- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- Cloud Network Security
- :
- Discussion
- :
- Radius Authentication doesn't work on Cloudguard I...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Radius Authentication doesn't work on Cloudguard IaaS in Azure
Hello,
We’ve configured RADIUS authentication on our Check Point devices using the configuration:
add aaa radius-servers priority 1 host <Primary_RADIUS_Server_IP_Address> port 1812 secret <shared_key_1> timeout 3
set aaa radius-servers default-shell /bin/bash
set aaa radius-servers super-user-uid 0
add aaa radius-servers priority 2 host <Secondary_RADIUS_Server_IP_Address> port 1812 secret <shared_key_2> timeout 3
set aaa radius-servers default-shell /bin/bash
set aaa radius-servers super-user-uid 0
add rba role radius-group-any domain-type System all-features
save config
It works well for all onsite gateways and we access devices directly in expert mode.
For our CloudGuard IaaS in Azure, the authentication works but we cannot perform some commands in Expert Mode (see enclosed).
Thanks in advance for your support.
Regards,
Alain IKULA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is it always the same commands that fail and how many admins are connected?
If there are parallel sessions do the privileges change upon logout of the other user or it happens regardless?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you Chris for your feedback.
I haven't tested all expert mode commands but it looks like most of them don't work (cpconfig, cphaprob stat, cphaprob -a if, etc...). So far, only ifconfig and netstat work. I'm the only connected admin.
Thanks !
Regards,
Alain IKULA
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Understood,if the issues persist with the latest GA Jumbo applied for your version I would consult further with TAC on the issue.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We're on R80.30 Take 251. The latest GA Jumbo for this version is Take 254. I've raised a case with TAC.
Thanks !
Regards,
Alain IKULA