> Source: [sk90640](https://support.checkpoint.com/results/sk/sk90640)

# sk90640 - "Access denied - wrong user name or password" error in VPN client

| Property | Value |
|----------|-------|
| Solution ID | sk90640 |
| Date Created | 2013-01-10 |
| Last Modified | 2021-06-27 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * "`Negotiation with gateway `*Name_of_VPN_GW*` at site `*Name_of_VPN_Site*` has failed. Access denied - wrong user name or password`" error in VPN client.   

* SmartView Tracker shows:   

  `Reject Reason: IKE failure`  
  `
  Information: reason: Client Encryption: Could not obtain user object. Timeout reached.`   

  `Reject Reason: IKE failure`  
  `
  Information: MAC: XX-xx-xx-xx-xx-xx`  
  `
  OM: - requested address is assigned to another client`  
  `
  om_method: IP pools`   

* After repeated attempts, the VPN client is able to connect.  

* Remote users are defined on a RADIUS server when there are also LDAP servers in the setup.   

* *vpnd.elg* shows:   

  `[] fwIsakmp_Timeout: TIMEOUT ABORT: phase1state: `

## Cause

The issue results from uncoordinated timeouts. There is a hard coded timeout of 36 seconds for IKE and another configurable timeout for LDAP. The LDAP timeout is 20 seconds by default (refer to the Security Gateway's properties in SmartConsole).

The issue is that the Security Gateway tries to connect to the LDAP server several times, and therefore the IKE timeout elapses:

* If RADIUS authentication is used, the first Security Gateway tries to connect to the LDAP server(s), and only then tries to connect to the RADIUS server(s).  

* The Security Gateway waits for the response from the LDAP server(s). If the LDAP server(s) is (are) not working / non-reachable, the negotiation fails on a timeout (20 seconds is a timeout for 1 server, general timeout for IKE negotiation is 36 seconds).

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
