<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness not authentic user through identity agent with Radius in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153166#M25685</link>
    <description>&lt;P&gt;Thanks Chris&lt;/P&gt;&lt;P&gt;This make sense.&lt;/P&gt;&lt;P&gt;Just one problem, I am not able to specific user directory in IA authentication setting, no +/-. BTW, my firewall and smartconsole are version 81.10&lt;/P&gt;</description>
    <pubDate>Sun, 17 Jul 2022 21:17:07 GMT</pubDate>
    <dc:creator>FrankXie</dc:creator>
    <dc:date>2022-07-17T21:17:07Z</dc:date>
    <item>
      <title>Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153059#M25648</link>
      <description>&lt;P&gt;Hello Expert&lt;/P&gt;&lt;P&gt;I am trying to setup identity awareness in my environment. But somehow I found my secureGateway never send radius authentication to my configured authentication server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I always get this error&lt;/P&gt;&lt;P&gt;An error was detected while trying to authenticate against the AD server.&lt;BR /&gt;It may be a problem of bad configuration or connectivity.&lt;BR /&gt;Please refer to the troubleshooting guide for more help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Turning on pdp debug I can only find&amp;nbsp;[15 Jul 13:40:34] [RADIUS (TD::Events)] pdp::PDPRadiusManager::~PDPRadiusManager: enter d'tor about radius.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCPDUMP can't capture any packet with filter "port 1812".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 01:59:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153059#M25648</guid>
      <dc:creator>FrankXie</dc:creator>
      <dc:date>2022-07-15T01:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153068#M25652</link>
      <description>&lt;P&gt;Can you describe the flow in more detail?&lt;/P&gt;
&lt;P&gt;Typically Identity Awareness integration based on Radius would be looking at Radius Accounting 1813.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 08:13:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153068#M25652</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-15T08:13:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153073#M25654</link>
      <description>&lt;P&gt;Thanks Chris&lt;/P&gt;&lt;P&gt;The first flow is download identity agent through portal after authenticate through ldap server which works fine and I also think it is not relevant.&lt;/P&gt;&lt;P&gt;Second flow is getting identity information through connecting identity agent. It is using user name and password authentication through radius server. Actually I am quite understand how this works because I don’t know there’s any group information in radius response. Anyway I got that error message and with pdp debug I can see it querying ad server but not sending authentication. Would it because my test account not in any ad server? And does it mean pdp query ad server to get identity information before sending radius authentication?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Frank&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 08:51:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153073#M25654</guid>
      <dc:creator>FrankXie</dc:creator>
      <dc:date>2022-07-15T08:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153102#M25663</link>
      <description>&lt;P&gt;The relationship between the User Directories &amp;amp; Authentication is referenced in the admin guide, the user has to exist somewhere in a repository before it is authenticated.&lt;/P&gt;
&lt;P&gt;Refer: Authentication Settings &amp;gt; User Directories&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Configuring-Identity-Agents-Configuring-Identity-Agents-in-SmartConsole.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Configuring-Identity-Agents-Configuring-Identity-Agents-in-SmartConsole.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2022 14:09:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153102#M25663</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-15T14:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153166#M25685</link>
      <description>&lt;P&gt;Thanks Chris&lt;/P&gt;&lt;P&gt;This make sense.&lt;/P&gt;&lt;P&gt;Just one problem, I am not able to specific user directory in IA authentication setting, no +/-. BTW, my firewall and smartconsole are version 81.10&lt;/P&gt;</description>
      <pubDate>Sun, 17 Jul 2022 21:17:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153166#M25685</guid>
      <dc:creator>FrankXie</dc:creator>
      <dc:date>2022-07-17T21:17:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153173#M25687</link>
      <description>&lt;P&gt;If you have the user directories such as an LDAP Account Unit already defined it should allow you to select it, if you need specific configuration for this gateway/cluster versus global. With that said their does appear to be a glitch in the UI when comparing the screens below as the +/- buttons aren't shown. Please report this to TAC if it's critical for your setup and I will also follow-up internally.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Identity Agent&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Directories.png" style="width: 980px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17204i6F8AAE6C65E53141/image-size/large?v=v2&amp;amp;px=999" role="button" title="Directories.png" alt="Directories.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Browser Based&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Browser.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17205iEE8929C89951AE07/image-size/large?v=v2&amp;amp;px=999" role="button" title="Browser.png" alt="Browser.png" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 01:53:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153173#M25687</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-18T01:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153326#M25716</link>
      <description>&lt;P&gt;Check the Windows magnification level is not different than 100% [Display &amp;gt; Scale and layout] and it should work around the UI glitch in the interim.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 23:26:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153326#M25716</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-19T23:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153436#M25745</link>
      <description>&lt;P&gt;Thanks Chris&lt;/P&gt;&lt;P&gt;Sorry for the late reply.&lt;/P&gt;&lt;P&gt;I am talking about identity agent authentication.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Change display scale not help. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 744px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17253i048E8904FD3D1A8E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 20:54:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153436#M25745</guid>
      <dc:creator>FrankXie</dc:creator>
      <dc:date>2022-07-19T20:54:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153442#M25748</link>
      <description>&lt;P&gt;Did you relaunch the application after changing the scale setting? (It corrected the issue in my testing).&lt;/P&gt;
&lt;P&gt;If the issue persists and or the "All Gateways Directories" option isn't suitable in your case please contact TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 06:25:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153442#M25748</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-07-20T06:25:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not authentic user through identity agent with Radius</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153444#M25749</link>
      <description>&lt;P&gt;you absolutely right, relaunch application after changing display scale +/- shows. Thanks a lot, you really a expert.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 07:16:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-not-authentic-user-through-identity-agent/m-p/153444#M25749</guid>
      <dc:creator>FrankXie</dc:creator>
      <dc:date>2022-07-20T07:16:07Z</dc:date>
    </item>
  </channel>
</rss>

