<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN Authentication Failure in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137387#M20799</link>
    <description>&lt;P&gt;Email me some screenshots directly, let me check.&lt;/P&gt;</description>
    <pubDate>Wed, 29 Dec 2021 16:02:49 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-12-29T16:02:49Z</dc:date>
    <item>
      <title>Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137378#M20795</link>
      <description>&lt;P&gt;Hello Experts!&lt;/P&gt;
&lt;P&gt;We are currently experiencing issues with the Remote Access VPN. The issue is when new user is created on the existing (Working) ClientlessVPNGroup and try to connect via browser fails the login with the error: "Unknown user". T/S was made creating new users using the same default template and the same results. However when creating new user on the internal AD which is part of the same RemoteAcessVPN Community and FW Rule it authenticates without issues. Publish &amp;amp; Install and Install Database was properly done.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Current environment:&lt;BR /&gt;SMS r81.10 (Was upgraded like 19 days ago from r80.30 to r81.10 and everything was seamlessly working until yesterday. &lt;BR /&gt;Cluster (2 Gateways) running r80.30&lt;/P&gt;
&lt;P&gt;Only change that was made yesterday was on the default template object witch is included on the uploaded file. I Appreciate any tips or suggestions on this issue. &lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 15:51:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137378#M20795</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-29T15:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137383#M20796</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Did you make sure user belongs to the group allowed to access stuff via remote access community?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 15:59:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137383#M20796</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T15:59:17Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137384#M20797</link>
      <description>&lt;P&gt;Yeah brother!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:00:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137384#M20797</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-29T16:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137386#M20798</link>
      <description>&lt;P&gt;Normally, if you add user via AD, say if you have radius auth (just as an example) and AD integrated via dashboard, sometimes you may need to push policy to reflect the changes, though in most cases, it would reflect right away.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137386#M20798</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T16:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137387#M20799</link>
      <description>&lt;P&gt;Email me some screenshots directly, let me check.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:02:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137387#M20799</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T16:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137391#M20800</link>
      <description>&lt;P&gt;Yeah push policy was done with new AD user and worked but the issue at the moment is presented when creating new local users, current existing local users on the same group are working.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:13:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137391#M20800</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-29T16:13:59Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137392#M20801</link>
      <description>&lt;P&gt;Done buddy!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:14:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137392#M20801</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-29T16:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137393#M20802</link>
      <description>&lt;P&gt;K, just send zoom or webex, I think I can figure this out quick...Im sure its some minor misconfiguration.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137393#M20802</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T16:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137394#M20803</link>
      <description>&lt;P&gt;Done&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:21:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137394#M20803</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-29T16:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137397#M20804</link>
      <description>&lt;P&gt;Sounds suspiciously similar to the following, what happens if you set the template expiration date to 2029 instead of 2030 and then create a user with it?&lt;/P&gt;
&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk167103&amp;amp;partition=Advanced&amp;amp;product=SmartConsole" target="_blank"&gt;sk167103: Expiration Date configured to after 2030 is considered as expired&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 16:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137397#M20804</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-12-29T16:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137405#M20808</link>
      <description>&lt;P&gt;Thanks for the suggestion &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; will try that and keep you guys posted of the results.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 17:49:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137405#M20808</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-29T17:49:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137406#M20809</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;...I just did remote with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/64197"&gt;@K_montalvo&lt;/a&gt;&amp;nbsp;and since we could not look at the actual environment, we went through some basic setup on lab mgmt and I also saw that for one customer I always help with, any local vpn users are by default set to same date (December 31st, 2030) and works fine. I believe sk you mentioned strictly references to new admin, as "never" option is not there for vpn user. Either way, I asked Kenny to try change it to say 2025 and see if it makes any difference. Personally, though I showed him the option for mobile access via blades (under manage and settings), considering this is the only user with a problem, does not logically sound like its an issue with the MA blade configuration. Regardless, they will test all we discuss and update us.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 17:58:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137406#M20809</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-29T17:58:20Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137461#M20818</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt; I was able to do T/S today and posibbly identified the issue:&lt;/P&gt;
&lt;P&gt;What we are seeing is and error when the Standard Access Policy installation could that be the issue? If so can you guys guide me if theres a command to fix it or steps i shall follow to resolved the issue?&lt;/P&gt;
&lt;P&gt;I really appreciate your help!&lt;/P&gt;
&lt;P&gt;Thanks!&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/14733i7C68FBFE1E76972C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot.PNG" alt="Screenshot.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 15:46:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137461#M20818</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-30T15:46:29Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137462#M20819</link>
      <description>&lt;P&gt;Sounds like the ranges specified in the Translated Source field are incorrectly set for static instead of hide.&amp;nbsp; You can right-click in that field and force it to Hide.&amp;nbsp; If this is not the case please post a screenshot of the NAT rules in question.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 15:51:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137462#M20819</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2021-12-30T15:51:45Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137463#M20820</link>
      <description>&lt;P&gt;Hey buddy,&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;is absolutely right. Sounds like nat method is wrong if thats the message you are seeing. Can you paste actual NAT rule?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 15:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137463#M20820</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-30T15:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137472#M20825</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This was actually the issue with a source network with a /16 translated to a /24 on a couple of NAT rules created a couple years ago. Somehow they started to present the issue recently. The TAC was also very helpful.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 19:05:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137472#M20825</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-30T19:05:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137473#M20826</link>
      <description>&lt;P&gt;Hello buddy,&lt;/P&gt;
&lt;P&gt;Yeah what &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp; posted above was the issue. I know if in the remote session yesterday with you had access to the actual environment you would figure it out. Many thanks as always for your support and friendship!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 19:07:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137473#M20826</guid>
      <dc:creator>K_montalvo</dc:creator>
      <dc:date>2021-12-30T19:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Authentication Failure</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137474#M20827</link>
      <description>&lt;P&gt;Any time, no problem at all.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;is the man, I think he knows everything CP related, so always amazing resource.&lt;/P&gt;
&lt;P&gt;HAPPY NEW YEAR!&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 19:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-Access-VPN-Authentication-Failure/m-p/137474#M20827</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-12-30T19:09:14Z</dc:date>
    </item>
  </channel>
</rss>

