<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NPS Radius Gaia admin authenication in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107638#M14417</link>
    <description>&lt;P&gt;I’m not clear what the intended goal is here in terms of permissions.&lt;BR /&gt;Do you want the users to be “admin” level or just to be able to run certain commands?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jan 2021 17:27:50 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-01-12T17:27:50Z</dc:date>
    <item>
      <title>NPS Radius Gaia admin authenication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107620#M14413</link>
      <description>&lt;LI-SPOILER&gt;&amp;nbsp;&lt;/LI-SPOILER&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am authenticating Gaia web/ssh admins using Windows Server 2019 NPS Radius with MFA.&lt;/P&gt;&lt;P&gt;It works fine, it is possible to login and the MFA is working as well but i have issues with ssh users, it seems they do not get correct permissions.&lt;/P&gt;&lt;P&gt;The gaia config is as follows:&lt;/P&gt;&lt;P&gt;add rba role radius-group-RW domain-type System all-features&lt;/P&gt;&lt;P&gt;add aaa radius-servers priority 1 host ip_radius1 port 1812 secret ***** timeout 15&lt;BR /&gt;add aaa radius-servers priority 2 host ip_radius2 port 1812 secret ***** timeout 15&lt;BR /&gt;set aaa radius-servers NAS-IP PUBLIC_IP_OF_GW&lt;BR /&gt;set aaa radius-servers default-shell /bin/bash&lt;BR /&gt;set aaa radius-servers super-user-uid 96&lt;/P&gt;&lt;P&gt;Windows NPS Radius configured according to sk72940 (The NPS path, and also tried the Radius which had some different values.)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="radius.jpg" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10198i2CF1A0C0813D4502/image-size/large?v=v2&amp;amp;px=999" role="button" title="radius.jpg" alt="radius.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now to the problem, when admin logins with an AD (Radius) account it is not possible to run cphaprob for example.&lt;/P&gt;&lt;P&gt;[Expert@gw1:0]# cphaprob&lt;BR /&gt;-bash: cphaprob: command not found&lt;BR /&gt;[Expert@gw:0]# clish&lt;BR /&gt;gw1&amp;gt; cphaprob&lt;BR /&gt;/tmp/.CPprofile.sh: line 1: /opt/CPshrd-R80.30/scripts/cpprofile_functions.sh: Permission denied&lt;/P&gt;&lt;P&gt;gw1&amp;gt; [Expert@gw1:0]#&lt;BR /&gt;[Expert@gw1:0]#&lt;BR /&gt;[Expert@gw1:0]#&lt;BR /&gt;[Expert@gw1:0]# id&lt;BR /&gt;uid=96(_nonlocl) gid=100(users) groups=100(users)&lt;/P&gt;&lt;P&gt;Clish commands seem to run fine.&lt;/P&gt;&lt;P&gt;Gateway version is R80.30 Take 219&lt;/P&gt;&lt;P&gt;We have tried many things to overcome this issue, like changing group names etc.&lt;/P&gt;&lt;P&gt;Also changed the superuser id for radius to 0&lt;/P&gt;&lt;P&gt;set aaa radius-servers super-user-uid 0&lt;/P&gt;&lt;P&gt;But it makes no difference.&lt;/P&gt;&lt;P&gt;If i create an local user on the gw and make it member of same group as the radius users should have then it runs without issues.&lt;/P&gt;&lt;P&gt;For what i can understand, the radius user does not simply have permissions to run this command, since it is member of group 100 users.&lt;/P&gt;&lt;P&gt;-rwxr-x--- 1 admin bin 2982 Apr 30 2019 /opt/CPshrd-R80.30/scripts/cpprofile_functions.sh&lt;/P&gt;&lt;P&gt;The webgui seems to work as it should.&lt;/P&gt;&lt;P&gt;Would be grateful for any pointers or assistance here, this is a new setup so it has not worked before.&lt;/P&gt;&lt;P&gt;Thanks, Rickard&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 16:01:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107620#M14413</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-12T16:01:15Z</dc:date>
    </item>
    <item>
      <title>Re: NPS Radius Gaia admin authenication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107638#M14417</link>
      <description>&lt;P&gt;I’m not clear what the intended goal is here in terms of permissions.&lt;BR /&gt;Do you want the users to be “admin” level or just to be able to run certain commands?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 17:27:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107638#M14417</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-12T17:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: NPS Radius Gaia admin authenication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107645#M14419</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes correct, the users should be able to run all commands. Same as admin user.&lt;/P&gt;&lt;P&gt;Best Regards,Rickard&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 19:00:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107645#M14419</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-12T19:00:34Z</dc:date>
    </item>
    <item>
      <title>Re: NPS Radius Gaia admin authenication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107670#M14423</link>
      <description>&lt;P&gt;This topic is discussed here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk72940" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk72940&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 03:40:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107670#M14423</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-13T03:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: NPS Radius Gaia admin authenication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107695#M14429</link>
      <description>&lt;P&gt;Found the solution here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105575" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105575&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thanks for replying&lt;/P&gt;&lt;P&gt;Br, Rickard&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 09:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/NPS-Radius-Gaia-admin-authenication/m-p/107695#M14429</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-13T09:48:33Z</dc:date>
    </item>
  </channel>
</rss>

