<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Strange R81.20 web UI issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166018#M29832</link>
    <description>&lt;P&gt;Logs I see. Weird thing is, I dont even have any radius users, just a local admin user tryng to log in...&lt;/P&gt;
&lt;P&gt;Dec 24 22:04:12 2022 QUANTUM-GATEWAY clish[18759]: cmd by admin: Start executing&lt;BR /&gt;: exit (cmd md5: f24f62eeb789199b9b2e467df3b1876b)&lt;BR /&gt;Dec 24 22:04:12 2022 QUANTUM-GATEWAY xpand[10811]: admin localhost t -volatile:c&lt;BR /&gt;lish:admin:18759&lt;BR /&gt;Dec 24 22:04:12 2022 QUANTUM-GATEWAY clish[18759]: User admin logged out from C&lt;BR /&gt;LI shell&lt;BR /&gt;Dec 24 22:04:43 2022 QUANTUM-GATEWAY xpand[10811]: admin localhost t +volatile:c&lt;BR /&gt;lish:admin:18874 t&lt;BR /&gt;Dec 24 22:04:43 2022 QUANTUM-GATEWAY clish[18874]: User admin logged in with Rea&lt;BR /&gt;dWrite permission&lt;BR /&gt;Dec 24 22:04:45 2022 QUANTUM-GATEWAY clish[18874]: cmd by admin: Start executing&lt;BR /&gt;: expert (cmd md5: b9b83bad6bd2b4f7c40109304cf580e1)&lt;BR /&gt;Dec 24 22:04:45 2022 QUANTUM-GATEWAY clish[18874]: cmd by admin: Processing : ex&lt;BR /&gt;pert (cmd md5: b9b83bad6bd2b4f7c40109304cf580e1)&lt;BR /&gt;Dec 24 22:05:18 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 24 22:05:21 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;Dec 24 22:11:03 2022 QUANTUM-GATEWAY pm[10793]: Restarted /rest_api/scripts/rest&lt;BR /&gt;_api_docs[19682], count=55&lt;BR /&gt;Dec 24 22:11:03 2022 QUANTUM-GATEWAY pm[19682]: init LD_LIBRARY_PATH for /rest_a&lt;BR /&gt;pi/scripts/rest_api_docs&lt;BR /&gt;Dec 24 22:11:04 2022 QUANTUM-GATEWAY pm[10793]: Reaped: rest_api_docs[19682]&lt;BR /&gt;Dec 24 22:11:04 2022 QUANTUM-GATEWAY pm[10793]: Scheduled rest_api_docs for +900&lt;BR /&gt;secs&lt;BR /&gt;Dec 24 22:23:25 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 24 22:23:27 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;[Expert@QUANTUM-GATEWAY:0]#&lt;/P&gt;</description>
    <pubDate>Sun, 25 Dec 2022 03:39:05 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-12-25T03:39:05Z</dc:date>
    <item>
      <title>Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166005#M29827</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I know holidays are here, so I dont expect response any time soon, but wanted to mention super odd R81.20 web UI behavior I encountered in the lab and see if anyone may have an idea how to fix this. So, yesterday, I tried to log in to web UI (which I had many times since I created the lab few weeks ago) and noticed it kept saying "permission denied". Now, I use exact same password in my lab for regular shell and expert mode, so password was 100% right, as ssh worked just fine.&lt;/P&gt;
&lt;P&gt;I then followed below link, no luck.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://pingtool.org/adding-new-admin-user-to-checkpoint-gaia-with-expert-permissions/" target="_blank" rel="noopener"&gt;https://pingtool.org/adding-new-admin-user-to-checkpoint-gaia-with-expert-permissions/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I also tried from clich -&amp;gt; set user admin password&lt;/P&gt;
&lt;P&gt;That asked me to enter new pass, which I did, save config, no luck. Any idea why this would happen at all? I even tried rebooting, same issue.&lt;/P&gt;
&lt;P&gt;Keep in mind, there was absolutely no changes done at all to this firewall in last 10 days and I logged into web UI many times in that time period.&lt;/P&gt;
&lt;DIV id="tinyMceEditorthe_rock_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18900iED1883BFB95770B0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Happy holidays everyone!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 24 Dec 2022 14:40:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166005#M29827</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-24T14:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166018#M29832</link>
      <description>&lt;P&gt;Logs I see. Weird thing is, I dont even have any radius users, just a local admin user tryng to log in...&lt;/P&gt;
&lt;P&gt;Dec 24 22:04:12 2022 QUANTUM-GATEWAY clish[18759]: cmd by admin: Start executing&lt;BR /&gt;: exit (cmd md5: f24f62eeb789199b9b2e467df3b1876b)&lt;BR /&gt;Dec 24 22:04:12 2022 QUANTUM-GATEWAY xpand[10811]: admin localhost t -volatile:c&lt;BR /&gt;lish:admin:18759&lt;BR /&gt;Dec 24 22:04:12 2022 QUANTUM-GATEWAY clish[18759]: User admin logged out from C&lt;BR /&gt;LI shell&lt;BR /&gt;Dec 24 22:04:43 2022 QUANTUM-GATEWAY xpand[10811]: admin localhost t +volatile:c&lt;BR /&gt;lish:admin:18874 t&lt;BR /&gt;Dec 24 22:04:43 2022 QUANTUM-GATEWAY clish[18874]: User admin logged in with Rea&lt;BR /&gt;dWrite permission&lt;BR /&gt;Dec 24 22:04:45 2022 QUANTUM-GATEWAY clish[18874]: cmd by admin: Start executing&lt;BR /&gt;: expert (cmd md5: b9b83bad6bd2b4f7c40109304cf580e1)&lt;BR /&gt;Dec 24 22:04:45 2022 QUANTUM-GATEWAY clish[18874]: cmd by admin: Processing : ex&lt;BR /&gt;pert (cmd md5: b9b83bad6bd2b4f7c40109304cf580e1)&lt;BR /&gt;Dec 24 22:05:18 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 24 22:05:21 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;Dec 24 22:11:03 2022 QUANTUM-GATEWAY pm[10793]: Restarted /rest_api/scripts/rest&lt;BR /&gt;_api_docs[19682], count=55&lt;BR /&gt;Dec 24 22:11:03 2022 QUANTUM-GATEWAY pm[19682]: init LD_LIBRARY_PATH for /rest_a&lt;BR /&gt;pi/scripts/rest_api_docs&lt;BR /&gt;Dec 24 22:11:04 2022 QUANTUM-GATEWAY pm[10793]: Reaped: rest_api_docs[19682]&lt;BR /&gt;Dec 24 22:11:04 2022 QUANTUM-GATEWAY pm[10793]: Scheduled rest_api_docs for +900&lt;BR /&gt;secs&lt;BR /&gt;Dec 24 22:23:25 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 24 22:23:27 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;[Expert@QUANTUM-GATEWAY:0]#&lt;/P&gt;</description>
      <pubDate>Sun, 25 Dec 2022 03:39:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166018#M29832</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-25T03:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166035#M29841</link>
      <description>&lt;P&gt;This is what I find most confusing. So file "server" in /etc/rdddb and /etc/tacdb directories , is exactly the same as on brand new R81.20 install and even in working R81.10, but same issue persists...honestly, makes no sense to me and Im not sure why it keeps giving the error below when I try to log into web UI. Even gave it permissions 0600 as indicated inside of file itself, but same problem.&lt;/P&gt;
&lt;P&gt;Dec 25 21:27:07 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 25 21:27:09 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;Dec 25 21:29:25 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 25 21:29:27 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;Dec 25 21:31:33 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 25 21:31:35 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;Dec 25 21:36:26 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 25 21:36:29 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;Dec 25 21:39:28 2022 QUANTUM-GATEWAY httpauth: pam_radius_auth: Could not open c&lt;BR /&gt;onfiguration file /etc/raddb/server: Permission denied&lt;BR /&gt;Dec 25 21:39:31 2022 QUANTUM-GATEWAY httpd2: HTTP login denied from 172.16.10.10&lt;BR /&gt;3 for admin&lt;BR /&gt;[Expert@QUANTUM-GATEWAY:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 03:05:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166035#M29841</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-26T03:05:18Z</dc:date>
    </item>
    <item>
      <title>Re: Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166037#M29843</link>
      <description>&lt;P&gt;Bug for sure?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 02:43:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166037#M29843</guid>
      <dc:creator>Blason_R</dc:creator>
      <dc:date>2022-12-26T02:43:34Z</dc:date>
    </item>
    <item>
      <title>Re: Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166039#M29845</link>
      <description>&lt;P&gt;I dont know mate, worked fine for about a month and stopped without any changes...I dont get it. Lets see if our friend from Israel&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/14307"&gt;@Ilya_Yusupov&lt;/a&gt;&amp;nbsp;will be able to do his magic with this : - )&lt;/P&gt;
&lt;P&gt;Merry Christmas by the way!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Dec 2022 13:00:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166039#M29845</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-26T13:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166149#M29881</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;The given print is not related to WEBUI login by local user&lt;/P&gt;
&lt;P&gt;As you were able to login by SSH it means your password wasn’t denied by several unauthorized attempts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We couldn’t replicate this in-house, I would like to ask for 2 things:&lt;/P&gt;
&lt;P&gt;Are you able to connect with a different user?&lt;/P&gt;
&lt;P&gt;Would it be possible to have remote session to see this thru with you?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 13:04:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166149#M29881</guid>
      <dc:creator>Ambar</dc:creator>
      <dc:date>2022-12-27T13:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166150#M29882</link>
      <description>&lt;P&gt;Sure! Im free Wednesday any time.Btw, if you read my initial post, link I gave gives steps to give full admin permissions to a user, but no luck. That tells me its something fw, not user related, but we can check on remote session, that sounds good!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 27 Dec 2022 13:14:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166150#M29882</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-27T13:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Strange R81.20 web UI issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166266#M29911</link>
      <description>&lt;P&gt;Thanks to Gilad and the guys in Israel for having remote session with me. We narrowed down that last time web UI worked was December 14th, when ISPR cpisp_update file was modified for issue customer was having (I replaced the actual file with one provided to me from R&amp;amp;D in the lab). Not sure how that broke web UI, but seems that it did. Anyway, since we could not fix it even after removing ispr config and also putting back old cpisp_update file, I decided to totally reinstall, which fixed the issue. One thing I found super odd is that ever time I tried deleting 2 ISP links on gateway object, would remove them, then I publish, go back and they were still there. I also tried removing any references of them in guidbedit, but could not locate them anywhere. Either way, easier to just reinstall : - )&lt;/P&gt;
&lt;P&gt;Thanks again guys and happ holidays!&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 18:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Strange-R81-20-web-UI-issue/m-p/166266#M29911</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-28T18:48:35Z</dc:date>
    </item>
  </channel>
</rss>

