<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IP pool assignment using radius in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9207#M12534</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;Close - but not quite there. I have used the referenced SK to set up in the lab and the clients are getting the SAME ip address. This is so because the RADIUS server is dumb and is not controlling IP allocation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My RADIUS server is sending the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;Framed-IP-Address - 192.168.48.0&lt;BR /&gt;Framed-IP-Netmask - 255.255.255.0&lt;/P&gt;&lt;P&gt;Framed-Protocol - PPP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each client to connect gets a PPP connection: their IP 192.168.48.0 and the gateway is correct at 192.168.100.2. Always the same...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need the gateway itself to handle IP allocation as my Radius server cannot do IP pools. I can send the above attributes or even a string with the name of an IP pool, but the gateway must take this info and make its own decisions about IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way for this to happen or will the Checkpoint Gateway always expect an IP from the radius server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Mar 2019 13:39:08 GMT</pubDate>
    <dc:creator>Gary_Napier</dc:creator>
    <dc:date>2019-03-04T13:39:08Z</dc:date>
    <item>
      <title>IP pool assignment using radius</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9205#M12532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;Looking for a technology go/no go for this scenario: Can you please let me know if this will work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;R80.10 - RA VPN for 2 user groups:&amp;nbsp;&lt;BR /&gt;Group 1 will use the Endpoint client, be Windows based and will receive office mode IP's - already works.&lt;/P&gt;&lt;P&gt;Group 2 will use L2TP (shared secret string) and be Linux based. I would like them to receive custom IP's from a pool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both sets of users authenticate via a Radius server (with accounting). For Group 2, the radius server can send the IP pool name that they should be allocated from.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Key here is that CheckPoint will hand out DHCP addresses&amp;nbsp;instead of the Radius server - as with traditional RADIUS accounting..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 03 Mar 2019 22:14:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9205#M12532</guid>
      <dc:creator>Gary_Napier</dc:creator>
      <dc:date>2019-03-03T22:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool assignment using radius</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9206#M12533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Believe what you are looking for is:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43857" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk43857"&gt;How to configure RADIUS to assign Office Mode IP addresses&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2019 10:08:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9206#M12533</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-04T10:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool assignment using radius</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9207#M12534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;Close - but not quite there. I have used the referenced SK to set up in the lab and the clients are getting the SAME ip address. This is so because the RADIUS server is dumb and is not controlling IP allocation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My RADIUS server is sending the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;Framed-IP-Address - 192.168.48.0&lt;BR /&gt;Framed-IP-Netmask - 255.255.255.0&lt;/P&gt;&lt;P&gt;Framed-Protocol - PPP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Each client to connect gets a PPP connection: their IP 192.168.48.0 and the gateway is correct at 192.168.100.2. Always the same...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need the gateway itself to handle IP allocation as my Radius server cannot do IP pools. I can send the above attributes or even a string with the name of an IP pool, but the gateway must take this info and make its own decisions about IP's.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way for this to happen or will the Checkpoint Gateway always expect an IP from the radius server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2019 13:39:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9207#M12534</guid>
      <dc:creator>Gary_Napier</dc:creator>
      <dc:date>2019-03-04T13:39:08Z</dc:date>
    </item>
    <item>
      <title>Re: IP pool assignment using radius</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9208#M12535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can do IP assignment based on groups as described here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33422" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk33422"&gt;Office Mode IP and ipassignment.conf file&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However the actual subnet to assign IPs from must be specified in ipassignment.conf.&lt;/P&gt;&lt;P&gt;We do not support taking the subnet to assign IPs from via RADIUS.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Mar 2019 15:06:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/IP-pool-assignment-using-radius/m-p/9208#M12535</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-03-04T15:06:00Z</dc:date>
    </item>
  </channel>
</rss>

