Hello guys.
I'm running into an issue when trying to use an LDAP Group to authenticate my VPN users.
What I would like to do:
Create a "Remote Access" group in my AD and add authorized accounts to this group.
In SmartConsole - under Users\Identities, create a new LDAP group with my "Account Unit" being my AD Group object I've already configured.
For the LDAP Group "Scope", I'm choosing the middle option: "Only Group in Branch (DN prefix)
When I select that option, my domain gets filled in in the field on the right: ,DC=mydomain, DC=com (lead comma)
In the left field I input the rest of the DN of the group: CN=remote_users, CN=users (no trailing comma)
However I cannot login via my Check Point Mobile client with this option for LDAP Group.
When I try and connect with my VPN client:
User name - OK
Password - OK
DUO prompt - click OK
Immediately kicked out with bad username/password error.
I can connect if I change the LDAP group option to "All Account-Unit's Users".
Any ideas?
Edit for future visitors to this question:
Cannot use "Domain Users" for an LDAP group:
https://support.checkpoint.com/results/sk/sk32479
Solution - create an AD security group for remote access and use that.