Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Micha
Participant
Jump to solution

RADIUS to SmartConsole works only for some users

Hi,

At two different customers I have the same issue.  One is running R81, the other R81.10.

RADIUS is configured for HTTPS/SSH (GAIA level) and for SmartConsole.  Same RADIUS server. 

All RADIUS users can connect with SSH/HTTPS without any issues.

When opening SmartConsole,  some users can connect.   Others cannot.   All the users are defined with the same RADIUS server.

Checkpoint logs show "Wrong password" even though the user is connecting with SSH with the same password

I did TCPDUMP.  Couldn't find the firewall acting differently for different users.    Access-Request and then Access-Reject for some of the RADIUS users to SmartConsole.  Access-Accept for the the others.

Has anyone encountered this problem?

Thanks

micha

P.S. The only workaround we found is to change the SmartConsole user to a local Checkpoint Password user.

0 Kudos
1 Solution

Accepted Solutions
Chris_Atkinson
Employee Employee
Employee

Radius V1 will likely have password length constraints (16 characters or less), perhaps test to confirm that is the issue?

CCSM R77/R80/ELITE

View solution in original post

(1)
8 Replies
Chris_Atkinson
Employee Employee
Employee

What method is used i.e. Radius 2.0 and PAP or CHAP?

CCSM R77/R80/ELITE
0 Kudos
Micha
Participant

PAP with RADIUS V1.

CHAP didn't work.

Chris_Atkinson
Employee Employee
Employee

Radius V1 will likely have password length constraints (16 characters or less), perhaps test to confirm that is the issue?

CCSM R77/R80/ELITE
(1)
Micha
Participant

sk13740 - RADIUS authentication fails when using passwords longer than 16 characters

Never thought of that.

Changed it to V2 and all users can now authenticate.  Thanks!

0 Kudos
the_rock
Legend
Legend

I always had same experience.

0 Kudos
Micha
Participant

Check which RADIUS version you configured.   Change to V2.

the_rock
Legend
Legend

For sure, I learned that long time ago. Usually switching from v1 to v2 or other way around works.

Cheers,

Andy

0 Kudos
the_rock
Legend
Legend

I always found that while PAP is way less secure, it appears to always solve any Radius auth issues when it comes to Check Point.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events