> Source: [sk66087](https://support.checkpoint.com/results/sk/sk66087)

# sk66087 - Identity Agent for a Terminal Server (MUH) does not work for specific users

| Property | Value |
|----------|-------|
| Solution ID | sk66087 |
| Date Created | 2011-12-07 |
| Last Modified | 2026-06-27 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS) |

## Symptoms

- * Some users cannot authenticate with Identity Agent.
* Output of `pdp debug` shows "`data length: XXXX,exceeds the maximum of: YYYY`". Example: "`data length: 8515 ,exceeds the maximum of: 8196" line in the output of pdp debug.`"
* Identity Agent is disconnected. The Identity Agent log file *ia_client.log* shows "`404 File Not Found: The URL you requested could not be found on this server.`"
* The PDP receives a secondary session request from the same IP address. This causes the current session to log out.
* Multi User Host Agent is disconnected. The *helpdesk_Logs.txt* file shows:

  ```
  User XXXX failed to authenticate 
  Disconnected from PDP: YYYY called, with the following reason: Communication error
  ```

  The log file *ia_client_Logs.log* shows: `responseCompleted: Couldn't convert to set`
* In a rare scenario, the same issue can occur for Terminal Servers Identity Agent.
* When a user belongs to a large number of AD groups, the user cannot use Identity Agent for a Terminal Server or Identity Agent for a User Endpoint Computer to authenticate on the Security Gateway.

## Cause

The limit of CCC message size was reached. This can occur when the DC database is large.

## Solution

This problem was fixed. The fix is included starting from:

* [Check Point R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715) Customer experience this issue in R81.20 we should avoid providing specific versions in the sks as it undermines customer confidence in our knowledge base

**Important** - The fix is supported only for a clean installation of a Security Management Server / Multi-Domain Server version R81, R81.10, or R81.20. This fix is **not** supported for a Security Management Server / Multi-Domain Server that was upgraded.  

**Workaround Procedure for Versions R80.40 and Lower**   

Follow these steps:

1. Connect with SmartConsole to the Security Management Server / Domain Management Server.

2. In the top left corner, click ***Menu*** \> ***Database Revision Control*** \> create a revision snapshot.

   Note: Database Revision Control is not supported for VSX objects ([sk65420](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk65420)) and Endpoint Security Servers.

   In addition, refer to:
   * [sk108902 - Best Practices - Backup on Gaia OS](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108902)
   * [sk91400 - System Backup and Restore feature in Gaia](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk91400)
   * [sk98153 - How to take a snapshot of Endpoint Security Management Server database](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk98153)
3. Close **all** SmartConsole windows.

   Verify by running the "*cpstat mg* " command on Security Management Server / in the context of *each* Domain Management Server.
4. Connect with [GuiDBedit Tool](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk13009) to the Security Management Server / Domain Management Server.

5. In the upper left pane, go to ***Table*** \> ***Network Objects*** \> **network_objects**.

6. In the upper right pane, select the relevant Gateway or Cluster object.

7. Press CTRL+F (or go to ***Search*** menu \> ***Find*** ) \> paste **ccc_max_msg_size** \> click ***Find Next***.

8. In the lower pane, right-click on the **ccc_max_msg_size** \> select ***Edit*** \> select "***65535*** " \> click ***OK***.

9. Save the changes: go to the ***File*** menu \> click ***Save All***.

10. Close the GuiDBedit Tool.

11. Connect with SmartConsole to the Security Management Server / Domain Management Server.

12. Install the Security Policy onto the applicable Security Gateway / Cluster / VSX Virtual System object.  

13. Restart PDP process on the Gateway: `fw kill pdpd`

<br />

**Related solution** : [sk145832 - Identity Agent fails to authenticate using Kerberos SSO](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk145832)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
