<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Client Enforcing Settings Not Configured in Gateway in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/206929#M3987</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The first experience I am getting is this....&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;The gateway is configured to perform "Single Authentication" / "Compatibility with Older clients". The authentication method is RADIUS and &lt;STRONG&gt;is not&lt;/STRONG&gt; configured to ask for password as first challenge. There is no "MultiAuthenicaiton client settings" configured. All fairly standard stuff.&lt;/P&gt;&lt;P&gt;If you take a clean installer it will connect to the gateway and the ask for the username but the password field will be greyed out (as i would expect). You click next enter the RADIUS prompt and the client throws a wobbly that the password is wrong. Slightly less standard stuff!&lt;/P&gt;&lt;P&gt;If I install the customers customised installer then the client will ask me for the username &lt;STRONG&gt;and the password&lt;/STRONG&gt; move onto the RADIUS token then let me login.&lt;/P&gt;&lt;P&gt;So obviously the client has been configured at some point in this environments long and distant past to require the user to provide the password regardless... but what gives with the gateway? Where is the setting requiring the password... but not requiring the password is some strange setting in the gateway I just cant find? Is this a 'feature'? What am I missing?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;The second strange experience I am getting is...&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You try and connect to the Gateway using a domain machine you are let in without issue. You try and connect using a non-domain machine and you can connect but get a message in the client isnt a member of the domain and you can access internal resources. However if you add a registry entry with the domain name under System\CurrentControlSet\Services\Tcpip\Parameters\Domain then you can get in without issue.&lt;/P&gt;&lt;P&gt;So you think maybe Mobile Access is configured to perform compliance Checking. You look at the Gateway Properties -&amp;gt; Mobile Access -&amp;gt; Endpoint compliance but its disabled. So you open up the local.scv file on the gateway but this is a completely standard unedited file.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Facts and Figures&lt;/STRONG&gt; &lt;/U&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;OS/version of the client PC = Windows 10 / Windows 11&lt;/LI&gt;&lt;LI&gt;Version of Remote Access client = It looks like this experience has been the same for years, current version 87.30.&lt;/LI&gt;&lt;LI&gt;Exact version/JHF take level of gateway = Its been configured like this since R77 days. Current version is R81.10.&lt;/LI&gt;&lt;LI&gt;For Endpoint/Remote Access, please include the client versions = eh?&lt;/LI&gt;&lt;LI&gt;A simplified network diagram is always appreciated = Fairly standard Internet -&amp;gt; Gateway -&amp;gt; Internal network, not sure its required for this post.&lt;/LI&gt;&lt;LI&gt;References to precise documentation you followed, the results you were expecting, and the results = None&lt;/LI&gt;&lt;LI&gt;Relevant screenshots are helpful = Not sure these are too helpful at this point this is all fairly standard messages.&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Thu, 22 Feb 2024 21:31:38 GMT</pubDate>
    <dc:creator>tmorgan</dc:creator>
    <dc:date>2024-02-22T21:31:38Z</dc:date>
    <item>
      <title>VPN Client Enforcing Settings Not Configured in Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/206929#M3987</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;The first experience I am getting is this....&lt;/STRONG&gt;&lt;/U&gt;&lt;/P&gt;&lt;P&gt;The gateway is configured to perform "Single Authentication" / "Compatibility with Older clients". The authentication method is RADIUS and &lt;STRONG&gt;is not&lt;/STRONG&gt; configured to ask for password as first challenge. There is no "MultiAuthenicaiton client settings" configured. All fairly standard stuff.&lt;/P&gt;&lt;P&gt;If you take a clean installer it will connect to the gateway and the ask for the username but the password field will be greyed out (as i would expect). You click next enter the RADIUS prompt and the client throws a wobbly that the password is wrong. Slightly less standard stuff!&lt;/P&gt;&lt;P&gt;If I install the customers customised installer then the client will ask me for the username &lt;STRONG&gt;and the password&lt;/STRONG&gt; move onto the RADIUS token then let me login.&lt;/P&gt;&lt;P&gt;So obviously the client has been configured at some point in this environments long and distant past to require the user to provide the password regardless... but what gives with the gateway? Where is the setting requiring the password... but not requiring the password is some strange setting in the gateway I just cant find? Is this a 'feature'? What am I missing?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;U&gt;The second strange experience I am getting is...&lt;/U&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;You try and connect to the Gateway using a domain machine you are let in without issue. You try and connect using a non-domain machine and you can connect but get a message in the client isnt a member of the domain and you can access internal resources. However if you add a registry entry with the domain name under System\CurrentControlSet\Services\Tcpip\Parameters\Domain then you can get in without issue.&lt;/P&gt;&lt;P&gt;So you think maybe Mobile Access is configured to perform compliance Checking. You look at the Gateway Properties -&amp;gt; Mobile Access -&amp;gt; Endpoint compliance but its disabled. So you open up the local.scv file on the gateway but this is a completely standard unedited file.&lt;/P&gt;&lt;P&gt;&lt;U&gt;&lt;STRONG&gt;Facts and Figures&lt;/STRONG&gt; &lt;/U&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;OS/version of the client PC = Windows 10 / Windows 11&lt;/LI&gt;&lt;LI&gt;Version of Remote Access client = It looks like this experience has been the same for years, current version 87.30.&lt;/LI&gt;&lt;LI&gt;Exact version/JHF take level of gateway = Its been configured like this since R77 days. Current version is R81.10.&lt;/LI&gt;&lt;LI&gt;For Endpoint/Remote Access, please include the client versions = eh?&lt;/LI&gt;&lt;LI&gt;A simplified network diagram is always appreciated = Fairly standard Internet -&amp;gt; Gateway -&amp;gt; Internal network, not sure its required for this post.&lt;/LI&gt;&lt;LI&gt;References to precise documentation you followed, the results you were expecting, and the results = None&lt;/LI&gt;&lt;LI&gt;Relevant screenshots are helpful = Not sure these are too helpful at this point this is all fairly standard messages.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 22 Feb 2024 21:31:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/206929#M3987</guid>
      <dc:creator>tmorgan</dc:creator>
      <dc:date>2024-02-22T21:31:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client Enforcing Settings Not Configured in Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/206970#M3988</link>
      <description>&lt;P&gt;I would definitely see if you can do remote with TAC for this...sounds like it may need some more investigation.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 03:08:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/206970#M3988</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T03:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client Enforcing Settings Not Configured in Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/207030#M3989</link>
      <description>&lt;P&gt;Yeah I had a feeling that was the case. I just wanted to see if there was any obvious points I had missed. I tend to try and avoid CP TAC as it tends to be a bit... abrasive... in the UK.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 15:01:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/207030#M3989</guid>
      <dc:creator>tmorgan</dc:creator>
      <dc:date>2024-02-23T15:01:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client Enforcing Settings Not Configured in Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/207031#M3990</link>
      <description>&lt;P&gt;I hear ya. Lets see if others will have some ideas.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 15:02:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/207031#M3990</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T15:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Client Enforcing Settings Not Configured in Gateway</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/210487#M3991</link>
      <description>&lt;P&gt;So a quick update on this one. After a lot of back an forwards with TAC I am starting to suspect that whoever did the last major upgrade on this firewall copied the state files on the gateways instead of the config files on the SMS eg $FWDIR/state/ instead of $FWDIR/conf/.&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have been given the below advice from TAC. However, to a number of issues in this environment I suspect I am going to recommend a clean install to R81.20 in the hope to move us to a known, and soon to be documented, condition.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;BLOCKQUOTE&gt;SCV configuration is incomplete without enabling "policy server" blade on the FW.&lt;P class=""&gt;&lt;BR /&gt;After making the changes on the&amp;nbsp;&lt;EM&gt;$FWDIR/conf/local.scv&lt;/EM&gt;&amp;nbsp;file in the MGMT server.&lt;BR /&gt;During policy installation,&amp;nbsp;&lt;EM&gt;$FWDIR/conf/local.scv&lt;/EM&gt;&amp;nbsp;file in the MGMT is copied to following locations:&lt;BR /&gt;$FWDIR/state/&amp;lt;Name_of_GW_Object&amp;gt;/PS ------- of the MGMT server&lt;BR /&gt;$FWDIR/state/local/PS/ -------- of the Security Gateway&lt;BR /&gt;&lt;BR /&gt;In our case,&amp;nbsp;&lt;BR /&gt;$FWDIR/state/ - files are not default&amp;nbsp;&lt;BR /&gt;$FWDIR/conf/ - files are default&lt;BR /&gt;&lt;BR /&gt;We believe that those are have become corrupt.&lt;BR /&gt;&lt;BR /&gt;I'm attaching&amp;nbsp;&lt;EM&gt;$FWDIR/conf/local.scv&lt;/EM&gt;&amp;nbsp;file from my Lab MGMT server (R81.10 take 130) in the outgoing folder of SFTP server.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;Backup the files:&lt;BR /&gt;$FWDIR/state/&amp;lt;Name_of_GW_Object&amp;gt;/PS ------- of the MGMT server&lt;BR /&gt;$FWDIR/state/local/PS/ -------- of the Security Gateway&lt;BR /&gt;&lt;BR /&gt;&amp;gt;Download the local.scv file from the SFTP server&lt;BR /&gt;&amp;gt;Load it in&amp;nbsp;&lt;EM&gt;$FWDIR/conf/&lt;/EM&gt;&amp;nbsp;of the MGMT server.&lt;BR /&gt;&amp;gt;Install the database&lt;BR /&gt;&amp;gt;Install the policy&lt;BR /&gt;&lt;BR /&gt;This should resolve your issue.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 19:38:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Client-Enforcing-Settings-Not-Configured-in-Gateway/m-p/210487#M3991</guid>
      <dc:creator>tmorgan</dc:creator>
      <dc:date>2024-04-04T19:38:40Z</dc:date>
    </item>
  </channel>
</rss>

