Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Durin
Contributor
Jump to solution

Gateway is trying to authenticate by LDAP first even if Radius is configured

Hi,

 

While setting up Radius authentication (with MFA) for Mobile Access (SNX and Capsule) i have stumbled upon an issue i cannot solve.

I followed a guide Checkpoint_Azure_MFA_2020_v2_CheckMates.pdf and succesfully managed to configure a gateway (R80.20)

Radius works and MFA as well for both Capsule and MAB portal.

On the same SMS (R80.40)  i configured another gateway (R80.30) with the same authentication scheme and if i login with Capsule, Radius and MFA works perfectly fine.

But if i use the MAB portal the gateway is trying to authenticate the user by LDAP first (querying the servers i have in ldap account units) and there is a delay for 2 minutes before the authentication is done by Radius.

The user is authenticated by MFA after that.

Since the configuration on gateway/cluster object is not so much i cannot understand what the difference is here.

Grateful for any pointers or hints 🙂

 

1 Solution

Accepted Solutions
the_rock
Legend
Legend

Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.

Andy

View solution in original post

10 Replies
the_rock
Legend
Legend

Hi Durin,

I have a feeling I may know what the solution here is. First off, how is auth configured on the gateway object itself? Under vpn or mobile access (depending which one you have issue with), there is a setting for authentication and you can configure auth methods there. Can you send a screenshot of how thats set up? I think it may give us some clue.

 

Andy

Durin
Contributor

It is the same config under VPN Clients as for Mobile Access on both gateways. Without delay and the one with delay, use same Radius object.

Tried with and witjout support for older clients.

the_rock
Legend
Legend

Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.

Andy

Durin
Contributor

Hi,

Thanks! I removed from auth list and now it works!

 

the_rock
Legend
Legend

For you, no charge ; )

Durin
Contributor

Much obliged 😉

the_rock
Legend
Legend

Glad I could help...thats what I love about this community. 90% of the time, people find solutions from others without having to waste time on hold and talk to TAC, which USUALLY ends up in them asking for debugs that have nothing to do with the problem anyway.

 

Have a nice weekend!!

Durin
Contributor

Totally agree, this is a good community with useful stuff and people with a lot of knowledge.

Have a nice weekend you also and thanks one more time 🙂

the_rock
Legend
Legend

Thanks mate, you as well...cheers!

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events