- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Issues with CP RADIUS using Duo Auth after ins...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Issues with CP RADIUS using Duo Auth after installing MS KB5040430 or KB5040434
This is an issue we are trying to cover all products in the chain and I wanted to reach out to the community to see if there was anyone else experiencing the issue as we have.
The issue seen is that we run Windows updates, as we normally do, but when we run these updates in the subject on a Windows server running the Duo Authentication Proxy we then start seeing issues with Check Point RADIUS authentications. In the CP logs we get the message of RADIUS server not found.
So we have auth failures with CP Mobile Access VPNs setup to use Duo as well as CP Management access setup to auth through RADIUS/Duo.
I wasn't going to reach out here, but we have an external VPN running Cisco Secure Client and AnyConnect that does not have an issue at all with these updates and function as it should. The only issues currently seems to be with CP.
Is anyone else with this combo of CP/Duo/Windows having these same issues? Thanks!
- Tags:
- r81.10
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would put my money on this SK:https://support.checkpoint.com/results/sk/sk42184
Would also recommend to cpstop;cpstart the relevant system after all steps taken.
If you like this post please give a thumbs up(kudo)! 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That does look promising. We'll set it up in the lab tomorrow. Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had 3 customers try that sk before and sadly did not help.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
100% it has to do with windows update and pretty much for now, thats the best option to fix it, uninstall the updates.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That's what we've been doing but I'm not holding out on MS fixing it anytime soon. We haven't found anything on this from any front yet. Thanks for the reply!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Personally, considering they cant fix January windows 10 update thats broken, no offense, it highly unlikely they will fix this any time soon lol
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Agreed. Just kinda sad that the only issue we are seeing is tied to CP.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I hear ya...lets hope it all goes back to normal soon.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I suspect this is related to the fixes needed to mitigate BLAST RADIUS: https://support.checkpoint.com/results/sk/sk182516
A possible workaround for this would be to implement: https://support.checkpoint.com/results/sk/sk42184
Fixes for this have not yet been rolled into the JHF.
Best to consult with TAC here.
