<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Smartconsole Access problem after Hotfix in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163852#M70252</link>
    <description>&lt;P&gt;Hm, thats really unfortunate. Just a suggestion, any idea you can remove it and test again? If that works, then you know 100% it was indeed the fix they provided. At that point, TAC would need to investigate further as to why. Based on what you posted, seems like you did an excellent job in figuring out whats going on.&lt;/P&gt;
&lt;P&gt;Ok, I know this may sound silly what I will say now, but would you mind confirming nothing changed as far as routing/topology AFTER applying that fix?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 01 Dec 2022 12:56:23 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-12-01T12:56:23Z</dc:date>
    <item>
      <title>Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163836#M70251</link>
      <description>&lt;P&gt;Hello Checkmates!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am having a problem with all our MDS, currently I have installed R80.40 JHF 156, due to some problems TAC requested us to apply JHF 176/180.&lt;/P&gt;&lt;P&gt;After we apply this hotfix we notice that we are not able to login with our TACACS users.&lt;/P&gt;&lt;P&gt;Doing some troubleshooting we notice the traffic is not following the correct route.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RADIUS Server is IP&amp;nbsp; &lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"add aaa tacacs-servers priority 1 server &lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt; key ***** timeout 5"&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;MDS &lt;FONT color="#3366FF"&gt;Mgmt 1.2.3.4&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;MDS &lt;FONT color="#FF6600"&gt;eth1 21.22.13.200&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;[Expert@MDS:0]# ip r&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366FF"&gt;default via&lt;/FONT&gt; &lt;FONT color="#3366FF"&gt;1.2.3.1 dev Mgmt&lt;/FONT&gt; proto 7&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;21.22.23.0/24 via 21.22.13.1&lt;/FONT&gt; &lt;FONT color="#FF9900"&gt;dev eth1&lt;/FONT&gt; proto 7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After applying the hotfix, &lt;STRIKE&gt;the radius traffic goes out through the Mgmt interface&lt;/STRIKE&gt;. (Trying to access to Smartconsole)&lt;/P&gt;&lt;P&gt;EDIT: The traffic goes out through the right interface, eth1 but with the IP of the mgmt interface.&lt;/P&gt;&lt;P&gt;[Expert@MDS:0]# tcpdump -nni any host&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;IP &lt;FONT color="#3366FF"&gt;1.2.3.4&lt;/FONT&gt;.46379 &amp;gt;&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;FONT color="#000000"&gt;.1645 RADIUS&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;IP &lt;FONT color="#3366FF"&gt;1.2.3.4&lt;/FONT&gt;.46379 &amp;gt;&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;FONT color="#000000"&gt;.1645 RADIUS&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;IP &lt;FONT color="#3366FF"&gt;1.2.3.4&lt;/FONT&gt;.46379&lt;/FONT&gt; &lt;FONT color="#000000"&gt;&amp;gt;&lt;/FONT&gt;&amp;nbsp;21.22.23.220&lt;FONT color="#000000"&gt;.1645 RADIUS&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;But when accesing to SSH(TACACS port) follows the right route.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;[Expert@MDS:0]# tcpdump -nni any host&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;IP &lt;FONT color="#FF6600"&gt;21.22.13.200&lt;/FONT&gt;.54379 &amp;gt;&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;FONT color="#000000"&gt;.49&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;IP &lt;FONT color="#3366FF"&gt;&lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/FONT&gt;.49 &amp;gt; &lt;FONT color="#FF6600"&gt;21.22.13.200&lt;/FONT&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;.54379&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;IP &lt;FONT color="#FF6600"&gt;21.22.13.200&lt;/FONT&gt;.54379&lt;/FONT&gt; &lt;FONT color="#000000"&gt;&amp;gt;&lt;/FONT&gt;&amp;nbsp;21.22.23.220&lt;FONT color="#000000"&gt;.49&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what could be happening? How does the Smartconsole login works that trows the conection via Mgmt and not by the interface that the static route indicates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every idea is welcome!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 15:24:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163836#M70251</guid>
      <dc:creator>Devilmac</dc:creator>
      <dc:date>2022-12-01T15:24:09Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163852#M70252</link>
      <description>&lt;P&gt;Hm, thats really unfortunate. Just a suggestion, any idea you can remove it and test again? If that works, then you know 100% it was indeed the fix they provided. At that point, TAC would need to investigate further as to why. Based on what you posted, seems like you did an excellent job in figuring out whats going on.&lt;/P&gt;
&lt;P&gt;Ok, I know this may sound silly what I will say now, but would you mind confirming nothing changed as far as routing/topology AFTER applying that fix?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 12:56:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163852#M70252</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-01T12:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163862#M70253</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Did you now installed Jumbo take 176 or 180? The reason I ask this is because I cannot find take 176 anymore maybe it has been pulled offline? Issue started after take 176 or 180?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Second what I see is that you TCPdump on ANY interface. So there is no way for me to see what routing it takes. Because it can be either MGMT or eth1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you want to be sure regarding routing capture with interface filter:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;tcpdump -nni eth1 host&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;FONT color="#339966"&gt;&amp;nbsp;tcpdump -nni Mgmt host&amp;nbsp;21.22.23.220&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 13:22:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163862#M70253</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2022-12-01T13:22:42Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163877#M70254</link>
      <description>&lt;P&gt;Sorry, not 176... we tried both 173 and 180. Both of the times uninstalling reverting the hotfix solved the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For SSH Athentication, traffic goes through eth1&amp;nbsp;&lt;/P&gt;&lt;P&gt;[Expert@MDS:0]# tcpdump -nni eth1 host&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;IP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF6600"&gt;21.22.13.200&lt;/FONT&gt;.54379 &amp;gt;&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;FONT color="#000000"&gt;.49&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;IP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#3366FF"&gt;&lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/FONT&gt;.49 &amp;gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF6600"&gt;21.22.13.200&lt;/FONT&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;.54379&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;IP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#FF6600"&gt;21.22.13.200&lt;/FONT&gt;.54379&lt;/FONT&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#000000"&gt;&amp;gt;&lt;/FONT&gt;&amp;nbsp;21.22.23.220&lt;FONT color="#000000"&gt;.49&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;But here comes the fancy traffic, for Smartconsole login traffic,&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;The inital traffic goes to the Tacacs Server through eth1 but with the Mgmt IP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;[Expert@MDS:0]# tcpdump -nni eth1 host&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;IP&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color="#3366FF"&gt;1.2.3.4&lt;/FONT&gt;.46379 &amp;gt;&amp;nbsp;&lt;FONT color="#339966"&gt;21.22.23.220&lt;FONT color="#000000"&gt;.1645 RADIUS&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#339966"&gt;&lt;FONT color="#000000"&gt;Maybe is taking the IP defined in the /etc/hosts?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 15:22:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163877#M70254</guid>
      <dc:creator>Devilmac</dc:creator>
      <dc:date>2022-12-01T15:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163879#M70255</link>
      <description>&lt;P&gt;Hello, thanks for the help&lt;/P&gt;&lt;P&gt;No routing/topology has been changed. And yes,&lt;SPAN&gt;&amp;nbsp;uninstalling hotfix solves the issue.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 14:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163879#M70255</guid>
      <dc:creator>Devilmac</dc:creator>
      <dc:date>2022-12-01T14:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163880#M70256</link>
      <description>&lt;P&gt;Ok, so that clearly 100% tells us its hotfix issue, so sounds like TAC case would be needed to investigate it further. Sorry, wish I could give any other suggestions, but cant think of any at this time. They may suggest debugs when issue is there, but Im not so sure those would tell you anything, as it does not appear there is specific process thats broken, it simply takes wrong path to get where its going.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Dec 2022 14:58:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163880#M70256</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-12-01T14:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163920#M70257</link>
      <description>&lt;P&gt;Radius has the concept of a NAS-IP have you defined this in your GAiA config?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 01:58:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163920#M70257</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-02T01:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163950#M70258</link>
      <description>&lt;P&gt;Hello!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Chris, NAS IP description seems to fit perfectly with out problem. But after i have confiured it with the desired interface. I am having the same behauviour, the request goes with the hostname ip.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 11:52:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163950#M70258</guid>
      <dc:creator>Devilmac</dc:creator>
      <dc:date>2022-12-02T11:52:45Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163961#M70259</link>
      <description>&lt;P&gt;Maybe same issue like here&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Breaking-Gaia-RADIUS-Change-in-R81-10-T79/m-p/162992#" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/Breaking-Gaia-RADIUS-Change-in-R81-10-T79/m-p/162992#&lt;/A&gt; .&lt;/P&gt;
&lt;P&gt;try to remove the radius setting and set it again.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Dec 2022 13:48:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/163961#M70259</guid>
      <dc:creator>D_W</dc:creator>
      <dc:date>2022-12-02T13:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Smartconsole Access problem after Hotfix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/164135#M70260</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Doyou know if the NAS IP defined work for TACACS authentication?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2022 11:14:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Smartconsole-Access-problem-after-Hotfix/m-p/164135#M70260</guid>
      <dc:creator>Devilmac</dc:creator>
      <dc:date>2022-12-05T11:14:09Z</dc:date>
    </item>
  </channel>
</rss>

