- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- R80.40 Gateway- AD Authentication error - "Invalid...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R80.40 Gateway- AD Authentication error - "Invalid username and password" for Citrix VPN users
Hi All,
I Updated 5800 Gateway to R80.40. VPN Clients could VPN in and authenticate via AD and OTP through Citrix portal but after sometime, everyone on Citrix will be kicked out and if they login again, all of them will get the same error "Invalid username and password"
Now if you reboot the gateway, then they can authenticate fine but only for a while, may be 15 minutes and then the same error appears if they try to login.
Disabling SecureXL resolved the issue.
Template creation stops at the exact rule which is responsible for client authentication to AD.
It almost seems like the previous Kerberos Ticket is carried forward by SecureXL and authentication fails.
I want to understand if Templates are disabled at that same rule, what else SecureXL is doing that users are getting invalid username or password error when SecureXL is enabled. Something different in R80.40 may be?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If disabling SecureXL "solves" any issue, the TAC should be involved.
Meanwhile, what is the precise rule you’re referring to?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
Thanks for your reply. TAC case is raised already. I was thinking may be someone else might have the same issue with R80.40.
The rule allows remote client addresses to contact AD. services include Kerberos as well in that rule.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
A screenshot would be helpful
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here is the screenshot please.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Nothing in that rule should disable SecureXL that I’m aware of, but could be wrong.
The TAC SR in PM may be helpful.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All,
the issue was resolved after installing HFA take 89 - something in base R80.40 image that would prevent SecureXL working as it should.
