Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
akshay101
Explorer

LOM port configuration with radius

I have configured the LOM port on the Check Point firewall and can access it using the admin credentials.

We have also configured a RADIUS profile, but when attempting to log in using RADIUS authentication, the login fails. On the ISE side, the logs show a failure due to an invalid password or shared key, even though I am using the correct credentials and key.

When we change the shared key to a simpler one on both ISE and LOM, I’m able to reach the login prompt but receive a “User access denied, contact admin” message. Meanwhile, ISE shows that the authentication was successful.

0 Kudos
12 Replies
_Val_
Admin
Admin

Are you using a non-English locale? It is probably that LOM is set to an English keyboard, while you are not, hence the special characters used with your password are not the same.

0 Kudos
akshay101
Explorer

@_Val_ we tried with simple password as well, on ISE radius user getting authenticated but on LOM page its showing user access denied. contact administrator.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Did you check with TAC? Its possible this might be a known limitation.

Andy

Best,
Andy
0 Kudos
_Val_
Admin
Admin

Yet, you did not answer the question. Do you, or do you not, use a non-English keyboard? Also, are you sure your LOM is set correctly?

akshay101
Explorer

Yes, using english keyboard. yes its accessible with admin but not with radius users.

0 Kudos
_Val_
Admin
Admin

Thanks. Please open a TAC case for this

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hopefully TAC can help you fix it.

Best,
Andy
0 Kudos
genisis__
MVP Silver
MVP Silver

Whats the appliances and LOM type also firmware version - I've not had any issue with the LOM sending the RADIUS request to the ISE server however there is some work to do on the iSE server to get it working (not had the time for it).

It would be nice if TACACS+ was supported.

0 Kudos
akshay101
Explorer

We had created a new policy on ISE with simple shared keys but still issue is there. 

 

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Please let us know once this is solved.

Thank you!

Best,
Andy
0 Kudos
Lesley
MVP Gold
MVP Gold

Most LOM issues are because of outdated LOM software. What LOM version you have installed? Java or HTML5 based? In what appliance it is running? 

Second tip: does this authentication flow go via the firewall that has the LOM installed. Just from practical view: imagine firewall is crashed and you have to login. LOM tries to do RADIUS traffic via the firewall that has crashed and then you cannot login. Bit like chicken and egg discussion 😉 

-------
Please press "Accept as Solution" if my post solved it 🙂
0 Kudos
genisis__
MVP Silver
MVP Silver

100% Lesley!

also here's the link to the firmware page:
https://support.checkpoint.com/results/sk/sk88064

routing, firewall rules all should be considered (could even be asymmetric routing issue, the other test that can be done, and I know it may not be practical,  configure a dummy switch with 'aaa' configuration using RADIUS, give it the same IP as the LOM (clearly both should not be on the same network), and test, if this work you have then isolated the issue to the Checkpoint appliance and can take the next steps accordingly.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events