- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello everyone,
I have a Remote Access VPN implementation configured with MFA authentication. The issue I’m facing is that the authentication fails when I connect using my home Internet Service Provider’s network.
The error message shows an App registration that doesn’t exist in my Azure tenant and isn’t linked to any Identity Provider configured in my Management Server.
However, when I connect using my mobile hotspot, the authentication works perfectly, and the URLs correspond to the current Identity Provider configured on the gateway.
Could this behavior be related to how the ISP handles IP assignment (NAT, CGNAT, etc.)?
Is there any known limitation or recommendation regarding authentication flows behind carrier-grade NAT or similar configurations?
Thanks in advance for any insight or suggestions.
Im not expert in this particular subject by any means, but I do know those values have to come from Azure/gw side. By the way, I see the option for importing file, you did not do so, you chose manual...any reason why?
I tried a different approach because it wouldn’t start before. It starts now, but it’s showing some strange behavior.
Did you try importing the file approach?
I meant below settings, more less what you had in your screenshot.
In the previous cases, I followed this approach.
And I assume it was same error?
It doesn’t have any impact, but the idea was to test an alternative approach.
Small favor, if you dont mind...can you please paste the text error itself, rather than the screenshot?
AADSTS700016: Application with identifier 'https://IP/saml-vpn/spPortal/ACS/ID/e630b697-b47e-4029-be4b-33599e317cb0' was not found in the directory 'XXXXXX'. This can happen if the application has not been installed by the administrator of the tenant or consented to by any user in the tenant. You may have sent your authentication request to the wrong tenant.
Give me some time, let me look into it.
Here are some things I would check, from my previous notes:
1) Check the tenant
2) check the app registration
3) confirm the identifier
But why would the scenario that authenticates me vary depending on the connection?
Just thought of something, might not be related, but lets double check. What are dns servers when it works and when it does not, can you check?
falis
fails
Worksworks
K, so lets take a step back, as they say. So, with one that fails, are you able to resolve google dns, say google.com. Does that work?
I would open TAC case, see if they provide specific vpn debug for this.
Thank you very much for your time and for the validation tips. I will share any updates as soon as I have them, in case they’re helpful for future cases.
Yes, thanks a lot for that, appreciated.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY