cancel
Showing results for 
Search instead for 
Did you mean: 
Create a Post

Capsule vs SNX for LDAP authentication

Hey all,

We're trying to configure capsule connect to allow smartphones to build a VPN tunnel and want the users to authenticate using their active directory account.  We've previously configured SNX and have successfully used our active directory account to authenticate and build the ssl VPN tunnel, but whenever we try to use our AD account on capsule, it fails saying wrong user/pass.  Using capsule with a local account (local to Checkpoint) works fine, but it's when we try our AD account is when it fails.

We're running unified policy.

Anyone have any ideas or run into this themselves?

Tags (2)
1 Reply

Re: Capsule vs SNX for LDAP authentication

Nevermind, I solved it myself.

Turned out we needed to change a setting with our LDAP account unit object.  Under the authentication tab, we needed to have 'Users default value' > 'Default Authentication Scheme' checked and set to checkpoint password.  No idea why this would affect only Capsule, and only Capsule LDAP auth, but there it is.

Leaving this up in case others experience the same problem.