- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Gateway is trying to authenticate by LDAP firs...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Gateway is trying to authenticate by LDAP first even if Radius is configured
Hi,
While setting up Radius authentication (with MFA) for Mobile Access (SNX and Capsule) i have stumbled upon an issue i cannot solve.
I followed a guide Checkpoint_Azure_MFA_2020_v2_CheckMates.pdf and succesfully managed to configure a gateway (R80.20)
Radius works and MFA as well for both Capsule and MAB portal.
On the same SMS (R80.40) i configured another gateway (R80.30) with the same authentication scheme and if i login with Capsule, Radius and MFA works perfectly fine.
But if i use the MAB portal the gateway is trying to authenticate the user by LDAP first (querying the servers i have in ldap account units) and there is a delay for 2 minutes before the authentication is done by Radius.
The user is authenticated by MFA after that.
Since the configuration on gateway/cluster object is not so much i cannot understand what the difference is here.
Grateful for any pointers or hints 🙂
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Durin,
I have a feeling I may know what the solution here is. First off, how is auth configured on the gateway object itself? Under vpn or mobile access (depending which one you have issue with), there is a setting for authentication and you can configure auth methods there. Can you send a screenshot of how thats set up? I think it may give us some clue.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is the same config under VPN Clients as for Mobile Access on both gateways. Without delay and the one with delay, use same Radius object.
Tried with and witjout support for older clients.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thanks! I removed from auth list and now it works!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For you, no charge ; )
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Much obliged 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Glad I could help...thats what I love about this community. 90% of the time, people find solutions from others without having to waste time on hold and talk to TAC, which USUALLY ends up in them asking for debugs that have nothing to do with the problem anyway.
Have a nice weekend!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Totally agree, this is a good community with useful stuff and people with a lot of knowledge.
Have a nice weekend you also and thanks one more time 🙂
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks mate, you as well...cheers!
Andy