sk180661 - Capsule VPN for Android / Capsule Connect for iOS / Capsule VPN Plugin for Windows loses access to internal resources
Capsule VPN for Android / Capsule Connect for iOS / Capsule VPN Plugin for Windows loses access to internal resources
Product: Mobile Access / SSL VPN, Remote Access VPN
Version: R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20
OS: Gaia
Last Modified: 2026-02-18
Symptoms
- Remote Access user loses access to internal resources after some time, but stays connected to the VPN.
- Capsule VPN for Android / Capsule Connect for iOS / Capsule VPN Plugin for Windows uses SSL to connect to the gateway.
- The realm used for authentication is different from the realm set for the user in the legacy authentication.
- Drops are seen on the gateway for vpn_inbound_tagging_ex: check_userc_tables returns -1;
If SSL is the method of connection the drop will be dropped by vpnktcpt_genpacket Reason: failed to write SSL decrypted message;"
Cause
When a Remote Access user authenticates the gateway (VPN) on the first connection, the user information is stored in the cache.
When the user information is removed from the cache, the gateway tries to lookup the user using the default realm (vpn) instead of the realm used for authentication. This causes the gateway to drop the traffic for the user.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R81.20 starting from Take 126
If you choose not to upgrade, Check Point can supply a Hotfix. Contact Check Point Support to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect CPinfo files from the Security Management Server and Security Gateways involved in the case.
Hotfix installation instructions:
Refer to sk168597 - How to install a Hotfix.
This workaround is available:
Configure the default realm (vpn) to use several fetching methods. You can use this for both Remote Access and Identity Awareness blades.
For more information, see the "My Identity Source is using both sAMAccountName and UserPrincipleName - what should I do?" section in sk149854.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2023-02-24
Last Modified: 2026-02-18