- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Checkmates!
I am having a problem with all our MDS, currently I have installed R80.40 JHF 156, due to some problems TAC requested us to apply JHF 176/180.
After we apply this hotfix we notice that we are not able to login with our TACACS users.
Doing some troubleshooting we notice the traffic is not following the correct route.
RADIUS Server is IP 21.22.23.220
"add aaa tacacs-servers priority 1 server 21.22.23.220 key ***** timeout 5"
MDS Mgmt 1.2.3.4
MDS eth1 21.22.13.200
[Expert@MDS:0]# ip r
default via 1.2.3.1 dev Mgmt proto 7
21.22.23.0/24 via 21.22.13.1 dev eth1 proto 7
After applying the hotfix, the radius traffic goes out through the Mgmt interface. (Trying to access to Smartconsole)
EDIT: The traffic goes out through the right interface, eth1 but with the IP of the mgmt interface.
[Expert@MDS:0]# tcpdump -nni any host 21.22.23.220
IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS
IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS
IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS
But when accesing to SSH(TACACS port) follows the right route.
[Expert@MDS:0]# tcpdump -nni any host 21.22.23.220
IP 21.22.13.200.54379 > 21.22.23.220.49
IP 21.22.23.220.49 > 21.22.13.200.54379
IP 21.22.13.200.54379 > 21.22.23.220.49
Any ideas what could be happening? How does the Smartconsole login works that trows the conection via Mgmt and not by the interface that the static route indicates?
Every idea is welcome!
Hm, thats really unfortunate. Just a suggestion, any idea you can remove it and test again? If that works, then you know 100% it was indeed the fix they provided. At that point, TAC would need to investigate further as to why. Based on what you posted, seems like you did an excellent job in figuring out whats going on.
Ok, I know this may sound silly what I will say now, but would you mind confirming nothing changed as far as routing/topology AFTER applying that fix?
Andy
Hello, thanks for the help
No routing/topology has been changed. And yes, uninstalling hotfix solves the issue.
Ok, so that clearly 100% tells us its hotfix issue, so sounds like TAC case would be needed to investigate it further. Sorry, wish I could give any other suggestions, but cant think of any at this time. They may suggest debugs when issue is there, but Im not so sure those would tell you anything, as it does not appear there is specific process thats broken, it simply takes wrong path to get where its going.
Hello,
Did you now installed Jumbo take 176 or 180? The reason I ask this is because I cannot find take 176 anymore maybe it has been pulled offline? Issue started after take 176 or 180?
Second what I see is that you TCPdump on ANY interface. So there is no way for me to see what routing it takes. Because it can be either MGMT or eth1.
If you want to be sure regarding routing capture with interface filter:
tcpdump -nni eth1 host 21.22.23.220
tcpdump -nni Mgmt host 21.22.23.220
Sorry, not 176... we tried both 173 and 180. Both of the times uninstalling reverting the hotfix solved the issue.
For SSH Athentication, traffic goes through eth1
[Expert@MDS:0]# tcpdump -nni eth1 host 21.22.23.220
IP 21.22.13.200.54379 > 21.22.23.220.49
IP 21.22.23.220.49 > 21.22.13.200.54379
IP 21.22.13.200.54379 > 21.22.23.220.49
But here comes the fancy traffic, for Smartconsole login traffic,
The inital traffic goes to the Tacacs Server through eth1 but with the Mgmt IP
[Expert@MDS:0]# tcpdump -nni eth1 host 21.22.23.220
IP 1.2.3.4.46379 > 21.22.23.220.1645 RADIUS
Maybe is taking the IP defined in the /etc/hosts?
Radius has the concept of a NAS-IP have you defined this in your GAiA config?
Hello!
Chris, NAS IP description seems to fit perfectly with out problem. But after i have confiured it with the desired interface. I am having the same behauviour, the request goes with the hostname ip.
Hello,
Doyou know if the NAS IP defined work for TACACS authentication?
Maybe same issue like here https://community.checkpoint.com/t5/Security-Gateways/Breaking-Gaia-RADIUS-Change-in-R81-10-T79/m-p/... .
try to remove the radius setting and set it again.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 22 | |
| 15 | |
| 11 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY