<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TACACS Authentication in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/269511#M45259</link>
    <description>&lt;P&gt;What Vince said makes sense. See if below is configured:&lt;/P&gt;
&lt;DIV&gt;
&lt;H1&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Most Likely Root Cause&lt;/STRONG&gt;&lt;/H1&gt;
&lt;H3&gt;&lt;STRONG&gt;Your TACACS server is not returning the required Check Point–specific TACACS attributes.&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Check Point uses two role names that must be &lt;EM&gt;exact matches&lt;/EM&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;TACP-0&lt;/STRONG&gt; → Read‑only&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TACP-15&lt;/STRONG&gt; → Superuser&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If TACACS returns &lt;STRONG&gt;no role&lt;/STRONG&gt;, or a &lt;STRONG&gt;role name mismatch&lt;/STRONG&gt;, Check Point:&lt;/P&gt;
&lt;P&gt;✔ Accepts authentication&lt;BR /&gt;✘ Fails authorization → session closed (CLI) / no web access (GUI)&lt;/P&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 03 Feb 2026 02:35:13 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-02-03T02:35:13Z</dc:date>
    <item>
      <title>TACACS Authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/269400#M45226</link>
      <description>&lt;P&gt;Hi Experts ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;We are currently integrating Check Point devices (firewalls, management servers, MHOs) with TACACS for administrator authentication.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;Authentication via TACACS is &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;successful&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;, and we can see the success logs on the TACACS server. However, after login:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;CLI access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: User is authenticated but immediately logged out&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;STRONG&gt;&lt;SPAN&gt;GUI / SmartConsole&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt;: Error displayed – &lt;/SPAN&gt;&lt;EM&gt;&lt;SPAN&gt;“You are not configured for Web access”&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;&lt;SPAN&gt;We have already followed the Check Point Admin Guide and:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class=""&gt;&lt;SPAN&gt;Enabled TACACS authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN&gt;Created the required roles on Check Point (TACP-0 and TACP-15) with appropriate permissions&lt;/SPAN&gt;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;What could be the issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sijeel&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 10:44:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/269400#M45226</guid>
      <dc:creator>Malik1</dc:creator>
      <dc:date>2026-02-02T10:44:13Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/269402#M45227</link>
      <description>&lt;P&gt;For me it looks like you are facing a successful authentication followed by a failed authorization.&lt;BR /&gt;Maybe it is a misconfiguration on your end but maybe not.&lt;BR /&gt;My idea:&lt;BR /&gt;The Check Point Gaia OS receives a "Password Correct" message from your TACACS server, but because the server doesn't send instructions on what the user is allowed to do, Gaia defaults to the most restrictive state (immediate logout for CLI and "not configured" for Web).&lt;BR /&gt;&lt;BR /&gt;I guess Custom Attributes to be defined on TACACs server.&lt;BR /&gt;On the sk I know about TACACs i don't see anything about that but in our environment we do authorization via TACACs server, in our Case Cisco ISE and it's done like this:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;Policy Elements::&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Device Administration&lt;/SPAN&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Tacacs+ Profiles&lt;/SPAN&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;CheckPoint&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;1.&amp;nbsp;&lt;STRONG&gt;General tab&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Name:&amp;nbsp;CheckPoint&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Description:&amp;nbsp;CheckPoint Firewall&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;2.&amp;nbsp;&lt;STRONG&gt;Custom Attibutes tab&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;EM&gt;Attribute/Requirement/Valu&lt;/EM&gt;e:&lt;/SPAN&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;CheckPoint-SuperUser-Access=1&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Mandatory&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;1&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;&lt;EM&gt;Attribute/Requirement/Value:&lt;/EM&gt;&lt;/SPAN&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;Checkpoint-User-Role=adminRole&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Mandatory&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;adminRole&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Feb 2026 11:22:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/269402#M45227</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-02-02T11:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/269511#M45259</link>
      <description>&lt;P&gt;What Vince said makes sense. See if below is configured:&lt;/P&gt;
&lt;DIV&gt;
&lt;H1&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; &lt;STRONG&gt;Most Likely Root Cause&lt;/STRONG&gt;&lt;/H1&gt;
&lt;H3&gt;&lt;STRONG&gt;Your TACACS server is not returning the required Check Point–specific TACACS attributes.&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Check Point uses two role names that must be &lt;EM&gt;exact matches&lt;/EM&gt;:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;TACP-0&lt;/STRONG&gt; → Read‑only&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;TACP-15&lt;/STRONG&gt; → Superuser&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If TACACS returns &lt;STRONG&gt;no role&lt;/STRONG&gt;, or a &lt;STRONG&gt;role name mismatch&lt;/STRONG&gt;, Check Point:&lt;/P&gt;
&lt;P&gt;✔ Accepts authentication&lt;BR /&gt;✘ Fails authorization → session closed (CLI) / no web access (GUI)&lt;/P&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 03 Feb 2026 02:35:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/269511#M45259</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-03T02:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: TACACS Authentication</title>
      <link>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/270008#M45343</link>
      <description>&lt;P&gt;Hey Malik,&lt;/P&gt;
&lt;P&gt;Were you able to figure this out?&lt;/P&gt;</description>
      <pubDate>Sun, 08 Feb 2026 23:52:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/TACACS-Authentication/m-p/270008#M45343</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-02-08T23:52:32Z</dc:date>
    </item>
  </channel>
</rss>

