Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Manoj_Tiwari
Explorer

Tacacs server authentication issue in checkpoint smartconsole

I have a tacacs server in one of my client to for the user authentication. I have done all the configuration in tacacs and it is working perfectly in other vendor product and checkpoint WEBGUI and CLI login. But in the case of smartconsole it is not authenticated.

I have followed this procedure for the smartconsole user authentication:

How to Setup Authentication for Admins – WebUI / SSH/ SmartDashboard – Check Point GAIA | Indeni 

Also, could i use same user that I have created for smartconsole login using tacacs server to the vpn user authentication by adding that user to the vpn access  user group?

This is the log message  that I get in tacacs server while smartconsole authentication is failure: 

Apr 12 16:35:16 localhost tac_plus[6508]: connect from 10.10.10.250 [10.10.10.250]
Apr 12 16:35:16 localhost tac_plus[6508]: Error 10.10.10.250 : Invalid AUTHEN/START packet (check keys)

2 Replies
Wei_Soon_Heng
Contributor
Contributor

Hi Manoj,

I am facing the same issue, how do u resolved it?


0 Kudos
tmorgan
Contributor

Two questions:

What technology are you using for authenication, ACS, ISE, TAC-Plus etc? Is it configured for TACACS or TACACS+?

Check keys suggests shared secrets between the two boxes are not matched.

Cheers,

Tom

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events