<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SNX Authentication with User Directory (LDAP not AD) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-Authentication-with-User-Directory-LDAP-not-AD/m-p/97924#M9828</link>
    <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;I configured a Unit Account with profile "Domino_DS" and added it to User Directory (VPN Clients &amp;gt; Authentication &amp;gt; Multiple Authentication Clients Settings) since I want to use LDAP accounts (email addresses) to allow users to connect in VPN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp01.PNG" style="width: 847px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8221i7E1F0954D8F584E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp01.PNG" alt="cp01.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I mapped the email address as UID.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp02.PNG" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8222i9E019BC22F8E1A27/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp02.PNG" alt="cp02.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp03.PNG" style="width: 712px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8223i0070387E8BC8F405/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp03.PNG" alt="cp03.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The connection using Check Point Mobile client under Windows works well, but SNX under Linux cannot authenticate:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp04.png" style="width: 530px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8224i485BA3FC91FFE927/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp04.png" alt="cp04.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I use a local VPN account with SNX, then it works.&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Francesco&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 14:04:45 GMT</pubDate>
    <dc:creator>redcrow</dc:creator>
    <dc:date>2020-09-30T14:04:45Z</dc:date>
    <item>
      <title>SNX Authentication with User Directory (LDAP not AD)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-Authentication-with-User-Directory-LDAP-not-AD/m-p/97924#M9828</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;I configured a Unit Account with profile "Domino_DS" and added it to User Directory (VPN Clients &amp;gt; Authentication &amp;gt; Multiple Authentication Clients Settings) since I want to use LDAP accounts (email addresses) to allow users to connect in VPN.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp01.PNG" style="width: 847px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8221i7E1F0954D8F584E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp01.PNG" alt="cp01.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I mapped the email address as UID.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp02.PNG" style="width: 831px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8222i9E019BC22F8E1A27/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp02.PNG" alt="cp02.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp03.PNG" style="width: 712px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8223i0070387E8BC8F405/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp03.PNG" alt="cp03.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The connection using Check Point Mobile client under Windows works well, but SNX under Linux cannot authenticate:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cp04.png" style="width: 530px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8224i485BA3FC91FFE927/image-size/large?v=v2&amp;amp;px=999" role="button" title="cp04.png" alt="cp04.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;If I use a local VPN account with SNX, then it works.&lt;/P&gt;&lt;P&gt;What am I doing wrong?&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Francesco&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 14:04:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-Authentication-with-User-Directory-LDAP-not-AD/m-p/97924#M9828</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-09-30T14:04:45Z</dc:date>
    </item>
    <item>
      <title>Re: SNX Authentication with User Directory (LDAP not AD)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-Authentication-with-User-Directory-LDAP-not-AD/m-p/98004#M9829</link>
      <description>&lt;P&gt;Do a packet capture between the gateway and the ldap server and check if its connecting. First make sure the connection is successful. Then look at the ldap conversation to see if its correct.&lt;/P&gt;&lt;P&gt;Could be&lt;/P&gt;&lt;P&gt;Firewall can't connect to ldap server.&lt;/P&gt;&lt;P&gt;Firewall can't login to ldap to generate a query.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ldap server is rejecting login request for client.&lt;/P&gt;&lt;P&gt;I will say I don't think I've seen many people using none MS AD ldap so possible bug but check the other things first.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 13:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-Authentication-with-User-Directory-LDAP-not-AD/m-p/98004#M9829</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-10-01T13:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: SNX Authentication with User Directory (LDAP not AD)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-Authentication-with-User-Directory-LDAP-not-AD/m-p/98007#M9830</link>
      <description>&lt;P&gt;Thank you for your reply. I will check that. Anyway, if the problem is connection between Gateway and LDAP (I'm sure it isn't), the Windows Endpoint shouldn't work, but it works.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 13:56:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SNX-Authentication-with-User-Directory-LDAP-not-AD/m-p/98007#M9830</guid>
      <dc:creator>redcrow</dc:creator>
      <dc:date>2020-10-01T13:56:49Z</dc:date>
    </item>
  </channel>
</rss>

