- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hi,
While setting up Radius authentication (with MFA) for Mobile Access (SNX and Capsule) i have stumbled upon an issue i cannot solve.
I followed a guide Checkpoint_Azure_MFA_2020_v2_CheckMates.pdf and succesfully managed to configure a gateway (R80.20)
Radius works and MFA as well for both Capsule and MAB portal.
On the same SMS (R80.40) i configured another gateway (R80.30) with the same authentication scheme and if i login with Capsule, Radius and MFA works perfectly fine.
But if i use the MAB portal the gateway is trying to authenticate the user by LDAP first (querying the servers i have in ldap account units) and there is a delay for 2 minutes before the authentication is done by Radius.
The user is authenticated by MFA after that.
Since the configuration on gateway/cluster object is not so much i cannot understand what the difference is here.
Grateful for any pointers or hints 🙂
Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.
Andy
Hi Durin,
I have a feeling I may know what the solution here is. First off, how is auth configured on the gateway object itself? Under vpn or mobile access (depending which one you have issue with), there is a setting for authentication and you can configure auth methods there. Can you send a screenshot of how thats set up? I think it may give us some clue.
Andy
It is the same config under VPN Clients as for Mobile Access on both gateways. Without delay and the one with delay, use same Radius object.
Tried with and witjout support for older clients.
Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.
Andy
Hi,
Thanks! I removed from auth list and now it works!
For you, no charge ; )
Much obliged 😉
Glad I could help...thats what I love about this community. 90% of the time, people find solutions from others without having to waste time on hold and talk to TAC, which USUALLY ends up in them asking for debugs that have nothing to do with the problem anyway.
Have a nice weekend!!
Totally agree, this is a good community with useful stuff and people with a lot of knowledge.
Have a nice weekend you also and thanks one more time 🙂
Thanks mate, you as well...cheers!
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY