EDIT: fixed my problem by setting a new Shared Secret, only letters and numbers.
I've done this successfully in my R80.40 lab environment but it my prod environment with R80.30(latest JHF) it fails right at the end.
With PAP it was worse but with MS-CHAPv2 I get this far:
- in the VPN client I enter the user and password
- on my mobile app I get the push notification and I accept it
- NPS and Azure MFA logs on my NPS(RADIUS) server say authentication was successful.
- TCPdump on the gateway says it received the response from the RADIUS server:
18:44:34.494608 IP 192.168.XX.XX.datametrics > CKP-GW.49100: RADIUS, Access Accept (2), id: 0xde length: 273
So the gateway does seem to get a response and yet:
-the client says: Negotiation with the site failed
-the CKP logs says:
---Action: Failed log in
---Failed login factor: RADIUS
---Reason: RADIUS servers not responding
-I also get a 2nd and maybe 3rd push notification on my mobile which shouldn't happen
I've done all the settings (including GLobal options and Guidb options) in the tutorial by JesusOrtiz:https://community.checkpoint.com/t5/Remote-Access-VPN/Check-Point-EndPoint-Security-VPN-with-Azure-A...
Also the ones in sk112933.
I've also cloned the RADIUS service template to use it with aggressive aging disabled and virtual session timeout set to 120 seconds