- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: RADIUS to SmartConsole works only for some use...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
RADIUS to SmartConsole works only for some users
Hi,
At two different customers I have the same issue. One is running R81, the other R81.10.
RADIUS is configured for HTTPS/SSH (GAIA level) and for SmartConsole. Same RADIUS server.
All RADIUS users can connect with SSH/HTTPS without any issues.
When opening SmartConsole, some users can connect. Others cannot. All the users are defined with the same RADIUS server.
Checkpoint logs show "Wrong password" even though the user is connecting with SSH with the same password
I did TCPDUMP. Couldn't find the firewall acting differently for different users. Access-Request and then Access-Reject for some of the RADIUS users to SmartConsole. Access-Accept for the the others.
Has anyone encountered this problem?
Thanks
micha
P.S. The only workaround we found is to change the SmartConsole user to a local Checkpoint Password user.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Radius V1 will likely have password length constraints (16 characters or less), perhaps test to confirm that is the issue?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What method is used i.e. Radius 2.0 and PAP or CHAP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PAP with RADIUS V1.
CHAP didn't work.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Radius V1 will likely have password length constraints (16 characters or less), perhaps test to confirm that is the issue?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk13740 - RADIUS authentication fails when using passwords longer than 16 characters
Never thought of that.
Changed it to V2 and all users can now authenticate. Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I always had same experience.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check which RADIUS version you configured. Change to V2.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For sure, I learned that long time ago. Usually switching from v1 to v2 or other way around works.
Cheers,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I always found that while PAP is way less secure, it appears to always solve any Radius auth issues when it comes to Check Point.
Andy
