<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sometimes error &amp;quot;negotiation with site failed&amp;quot; in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153460#M5926</link>
    <description>&lt;P&gt;i'll found in the VPND.elg that when the authentication fails, the checkpoint did only LDAP-requests to our external domain controllers instead of the internal domain.&lt;/P&gt;&lt;P&gt;When i try to remove the specific participant groups in de remote access community and change it to "all rules" it works properly.&lt;/P&gt;&lt;P&gt;But it is strangely working properly on the office mode assigned group (this is exact the same group as a configured in the participant user groups).&lt;/P&gt;&lt;P&gt;How is it possible that, checkpoint does the request to the wrong AD?&lt;/P&gt;</description>
    <pubDate>Wed, 20 Jul 2022 10:42:21 GMT</pubDate>
    <dc:creator>Networking-TNL</dc:creator>
    <dc:date>2022-07-20T10:42:21Z</dc:date>
    <item>
      <title>Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153221#M5911</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I'm currently configuring a new cluster with a new mgmt-server only for VPN.&lt;/P&gt;&lt;P&gt;i've build on a VSX-cluster 2 VS's, one test and one production VS.&lt;/P&gt;&lt;P&gt;VS3, I've build the test vs, with smartcard authentication which connects to our external AD. machine/user are handled by our external domain and the smartcard authentication is as well handled on this external domain, this solution works properly.&lt;/P&gt;&lt;P&gt;VS4, I've build the production VS, which the machine/user connects to our internal domain and the MFA is handled by Radius against the external AD.&lt;/P&gt;&lt;P&gt;on this VS i have the issue when i'm trying to logon that I'll get the error "Negotiation with site failed". I don't get it always, the other attempts are working well, let's say it fails 1 out of 3 attempts. Smartlog says the user does not belong to the remote community.&lt;/P&gt;&lt;P&gt;The AD LDAP account unit of both domains are identical in the management server and in the Remote Access community in the participant user groups i have added a user group based on a security group.&lt;/P&gt;&lt;P&gt;Does anybody have an idea what could go wrong?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 11:18:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153221#M5911</guid>
      <dc:creator>Networking-TNL</dc:creator>
      <dc:date>2022-07-18T11:18:59Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153225#M5912</link>
      <description>&lt;P&gt;Intermittent connectivity issues with LDAP maybe? Do you have multiple servers defined in a single LDAP account unit object?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 11:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153225#M5912</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-18T11:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153357#M5920</link>
      <description>&lt;P&gt;Tried both, started with ldap account unit with three AD-servers and changed it later to one and also switcht from one to another one, but still the same issues unfortunately.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 08:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153357#M5920</guid>
      <dc:creator>Networking-TNL</dc:creator>
      <dc:date>2022-07-19T08:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153395#M5921</link>
      <description>&lt;P&gt;Are you able to do say fw ctl zdebug + drop | grep username command (just replace username with actual user itself). Not sure this may give us more info, but worth a try.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 13:06:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153395#M5921</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-07-19T13:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153397#M5922</link>
      <description>&lt;P&gt;nope doesn't give any results.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 13:18:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153397#M5922</guid>
      <dc:creator>Networking-TNL</dc:creator>
      <dc:date>2022-07-19T13:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153460#M5926</link>
      <description>&lt;P&gt;i'll found in the VPND.elg that when the authentication fails, the checkpoint did only LDAP-requests to our external domain controllers instead of the internal domain.&lt;/P&gt;&lt;P&gt;When i try to remove the specific participant groups in de remote access community and change it to "all rules" it works properly.&lt;/P&gt;&lt;P&gt;But it is strangely working properly on the office mode assigned group (this is exact the same group as a configured in the participant user groups).&lt;/P&gt;&lt;P&gt;How is it possible that, checkpoint does the request to the wrong AD?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jul 2022 10:42:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153460#M5926</guid>
      <dc:creator>Networking-TNL</dc:creator>
      <dc:date>2022-07-20T10:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153973#M5935</link>
      <description>&lt;P&gt;This topic can be closed, solved this issue by configuring specifically the proper active directory under the VS &amp;gt; other &amp;gt; user directory and configure the proper AD.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 12:16:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153973#M5935</guid>
      <dc:creator>Networking-TNL</dc:creator>
      <dc:date>2022-07-27T12:16:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sometimes error "negotiation with site failed"</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153988#M5936</link>
      <description>&lt;P&gt;Great to hear&lt;/P&gt;</description>
      <pubDate>Wed, 27 Jul 2022 13:22:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sometimes-error-quot-negotiation-with-site-failed-quot/m-p/153988#M5936</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-07-27T13:22:08Z</dc:date>
    </item>
  </channel>
</rss>

