<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New LDAP Account Unit and Radius Server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257548#M61686</link>
    <description>&lt;P&gt;Hey Steve,&lt;/P&gt;
&lt;P&gt;I read your post carefully and in my mind, the way Im looking at this is as long as new ldap account unit you create in smart console, if server referenced has connection to the gateway, it can be tested that way, without having to make authentication mandatory, at least for the time being.&lt;/P&gt;
&lt;P&gt;Now, since you said no one seems to know SSO password, then making that work in smart console would be an issue. Doing tcpdump on port 1812 would be easiest way to see if this would function, but again, thats only if communication is there, otherwise it will fail.&lt;/P&gt;
&lt;P&gt;Lets see if someone else may have an idea.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 17 Sep 2025 23:12:30 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-09-17T23:12:30Z</dc:date>
    <item>
      <title>New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257488#M61685</link>
      <description>&lt;P&gt;I am looking at testing a new Radius server to replace an existing third party one that is being removed from the environment. The replacement is a Microsoft NPS server, but i'm not overly familiar with this.&lt;/P&gt;&lt;P&gt;So I'm looking for a way to test this without removing or changing the current LDAP Account unit and Radius server objects, hence creating new ones, however i'm not sure the best way forward. Firstly nobody seems to know the password for the SSO account in AD, so that will need to be changed, but hopefully once updated on the existing objects this won't cause a problem. Once thats done, I can create the new ones but not sure how to configure the NPS side.&lt;/P&gt;&lt;P&gt;I've seen articles about configuring it for use with Gaia, but this is for use with Identity Awareness agents so not sure if that will be the same.&lt;/P&gt;&lt;P&gt;Can anyone point me in the right direction or to an SK that details this at all please?&lt;/P&gt;&lt;P&gt;It would also be nice to use encrypted authentication rather than simple PAP.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 14:02:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257488#M61685</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2025-09-17T14:02:27Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257548#M61686</link>
      <description>&lt;P&gt;Hey Steve,&lt;/P&gt;
&lt;P&gt;I read your post carefully and in my mind, the way Im looking at this is as long as new ldap account unit you create in smart console, if server referenced has connection to the gateway, it can be tested that way, without having to make authentication mandatory, at least for the time being.&lt;/P&gt;
&lt;P&gt;Now, since you said no one seems to know SSO password, then making that work in smart console would be an issue. Doing tcpdump on port 1812 would be easiest way to see if this would function, but again, thats only if communication is there, otherwise it will fail.&lt;/P&gt;
&lt;P&gt;Lets see if someone else may have an idea.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 23:12:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257548#M61686</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-17T23:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257674#M61687</link>
      <description>&lt;P&gt;Hey Steve,&lt;/P&gt;
&lt;P&gt;I had similar ask today from a customer, but in regards to remote access. I ended up opening TAC case, since I find its always better to have those things in writting. Probably would not hurt if you do the same, hopefully they can provide good suggestions.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 22:25:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257674#M61687</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-18T22:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257707#M61688</link>
      <description>&lt;P&gt;Hi Andy,&lt;/P&gt;&lt;P&gt;I was thinking the same thing, but first I wanted to sort the password issue out so I got this reset last night and applied the password to the config. That looks good, no issues reported so far, both RA and IA that use the Account unit are working normally, so I'm going to open a TAC case today to see if they can provide the required info.&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2025 06:45:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257707#M61688</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2025-09-19T06:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257731#M61689</link>
      <description>&lt;P&gt;Good idea Steve!&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2025 10:37:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/257731#M61689</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-19T10:37:13Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258649#M61690</link>
      <description>&lt;P&gt;Morning Andy,&lt;/P&gt;&lt;P&gt;I have this sorted now, but have discovered a couple of things you may be interested to know.....&lt;/P&gt;&lt;P&gt;There is a bug in SmartConsole build 671 whereby if you open an account unit object and as much as click on the Object management tab then you can't save any changes you've made. Even if you don't change anything, you will not be able to click OK to come out again as it doesn't read the branches. TAC confirmed this is an issue.&lt;/P&gt;&lt;P&gt;Secondly, SmartConsole does not play nicely if you change the screen scale to anything above 100% in the windows display&amp;nbsp; settings. There is nothing obvious but on certain screens it doesn't display the forms properly. (for example, Cluster properties, Identity Awareness, Identity Agent Settings, Authentication Settings, there is a little table listing the user directories, with Green/Red +/- buttons to the right side. If you have the screen scale above 100% these buttons will not be visible !!)&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 09:00:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258649#M61690</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2025-10-01T09:00:25Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258650#M61691</link>
      <description>&lt;P&gt;Excellent Steve, thanks for letting us know!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 09:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258650#M61691</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T09:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258658#M61692</link>
      <description>&lt;P&gt;Btw Steve, I just tested that smart console build in the lab, did not have that issue...I am on win 11.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 10:03:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258658#M61692</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T10:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258680#M61693</link>
      <description>&lt;P&gt;Which issue were you testing?&lt;/P&gt;&lt;P&gt;I'm on Win 11 SC build 671, on a Dell Pro Max 18 laptop&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 11:49:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258680#M61693</guid>
      <dc:creator>Steve_Pearson</dc:creator>
      <dc:date>2025-10-01T11:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: New LDAP Account Unit and Radius Server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258681#M61694</link>
      <description>&lt;P&gt;What you described below...&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;&lt;P&gt;There is a bug in SmartConsole build 671 whereby if you open an account unit object and as much as click on the Object management tab then you can't save any changes you've made. Even if you don't change anything, you will not be able to click OK to come out again as it doesn't read the branches. TAC confirmed this is an issue.&lt;/P&gt;&lt;P&gt;Secondly, SmartConsole does not play nicely if you change the screen scale to anything above 100% in the windows display&amp;nbsp; settings. There is nothing obvious but on certain screens it doesn't display the forms properly. (for example, Cluster properties, Identity Awareness, Identity Agent Settings, Authentication Settings, there is a little table listing the user directories, with Green/Red +/- buttons to the right side. If you have the screen scale above 100% these buttons will not be visible !!)&lt;/P&gt;</description>
      <pubDate>Wed, 01 Oct 2025 11:50:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-LDAP-Account-Unit-and-Radius-Server/m-p/258681#M61694</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-01T11:50:47Z</dc:date>
    </item>
  </channel>
</rss>

