- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters E7:
How CPR Broke ChatGPT's Isolation and What It Means for You
Blueprint Architecture for Securing
The AI Factory & AI Data Center
Call For Papers
Your Expertise. Our Stage
Good, Better, Best:
Prioritizing Defenses Against Credential Abuse
Ink Dragon: A Major Nation-State Campaign
Watch HereCheckMates Go:
CheckMates Fest
Hello everyone,
I have a Remote Access VPN implementation configured with MFA authentication. The issue I’m facing is that the authentication fails when I connect using my home Internet Service Provider’s network.
The error message shows an App registration that doesn’t exist in my Azure tenant and isn’t linked to any Identity Provider configured in my Management Server.
However, when I connect using my mobile hotspot, the authentication works perfectly, and the URLs correspond to the current Identity Provider configured on the gateway.
Could this behavior be related to how the ISP handles IP assignment (NAT, CGNAT, etc.)?
Is there any known limitation or recommendation regarding authentication flows behind carrier-grade NAT or similar configurations?
Thanks in advance for any insight or suggestions.
Im not expert in this particular subject by any means, but I do know those values have to come from Azure/gw side. By the way, I see the option for importing file, you did not do so, you chose manual...any reason why?
I tried a different approach because it wouldn’t start before. It starts now, but it’s showing some strange behavior.
Did you try importing the file approach?
I meant below settings, more less what you had in your screenshot.
In the previous cases, I followed this approach.
And I assume it was same error?
It doesn’t have any impact, but the idea was to test an alternative approach.
Small favor, if you dont mind...can you please paste the text error itself, rather than the screenshot?
AADSTS700016: Application with identifier 'https://IP/saml-vpn/spPortal/ACS/ID/e630b697-b47e-4029-be4b-33599e317cb0' was not found in the directory 'XXXXXX'. This can happen if the application has not been installed by the administrator of the tenant or consented to by any user in the tenant. You may have sent your authentication request to the wrong tenant.
Give me some time, let me look into it.
Here are some things I would check, from my previous notes:
1) Check the tenant
2) check the app registration
3) confirm the identifier
But why would the scenario that authenticates me vary depending on the connection?
Just thought of something, might not be related, but lets double check. What are dns servers when it works and when it does not, can you check?
falis
fails
Worksworks
K, so lets take a step back, as they say. So, with one that fails, are you able to resolve google dns, say google.com. Does that work?
I would open TAC case, see if they provide specific vpn debug for this.
Thank you very much for your time and for the validation tips. I will share any updates as soon as I have them, in case they’re helpful for future cases.
Yes, thanks a lot for that, appreciated.
The issue was finally resolved by running the following commands on the gateway:
fw kill vpnd
cpstop
cpstart
After executing these commands, the Remote Access VPN authentication started working correctly from different ISPs without any issues.
I would like to thank everyone for your comments, insights, and the time you took to help me troubleshoot this problem. Your support was greatly appreciated.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
Tue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 28 Apr 2026 @ 06:00 PM (IDT)
Under the Hood: Securing your GenAI-enabled Web Applications with Check Point WAFTue 12 May 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point Cloud Firewall delivered as a serviceThu 30 Apr 2026 @ 03:00 PM (PDT)
Hillsboro, OR: Securing The AI Transformation and Exposure ManagementAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY