> Source: [sk26059](https://support.checkpoint.com/results/sk/sk26059)

# sk26059 - Mobile Access / Remote Access fail to authenticate to an LDAP server located behind a remote Security Gateway over VPN

| Property | Value |
|----------|-------|
| Solution ID | sk26059 |
| Date Created | 2004-04-29 |
| Last Modified | 2026-04-20 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |

## Symptoms

- * Mobile Access / Remote Access fails.  

* Identity Awareness / Users cannot authenticate using Captive Portal and see this error message:  
  "`Login failed. If the issue persists please contact your administrator.`"  

* When users access IPSec VPN with SecureClient / SecuRemote, a "`Wrong Username or PW`" error appears.  

* "`Test could not be completed. Check connectivity between the Management and the Gateway and try again.`"

## Cause

The problem is caused by a failure to authenticate with an LDAP address that is located behind a remote Security Gateway.  

LDAP queries are defined as connections originating at the Security gateway and destined for the LDAP server.  

When users attempt to authenticate, the remote Security Gateway sends LDAP queries to the LDAP server. These LDAP queries are considered part of Security Gateway Control Connections. Therefore, these LDAP queries are performed before any rules in the Rule Base. LDAP queries are sent in clear text.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
