> Source: [sk97806](https://support.checkpoint.com/results/sk/sk97806)

# sk97806 - Mobile Access LDAP user fails to connect or is not matched to a relevant policy rule

| Property | Value |
|----------|-------|
| Solution ID | sk97806 |
| Date Created | 2013-12-22 |
| Last Modified | 2013-12-31 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * A single LDAP user defined in Mobile Access policy with the '`Picker`', fails to connect or is not matched to the relevant rule (in which this user is defined).  

* Same issue may occur with an LDAP group added via the '`Picker`' (automatically added from the policy - not via legacy LDAP group) - users are not matched to the relevant rule, despite being members of the group in LDAP.  

* *Example:*

  ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk97806/sk97806_all_ldap_grp.png)

## Cause

The user or group were moved in the LDAP tree.

When the 'Picker' in Mobile Access policy automatically creates the user or the group, it saves it with its current DN in LDAP.

If the user or the group are moved in the LDAP database, then they will no longer be matched to the relevant rule.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
