- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi CheckMates,
I've configured tacacs+ on my gateways and it's working properly.
However, when the user type a bad password, the account is locked instantly on AD.
The gateway is retrying the same authentication with bad credentials, until the user got blocked.
I would like to know, if is there any fine tuning on tacacs configuration in the gateways to avoid this problem.
I'm using 2 tacacs servers with 60s of timeout.
Not sure if it should be trying to authenticate on both TACACS+ servers.
A TAC case is probably warranted here: https://help.checkpoint.com
What version/JHF?
What functionality is TACACS+ configured to provide authentication for?
Hi,
All gateways are in R81.10 with JHF 95 or JHF 110, also I've a mix of maestro and traditional clusters.
We're using TACACS+ to authenticate users by console via ssh and gaia via https.
We configured the roles TACP-0 with a few features in read-only and some custom commands and TACP-15 with all features in read-write.
On my TACACS+ server, I noticed 2 attempts in a row, coming from the gateway with a difference of 6s or less, the gateway is trying to authenticate on both servers, that result in 4 failed authentications.
Our password policy on AD, block the user with 3 failed attemtps.
is it expected to gateway try authenticate the user twice? Is there any configuration that I can do or is better to open a case with TAC?
Not sure if it should be trying to authenticate on both TACACS+ servers.
A TAC case is probably warranted here: https://help.checkpoint.com
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 17 | |
| 13 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY