<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Legacy remote user connection error in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183215#M4864</link>
    <description>&lt;P&gt;Hi, Bro.&lt;/P&gt;
&lt;P&gt;This is what appears to me in the log detail.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LU.png" style="width: 690px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21268i271236E33D497D9F/image-size/large?v=v2&amp;amp;px=999" role="button" title="LU.png" alt="LU.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The user is a TACACS+ user, and the security rule in the Firewall is created in the source field with the "add legacy user access".&lt;/P&gt;
&lt;P&gt;I have created a user object, and in turn a group object, the group object, I have authenticated it with the tacacs+ server.&lt;/P&gt;
&lt;P&gt;Within the VPN Community of Remote Access VPN, I have already called the group object, but still, I still cannot log the user in.&lt;/P&gt;
&lt;P&gt;Any idea where the error could be?&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jun 2023 13:51:51 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-06-05T13:51:51Z</dc:date>
    <item>
      <title>Legacy remote user connection error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183166#M4862</link>
      <description>&lt;P&gt;Hello, team.&lt;/P&gt;
&lt;P&gt;I have remote VPN users, who connect to my ClusterXL, but the particularity of these users, is that they are TACACS+ users.&lt;/P&gt;
&lt;P&gt;I understand that the way to add a new user is with the "Add Legacy User Access" option, is this correct?&lt;/P&gt;
&lt;P&gt;I have added a new user.&lt;/P&gt;
&lt;P&gt;I only created a user object, and a user group object, and I call it to my security rule, but the user indicates that he cannot log in, and in the logs I only see a "Log Failed" event.&lt;/P&gt;
&lt;P&gt;This is a problem to be solved from TACACS+???? itself.&lt;/P&gt;
&lt;P&gt;This option of "Legacy Users", is for all the environments in which it is integrated to the SMS with a TACACS+?????&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 00:21:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183166#M4862</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-05T00:21:45Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy remote user connection error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183167#M4863</link>
      <description>&lt;P&gt;Log failed, thats it? No any other logs?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 01:14:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183167#M4863</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-06-05T01:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy remote user connection error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183215#M4864</link>
      <description>&lt;P&gt;Hi, Bro.&lt;/P&gt;
&lt;P&gt;This is what appears to me in the log detail.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LU.png" style="width: 690px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21268i271236E33D497D9F/image-size/large?v=v2&amp;amp;px=999" role="button" title="LU.png" alt="LU.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The user is a TACACS+ user, and the security rule in the Firewall is created in the source field with the "add legacy user access".&lt;/P&gt;
&lt;P&gt;I have created a user object, and in turn a group object, the group object, I have authenticated it with the tacacs+ server.&lt;/P&gt;
&lt;P&gt;Within the VPN Community of Remote Access VPN, I have already called the group object, but still, I still cannot log the user in.&lt;/P&gt;
&lt;P&gt;Any idea where the error could be?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 13:51:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183215#M4864</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-06-05T13:51:51Z</dc:date>
    </item>
    <item>
      <title>Re: Legacy remote user connection error</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183250#M4865</link>
      <description>&lt;P&gt;Wrong username or password is an issue that would have to be resolved with the TACACS+ configuration.&lt;BR /&gt;Or it could be that the user has either non-ASCII characters and/or a password that is longer than is supported similar to what occurs with RADIUS v1.&lt;/P&gt;
&lt;P&gt;For your Access Policy, the correct approach is to create an Access Role for your users.&lt;BR /&gt;These can be created in terms of the group object you've created.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2023 17:06:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Legacy-remote-user-connection-error/m-p/183250#M4865</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-05T17:06:49Z</dc:date>
    </item>
  </channel>
</rss>

