<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Strip domain part from username in Endpoint Connect in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Strip-domain-part-from-username-in-Endpoint-Connect/m-p/110805#M9166</link>
    <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;One of our customer uses AD authentication when using remote access with Endpoint Connect. In the Endpoint Connect client, we are entering this AD username and password and this is working fine. The username is in the format:&amp;nbsp;&lt;EM&gt;username&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;But now, a second authentication step is needed with RADIUS and the RADIUS server requires the username to be in the pre-Windows 2000 format. So &lt;EM&gt;domain\username&lt;/EM&gt;. We have configured the New Login Options feature within SmartConsole.&lt;/P&gt;&lt;P&gt;In this new setup, AD authentication works fine because the gateways recognizes the username by the entered username. But the second authentication step fails because the RADIUS server expects&amp;nbsp;&lt;EM&gt;domain\username&lt;/EM&gt; but just receives&amp;nbsp;&lt;EM&gt;username.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If we enter &lt;EM&gt;domain\username&lt;/EM&gt; in the Endpoint Connect client we get an unkown user right away.&lt;/P&gt;&lt;P&gt;Can we strip the domain part of the username entered in Endpoint Connect so Check Point recognizes the user, but send the complete name (including the domain) to the RADIUS server? Has anyone ever done this before?&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
    <pubDate>Mon, 15 Feb 2021 10:57:38 GMT</pubDate>
    <dc:creator>Martijn</dc:creator>
    <dc:date>2021-02-15T10:57:38Z</dc:date>
    <item>
      <title>Strip domain part from username in Endpoint Connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Strip-domain-part-from-username-in-Endpoint-Connect/m-p/110805#M9166</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;One of our customer uses AD authentication when using remote access with Endpoint Connect. In the Endpoint Connect client, we are entering this AD username and password and this is working fine. The username is in the format:&amp;nbsp;&lt;EM&gt;username&lt;/EM&gt;.&lt;/P&gt;&lt;P&gt;But now, a second authentication step is needed with RADIUS and the RADIUS server requires the username to be in the pre-Windows 2000 format. So &lt;EM&gt;domain\username&lt;/EM&gt;. We have configured the New Login Options feature within SmartConsole.&lt;/P&gt;&lt;P&gt;In this new setup, AD authentication works fine because the gateways recognizes the username by the entered username. But the second authentication step fails because the RADIUS server expects&amp;nbsp;&lt;EM&gt;domain\username&lt;/EM&gt; but just receives&amp;nbsp;&lt;EM&gt;username.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If we enter &lt;EM&gt;domain\username&lt;/EM&gt; in the Endpoint Connect client we get an unkown user right away.&lt;/P&gt;&lt;P&gt;Can we strip the domain part of the username entered in Endpoint Connect so Check Point recognizes the user, but send the complete name (including the domain) to the RADIUS server? Has anyone ever done this before?&lt;/P&gt;&lt;P&gt;Thanks for any help.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 10:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Strip-domain-part-from-username-in-Endpoint-Connect/m-p/110805#M9166</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2021-02-15T10:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: Strip domain part from username in Endpoint Connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Strip-domain-part-from-username-in-Endpoint-Connect/m-p/110806#M9167</link>
      <description>&lt;P&gt;Out of interest what is the Radius server, is it NPS or something else?&lt;/P&gt;
&lt;P&gt;A lot of radius servers support the concept of domain / realm stripping or normalisation for these types of scenarios.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 11:15:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Strip-domain-part-from-username-in-Endpoint-Connect/m-p/110806#M9167</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-02-15T11:15:29Z</dc:date>
    </item>
    <item>
      <title>Re: Strip domain part from username in Endpoint Connect</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Strip-domain-part-from-username-in-Endpoint-Connect/m-p/110807#M9168</link>
      <description>&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;Customer uses Safenet.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also believe customer has several AD domains and several LDAP Account Unit objects and users are unique.&lt;BR /&gt;Maybe Safenet needs the domain part to search the correct domain.&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Mon, 15 Feb 2021 11:38:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Strip-domain-part-from-username-in-Endpoint-Connect/m-p/110807#M9168</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2021-02-15T11:38:54Z</dc:date>
    </item>
  </channel>
</rss>

