<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed login alerts because of TACACS+ authentication failure in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243761#M40704</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Logs coming up, give me sometime.&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
    <pubDate>Thu, 13 Mar 2025 17:52:35 GMT</pubDate>
    <dc:creator>Firewall_Head</dc:creator>
    <dc:date>2025-03-13T17:52:35Z</dc:date>
    <item>
      <title>Failed login alerts because of TACACS+ authentication failure</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243729#M40701</link>
      <description>&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;I have a firewall with TACACS+ enabled and it's working fine.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I also have some local users configured for administration, but whenever I login using the local user ID, it creates a &lt;STRONG&gt;"failed authentication"&lt;/STRONG&gt; log.&lt;/P&gt;&lt;P&gt;Why is my local user even getting authenticated with the TACACS+ server.&lt;/P&gt;&lt;P&gt;Can somebody help me on this ? This is creating a headache for the SOC team.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance !&lt;/P&gt;&lt;P&gt;========&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 12:20:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243729#M40701</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-03-13T12:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: Failed login alerts because of TACACS+ authentication failure</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243755#M40703</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Do you have a screenshot of it by any chance?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 16:01:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243755#M40703</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-13T16:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Failed login alerts because of TACACS+ authentication failure</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243761#M40704</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Logs coming up, give me sometime.&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;WR,&lt;/P&gt;&lt;P&gt;FH&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 17:52:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243761#M40704</guid>
      <dc:creator>Firewall_Head</dc:creator>
      <dc:date>2025-03-13T17:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: Failed login alerts because of TACACS+ authentication failure</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243762#M40705</link>
      <description>&lt;P&gt;If it does not help, we can do quick remote tomorrow.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2025 17:53:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243762#M40705</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-13T17:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: Failed login alerts because of TACACS+ authentication failure</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243967#M40730</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Just thought of something. IF you want to block local users from connecting, you can run blockSFAInternalUsers command from fw expert mode to see what it shows, just add -s flag and it would show you how to block it if you want.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;[Expert@R82:0]# blockSFAInternalUsers&lt;/P&gt;
&lt;P&gt;Internal User, Single Factor Auth. Blocking Utility&lt;/P&gt;
&lt;P&gt;Usage: blockSFAInternalUsers [flags]&lt;/P&gt;
&lt;P&gt;-s show current status&lt;BR /&gt;-a allow internal users with password single factor to authenticate&lt;BR /&gt;-b block internal users with password single factor from authenticating&lt;/P&gt;
&lt;P&gt;[Expert@R82:0]# blockSFAInternalUsers -s&lt;/P&gt;
&lt;P&gt;blockSFAInternalUsers: Allowed&lt;/P&gt;
&lt;P&gt;[Expert@R82:0]#&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 16:33:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Failed-login-alerts-because-of-TACACS-authentication-failure/m-p/243967#M40730</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-17T16:33:04Z</dc:date>
    </item>
  </channel>
</rss>

