<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN clients still using LDAP while RADIUS is configured in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245058#M10380</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured RADIUS between my CheckPoint Firewall and my Microsoft NPS. This is working fine, for example I can logon to Smartconsole with a user via RADIUS authentication. I checked the logs on the NPS, the account I use on the smartconsole login gets authenticated correctly via RADIUS.&lt;/P&gt;&lt;P&gt;In smartconsole, in gateway cluster properties, in VPN clients and in remote access, in authentication (single authentication client settings) I selected RADIUS (and the RADIUS server that is configured).&lt;/P&gt;&lt;P&gt;Just to be sure, in smartdashboard is added RADIUS in multiple authentication.&lt;/P&gt;&lt;P&gt;Also, in gateways in smartdashboard, it says: This gateway allows single authentication clients to connect using: RADIUS&lt;/P&gt;&lt;P&gt;But... when I connect my VPN user (88.62 vpn-client), it still uses LDAP. Something is forcing LDAP over the RADIUS properties I selected.&lt;/P&gt;&lt;P&gt;I've been looking for some time now but I don't seem to find why. I did not perform the setup of this firewall and I'm certainly no expert. Can somebody give me a (not too complex) hint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Mar 2025 09:03:19 GMT</pubDate>
    <dc:creator>AlainC</dc:creator>
    <dc:date>2025-03-28T09:03:19Z</dc:date>
    <item>
      <title>VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245058#M10380</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured RADIUS between my CheckPoint Firewall and my Microsoft NPS. This is working fine, for example I can logon to Smartconsole with a user via RADIUS authentication. I checked the logs on the NPS, the account I use on the smartconsole login gets authenticated correctly via RADIUS.&lt;/P&gt;&lt;P&gt;In smartconsole, in gateway cluster properties, in VPN clients and in remote access, in authentication (single authentication client settings) I selected RADIUS (and the RADIUS server that is configured).&lt;/P&gt;&lt;P&gt;Just to be sure, in smartdashboard is added RADIUS in multiple authentication.&lt;/P&gt;&lt;P&gt;Also, in gateways in smartdashboard, it says: This gateway allows single authentication clients to connect using: RADIUS&lt;/P&gt;&lt;P&gt;But... when I connect my VPN user (88.62 vpn-client), it still uses LDAP. Something is forcing LDAP over the RADIUS properties I selected.&lt;/P&gt;&lt;P&gt;I've been looking for some time now but I don't seem to find why. I did not perform the setup of this firewall and I'm certainly no expert. Can somebody give me a (not too complex) hint?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 09:03:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245058#M10380</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-03-28T09:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245116#M10382</link>
      <description>&lt;P&gt;LDAP isn't used for authentication, it is used for authorization.&lt;BR /&gt;More specifically, it is used to retrieve groups for a given user.&lt;BR /&gt;This applies to both Remote Access and Identity Awareness.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 21:32:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245116#M10382</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-28T21:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245126#M10383</link>
      <description>&lt;P&gt;What Phoneboy said is 100% right...ldap is not used for authentication.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2025 22:45:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245126#M10383</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-28T22:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245146#M10384</link>
      <description>&lt;P&gt;Can you please send a screenshot of how that window is configured? I mean option for adding multiple auth methods...just blur out any sensitive data.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 29 Mar 2025 18:41:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245146#M10384</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-29T18:41:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245194#M10385</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="vpn.jpg" style="width: 762px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30071i28A51E618E8AB9A6/image-size/large?v=v2&amp;amp;px=999" role="button" title="vpn.jpg" alt="vpn.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've also found a VPN_user template that can be set to radius (but is set to checkpoint password). I have no idea where/how this template is used or where it is configured to be used. Told you before, just an amateur on this subject.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;thanks for the reply, but I don't have a clue what action I can perform based on that information&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 08:24:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245194#M10385</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-03-31T08:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245209#M10386</link>
      <description>&lt;P&gt;I dont believe user template should matter much here, but auth order seems right to me. Do you have TAC case open for it?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 10:50:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245209#M10386</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-31T10:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245270#M10388</link>
      <description>&lt;P&gt;Why are LDAP lookups done? Quite simple: you have LDAP Account Units defined.&lt;BR /&gt;With the exception of Azure/Entra ID users where the relevant groups are passed as part of the SAML Assertion (see&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk177267" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk177267&lt;/A&gt;) or Internal Password users, an LDAP lookup is required to associate a given user to groups for the purposes of defining Access Roles for specific groups of users.&lt;BR /&gt;In other words, LDAP lookups are expected behavior in Remote Access configurations.&lt;/P&gt;
&lt;P&gt;The only way to disable the LDAP lookups is to remove the LDAP Account Unit objects.&lt;BR /&gt;However, they are likely used for other purposes (i.e. Identity Awareness).&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 16:08:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245270#M10388</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-31T16:08:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245320#M10392</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not sure we're talking about the same thing...&lt;/P&gt;&lt;P&gt;It must be some simple detail somewhere...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Simplified Situation:&lt;/P&gt;&lt;P&gt;AD user xyz logs on to smartconsole. AD user xyz 's request to logon is directed to NPS and is seen in NPS (eventviewer).&lt;/P&gt;&lt;P&gt;The same AD user xyz logs on via Checkpoint VPN client. AD user xyz's logon request is not directed to NPS (nothing shows up in eventviewer).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 08:09:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245320#M10392</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-01T08:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245322#M10393</link>
      <description>&lt;P&gt;no case opened yet, I thought it would be a basic setting somewhere. I followed the procedure "Using RADIUS Authentication for Remote Access VPN" and had a little help from chatgpt. No luck &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 08:32:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245322#M10393</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-01T08:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245377#M10395</link>
      <description>&lt;P&gt;It wasn't clear that the RADIUS part wasn't working.&lt;BR /&gt;You may need to delete/re-add the site on the VPN client if you change the authentication methods.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 14:44:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245377#M10395</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-01T14:44:27Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245438#M10396</link>
      <description>&lt;P&gt;FYI&lt;/P&gt;&lt;P&gt;I've opened a case -&amp;gt; reaction = since this is a new configuration, we don't give any support, we&amp;nbsp;focus on resolving issues with existing configurations !!!! Really??!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 07:10:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245438#M10396</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-02T07:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245439#M10397</link>
      <description>&lt;P&gt;I've deleted and re-added the site on a client but this doesn't help. I can see the request arriving directly into AD and not passing via Network Policy Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 07:19:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245439#M10397</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-02T07:19:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245473#M10399</link>
      <description>&lt;P&gt;Are you using locally defined users?&lt;BR /&gt;If not, do you have an External User Profile defined in SmartDashboard?&lt;BR /&gt;If not, this is how you create it (and yes, I do mean legacy SmartDashboard):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30102i992966CC25597243/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Create this with the defaults:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30103i67C2B5C0B16B11FC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Note if this profile exists in your environment, change the Authentication to Undefined.&lt;BR /&gt;Click the Save icon (upper left) in SmartDashboard, Publish and Install Policy in SmartConsole to relevant gateways.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 13:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245473#M10399</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-02T13:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245549#M10404</link>
      <description>&lt;P&gt;I've found the error I made!&lt;/P&gt;&lt;P&gt;I used the management server IP in NPS. I've put the correct IP (gateway). Now it works fine!&lt;/P&gt;&lt;P&gt;Sorry for the trouble!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 09:44:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245549#M10404</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-03T09:44:57Z</dc:date>
    </item>
    <item>
      <title>Re: VPN clients still using LDAP while RADIUS is configured</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245553#M10405</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 10:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-clients-still-using-LDAP-while-RADIUS-is-configured/m-p/245553#M10405</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T10:41:38Z</dc:date>
    </item>
  </channel>
</rss>

