<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EndPoint VPN Error Following Upgrade in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150564#M6652</link>
    <description>&lt;P&gt;The only thing I found with those errors is below link, but not so sure it applies : (. Maybe worth TAC case, as that sounds like a pretty serious problem. Never mind, I see its same sk you mentioned as well...Just as a test, to be 100% sure, can you attempt user/pass method to see if that works?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115352&amp;amp;t=1535673600030" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115352&amp;amp;t=1535673600030&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 10 Jun 2022 13:08:49 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-06-10T13:08:49Z</dc:date>
    <item>
      <title>EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150553#M6649</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;Ive upgraded one of our FWs from r80.10 -&amp;gt; r80.40, and now I am recieving the below error for endpoint VPN connections.&amp;nbsp;&lt;/P&gt;&lt;P&gt;"You are not authorized to recieve and office mode IP address"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-06-10 at 11.15.27.png" style="width: 748px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16865i5735058A499EC87A/image-dimensions/748x442?v=v2" width="748" height="442" role="button" title="Screenshot 2022-06-10 at 11.15.27.png" alt="Screenshot 2022-06-10 at 11.15.27.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The only untoward message I can find in vpn.elg debug is below - but possibly a red herring, not certain.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;[vpnd 5997 4126250688]@CPFW-R77.20[10 June 13:40:22] check_uint_attribute_value: failed to get attribute [sr_info_auth_grps_fetched] from userobject&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;[vpnd 5997 4126250688]@CPFW-R77.20[10 June 13:40:22] check_uint_attribute_value: read attribute [sr_info_auth_grps_fetched] on user object, value is 0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;The above error is mentioned in SK115352 &amp;gt;&amp;gt; however, user has NOT got multiple accounts internal and ldap, so I dont believe its a valid fix here.&lt;/P&gt;&lt;P&gt;SmartLog shows the authentication as successfull, but without any further entries.&lt;/P&gt;&lt;P&gt;The other GW is still on r80.10, and working fine with the same policy. Im not sure if that may have some impact here with differing versions.&lt;/P&gt;&lt;P&gt;Also, the clients use a certificate to authenticate. Im wondering has something changed with .10 and .40 in terms of certificates. The certificate is self signed.&lt;/P&gt;&lt;P&gt;Any thoughts much appreciated.&lt;/P&gt;&lt;P&gt;D&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 13:05:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150553#M6649</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-06-10T13:05:58Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150557#M6650</link>
      <description>&lt;P&gt;Hm, thats indeed a bit strange. So that message clearly would indicate that it believes that user is not authorized to get the OM IP address, though it does show its authenticated, so to me at least, would tell me that cert auth part is fine. Can you confirm that maybe office mode settings did not change on that firewall?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 12:29:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150557#M6650</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-10T12:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150558#M6651</link>
      <description>&lt;P&gt;Hi, no changes to office mode.&lt;/P&gt;&lt;P&gt;Ive updated the thread with the following errors / messages found in vpn.elg:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;[vpnd 5997 4126250688]@CPFW-R77.20[10 June 13:40:22] check_uint_attribute_value: failed to get attribute [sr_info_auth_grps_fetched] from userobject&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;[vpnd 5997 4126250688]@CPFW-R77.20[10 June 13:40:22] check_uint_attribute_value: read attribute [sr_info_auth_grps_fetched] on user object, value is 0&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 12:38:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150558#M6651</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-06-10T12:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150564#M6652</link>
      <description>&lt;P&gt;The only thing I found with those errors is below link, but not so sure it applies : (. Maybe worth TAC case, as that sounds like a pretty serious problem. Never mind, I see its same sk you mentioned as well...Just as a test, to be 100% sure, can you attempt user/pass method to see if that works?&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115352&amp;amp;t=1535673600030" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115352&amp;amp;t=1535673600030&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 13:08:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150564#M6652</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-10T13:08:49Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150581#M6655</link>
      <description>&lt;P&gt;That message indicates a license issue.&lt;BR /&gt;With cplic print from the relevant gateway, we can confirm if you have the correct license that allows for Office Mode.&lt;BR /&gt;If you have the correct license and the upgrade causes it to break, it's probably a bug and a TAC case will be necessary.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 15:53:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150581#M6655</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-10T15:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150583#M6656</link>
      <description>&lt;P&gt;Thanks - I thought so too. But licensing looks ok. Ive also dropped an eval on it, just to be sure, with no effect. Ive a call open with TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 15:55:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150583#M6656</guid>
      <dc:creator>superd</dc:creator>
      <dc:date>2022-06-10T15:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150585#M6657</link>
      <description>&lt;P&gt;Im pretty positive its not license issue.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 15:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150585#M6657</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-10T15:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150592#M6659</link>
      <description>&lt;P&gt;This week, I ran in to a very similar situation with a client.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Their environment was R80.10 JHF Take 30 upgrading to R80.10 JHF Take 55.&lt;/P&gt;&lt;P&gt;Upon upgrade, it immediately broke all VPN attempts with a very similar error (unable to obtain Office Mode IP).&amp;nbsp; In this particular situation, office mode IP addresses are administered by DHCP, which may be why the error differs.&lt;/P&gt;&lt;P&gt;This is a known issue in the later JHF releases, and support provided a specific hotfix to repair it.&lt;/P&gt;&lt;P&gt;Here is &lt;SPAN&gt;sk178767 for the issue:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178767&amp;amp;partition=Advanced&amp;amp;product=Remote" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk178767&amp;amp;partition=Advanced&amp;amp;product=Remote&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 17:05:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150592#M6659</guid>
      <dc:creator>Egenity</dc:creator>
      <dc:date>2022-06-10T17:05:10Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150597#M6660</link>
      <description>&lt;P&gt;Thats odd, because I never had that problem with any customers on those versions. Also, error message does not seem to match with what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70926"&gt;@superd&lt;/a&gt;&amp;nbsp;posted originally.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 18:53:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150597#M6660</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-10T18:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150598#M6661</link>
      <description>&lt;P&gt;Correct.&amp;nbsp; As my post indicated and explained, similar, not the same error message.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#3366FF"&gt;"&lt;SPAN&gt;This week, I ran in to a very &lt;U&gt;&lt;STRONG&gt;similar&lt;/STRONG&gt;&lt;/U&gt; situation with a client. "&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;FONT color="#3366FF"&gt;&lt;SPAN&gt;"Upon upgrade, it immediately broke all VPN attempts with a very similar error (unable to obtain Office Mode IP).&amp;nbsp; In this particular situation, office mode IP addresses are administered by DHCP,&lt;U&gt;&lt;STRONG&gt; which may be why the error differs&lt;/STRONG&gt;&lt;/U&gt;."&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 18:59:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150598#M6661</guid>
      <dc:creator>Egenity</dc:creator>
      <dc:date>2022-06-10T18:59:49Z</dc:date>
    </item>
    <item>
      <title>Re: EndPoint VPN Error Following Upgrade</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150599#M6662</link>
      <description>&lt;P&gt;Thats true : - ). Personally, I doubt its related, but if&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70926"&gt;@superd&lt;/a&gt;&amp;nbsp;is willing to try, he could also confirm with TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 19:01:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EndPoint-VPN-Error-Following-Upgrade/m-p/150599#M6662</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-06-10T19:01:18Z</dc:date>
    </item>
  </channel>
</rss>

