will show a log showing: Action: Log Out  
  Blade: Identity Awareness  
  Termination Reason: Session Expiration  
  Identity Source: VPN Remote Access  
* On the iked/pdpd log during the time the issue occur we can see the following: au_fetchuser_specific(o=): calling cpLdapGetUserList(name=) Instead of: au_fetchuser_specific(o=): calling cpLdapGetUserWithRealm(name=)

## Cause

The parameter display_au_list located on the MGMT server database was changed to "True".  
Be default, this parameter is set to "false". Once set to "true", the gateway will use the default method to lookup for the users.

<br />

<br />

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
