> Source: [sk93625](https://support.checkpoint.com/results/sk/sk93625)

# sk93625 - UDP 5500 (RSA/ACE/SecurID) packets are sent with wrong source IP

| Property | Value |
|----------|-------|
| Solution ID | sk93625 |
| Date Created | 2013-07-22 |
| Last Modified | 2020-12-06 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * SecurID authentication fails on all clients for all users.  

* fw monitor shows that port 5500 traffic from the gateway to the ACE server leaves with a source IP address different than the one defined on the ACE server as the gateway  

* Firewall log entries shows "Access denied - wrong username or password"

## Cause

Once the *sdconf.rec* file is generated from the ACE/Server and saved in */var/ace/sdconf.rec*, the gateway acts as an ACE/Agent 5.0 and directs all access requests to the RSA ACE/server for authentication.

The destination IP address is determined by the information in *sdconf.rec*. The source IP address is determined by the OS routing/NAT/cluster configuration/VSX configuration. This solution highlights configurations that should be taken into account to get the desired source IP, i.e. the one defined as the primary address of the Security Gateway on the ACE/Server.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
