<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint denies connection even after Push Approval in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179018#M32805</link>
    <description>&lt;P&gt;Did you disable some of the implied rules, by any chance?&lt;/P&gt;</description>
    <pubDate>Tue, 25 Apr 2023 07:23:45 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2023-04-25T07:23:45Z</dc:date>
    <item>
      <title>CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178943#M32787</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;we are implementing DUO MFA für CheckPoint 80.40 (we can't upgrade to the last version right now).&lt;/P&gt;&lt;P&gt;In our test environment everythig works good, but in the production environment&amp;nbsp;we faced an issue: even after connection was Approved in DUO App the CheckPorint VPN Client tells us: access denied - wrong credentials&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rad1.png" style="width: 766px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20604i373B6E1DC850972C/image-size/large?v=v2&amp;amp;px=999" role="button" title="rad1.png" alt="rad1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In DUO Proxy we don't see any denies:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2023-04-24T15:20:59.251297+0200 [duoauthproxy.lib.log#info] Sending request from CheckPoint_10.10.10.1 to radius_server_auto
2023-04-24T15:20:59.252485+0200 [duoauthproxy.lib.log#info] Received new request id 170 from ('CheckPoint_10.10.10.1', 47357)
2023-04-24T15:20:59.252921+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): login attempt for username 'test.vpn.mfa'
2023-04-24T15:20:59.253716+0200 [duoauthproxy.lib.log#info] Sending request for user 'test.vpn.mfa' to ('NPS_10.20.20.2', 1812) with id 106
2023-04-24T15:20:59.263847+0200 [duoauthproxy.lib.log#info] Got response for id 106 from ('NPS_10.20.20.2', 1812); code 2
2023-04-24T15:20:59.265053+0200 [duoauthproxy.lib.log#info] http POST to https://*****.duosecurity.com:443/rest/v1/preauth
2023-04-24T15:20:59.267428+0200 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Starting factory &amp;lt;_DuoHTTPClientFactory: b'https://*****.duosecurity.com:443/rest/v1/preauth'&amp;gt;
2023-04-24T15:20:59.395863+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Got preauth result for: 'auth'
2023-04-24T15:20:59.396312+0200 [duoauthproxy.lib.log#info] User IP not provided. Authorized Networks policies will not work for this authentication.
2023-04-24T15:20:59.396768+0200 [duoauthproxy.lib.log#info] http POST to https://*****.duosecurity.com:443/rest/v1/auth
2023-04-24T15:20:59.398511+0200 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Starting factory &amp;lt;_DuoHTTPClientFactory: b'https://*****.duosecurity.com:443/rest/v1/auth'&amp;gt;
2023-04-24T15:20:59.399225+0200 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Stopping factory &amp;lt;_DuoHTTPClientFactory: b'https://*****.duosecurity.com:443/rest/v1/preauth'&amp;gt;
2023-04-24T15:21:03.566848+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Duo authentication returned 'allow': 'Success. Logging you in...'
2023-04-24T15:21:03.568360+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Returning response code 2: AccessAccept
2023-04-24T15:21:03.568630+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Sending response
2023-04-24T15:21:03.568928+0200 [duoauthproxy.lib.http._DuoHTTPClientFactory#info] Stopping factory &amp;lt;_DuoHTTPClientFactory: b'https://*****.duosecurity.com:443/rest/v1/auth'&amp;gt;
2023-04-24T15:21:04.250528+0200 [duoauthproxy.lib.log#info] Sending request from CheckPoint_10.10.10.1 to radius_server_auto
2023-04-24T15:21:04.250895+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Received duplicate request
2023-04-24T15:21:04.251783+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Sending response
2023-04-24T15:21:09.250644+0200 [duoauthproxy.lib.log#info] Sending request from CheckPoint_10.10.10.1 to radius_server_auto
2023-04-24T15:21:09.250987+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Received duplicate request
2023-04-24T15:21:09.252491+0200 [duoauthproxy.lib.log#info] (('CheckPoint_10.10.10.1', 47357), test.vpn.mfa, 170): Sending response&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TCP Dump shows that Radius answeres:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;14:50:29.972117 IP DUO_10.10.10.22.datametrics &amp;gt; CheckPoint_10.10.10.1.57779: RADIUS, Access-Accept (2), id: 0xa4 length: 222
14:50:30.484452 IP CheckPoint_10.10.10.1.57779 &amp;gt; DUO_10.10.10.22.datametrics: RADIUS, Access-Request (1), id: 0xa4 length: 128
14:50:30.485961 IP DUO_10.10.10.22.datametrics &amp;gt; CheckPoint_10.10.10.1.57779: RADIUS, Access-Accept (2), id: 0xa4 length: 222
14:50:35.484615 IP CheckPoint_10.10.10.1.57779 &amp;gt; DUO_10.10.10.22.datametrics: RADIUS, Access-Request (1), id: 0xa4 length: 128
14:50:35.485912 IP DUO_10.10.10.22.datametrics &amp;gt; CheckPoint_10.10.10.1.57779: RADIUS, Access-Accept (2), id: 0xa4 length: 222&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have already tried following, but nothing helped:&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk117615" target="_blank" rel="noopener"&gt;Users defined for both LDAP and RADIUS fail to authenticate via RADIUS and their connection is dropped with a "wrong username or password" error (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk115355" target="_blank" rel="noopener"&gt;One Time Password (OTP) authentication fails with session timeout for Radius (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sk112933&lt;/STRONG&gt; is no more avaliable...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;very appreciated for any ideas!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 15:14:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178943#M32787</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-24T15:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178964#M32790</link>
      <description>&lt;P&gt;additional Info: CP FW has several Interfaces.&lt;/P&gt;&lt;P&gt;10.10.10.1 interface there the Duo Server is connected to.&lt;/P&gt;&lt;P&gt;172.16.16.1 interface we use for FW management...&lt;/P&gt;&lt;P&gt;I've collected a tcpdump and found follwing:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rad2.png" style="width: 654px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20609iFA9F6FC3D5C53854/image-size/large?v=v2&amp;amp;px=999" role="button" title="rad2.png" alt="rad2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;why in AVP we see mangt-IP? &lt;/STRONG&gt;this IP isn't configured in DUO and it will never answer to this IP&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 15:17:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178964#M32790</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-24T15:17:58Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178968#M32792</link>
      <description>&lt;P&gt;Can you try zdebug ONLY for port 1812 and see if anything comes up?&lt;/P&gt;
&lt;P&gt;fw ctl zdebug + drop | grep "1812"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 16:51:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178968#M32792</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-24T16:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178990#M32795</link>
      <description>&lt;P&gt;The IP of the interface which is needed to communicate with the RADIUS server will be used to originate the connections.&lt;BR /&gt;That won’t necessarily be your management IP.&lt;/P&gt;
&lt;P&gt;Having said that, I am curious: what precise IP are you using in SmartConsole for the relevant gateway?&lt;BR /&gt;Does it match the NAS IP in your tcpdump?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 23:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178990#M32795</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-24T23:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178992#M32796</link>
      <description>&lt;P&gt;Which endpoint vpn client version are you using out of interest and what Jumbo for R80.40?&lt;/P&gt;
&lt;P&gt;Does the following link work for you?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112933&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank" rel="noopener"&gt;sk112933: Endpoint Security VPN client timeout reached during the time that a third-party server is handling Multifactor Authentication (MFA)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 01:34:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/178992#M32796</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-25T01:34:38Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179014#M32804</link>
      <description>&lt;P&gt;Management IP: 172.16.16.1&lt;BR /&gt;Interface IP (Gateway for DUO Server): 10.10.10.1&lt;/P&gt;&lt;P&gt;It matches in the fields SRC/DST, but doesn't in RADIUS Data&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 06:24:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179014#M32804</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T06:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179018#M32805</link>
      <description>&lt;P&gt;Did you disable some of the implied rules, by any chance?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 07:23:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179018#M32805</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-04-25T07:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179030#M32806</link>
      <description>&lt;P&gt;no, we don't see any drops. Will do debug right now&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:00:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179030#M32806</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T08:00:29Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179031#M32807</link>
      <description>&lt;P&gt;on the MNGT Server Jumbo ist 180, and there is no Jumbo on Security Gateway&lt;/P&gt;&lt;P&gt;We changed timeouts, now we receive two Duo Pushes, but still no connection&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:08:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179031#M32807</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T08:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179032#M32808</link>
      <description>&lt;P&gt;Running without a jumbo isn't best practice given the age of R80.40 and how about the clients?&lt;/P&gt;
&lt;P&gt;Did you already allow/configure the NAS IP that you see in DUO?&lt;/P&gt;
&lt;P&gt;Which interface is the DUO server routed via?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 09:08:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179032#M32808</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-25T09:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179034#M32809</link>
      <description>&lt;P&gt;neither&amp;nbsp;fw ctl zdebug + drop | grep "&lt;STRONG&gt;1812&lt;/STRONG&gt;" nor&amp;nbsp;fw ctl zdebug + drop | grep "&lt;STRONG&gt;1645&lt;/STRONG&gt;" dropps anything&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:13:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179034#M32809</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T08:13:09Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179035#M32810</link>
      <description>&lt;P&gt;I found this article:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R80.20.40/CLI/Topics/set-global-radius-conf.htm?tocpath=Configuring%20NAS%20IP%20Address%20for%20RADIUS%20server|_____1" target="_blank"&gt;set global-radius-conf (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but how can check what is set &lt;STRONG&gt;right now&lt;/STRONG&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:14:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179035#M32810</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T08:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179036#M32811</link>
      <description>&lt;P&gt;First to confirm relevance of that document, what model is your gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:17:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179036#M32811</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-25T08:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179037#M32812</link>
      <description>&lt;P&gt;Try doing the same with grepping by the Radius server IP address. Also, check that the communication is actually getting back to the FW from your server. To do so, run fw monitor -e "host(Radius IP);"&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:18:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179037#M32812</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-04-25T08:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179040#M32813</link>
      <description>&lt;P&gt;not&amp;nbsp;&lt;SPAN&gt;Quantum Spark... Just a VM on VMWare&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:36:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179040#M32813</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T08:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179042#M32814</link>
      <description>&lt;P&gt;I don't see anything!&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@fw-outside:0]# fw monitor -e "host(10.10.10.22);"
PPAK 0: Get before set operation succeeded of fwmonitor_kiss_enable
PPAK 0: Get before set operation succeeded of simple_debug_filter_off
PPAK 0: Get before set operation succeeded of kiss_debug_force_kdprintf_enable
PPAK 0: Get before set operation succeeded of fwmonitorfreebufs
************************************************************** NOTE **************************************************************
*** Using "-e" filter will not monitor accelerated traffic. To monitor and filter accelerated traffic please use the "-F" filter ***
************************************************************************************************************************************
FW monitor will record only ip &amp;amp; transport layers in a packet
For capturing the whole packet please do -w
PPAK 0: Get before set operation succeeded of fwmonitor_ppak_all_position
monitor: getting filter (from command line)
monitor: compiling
monitorfilter:
Compiled OK.
monitor: loading
monitor: monitoring (control-C to stop)
PPAK 0: Get before set operation succeeded of fwmonitormaxpacket
PPAK 0: Get before set operation succeeded of fwmonitormask
PPAK 0: Get before set operation succeeded of fwmonitorallocbufs
PPAK 0: Get before set operation succeeded of printuuid
^C monitor: caught sig 2
 monitor: unloading
PPAK 0: Get before set operation succeeded of fwmonitor_kiss_enable
PPAK 0: Get before set operation succeeded of simple_debug_filter_off
PPAK 0: Get before set operation succeeded of kiss_debug_force_kdprintf_enable
PPAK 0: Get before set operation succeeded of fwmonitorfreebufs&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 08:38:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179042#M32814</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T08:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179045#M32815</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;VPN Client 86.50&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;What do you mean "NAS IP that you see in DUO?"&lt;BR /&gt;&lt;BR /&gt;Now we found something else: &lt;STRONG&gt;even if we set MS NPS as the RAIDUS (avoiding DUO) - it also doesn't work, even MS NPS allowed access&lt;/STRONG&gt;...&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 09:02:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179045#M32815</guid>
      <dc:creator>Exonix</dc:creator>
      <dc:date>2023-04-25T09:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179050#M32816</link>
      <description>&lt;P&gt;The NAS IP in the AVP shown in the captures versus (or in addition to) whichever you have configured it to currently accept messages from. Though&amp;nbsp;I think at this point you have two options:&lt;/P&gt;
&lt;P&gt;1. Engage TAC for a debug plan to investigate further.&lt;/P&gt;
&lt;P&gt;2. Apply a Jumbo to the Gateway to eliminate known issues such as:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Radius Timeout.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20624iE558EA5BC3D773C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Radius Timeout.PNG" alt="Radius Timeout.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 09:45:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179050#M32816</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-25T09:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179051#M32817</link>
      <description>&lt;P&gt;Mmmm, this is a bit odd, considering you do observe it on TCP dump.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;run the following:&lt;BR /&gt;fw monitor -F "10.10.10.22,0,10.10.10.1,0,0"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 09:45:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179051#M32817</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-04-25T09:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint denies connection even after Push Approval</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179052#M32818</link>
      <description>&lt;P&gt;BTW, all traces and debugging should be done in parallel with the authentication request. Just a reminder.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 09:46:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/CheckPoint-denies-connection-even-after-Push-Approval/m-p/179052#M32818</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-04-25T09:46:58Z</dc:date>
    </item>
  </channel>
</rss>

