<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Message-Authenticator RADIUS attribute (Okta) for Endpoint VPN... in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Message-Authenticator-RADIUS-attribute-Okta-for-Endpoint-VPN/m-p/245025#M2192</link>
    <description>&lt;P&gt;That SK is the correct one.&lt;BR /&gt;Prior to the releases listed, we didn't support sending or receiving the message authenticator attributes.&lt;BR /&gt;I assume if you upgrade to the relevant release and enable the setting to require message authenticator attributes will also send them.&lt;BR /&gt;If you find otherwise, I suggest a TAC case.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Mar 2025 18:46:22 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-03-27T18:46:22Z</dc:date>
    <item>
      <title>Message-Authenticator RADIUS attribute (Okta) for Endpoint VPN...</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Message-Authenticator-RADIUS-attribute-Okta-for-Endpoint-VPN/m-p/245010#M2191</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;R81.20 take 89&lt;/P&gt;&lt;P&gt;Our Endpoint Security VPN uses an Okta RADIUS integration.&amp;nbsp; We have been asked to upgrade the Okta (Windows) agents to the latest version 2.24.2 (from 2.17).&amp;nbsp; When we do this, VPN authentication fails and we see an error in the Okta logs of:&lt;/P&gt;&lt;P&gt;"The Message-Authenticator attribute was expected but not found in the request"&lt;/P&gt;&lt;P&gt;Okta have suggested we need to "upgrade the downstream integration"....&lt;BR /&gt;&lt;EM&gt;&lt;SPAN&gt;"If the downstream integration is not presently configured to send a Message-Authenticator attribute to the Okta RADIUS Agents, it will need to be reconfigured to include the Message-Authenticator attribute or upgraded so that they can support message-authenticator"&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And in their words, this would be a &lt;EM&gt;"Gateway/VPN device (like Cisco ASA, F5 VPN, etc.)"&lt;/EM&gt;.&amp;nbsp; Or in our case, I'm assuming the Check Point firewall.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I can't seem to find anything about how to "configure it to send a Message-Authenticator attribute".&amp;nbsp; I did find an SK...&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182516" target="_blank"&gt;sk182516 - Check Point Response to CVE-2024-3596 - Blast-RADIUS attack&lt;/A&gt;&amp;nbsp;(5th section of the table) but this seems to be to do with what the Firewall should do if it encounters the Message-Authenticator attribute, not to do with actually including it in a request.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Love and packets,&lt;BR /&gt;Mark&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 16:48:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Message-Authenticator-RADIUS-attribute-Okta-for-Endpoint-VPN/m-p/245010#M2191</guid>
      <dc:creator>Mraybone</dc:creator>
      <dc:date>2025-03-27T16:48:48Z</dc:date>
    </item>
    <item>
      <title>Re: Message-Authenticator RADIUS attribute (Okta) for Endpoint VPN...</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Message-Authenticator-RADIUS-attribute-Okta-for-Endpoint-VPN/m-p/245025#M2192</link>
      <description>&lt;P&gt;That SK is the correct one.&lt;BR /&gt;Prior to the releases listed, we didn't support sending or receiving the message authenticator attributes.&lt;BR /&gt;I assume if you upgrade to the relevant release and enable the setting to require message authenticator attributes will also send them.&lt;BR /&gt;If you find otherwise, I suggest a TAC case.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 18:46:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Message-Authenticator-RADIUS-attribute-Okta-for-Endpoint-VPN/m-p/245025#M2192</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-27T18:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: Message-Authenticator RADIUS attribute (Okta) for Endpoint VPN...</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Message-Authenticator-RADIUS-attribute-Okta-for-Endpoint-VPN/m-p/245026#M2193</link>
      <description>&lt;P&gt;Ok thanks for the info - another Okta article I read suggested that along with the Firewall and Okta agent change, a 3rd change is also required on the Okta side.&amp;nbsp; After following the SK with no luck before, I think that's probably why.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 18:49:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Message-Authenticator-RADIUS-attribute-Okta-for-Endpoint-VPN/m-p/245026#M2193</guid>
      <dc:creator>Mraybone</dc:creator>
      <dc:date>2025-03-27T18:49:03Z</dc:date>
    </item>
  </channel>
</rss>

