- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
We set up VPN in our environment. And we are using Radius authentication. We will activate MFA, we use Idaptive.
We have four Radius servers. Is it possible to balance Radius connections? Round-robin?
R:
Is it possible to check if the server is available before sending the connection?
R:
I understand, there is no balancing using Round-robin. In our scenario we have 7k users and we are having a crash problem because one server is not able to handle all connections.
We need a load balancer.
Hello PhoneBoy,
I have made this configuration on my environment, created a RADIUS group, and added both radius servers inside them with priority 1 to first and priority 2 to the second, but when the first server is down firewall doesn´t recognize that this server is down and doesn´t forward the connection to the second server, Does have any specific configuration to do on this case?
PS. If I configure my authentication to use directly the radius servers it works.
You might need a TAC case to understand why this isn’t working.
You probably need to adjust the values of radius_retrant_timeout and radius_retrant_num to shorten up how long the firewall waits before going on to the next server, see sk42449: How to change a failover timeout of RADIUS Server
Hi Timothy_Hall,
This information is not clear to me ( print with my configuration below ), today I have an MFA configured on these RADIUS servers and my user have until 60 seconds to inform the radius challenger and as I could understand field "radius_user_timeout" is responsible by it, but I have 750 seconds configured on this field.
Do you know how values I need to configure on properties below to have a failover in 60 seconds for example?
radius_retrant_num
radius_retrant_timeout
You want radius auth request to fail over to your other server in 60 seconds if first one time sout or does not respond, correct? Thats the setting you are looking for?
Im pretty sure its retrant timeout setting, but you may wish to confirm 100% with TAC.
Hi the_rock,
Exactly, if one server stay down the firewall send the authentication to another server inside de RADIUS group.
So phoneboy mentioned last year to create radius group for this, which works 100%, as I seen it with customers before, but again, for timeout setting, Im 95% sure its what I advised, but to be 100% positive, maybe better get confirmation from TAC.
Thanks everyone,
I will raise a case with TAC to check this issue.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
9 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 | |
5 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY