<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Using RADIUS Groups (RAD_&amp;lt;Group&amp;gt;) to Assign Permissions in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-RADIUS-Groups-RAD-lt-Group-gt-to-Assign-Permissions/m-p/123794#M8317</link>
    <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;(The whole post is attached as pdf for readability purpose)&lt;/P&gt;&lt;P&gt;Any idea on what goes wrong?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Run on R80.40 VSX,&lt;/LI&gt;&lt;LI&gt;Client is Endpoint Security VE84.70 Build 986200225 (MACOS)&lt;/LI&gt;&lt;LI&gt;Radius authentication to NPS Windows Server 2012R2&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Radius.jpg" style="width: 151px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12541i31B7883BD5077E59/image-size/large?v=v2&amp;amp;px=999" role="button" title="Radius.jpg" alt="Radius.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Configuration according to attached Checkpoint documentation (Radius authentication – Compatibility Mode)&lt;/LI&gt;&lt;LI&gt;2 accesss roles , matching 2 Policy Groups defined on the Radius/NPS server&lt;BR /&gt;1 access role, matching “any user"&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="denvin_1-1626255488760.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12537i45F41A1800D00D89/image-size/medium?v=v2&amp;amp;px=400" role="button" title="denvin_1-1626255488760.png" alt="denvin_1-1626255488760.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;vpnd.elg shows 3 radisu update for user groups attr. 26. None of them are known by the db&lt;BR /&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3217 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_by_reply: calling handler&lt;STRONG&gt; for attr 26.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3218 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): start. do_radgroups=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3219 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): Looking for group RAD_ S=83DEE04C8210C8AEBEB06357B72B078848BE87DC in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3220 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): group RAD_ S=83DEE04C8210C8AEBEB06357B72B078848BE87DC not found in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3221 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups: didn't add group [RAD_ S=83DEE04C8210C8AEBEB06357B72B078848BE87DC]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3222 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): Looking for group RAD_€yUŽŠôpF,6Þä{?*_EXhùót)06`"8Æ@¾ in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3223 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): group RAD_€yUŽŠôpF,6Þä{?*_EXhùót)06`"8Æ@¾ not found in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3224 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups: didn't add group [RAD_€yUŽŠôpF,6Þä{?*_EXhùót)06`"8Æ@¾]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3225 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): Looking for group RAD_€zÈ«+®N…–â…ËÆèŽ™j°iÕé3Óz†#m$Ôå¡® in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3226 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): group RAD_€zÈ«+®N…–â…ËÆèŽ™j°iÕé3Óz†#m$Ôå¡® not found in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3227 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups: didn't add group [RAD_€zÈ«+®N…–â…ËÆèŽ™j°iÕé3Óz†#m$Ôå¡®]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3228 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_callback(au=947d980): daemon: other, login info: valid, server object: valid, src_ip: 0&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Log shows:&lt;BR /&gt;&lt;BR /&gt;Source User Group: All Users&lt;BR /&gt;Roles :&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AccessRole_AllUsers&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Log shows.jpg" style="width: 297px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12538i77869AB1464446C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log shows.jpg" alt="Log shows.jpg" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Only rule 17 is matched&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Only rule 17.jpg" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12540i91FAAD8C9D5B2C04/image-size/large?v=v2&amp;amp;px=999" role="button" title="Only rule 17.jpg" alt="Only rule 17.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be happy to read your suggestions and/or comments&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jul 2021 11:13:39 GMT</pubDate>
    <dc:creator>DVI</dc:creator>
    <dc:date>2021-07-14T11:13:39Z</dc:date>
    <item>
      <title>Using RADIUS Groups (RAD_&lt;Group&gt;) to Assign Permissions</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-RADIUS-Groups-RAD-lt-Group-gt-to-Assign-Permissions/m-p/123794#M8317</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;(The whole post is attached as pdf for readability purpose)&lt;/P&gt;&lt;P&gt;Any idea on what goes wrong?&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Run on R80.40 VSX,&lt;/LI&gt;&lt;LI&gt;Client is Endpoint Security VE84.70 Build 986200225 (MACOS)&lt;/LI&gt;&lt;LI&gt;Radius authentication to NPS Windows Server 2012R2&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Radius.jpg" style="width: 151px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12541i31B7883BD5077E59/image-size/large?v=v2&amp;amp;px=999" role="button" title="Radius.jpg" alt="Radius.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Configuration according to attached Checkpoint documentation (Radius authentication – Compatibility Mode)&lt;/LI&gt;&lt;LI&gt;2 accesss roles , matching 2 Policy Groups defined on the Radius/NPS server&lt;BR /&gt;1 access role, matching “any user"&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="denvin_1-1626255488760.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12537i45F41A1800D00D89/image-size/medium?v=v2&amp;amp;px=400" role="button" title="denvin_1-1626255488760.png" alt="denvin_1-1626255488760.png" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;vpnd.elg shows 3 radisu update for user groups attr. 26. None of them are known by the db&lt;BR /&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3217 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_by_reply: calling handler&lt;STRONG&gt; for attr 26.&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3218 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): start. do_radgroups=1&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3219 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): Looking for group RAD_ S=83DEE04C8210C8AEBEB06357B72B078848BE87DC in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3220 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): group RAD_ S=83DEE04C8210C8AEBEB06357B72B078848BE87DC not found in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3221 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups: didn't add group [RAD_ S=83DEE04C8210C8AEBEB06357B72B078848BE87DC]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3222 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): Looking for group RAD_€yUŽŠôpF,6Þä{?*_EXhùót)06`"8Æ@¾ in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3223 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): group RAD_€yUŽŠôpF,6Þä{?*_EXhùót)06`"8Æ@¾ not found in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3224 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups: didn't add group [RAD_€yUŽŠôpF,6Þä{?*_EXhùót)06`"8Æ@¾]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3225 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): Looking for group RAD_€zÈ«+®N…–â…ËÆèŽ™j°iÕé3Óz†#m$Ôå¡® in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3226 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups(au=947d980): group RAD_€zÈ«+®N…–â…ËÆèŽ™j°iÕé3Óz†#m$Ôå¡® not found in db&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3227 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_update_user_groups: didn't add group [RAD_€zÈ«+®N…–â…ËÆèŽ™j°iÕé3Óz†#m$Ôå¡®]&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2"&gt;3228 [vpnd 3330 4081784768]@FW11ALBE001[14 Jul 12:40:54][AU] radius_callback(au=947d980): daemon: other, login info: valid, server object: valid, src_ip: 0&lt;/FONT&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Log shows:&lt;BR /&gt;&lt;BR /&gt;Source User Group: All Users&lt;BR /&gt;Roles :&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AccessRole_AllUsers&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Log shows.jpg" style="width: 297px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12538i77869AB1464446C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Log shows.jpg" alt="Log shows.jpg" /&gt;&lt;/span&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Only rule 17 is matched&lt;BR /&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="Only rule 17.jpg" style="width: 698px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12540i91FAAD8C9D5B2C04/image-size/large?v=v2&amp;amp;px=999" role="button" title="Only rule 17.jpg" alt="Only rule 17.jpg" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will be happy to read your suggestions and/or comments&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jul 2021 11:13:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-RADIUS-Groups-RAD-lt-Group-gt-to-Assign-Permissions/m-p/123794#M8317</guid>
      <dc:creator>DVI</dc:creator>
      <dc:date>2021-07-14T11:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: Using RADIUS Groups (RAD_&lt;Group&gt;) to Assign Permissions</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-RADIUS-Groups-RAD-lt-Group-gt-to-Assign-Permissions/m-p/124211#M8318</link>
      <description>&lt;P&gt;Groups in Access Roles come from LDAP, not RADIUS.&lt;BR /&gt;Do you have LDAP configured at all?&lt;/P&gt;</description>
      <pubDate>Fri, 16 Jul 2021 19:37:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-RADIUS-Groups-RAD-lt-Group-gt-to-Assign-Permissions/m-p/124211#M8318</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-16T19:37:12Z</dc:date>
    </item>
  </channel>
</rss>

