<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius authentication broken in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225423#M11326</link>
    <description>&lt;P&gt;When support has expired it is not an option.&lt;BR /&gt;Currently getting prices to get support again.&lt;/P&gt;</description>
    <pubDate>Tue, 03 Sep 2024 09:11:15 GMT</pubDate>
    <dc:creator>toha</dc:creator>
    <dc:date>2024-09-03T09:11:15Z</dc:date>
    <item>
      <title>Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225105#M11293</link>
      <description>&lt;P&gt;Users are unable to login to VPN with Radius with Azure MFA extension installed. Users receive 3 text messages but are not able to type in the numbers. Users are prompted with "Access denied - wrong username and password"&lt;/P&gt;&lt;P&gt;We use&amp;nbsp;&lt;SPAN&gt;Quantum Spark 1570 Appliance and Check Point VPN client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If I disable MFA extension users are also prompted with&amp;nbsp;"Access denied - wrong username and password"&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 09:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225105#M11293</guid>
      <dc:creator>toha</dc:creator>
      <dc:date>2024-08-30T09:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225114#M11294</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/91817"&gt;@toha&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This auth method ever worked before?&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 11:20:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225114#M11294</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-30T11:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225117#M11295</link>
      <description>&lt;P&gt;Is the appliance locally or centrally managed and which firmware version/build is used?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 11:30:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225117#M11295</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-08-30T11:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225129#M11297</link>
      <description>&lt;P&gt;Agree with the questions guys asked, we need bit more details.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 12:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225129#M11297</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-30T12:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225160#M11299</link>
      <description>&lt;P&gt;Most likely it is because of the mitigations related to BLAST RADIUS:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182516" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182516&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;To the best of my knowledge, we have not implemented&amp;nbsp;&lt;SPAN&gt;RADIUS Message-Authentication on the Check Point side, at least outside of the context of a specific fix from TAC.&lt;BR /&gt;&lt;/SPAN&gt;Please open a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2024 17:24:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225160#M11299</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-30T17:24:48Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225414#M11324</link>
      <description>&lt;P&gt;Hi guys&lt;/P&gt;&lt;P&gt;Sorry for the lack of details in my question, I was pushed from all directions to get this issue resolved.&lt;BR /&gt;I have found a Check Point SK that descripes the issue and provides a fix.&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk42184" target="_blank" rel="noopener"&gt;RADIUS authentication fails (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;but the solution is not available in R81.10 '&lt;EM&gt;&lt;STRONG&gt;VPN Remote Access - RADIUS attribute to be ignored'&amp;nbsp;&lt;/STRONG&gt;&lt;/EM&gt;is not visible.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 08:01:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225414#M11324</guid>
      <dc:creator>toha</dc:creator>
      <dc:date>2024-09-03T08:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225420#M11325</link>
      <description>&lt;P&gt;As &lt;SPAN class="UserName lia-user-name lia-user-rank-Admin lia-component-message-view-widget-author-username"&gt;&lt;A id="link_c90c8f62432dd" class="lia-link-navigation lia-page-link lia-user-name-link" style="color: #000000;" href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7" target="_self" aria-label="View Profile of PhoneBoy"&gt;&lt;/A&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&lt;/SPAN&gt; &lt;SPAN class="UserName lia-user-name lia-user-rank-Admin lia-component-message-view-widget-author-username"&gt;&amp;nbsp;wrote: Open a TAC case !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 09:02:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225420#M11325</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-03T09:02:28Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225423#M11326</link>
      <description>&lt;P&gt;When support has expired it is not an option.&lt;BR /&gt;Currently getting prices to get support again.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 09:11:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225423#M11326</guid>
      <dc:creator>toha</dc:creator>
      <dc:date>2024-09-03T09:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225427#M11328</link>
      <description>&lt;P&gt;Usually, the 30 days grace period is enough time to renew it.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 10:41:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225427#M11328</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-03T10:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225445#M11331</link>
      <description>&lt;P&gt;I know but we are talking years here &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 12:15:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225445#M11331</guid>
      <dc:creator>toha</dc:creator>
      <dc:date>2024-09-03T12:15:50Z</dc:date>
    </item>
    <item>
      <title>Re: Radius authentication broken</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225449#M11335</link>
      <description>&lt;P&gt;This will cost a lot as you have to pay for the time without support. Also, without services the SMB is pretty useless from a security standpoint - VPN can be created witth software, too, and you are not allowed to upgrade to a new firmware version.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 12:34:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-authentication-broken/m-p/225449#M11335</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-03T12:34:37Z</dc:date>
    </item>
  </channel>
</rss>

