<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Enabling SecureID Authentication on MobileAccess in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enabling-SecureID-Authentication-on-MobileAccess/m-p/148787#M6801</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;on a&amp;nbsp; ClusterXL Installation with R81 HF65 we want to use SecureID Authentication with SoftTokens on Mobile-Access / VPN-RAS.&lt;/P&gt;&lt;P&gt;The AM-Server ist setup and a SoftToken-Test from an iPhone is succesful.&lt;/P&gt;&lt;P&gt;We use the UDP-Agent Variant (no Radius).&lt;/P&gt;&lt;P&gt;The Authentication-Agent File sdconf.rec is distributed to both Gateways.&lt;/P&gt;&lt;P&gt;However the Gateways never send one Paket to the AM-Server on Authentication through the VPN-Portal.&lt;/P&gt;&lt;P&gt;The ACE-Server is correctly defined under Servers.&lt;/P&gt;&lt;P&gt;DNS-Resolution is ok from IP to FQDN and vice versa.&lt;/P&gt;&lt;P&gt;The correct Atuhentication Profile is shown in the VPN-Portal.&lt;/P&gt;&lt;P&gt;The LOG-Viewer only says:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Category: Session&lt;BR /&gt;Event Type: Login&lt;BR /&gt;Name: Mobile Access Portal&lt;BR /&gt;Version: R81&lt;BR /&gt;User: xxxxxxxxxx@domain.com&lt;BR /&gt;Authentication Method: SecurID&lt;BR /&gt;Login Option: New Login Option with Token&lt;BR /&gt;Failed Login Factor Number:1&lt;BR /&gt;OS Name: Windows&lt;BR /&gt;OS Version: 10.0&lt;BR /&gt;Browser: Edge Chromium&lt;BR /&gt;Re-authentication every:&lt;BR /&gt;Login Timestamp: 2022-05-17T10:06:55Z&lt;BR /&gt;Source Country: Germany&lt;BR /&gt;Source: xxx.xxx.xxx.xxx&lt;BR /&gt;Source Port: 59913&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;Data Protocol: SSL&lt;BR /&gt;&lt;STRONG&gt;Status: Failure&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Reason: Unknown user&lt;/STRONG&gt;&lt;BR /&gt;Suppressed Logs: 0&lt;BR /&gt;Mobile Access Session UID: 628373BF-0001-...&lt;BR /&gt;&lt;STRONG&gt;Action: Failed Log In&lt;/STRONG&gt;&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Mobile Access&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Marker: @A@@B@1652738400@C@1340235&lt;BR /&gt;Log Server Origin: 10.241.0.2&lt;BR /&gt;Origin Log Server IP: 10.241.0.2&lt;BR /&gt;Index Time: 2022-05-17T10:06:55Z&lt;BR /&gt;Lastupdatetime: 1652782015000&lt;BR /&gt;Lastupdateseqnum: 28&lt;BR /&gt;Severity: Informational&lt;BR /&gt;Confidence Level: N/A&lt;BR /&gt;Stored: true&lt;BR /&gt;OS: Windows 10.0&lt;BR /&gt;Login Option Factors: SecurID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing I have not done yet is to do a CPStop/CPStart on the Gateways after defining the SecureID-Server and pushing the Policy.&lt;/P&gt;&lt;P&gt;Is this a mandatory Step? I did not find anything about that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Joachim Brandt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 May 2022 10:18:51 GMT</pubDate>
    <dc:creator>JoBr</dc:creator>
    <dc:date>2022-05-17T10:18:51Z</dc:date>
    <item>
      <title>Enabling SecureID Authentication on MobileAccess</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enabling-SecureID-Authentication-on-MobileAccess/m-p/148787#M6801</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;on a&amp;nbsp; ClusterXL Installation with R81 HF65 we want to use SecureID Authentication with SoftTokens on Mobile-Access / VPN-RAS.&lt;/P&gt;&lt;P&gt;The AM-Server ist setup and a SoftToken-Test from an iPhone is succesful.&lt;/P&gt;&lt;P&gt;We use the UDP-Agent Variant (no Radius).&lt;/P&gt;&lt;P&gt;The Authentication-Agent File sdconf.rec is distributed to both Gateways.&lt;/P&gt;&lt;P&gt;However the Gateways never send one Paket to the AM-Server on Authentication through the VPN-Portal.&lt;/P&gt;&lt;P&gt;The ACE-Server is correctly defined under Servers.&lt;/P&gt;&lt;P&gt;DNS-Resolution is ok from IP to FQDN and vice versa.&lt;/P&gt;&lt;P&gt;The correct Atuhentication Profile is shown in the VPN-Portal.&lt;/P&gt;&lt;P&gt;The LOG-Viewer only says:&amp;nbsp;&lt;/P&gt;&lt;P&gt;Category: Session&lt;BR /&gt;Event Type: Login&lt;BR /&gt;Name: Mobile Access Portal&lt;BR /&gt;Version: R81&lt;BR /&gt;User: xxxxxxxxxx@domain.com&lt;BR /&gt;Authentication Method: SecurID&lt;BR /&gt;Login Option: New Login Option with Token&lt;BR /&gt;Failed Login Factor Number:1&lt;BR /&gt;OS Name: Windows&lt;BR /&gt;OS Version: 10.0&lt;BR /&gt;Browser: Edge Chromium&lt;BR /&gt;Re-authentication every:&lt;BR /&gt;Login Timestamp: 2022-05-17T10:06:55Z&lt;BR /&gt;Source Country: Germany&lt;BR /&gt;Source: xxx.xxx.xxx.xxx&lt;BR /&gt;Source Port: 59913&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;Data Protocol: SSL&lt;BR /&gt;&lt;STRONG&gt;Status: Failure&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;Reason: Unknown user&lt;/STRONG&gt;&lt;BR /&gt;Suppressed Logs: 0&lt;BR /&gt;Mobile Access Session UID: 628373BF-0001-...&lt;BR /&gt;&lt;STRONG&gt;Action: Failed Log In&lt;/STRONG&gt;&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Mobile Access&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Marker: @A@@B@1652738400@C@1340235&lt;BR /&gt;Log Server Origin: 10.241.0.2&lt;BR /&gt;Origin Log Server IP: 10.241.0.2&lt;BR /&gt;Index Time: 2022-05-17T10:06:55Z&lt;BR /&gt;Lastupdatetime: 1652782015000&lt;BR /&gt;Lastupdateseqnum: 28&lt;BR /&gt;Severity: Informational&lt;BR /&gt;Confidence Level: N/A&lt;BR /&gt;Stored: true&lt;BR /&gt;OS: Windows 10.0&lt;BR /&gt;Login Option Factors: SecurID&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The only thing I have not done yet is to do a CPStop/CPStart on the Gateways after defining the SecureID-Server and pushing the Policy.&lt;/P&gt;&lt;P&gt;Is this a mandatory Step? I did not find anything about that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Joachim Brandt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2022 10:18:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Enabling-SecureID-Authentication-on-MobileAccess/m-p/148787#M6801</guid>
      <dc:creator>JoBr</dc:creator>
      <dc:date>2022-05-17T10:18:51Z</dc:date>
    </item>
  </channel>
</rss>

