- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Tacacs server authentication issue in checkpoi...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Tacacs server authentication issue in checkpoint smartconsole
I have a tacacs server in one of my client to for the user authentication. I have done all the configuration in tacacs and it is working perfectly in other vendor product and checkpoint WEBGUI and CLI login. But in the case of smartconsole it is not authenticated.
I have followed this procedure for the smartconsole user authentication:
How to Setup Authentication for Admins – WebUI / SSH/ SmartDashboard – Check Point GAIA | Indeni
Also, could i use same user that I have created for smartconsole login using tacacs server to the vpn user authentication by adding that user to the vpn access user group?
This is the log message that I get in tacacs server while smartconsole authentication is failure:
Apr 12 16:35:16 localhost tac_plus[6508]: connect from 10.10.10.250 [10.10.10.250]
Apr 12 16:35:16 localhost tac_plus[6508]: Error 10.10.10.250 : Invalid AUTHEN/START packet (check keys)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Manoj,
I am facing the same issue, how do u resolved it?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Two questions:
What technology are you using for authenication, ACS, ISE, TAC-Plus etc? Is it configured for TACACS or TACACS+?
Check keys suggests shared secrets between the two boxes are not matched.
Cheers,
Tom
