<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: RADIUS Server Authentication VPN on Quantum Spark 1600 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239641#M12005</link>
    <description>&lt;P&gt;Did you try increasing the radius timeout and is the request arriving at the NPS with the correct source / NAS IP address that is permitted to act as a radius client?&lt;/P&gt;
&lt;P&gt;Where required their is a build of R81.10.15 available from TAC that mitigates BlastRADIUS also.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 27 Jan 2025 01:55:28 GMT</pubDate>
    <dc:creator>Chris_Atkinson</dc:creator>
    <dc:date>2025-01-27T01:55:28Z</dc:date>
    <item>
      <title>RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239635#M12004</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i want to setup RADIUS Authentication for VPN. My device is a Quantum Spark 1600 with latest Gaia OS. Actually i get no error von Windows Server NPS Server -&amp;gt; Event ID 6272 Access Granted but the connection hang at 47% and after some seconds it will stop to connect with Message: Username or Password are wrong. And i get no IP Adress from RADIUS Server. What can i do? Where is the correct log files and what have anybody an link to an how to?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rafael&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 12:51:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239635#M12004</guid>
      <dc:creator>LM-Rafael</dc:creator>
      <dc:date>2025-01-26T12:51:23Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239641#M12005</link>
      <description>&lt;P&gt;Did you try increasing the radius timeout and is the request arriving at the NPS with the correct source / NAS IP address that is permitted to act as a radius client?&lt;/P&gt;
&lt;P&gt;Where required their is a build of R81.10.15 available from TAC that mitigates BlastRADIUS also.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 01:55:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239641#M12005</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-27T01:55:28Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239643#M12006</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;i found some information in the log files see under the attachments (username: adminmu) and information from eventviewer:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV&gt;Der Netzwerkrichtlinienserver hat einem Benutzer den Zugriff gewährt.&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Benutzer:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Sicherheits-ID: ADMUS\adminmu&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Kontoname: adminmu&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Kontodomäne: ADMUS&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Vollqualifizierter Kontoname: ad.mustermann.gmbh/mustermann.gmbh/Benutzer/Service Benutzer/Administrator Mustermann&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Clientcomputer:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Sicherheits-ID: NULL SID&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Kontoname: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Vollqualifizierter Kontoname: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ID der Empfangsstation: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;ID der Anrufstation: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;NAS:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;NAS-IPv4-Adresse: 89.206.221.134&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;NAS-IPv6-Adresse: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;NAS-ID: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;NAS-Porttyp: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;NAS-Port: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;RADIUS-Client:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Clientanzeigename: MUSNFWC-FRA-01-01&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Client-IP-Adresse: 10.8.8.1&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Authentifizierungsdetails:&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Name der Verbindungsanforderungsrichtlinie: Verbindungen für virtuelles privates Netzwerk (VPN)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Netzwerkrichtlinienname: Verbindungen für virtuelles privates Netzwerk (VPN)&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Authentifizierungsanbieter: Windows&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Authentifizierungsserver: MUSSDC-FRA-01.ad.mustermann.gmbh&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Authentifizierungstyp: PAP&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;EAP-Typ: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Kontositzungs-ID: -&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&lt;SPAN&gt;Protokollierungsergebnisse: Die Kontoinformationen wurden in die lokale Protokolldatei geschrieben.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rafael&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jan 2025 15:58:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239643#M12006</guid>
      <dc:creator>LM-Rafael</dc:creator>
      <dc:date>2025-01-26T15:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239740#M12007</link>
      <description>&lt;P&gt;First i increase the timeout limit.&lt;/P&gt;&lt;P&gt;I see only in Eventlog that the User get access (access granted) for User Adminmu. Everything looks fine but not working.&lt;/P&gt;&lt;P&gt;Do you have an sk for setup A Windows RADIUS NPS server??&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 20:57:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239740#M12007</guid>
      <dc:creator>LM-Rafael</dc:creator>
      <dc:date>2025-01-27T20:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239753#M12008</link>
      <description>&lt;P&gt;Not aware of a specific SK but there are discussions here from others who have it working.&lt;/P&gt;
&lt;P&gt;Typically the issues align to one of those I eluded to above or ignoring specific radius attributes depending on the patch level of the NPS / AD environment.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jan 2025 23:36:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239753#M12008</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-01-27T23:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239837#M12009</link>
      <description>&lt;P&gt;If you are using a fully patched NPS server, then it is very likely this is failing because of the mitigations deployed as a result of the Blast RADIUS issue:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182516" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182516&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You need to do one of the following:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Disable Message Authenticator codes on the RADIUS Server&lt;/LI&gt;
&lt;LI&gt;Upgrade to a firmware version that has RADIUS Message Authenticator support (as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;noted, this needs to be procured from TAC for Quantum Spark appliances)&lt;/LI&gt;
&lt;LI&gt;Configure the gateway to ignore RADIUS attribute 80:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk42184" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk42184&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:23:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239837#M12009</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-28T14:23:30Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239839#M12010</link>
      <description>&lt;P&gt;Open a SR# with CP TAC to get this resolved asap !&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:28:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239839#M12010</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-01-28T14:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239884#M12011</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;both is not working. I cant find under advanced settings "&lt;EM&gt;&lt;STRONG&gt;VPN Remote Access - RADIUS attribute to be ignored&lt;/STRONG&gt;&lt;/EM&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;" (&lt;A href="https://support.checkpoint.com/results/sk/sk42184" target="_blank"&gt;sk42184 - RADIUS authentication fails in Remote Access VPN, Identity Awareness, Mobile Access or Smart Console admin login&lt;/A&gt;) and this is also not working:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182516" target="_blank"&gt;sk182516 - Check Point response to CVE-2024-3596 - Blast-RADIUS attack&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I have contact TAC and now i wait for response.&lt;/P&gt;&lt;P&gt;I have no ideas what can i do to solve this problem.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Rafael&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 18:22:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239884#M12011</guid>
      <dc:creator>LM-Rafael</dc:creator>
      <dc:date>2025-01-28T18:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: RADIUS Server Authentication VPN on Quantum Spark 1600</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239894#M12012</link>
      <description>&lt;P&gt;The RADIUS Server can require the Message Authenticator codes and fail also, I believe.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 20:57:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/RADIUS-Server-Authentication-VPN-on-Quantum-Spark-1600/m-p/239894#M12012</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-28T20:57:48Z</dc:date>
    </item>
  </channel>
</rss>

