Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
D_Riddleberger
Collaborator
Collaborator

Check Point R81.20 HF-170 Caused Remote Access User Outage when SMS was HF Updated

I have an environment SMS R81.20 HF-141 and multiple clusters R81.20 HF-141 and after the SMS was HF updated to HF-170 and policy was installed to gateways, all RA Users were unable to connect. The symptom was each RA User lost the ability to select Authentication methods in their VPN Client. Additionally, the gateway would not respond if a 'New Site' was attempted to be created. A TAC case has been opened but TAC is unable to re-create the issue.

 

Next question would be, has anyone else updated their R81.20 SMS to HF-170 and the environment supports RA Users??

0 Kudos
3 Replies
CheckPointerXL
Advisor
Advisor

Mhhh did u lost some custom file on mgmt side? Trac client? Are user authenticated against mgmt or ldap server/saml etc ?

0 Kudos
D_Riddleberger
Collaborator
Collaborator

OKTA Radius is used for authentication. We thought the same about missing file or file corruption on the SMS but so far, unable to reproduce.

0 Kudos
Ruan_Kotze
MVP Gold
MVP Gold

Sounds like maybe your trac_client_1.ttm got modified during the upgrade.  Do you have a gateway that you haven't pushed policy to since the upgrade?  The SMS pushes it down during policy install so it would be worthwhile to compare.  Otherwise if you have a backup of the SMS pre-upgrade you should be able to pull it from there.

Some files do get overwritten during JHF upgrades. As an example it resets our "always prompt for MFA" settings on our VPN gateways.

We've resorted to running the backup script on Checkmates which backs up the custom config files.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events