Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Wayne_Hammond
Collaborator

Checkpoint Endpoint VPN - 2 VPNs, only one works (via Endpoint VPN)

Hi,

We have 2 CheckPiont FWs. Our main one and a secondary managed on same Secure Gateway.

For FW 1, we have a VPN setup and users can config this in CheckPoint VPN and Capsule

Logon and auth is fine

For FW 2, we have a VPN setup and users  can config this in CheckPoint VPN and Capsule, however only logon and auth works via Capsule.

If we try and logon via Endpoint, we never get a prompt for password (in our case PIN and RSA), it just tries to authenticate.

When using Capsule, if lets us enter Pin and RSA.

I guess i must have configured something wrong, any thoughts?

Hope you are ok !!

 

Cheers and Happy New year

 

Wayne

 

9 Replies
PhoneBoy
Admin
Admin

What version/JHF of gateway?
What client version(s)?
What exactly did you configure where?
Screenshots (with sensitive details redacted) will help.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Screenshots would definitely help. Btw, do you have MEP for remote access configured?

Best,
Andy
0 Kudos
Wayne_Hammond
Collaborator

Screenshot 2025-12-30 083907.pngScreenshot 2025-12-30 083938.png

R82 JHF 44, various Enpoint Versions, including E88.30

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey Wayne,

Good morning! I was actually more referring to below:

https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/T...

Best,
Andy
0 Kudos
Wayne_Hammond
Collaborator

Hi Andy, 

No they are not configured in a cluster at all. 

Thanks and Happy New Year

 

Wayne

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey Wayne,

No clue how this started whole new thread from the original one, but maybe @PhoneBoy can correct it.

Best,
Andy
0 Kudos
PhoneBoy
Admin
Admin

No idea, but it's been merged back in.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Thank you! @Wayne_Hammond , I read the whole thing again and it appears to me all is correctly configured. Might be worth session with TAC to confirm all this, though from what you sent, appears radius is set globaly as auth, so should "kick in".

Best,
Andy
0 Kudos
Wayne_Hammond
Collaborator

Thanks all, enjoy the New Year festivities, wherever you are !!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events