Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Joshua_Snider
Participant

Capsule vs SNX for LDAP authentication

Hey all,

We're trying to configure capsule connect to allow smartphones to build a VPN tunnel and want the users to authenticate using their active directory account.  We've previously configured SNX and have successfully used our active directory account to authenticate and build the ssl VPN tunnel, but whenever we try to use our AD account on capsule, it fails saying wrong user/pass.  Using capsule with a local account (local to Checkpoint) works fine, but it's when we try our AD account is when it fails.

We're running unified policy.

Anyone have any ideas or run into this themselves?

1 Reply
Joshua_Snider
Participant

Nevermind, I solved it myself.

Turned out we needed to change a setting with our LDAP account unit object.  Under the authentication tab, we needed to have 'Users default value' > 'Default Authentication Scheme' checked and set to checkpoint password.  No idea why this would affect only Capsule, and only Capsule LDAP auth, but there it is.

Leaving this up in case others experience the same problem.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events