- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
While setting up Radius authentication (with MFA) for Mobile Access (SNX and Capsule) i have stumbled upon an issue i cannot solve.
I followed a guide Checkpoint_Azure_MFA_2020_v2_CheckMates.pdf and succesfully managed to configure a gateway (R80.20)
Radius works and MFA as well for both Capsule and MAB portal.
On the same SMS (R80.40) i configured another gateway (R80.30) with the same authentication scheme and if i login with Capsule, Radius and MFA works perfectly fine.
But if i use the MAB portal the gateway is trying to authenticate the user by LDAP first (querying the servers i have in ldap account units) and there is a delay for 2 minutes before the authentication is done by Radius.
The user is authenticated by MFA after that.
Since the configuration on gateway/cluster object is not so much i cannot understand what the difference is here.
Grateful for any pointers or hints 🙂
Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.
Andy
Hi Durin,
I have a feeling I may know what the solution here is. First off, how is auth configured on the gateway object itself? Under vpn or mobile access (depending which one you have issue with), there is a setting for authentication and you can configure auth methods there. Can you send a screenshot of how thats set up? I think it may give us some clue.
Andy
It is the same config under VPN Clients as for Mobile Access on both gateways. Without delay and the one with delay, use same Radius object.
Tried with and witjout support for older clients.
Technically, you do NOT need anything in auth list, since you are using radius as global auth method anyway.
Andy
Hi,
Thanks! I removed from auth list and now it works!
For you, no charge ; )
Much obliged 😉
Glad I could help...thats what I love about this community. 90% of the time, people find solutions from others without having to waste time on hold and talk to TAC, which USUALLY ends up in them asking for debugs that have nothing to do with the problem anyway.
Have a nice weekend!!
Totally agree, this is a good community with useful stuff and people with a lot of knowledge.
Have a nice weekend you also and thanks one more time 🙂
Thanks mate, you as well...cheers!
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 6 | |
| 3 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY