<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217194#M3681</link>
    <description>&lt;P&gt;Packet capture would maybe help if you load it in Wireshark, then you can compare the radius request between the working and non working gateway. Maybe there is a hint(or hint for TAC)&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2024 21:15:40 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2024-06-11T21:15:40Z</dc:date>
    <item>
      <title>After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217187#M3677</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;we have a VSX Cluster (2x 23800 appliances).&lt;/P&gt;&lt;P&gt;I have upgraded to R81.20 with latest recommended Hotfix T65 .&lt;/P&gt;&lt;P&gt;It seems, that the Gateway is blocking the 1 Factor Authentication to the RADIUS Server.&lt;/P&gt;&lt;P&gt;I noticed, that upgraded GWs are blocking 1 Factor for InternalUsers. That can be allowed by&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;blockSFAInternalUsers -a".&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unfortunately this does not work for RADIUS Server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Error Message is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed Login Factor:&amp;nbsp; &amp;nbsp;1st factor - RADIUS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Reason:&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;RADIUS servers not responding&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When failover to the GW without the T65, authentication works fine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any Ideas?&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 20:36:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217187#M3677</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-11T20:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217188#M3678</link>
      <description>&lt;P&gt;Are these user accounts locally-defined, but with Authentication set to "RADIUS"? &amp;nbsp;I bet that's what it is. &amp;nbsp;As for a fix, I wager that it's a TAC case.&lt;/P&gt;
&lt;P&gt;(I'm conjecturing and making a lot of assumptions for the below suggestion)&lt;/P&gt;
&lt;P&gt;However, if you do have users defined this way, you ought to consider using the multi-authentication profiles instead and have users deferred to RADIUS that way. &amp;nbsp;You can set multiple profiles for multiple types of authentications, then have the VPN client select that login method to select the right authentication. &amp;nbsp;You can combine the multi-auth profile with an LDAP AU to link them to an Access Role for policy enforcement.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 20:49:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217188#M3678</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-06-11T20:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217189#M3679</link>
      <description>&lt;P&gt;No, the Users are not locally defined on the Gateways.&lt;/P&gt;&lt;P&gt;The Gateway with T65 is blocking 1 Factor Authentication with the RADIUS.&lt;BR /&gt;Unfortunately, I am not the admin of the RADIUS. So I can not change the authentication mode.&lt;/P&gt;&lt;P&gt;I have opened a SR for this issue. Waiting for a respons from CP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 20:59:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217189#M3679</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-11T20:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217191#M3680</link>
      <description>&lt;P&gt;Are you still using the classic "generic*" user instead?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the authentication options, these are configured per gateway, not on the RADIUS servers:&lt;/P&gt;
&lt;UL class="lia-list-style-type-circle"&gt;
&lt;LI&gt;Double-click a gateway for gateway properties&lt;/LI&gt;
&lt;LI&gt;VPN Clients, on the left&lt;/LI&gt;
&lt;LI&gt;Authentication&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 21:07:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217191#M3680</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2024-06-11T21:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217194#M3681</link>
      <description>&lt;P&gt;Packet capture would maybe help if you load it in Wireshark, then you can compare the radius request between the working and non working gateway. Maybe there is a hint(or hint for TAC)&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 21:15:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217194#M3681</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-11T21:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217212#M3682</link>
      <description>&lt;P&gt;It is a VSX-Cluster. So the configuration is on the Management-Server.&lt;/P&gt;&lt;P&gt;We have decided to uninstall the T65 Hotfix. After Reboot SIngle Factor Authentication&lt;/P&gt;&lt;P&gt;with RADIUS works fine. So I also have upgraded the other member to R81.20.&lt;/P&gt;&lt;P&gt;Our maintenance window is closed, now.&amp;nbsp; Next evening I will install T65 again,&lt;/P&gt;&lt;P&gt;to do some troubleshooting with TAC.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 22:39:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217212#M3682</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-11T22:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrade with R81.20 JHF  T65 (CVE-2024-24919) Gateway is blocking 1 Factor - RADIUS</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217213#M3683</link>
      <description>&lt;P&gt;Yes, we have collected some tcpdumps.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We could see, that there is communication between GW and Radius.&lt;BR /&gt;I strongly believe, that the T65 is preventing to use single factor Authentication.&lt;/P&gt;&lt;P&gt;TAC engineer will check this with R&amp;amp;D.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2024 22:42:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/After-Upgrade-with-R81-20-JHF-T65-CVE-2024-24919-Gateway-is/m-p/217213#M3683</guid>
      <dc:creator>Axel_Winterberg</dc:creator>
      <dc:date>2024-06-11T22:42:16Z</dc:date>
    </item>
  </channel>
</rss>

