<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 1570r Hotspot integration with Radius auth in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129379#M5732</link>
    <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I'm trying to integrate hotspot authentication on a 1570r running R80.20.30 with a MS Radius server on an MDS enviroment.&lt;BR /&gt;But I can't find the details about how the NPS policy should look, or how the 1570r will do authentication to that Radius.&lt;BR /&gt;&lt;BR /&gt;Is the 1570r forwarding the request over the mgmt ip over port 1812 ?&amp;nbsp;&lt;BR /&gt;Or is the client (connected to the wifi) forwarding the request ?&lt;BR /&gt;&lt;BR /&gt;How should the NPS policy be setup ?&lt;BR /&gt;&lt;BR /&gt;Is there more cli config needed to force the hotspot to use radius auth ?&lt;BR /&gt;&lt;BR /&gt;I've read:&lt;BR /&gt;&lt;SPAN&gt;sk60301&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sk60501&lt;BR /&gt;sk106133&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R80.20.05/AdminGuides/Locally_Managed/EN/Content/Topics/Configuring-Hotspot.htm" target="_blank" rel="noopener"&gt;Configuring a Hotspot (checkpoint.com)&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://dl3.checkpoint.com/paid/65/65f6c5ad45354e107d2d70af288ebb28/CP_R80.20_1500_Appliance_Series_CLI_Guide.pdf?HashKey=1631612888_0f1326bf9b60595765753690f8c58324&amp;amp;xtn=.pdf" target="_blank" rel="noopener"&gt;SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide (checkpoint.com)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;But can't find anything specific...&lt;BR /&gt;&lt;BR /&gt;we use an MDS with a Global LDAP object defined.&lt;BR /&gt;(Enabling AD query on the 1570r does not work either, hotspot login fails)&lt;BR /&gt;Radius authentication for Wifi does work and also for the WebUI this works.&lt;BR /&gt;&lt;BR /&gt;Maybe someone can point me in the right direction ?&lt;BR /&gt;&lt;BR /&gt;Thx in advance&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 10:53:33 GMT</pubDate>
    <dc:creator>Tim_Tielens</dc:creator>
    <dc:date>2021-09-14T10:53:33Z</dc:date>
    <item>
      <title>1570r Hotspot integration with Radius auth</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129379#M5732</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I'm trying to integrate hotspot authentication on a 1570r running R80.20.30 with a MS Radius server on an MDS enviroment.&lt;BR /&gt;But I can't find the details about how the NPS policy should look, or how the 1570r will do authentication to that Radius.&lt;BR /&gt;&lt;BR /&gt;Is the 1570r forwarding the request over the mgmt ip over port 1812 ?&amp;nbsp;&lt;BR /&gt;Or is the client (connected to the wifi) forwarding the request ?&lt;BR /&gt;&lt;BR /&gt;How should the NPS policy be setup ?&lt;BR /&gt;&lt;BR /&gt;Is there more cli config needed to force the hotspot to use radius auth ?&lt;BR /&gt;&lt;BR /&gt;I've read:&lt;BR /&gt;&lt;SPAN&gt;sk60301&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;sk60501&lt;BR /&gt;sk106133&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R80.20.05/AdminGuides/Locally_Managed/EN/Content/Topics/Configuring-Hotspot.htm" target="_blank" rel="noopener"&gt;Configuring a Hotspot (checkpoint.com)&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://dl3.checkpoint.com/paid/65/65f6c5ad45354e107d2d70af288ebb28/CP_R80.20_1500_Appliance_Series_CLI_Guide.pdf?HashKey=1631612888_0f1326bf9b60595765753690f8c58324&amp;amp;xtn=.pdf" target="_blank" rel="noopener"&gt;SMB R80.20 1500 Appliance CLI Guide R80.20 Technical Reference Guide (checkpoint.com)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;But can't find anything specific...&lt;BR /&gt;&lt;BR /&gt;we use an MDS with a Global LDAP object defined.&lt;BR /&gt;(Enabling AD query on the 1570r does not work either, hotspot login fails)&lt;BR /&gt;Radius authentication for Wifi does work and also for the WebUI this works.&lt;BR /&gt;&lt;BR /&gt;Maybe someone can point me in the right direction ?&lt;BR /&gt;&lt;BR /&gt;Thx in advance&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 10:53:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129379#M5732</guid>
      <dc:creator>Tim_Tielens</dc:creator>
      <dc:date>2021-09-14T10:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: 1570r Hotspot integration with Radius auth</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129391#M5735</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;Quantum Spark 1500, 1600 and 1800 Appliance Series R80.20.30 Locally Managed Administration Guide p.89:&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV class="page" title="Page 89"&gt;
&lt;DIV class="layoutArea"&gt;
&lt;DIV class="column"&gt;
&lt;P&gt;&lt;SPAN&gt;Configuring a Hotspot&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;In the &lt;/SPAN&gt;&lt;SPAN&gt;Device &lt;/SPAN&gt;&lt;SPAN&gt;&amp;gt; &lt;/SPAN&gt;&lt;SPAN&gt;Hotspot &lt;/SPAN&gt;&lt;SPAN&gt;page, if a network interface was defined for hotspot, you can configure:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- &lt;/SPAN&gt;&lt;SPAN&gt;Guest access - A session is created for an IP address when a user accepts terms or authenticates in the Hotspot portal. The session expires after the configured timeout (240 minutes by default).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- &lt;/SPAN&gt;&lt;SPAN&gt;Hotspot portal - Customize the portal's appearance.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;- &lt;/SPAN&gt;&lt;SPAN&gt;Hotspot exceptions - Define specified IP addresses, IP ranges or networks to exclude from the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Hotspot.&lt;BR /&gt;If no network interface was defined for the Hotspot, click &lt;/SPAN&gt;&lt;SPAN&gt;Configure in Local Network&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;In the Access section of the page, you can configure if authentication is required and allow access to all users or to a specified user group (Active Directory, RADIUS or local).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hotspot is automatically activated in the system.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 14 Sep 2021 10:43:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129391#M5735</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-14T10:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: 1570r Hotspot integration with Radius auth</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129392#M5736</link>
      <description>&lt;P&gt;I'm sorry but i've read that and that is not this issue that i'm having.&lt;BR /&gt;Creating or enabling hotspot on the network or wifi is not the issue.&lt;/P&gt;&lt;P&gt;The question is:&lt;BR /&gt;1. how should the NPS look like on the Radius server ?&lt;BR /&gt;2. How does the hotspot initialize radius auth ?&lt;BR /&gt;- From the mgmt interface of the 1570r or the wifi client ip.&lt;BR /&gt;(because i'm not seeing any requests, but get auth failed)&lt;BR /&gt;Radius auth on the Wifi works and on the webui also, i've tested that.&lt;BR /&gt;&lt;BR /&gt;Maybe some other question would be, is it even supported...&lt;BR /&gt;I'm reading&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk159772" target="_blank"&gt;Check Point R80.20.X for 1500, 1600, and 1800 Appliances Features and Known Limitations&lt;/A&gt;&amp;nbsp;and there is nothing in it about it not working.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 10:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129392#M5736</guid>
      <dc:creator>Tim_Tielens</dc:creator>
      <dc:date>2021-09-14T10:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: 1570r Hotspot integration with Radius auth</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129396#M5737</link>
      <description>&lt;P&gt;You can involve TAC here.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 11:02:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/1570r-Hotspot-integration-with-Radius-auth/m-p/129396#M5737</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-09-14T11:02:23Z</dc:date>
    </item>
  </channel>
</rss>

