> Source: [sk91844](https://support.checkpoint.com/results/sk/sk91844)

# sk91844 - Remote Access connection fails with the error "User does not belong to the remote access community" when using certificates

| Property | Value |
|----------|-------|
| Solution ID | sk91844 |
| Date Created | 2013-01-29 |
| Last Modified | 2019-09-08 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |

## Symptoms

- * When Remote Access VPN users try to connect using certificates, and the authentication is configured as defined in the user record, the connection fails with an error message:  

  `User does not belong to the remote access community`.

* After upgrading the Security Gateway from version R75.X (or lower) to version R76 (or higher), Remote Access VPN users are not associated with *generic\** profile, and instead fetched from LDAP Account Units.

* In general, if the user wants to edit where the fetch will come from, the user can set the fetch options for a specific authentication realm.

## Cause

Since R76, in order to improve the connectivity of Mobile VPN users (licensed by the Mobile Access blade), LDAP Account Units are enabled for VPN users, as well (regardless of the User Directory global property, which requires a license).

This change could result in the user's being found from the LDAP Account Units before the generic\* profile (e.g., for RADIUS users) is used.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
