<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R80.40 Gateway- AD Authentication error - &amp;quot;Invalid username and password&amp;quot; for Citrix VPN users in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104524#M9965</link>
    <description>&lt;P&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I Updated 5800 Gateway to R80.40. VPN Clients could VPN in and authenticate via AD and OTP through Citrix portal but after sometime, everyone on Citrix will be kicked out and if they login again, all of them will get the same error "Invalid username and password" &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now if you reboot the gateway, then they can authenticate fine but only for a while, may be 15 minutes and then the same error appears if they try to login.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Disabling SecureXL resolved the issue. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Template creation stops at the exact rule which is responsible for client authentication to AD. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It almost seems like the previous Kerberos Ticket is carried forward by SecureXL and authentication fails.&lt;/P&gt;&lt;P&gt;I want to understand if Templates are disabled at that same rule, what else SecureXL is doing that users are getting invalid username or password error when SecureXL is enabled. Something different in R80.40 may be?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2020 15:33:46 GMT</pubDate>
    <dc:creator>Attiq786</dc:creator>
    <dc:date>2020-12-07T15:33:46Z</dc:date>
    <item>
      <title>R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix VPN users</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104524#M9965</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi All,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I Updated 5800 Gateway to R80.40. VPN Clients could VPN in and authenticate via AD and OTP through Citrix portal but after sometime, everyone on Citrix will be kicked out and if they login again, all of them will get the same error "Invalid username and password" &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now if you reboot the gateway, then they can authenticate fine but only for a while, may be 15 minutes and then the same error appears if they try to login.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Disabling SecureXL resolved the issue. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Template creation stops at the exact rule which is responsible for client authentication to AD. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;It almost seems like the previous Kerberos Ticket is carried forward by SecureXL and authentication fails.&lt;/P&gt;&lt;P&gt;I want to understand if Templates are disabled at that same rule, what else SecureXL is doing that users are getting invalid username or password error when SecureXL is enabled. Something different in R80.40 may be?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 15:33:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104524#M9965</guid>
      <dc:creator>Attiq786</dc:creator>
      <dc:date>2020-12-07T15:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix V</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104700#M9966</link>
      <description>&lt;P&gt;If disabling SecureXL "solves" any issue, the TAC should be involved.&lt;BR /&gt;Meanwhile, what is the precise rule you’re referring to?&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 19:31:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104700#M9966</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-08T19:31:21Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix V</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104717#M9967</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Thanks for your reply. TAC case is raised already. I was thinking may be someone else might have the same issue with R80.40.&lt;/P&gt;&lt;P&gt;The rule allows remote client addresses to contact AD. services include Kerberos as well in that rule.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 00:09:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104717#M9967</guid>
      <dc:creator>Attiq786</dc:creator>
      <dc:date>2020-12-09T00:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix V</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104718#M9968</link>
      <description>&lt;P&gt;A screenshot would be helpful&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 01:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104718#M9968</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T01:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix V</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104834#M9969</link>
      <description>&lt;P&gt;Here is the screenshot please.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 19:18:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104834#M9969</guid>
      <dc:creator>Attiq786</dc:creator>
      <dc:date>2020-12-09T19:18:47Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix V</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104842#M9970</link>
      <description>&lt;P&gt;Nothing in that rule should disable SecureXL that I’m aware of, but could be wrong.&lt;BR /&gt;The TAC SR in PM may be helpful.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 20:53:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/104842#M9970</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T20:53:36Z</dc:date>
    </item>
    <item>
      <title>Re: R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix V</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/107712#M14432</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;the issue was resolved after installing HFA take 89 - something in base R80.40 image that would prevent SecureXL working as it should.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 13:19:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R80-40-Gateway-AD-Authentication-error-quot-Invalid-username-and/m-p/107712#M14432</guid>
      <dc:creator>Attiq786</dc:creator>
      <dc:date>2021-01-13T13:19:23Z</dc:date>
    </item>
  </channel>
</rss>

