<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote VPn certificate based authentication issue. in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235487#M45651</link>
    <description>&lt;P&gt;Actually user which we are tring to connect is on AD not locally..&amp;nbsp; We have other users where there Account was expired on 31 dec 2020 which are on locally on checkpoint.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Dec 2024 14:29:32 GMT</pubDate>
    <dc:creator>Prasaddere</dc:creator>
    <dc:date>2024-12-12T14:29:32Z</dc:date>
    <item>
      <title>Remote VPn certificate based authentication issue.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235477#M45649</link>
      <description>&lt;P&gt;We have configured Certificate based authentication but we are getting message on VPN client that "User Account Expired 31 Dec 2020"&lt;/P&gt;&lt;P&gt;When user connect from Client to VPN, it shows user Certificate but whne he connect, it give above error message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have already added Root CA&amp;nbsp; in Trusted CA&amp;nbsp;and issuing CA in Subordinate CA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Generated CSR and got the Certificate from Internal CA&lt;/P&gt;&lt;P&gt;Selected Personal Certificate in Authetication in VPN Client as well in Mobile Access.&lt;/P&gt;&lt;P&gt;In Mobile access, Portal setting added another internal CA certification.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 14:02:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235477#M45649</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-12T14:02:14Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPn certificate based authentication issue.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235480#M45650</link>
      <description>&lt;P&gt;Is this field set properly for the user account in question?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="User_Expire.png" style="width: 511px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28765i574DD377D2DE854A/image-size/large?v=v2&amp;amp;px=999" role="button" title="User_Expire.png" alt="User_Expire.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 14:10:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235480#M45650</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2024-12-12T14:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPn certificate based authentication issue.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235487#M45651</link>
      <description>&lt;P&gt;Actually user which we are tring to connect is on AD not locally..&amp;nbsp; We have other users where there Account was expired on 31 dec 2020 which are on locally on checkpoint.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 14:29:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235487#M45651</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-12T14:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPn certificate based authentication issue.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235494#M45653</link>
      <description>&lt;P&gt;Below is the Message in Traffic logs&lt;/P&gt;&lt;P&gt;Main Mode Sent Notification to Peer: Client Encrypt Notification: User account expired on 31-Dec-2020.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;User account expired on 31-Dec-2020. ---This data is picked up from the checkpoint only in the backend but not sure from where?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 14:47:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235494#M45653</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-12T14:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPn certificate based authentication issue.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235536#M45657</link>
      <description>&lt;P&gt;It might be in the generic* user that you need to change the expiration on.&lt;BR /&gt;The only way to find this user (if it's indeed defined in your environment) is via &lt;STRONG&gt;SmartDashboard&lt;/STRONG&gt; (not SmartConsole).&lt;BR /&gt;Otherwise, I suggest contacting TAC.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 16:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235536#M45657</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-12-12T16:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPn certificate based authentication issue.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235581#M45672</link>
      <description>&lt;P&gt;Even if you are using AD for authentication, some settings are inherit from default password templates. Check following:&lt;/P&gt;
&lt;P&gt;LDAP Account Unit -&amp;gt; double click on correct AU -&amp;gt; Authentication -&amp;gt; Section "Users' default values". If "use user template" checkbox is ticked, then see which user template is used.&lt;/P&gt;
&lt;P&gt;Search for this user template in "User Templates" within object explorer. Open affected template and right in General tab you can see Expiration of this template (which is valid for all users, not just locally configured).&lt;/P&gt;
&lt;P&gt;If inside the user template you have "According to Global Properties", head to Global Properties -&amp;gt; User Accounts and there you should see Expiration.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Dec 2024 20:46:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235581#M45672</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-12-12T20:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: Remote VPn certificate based authentication issue.</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235609#M45683</link>
      <description>&lt;P&gt;Thanks, After changing the expiration on generic* user, message has gone but getting another message now on Endpoint security client that "Main Mode Sent Notification to Peer: Client Encrypt Notification: Access denied - wrong user name or password "&lt;/P&gt;</description>
      <pubDate>Fri, 13 Dec 2024 06:21:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Remote-VPn-certificate-based-authentication-issue/m-p/235609#M45683</guid>
      <dc:creator>Prasaddere</dc:creator>
      <dc:date>2024-12-13T06:21:15Z</dc:date>
    </item>
  </channel>
</rss>

