> Source: [sk183456](https://support.checkpoint.com/results/sk/sk183456)

# sk183456 - Capsule VPN SAML Authentication Fails on Second and Subsequent Connection Attempts

| Property | Value |
|----------|-------|
| Solution ID | sk183456 |
| Date Created | 2025-05-25 |
| Last Modified | 2025-05-26 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Android |

## Symptoms

- * When the user connects to the Capsule Connect VPN for the first time, everything works - inserting the site FQDN and getting redirected to IDP login, inserting all credentials results in a working connection. However, the second time, no FQDN insert is required, so when pressing the 'Connect' button, the Capsule app has a redirection issue:  
  **net::ERR_HTTP_RESPONSE_CODE_FAILURE**  
* Deleting the cache and app data as well as reinstalling the app brings back the cycle of first successful connection and later the failed scenario of all other connections after the first one.  
* `error_log` file from SAML debug reveals the following signature:  
  **SimpleSAML\\Assert\\AssertionFailedException: Expected an instance of SimpleSAML\\Session**  
* These errors appear in the client side logs (Logs from Capsule VPN):  
  `03-26 18:25:44.110 6269 4159 D NEMO.D 18:25:44.110 3728c80 ccc_server_rc_to_error: `**CCC_CLIENT_BAD_FORMAT**   
  `
  03-26 18:25:44.111 6269 4159 E NEMO.E 18:25:44.110 3728c80 auth failed`  
  `
  03-26 18:25:44.111 6269 4158 D NEMO.In Service main: cancel took 0 seconds`  
  `
  03-26 18:25:44.111 6269 4158 D NEMO.In Service Main: finished handling DISCONNECT request`  
  `
  03-26 18:25:44.111 6269 2 D NEMO.SyncController::handleMessage: got msg from service: type = CANCEL`  
  `
  03-26 18:25:44.111 6269 2 W NEMO.SyncController::handleMessage: no listener registered to handle the reply`  
  `
  03-26 18:25:44.111 6269 4159 E NEMO.E 18:25:44.110 3728c80 auth: ccc_auth_step failed: `**This authentication operation is not supported (1100)**   
  `
  03-26 18:25:44.111 6269 4159 E NEMO.E 18:25:44.110 3728c80 auth: set error: `**This authentication operation is not supported**   
  `
  03-26 18:25:44.112 6269 4159 E NEMO.E 18:25:44.110 3728c80 ccchl_connect: iterate failed`  
  `
  03-26 18:25:44.112 6269 4159 D NEMO.D 18:25:44.110 3728c80 stop: called`  
  `
  03-26 18:25:44.112 6269 4159 D NEMO.D 18:25:44.110 6269 ccc_enable_io: called`  
  `
  03-26 18:25:44.112 6269 4159 D NEMO.D 18:25:44.110 6269 ccc_destroy: called`  
  `
  03-26 18:25:44.112 6269 4159 D NEMO.D 18:25:44.111 6269 stop: called`  
  `
  03-26 18:25:44.112 6269 4159 D NEMO.D 18:25:44.111 6269 stop: called`

## Cause

Error in loading values from the `idp_session_table_sslvpn` table.

## Solution

[Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
