<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password” in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266414#M52624</link>
    <description>&lt;P&gt;That could be AD server issue...any relevant logs there?&lt;/P&gt;</description>
    <pubDate>Sat, 03 Jan 2026 01:47:56 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-01-03T01:47:56Z</dc:date>
    <item>
      <title>R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266386#M52614</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;&lt;P&gt;I have a Check Point R81.20 (JHF 119) Security Gateway deployed on an Open Server for a customer. The customer is looking to implement Browser-Based Authentication (Captive Portal) for known users, with FreeRADIUS as the backend authentication source. The FreeRADIUS server is running on Ubuntu 24.04, and users are defined locally with Cleartext-Password entries.&lt;/P&gt;&lt;P&gt;I have followed the R81.20 Identity Awareness Admin Guide to configure Browser-Based Authentication using RADIUS. However, when a user attempts to authenticate via the Captive Portal, I consistently see “Bad username or password” events in SmartView Logs.&lt;/P&gt;&lt;P&gt;The key observation is that no RADIUS Access-Request packets are sent from the gateway:&lt;/P&gt;&lt;P&gt;- tcpdump on the gateway (any interface, port 1812) shows no outbound RADIUS traffic&lt;BR /&gt;- No packet drops are observed on the gateway&lt;BR /&gt;- This suggests the authentication failure is occurring locally on the gateway before RADIUS is invoked&lt;/P&gt;&lt;P&gt;Below are the relevant configuration snippets from the Check Point gateway (Browser-Based Authentication settings, RADIUS server object, and Access Control rule).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Authentication Settings" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32601i7A0F9D454470D58B/image-size/large?v=v2&amp;amp;px=999" role="button" title="radius_auth.png" alt="Authentication Settings" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Authentication Settings&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Portal Settings" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32602iAA5C8394A14DBAC9/image-size/large?v=v2&amp;amp;px=999" role="button" title="portal_settings.png" alt="Portal Settings" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Portal Settings&lt;/span&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Freeradius object" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32603i178866E8F8013C90/image-size/large?v=v2&amp;amp;px=999" role="button" title="freeradius_config.png" alt="Freeradius object" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Freeradius object&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I would appreciate any help in this regard:&lt;/P&gt;&lt;P&gt;- Any known R81.20 caveats or prerequisites specific to Browser-Based Authentication with RADIUS?&lt;BR /&gt;- Is there a built-in CLI tool to test RADIUS authentication from the gateway, similar to test_ad_connectivity.sh for AD?&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Abdul Tayyeb R.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 16:32:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266386#M52614</guid>
      <dc:creator>abutayyab</dc:creator>
      <dc:date>2026-01-02T16:32:41Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266387#M52615</link>
      <description>&lt;P&gt;Under accessibility settings, is it set to all interfaces or only internal?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 16:43:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266387#M52615</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-02T16:43:22Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266392#M52616</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/124051"&gt;@abutayyab&lt;/a&gt;&amp;nbsp;I was referring to below.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32604i132972053A844E43/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 17:04:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266392#M52616</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-02T17:04:43Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266393#M52617</link>
      <description>&lt;P&gt;It's set to "Through internal interfaces". The captive portal is accessible. Had there been some issue with accessibility settings, the captive portal itself wouldn't have shown up in that case.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 18:42:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266393#M52617</guid>
      <dc:creator>abutayyab</dc:creator>
      <dc:date>2026-01-02T18:42:10Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266394#M52618</link>
      <description>&lt;P&gt;True, makes sense. So you dont see anything on port 1812 outbound at all?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 18:43:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266394#M52618</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-02T18:43:25Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266402#M52621</link>
      <description>&lt;P&gt;You need to configure where the fw has to look for the users. No options are selected user directories&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="mc-main-content" role="main"&gt;
&lt;UL class="listbullet"&gt;
&lt;LI class="listbullet"&gt;&lt;STRONG class="bold"&gt;User Directories&lt;/STRONG&gt; - Select one or more places where the Security Gateway searches to find users when they try to authenticate.
&lt;UL class="listbullet2"&gt;
&lt;LI class="listbullet2"&gt;&lt;STRONG class="bold"&gt;Internal users&lt;/STRONG&gt; - The directory of internal users.&lt;/LI&gt;
&lt;LI class="listbullet2"&gt;&lt;STRONG class="bold"&gt;LDAP users&lt;/STRONG&gt; - The directory of LDAP users. Either:
&lt;UL class="listbullet3"&gt;
&lt;LI class="listbullet3"&gt;&lt;STRONG class="bold"&gt;Any&lt;/STRONG&gt; - Users from all LDAP servers.&lt;/LI&gt;
&lt;LI class="listbullet3"&gt;&lt;STRONG class="bold"&gt;Specific&lt;/STRONG&gt; - Users from an LDAP server that you select.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI class="listbullet2"&gt;&lt;STRONG class="bold"&gt;External user profiles&lt;/STRONG&gt; - The directory of users who have external user profiles.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Jan 2026 19:52:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266402#M52621</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-01-02T19:52:53Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266406#M52622</link>
      <description>&lt;P&gt;Totally valid point...I missed that from the screenshots, but its 100% required.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jan 2026 20:00:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266406#M52622</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-02T20:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266413#M52623</link>
      <description>&lt;P&gt;I have already selected "External user profiles". Do I need to select something else here? While troubleshooting the issue, I had selected all 3 directory options hoping to resolve the issue, but then I ended up getting a different error as mentioned below:&lt;/P&gt;&lt;P&gt;"An error was detected while trying to authenticate against the AD server. It may be a problem of bad configuration or connectivity. Please refer to the troubleshooting guide for more help"&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2026 01:34:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266413#M52623</guid>
      <dc:creator>abutayyab</dc:creator>
      <dc:date>2026-01-03T01:34:45Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266414#M52624</link>
      <description>&lt;P&gt;That could be AD server issue...any relevant logs there?&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2026 01:47:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266414#M52624</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-03T01:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266422#M52630</link>
      <description>&lt;P&gt;Does your LDAP account unit work correctly? Able to fetch finger print? Do you see identities in the firewall logs? Able to search LDAP groups and use them in the rulebase from SmartConsole? I would use&amp;nbsp;&lt;STRONG class="bold"&gt;LDAP users&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;instead of External&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2026 11:51:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266422#M52630</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2026-01-03T11:51:24Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266428#M52635</link>
      <description>&lt;P&gt;There is NO LDAP server in the network. There's only one RADIUS server that has users/contractors defined. And I want these users to be authenticated before they're given Internet access. Is something wrong with my setup?&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2026 16:33:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266428#M52635</guid>
      <dc:creator>abutayyab</dc:creator>
      <dc:date>2026-01-03T16:33:12Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266429#M52636</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yes. LDAP users are enabled but no LDAP directory exists. With Browser-Based Authentication the gateway must first resolve the user in a selected directory before RADIUS is used. Since LDAP lookup fails, authentication stops locally and never reaches RADIUS. Disable LDAP users and use Internal Users or External User Profiles that authenticate via RADIUS.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2026 19:28:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266429#M52636</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-01-03T19:28:12Z</dc:date>
    </item>
    <item>
      <title>Re: R81.20 Browser-Based Authentication with RADIUS – “Bad username or password”</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266430#M52637</link>
      <description>&lt;P&gt;Makes perfect sense!&lt;/P&gt;</description>
      <pubDate>Sat, 03 Jan 2026 20:03:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-20-Browser-Based-Authentication-with-RADIUS-Bad-username-or/m-p/266430#M52637</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-01-03T20:03:55Z</dc:date>
    </item>
  </channel>
</rss>

