<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius on Gaia Embedded in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5273#M86</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon -- I'm opening up a case with our engineers and I'll see if they have the same "fix".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Aug 2017 19:16:08 GMT</pubDate>
    <dc:creator>Bryce_Myers</dc:creator>
    <dc:date>2017-08-14T19:16:08Z</dc:date>
    <item>
      <title>Radius on Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5271#M84</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone here have Radius configured on their Gaia Embedded boxes?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have it working fine from the CLI, but when someone tries to login to&amp;nbsp;the WebUI it instantly returns "invalid username or password". &amp;nbsp;I am currently running R77.20.51 on these boxes. &amp;nbsp;I did a tcpdump and I see the radius traffic when a CLI attempt is made, but no radius traffic when an attempt is made from the WebUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I went through the Gaia Embedded documentation related to radius and I didn't see anything about this being a known limitation.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 18:03:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5271#M84</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-08-14T18:03:11Z</dc:date>
    </item>
    <item>
      <title>Re: Radius on Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5272#M85</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It appears that certain characters in the RADIUS shared secret are problematic for logging in via the WebUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This was an issue targeted to be resolved in the&amp;nbsp;R77.20.60 release, which can be downloaded here:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117732" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117732"&gt;R77.20.60 for Small and Medium Business Appliances&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this doesn't resolve the issue,&amp;nbsp;I recommend opening a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 18:51:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5272#M85</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-14T18:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: Radius on Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5273#M86</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon -- I'm opening up a case with our engineers and I'll see if they have the same "fix".&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 19:16:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5273#M86</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-08-14T19:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Radius on Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5274#M87</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have no problem with it. All I did&amp;nbsp;was run this commands in clish:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;set radius-server priority 1 ipv4-address X.X.X.X&amp;nbsp;udp-port 1812 shared-secret &amp;lt;shared-secret&amp;gt; timeout 5&lt;BR /&gt;set administrators radius-auth enable use-radius-groups false permission read-write&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to use a shared-secret with only letters and numbers&amp;nbsp;for testing as Dameon suggested.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 19:59:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5274#M87</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2017-08-14T19:59:31Z</dc:date>
    </item>
    <item>
      <title>Re: Radius on Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5275#M88</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also note, there are advanced settings for modifying the RADIUS timeouts. &amp;nbsp;When using 2FA, you would be best to allow users more time to answer phone call/text or enter a TOTP code.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Sep 2017 17:05:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5275#M88</guid>
      <dc:creator>Kurtis_Johnson</dc:creator>
      <dc:date>2017-09-11T17:05:15Z</dc:date>
    </item>
    <item>
      <title>Re: Radius on Gaia Embedded</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5276#M89</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;R77.20.60 fixed our Radius issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue wasn't with the shared secret, rather which characters the WebUI will accept vs the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Prior to R77.20.60 if you used certain special characters in the WebUI - it would instantly tell you bad username/password.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 30 Nov 2017 19:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Radius-on-Gaia-Embedded/m-p/5276#M89</guid>
      <dc:creator>Bryce_Myers</dc:creator>
      <dc:date>2017-11-30T19:10:09Z</dc:date>
    </item>
  </channel>
</rss>

