<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Gateway is trying to authenticate by LDAP first even if Radius is configured in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108411#M9280</link>
    <description>&lt;P&gt;Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jan 2021 14:43:29 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-01-21T14:43:29Z</dc:date>
    <item>
      <title>Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108400#M9276</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;While setting up Radius authentication (with MFA) for Mobile Access (SNX and Capsule) i have stumbled upon an issue i cannot solve.&lt;/P&gt;&lt;P&gt;I followed a guide Checkpoint_Azure_MFA_2020_v2_CheckMates.pdf and succesfully managed to configure a gateway (R80.20)&lt;/P&gt;&lt;P&gt;Radius works and MFA as well for both Capsule and MAB portal.&lt;/P&gt;&lt;P&gt;On the same SMS (R80.40)&amp;nbsp; i configured another gateway (R80.30) with the same authentication scheme and if i login with Capsule, Radius and MFA works perfectly fine.&lt;/P&gt;&lt;P&gt;But if i use the MAB portal the gateway is trying to authenticate the user by LDAP first (querying the servers i have in ldap account units) and there is a delay for 2 minutes before the authentication is done by Radius.&lt;/P&gt;&lt;P&gt;The user is authenticated by MFA after that.&lt;/P&gt;&lt;P&gt;Since the configuration on gateway/cluster object is not so much i cannot understand what the difference is here.&lt;/P&gt;&lt;P&gt;Grateful for any pointers or hints &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 14:08:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108400#M9276</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-21T14:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108407#M9277</link>
      <description>&lt;P&gt;Hi Durin,&lt;/P&gt;&lt;P&gt;I have a feeling I may know what the solution here is. First off, how is auth configured on the gateway object itself? Under vpn or mobile access (depending which one you have issue with), there is a setting for authentication and you can configure auth methods there. Can you send a screenshot of how thats set up? I think it may give us some clue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 14:22:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108407#M9277</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-21T14:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108409#M9278</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="rad_delay.PNG" style="width: 763px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/10286i1DC89F73D5B80EC2/image-size/large?v=v2&amp;amp;px=999" role="button" title="rad_delay.PNG" alt="rad_delay.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 14:40:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108409#M9278</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-21T14:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108410#M9279</link>
      <description>&lt;P&gt;It is the same config under VPN Clients as for Mobile Access on both gateways. Without delay and the one with delay, use same Radius object.&lt;/P&gt;&lt;P&gt;Tried with and witjout support for older clients.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 14:49:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108410#M9279</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-21T14:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108411#M9280</link>
      <description>&lt;P&gt;Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 14:43:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108411#M9280</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-21T14:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108414#M9281</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Thanks! I removed from auth list and now it works!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 15:09:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108414#M9281</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-21T15:09:14Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108428#M9282</link>
      <description>&lt;P&gt;For you, no charge ; )&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 17:07:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108428#M9282</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-21T17:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108445#M9283</link>
      <description>&lt;P&gt;Much obliged &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jan 2021 20:01:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108445#M9283</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-21T20:01:59Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108528#M9284</link>
      <description>&lt;P&gt;Glad I could help...thats what I love about this community. 90% of the time, people find solutions from others without having to waste time on hold and talk to TAC, which USUALLY ends up in them asking for debugs that have nothing to do with the problem anyway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have a nice weekend!!&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 14:51:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108528#M9284</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-22T14:51:10Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108533#M9285</link>
      <description>&lt;P&gt;Totally agree, this is a good community with useful stuff and people with a lot of knowledge.&lt;/P&gt;&lt;P&gt;Have a nice weekend you also and thanks one more time &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 15:03:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108533#M9285</guid>
      <dc:creator>Durin</dc:creator>
      <dc:date>2021-01-22T15:03:29Z</dc:date>
    </item>
    <item>
      <title>Re: Gateway is trying to authenticate by LDAP first even if Radius is configured</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108619#M9286</link>
      <description>&lt;P&gt;Thanks mate, you as well...cheers!&lt;/P&gt;&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 23 Jan 2021 21:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Gateway-is-trying-to-authenticate-by-LDAP-first-even-if-Radius/m-p/108619#M9286</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-01-23T21:46:46Z</dc:date>
    </item>
  </channel>
</rss>

