CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA or CCSE One-Week Certification Training Courses with CPUG in Beautiful San Francisco!
    R70 CCSA Courses Starting (2010) 6/7, 7/12, 8/9, 10/11, 11/8, 12/6.  R70 CCSE Courses Starting (2010) 8/16.
2. CPUG CON 2010 EUROPE, the User Conference in Switzerland, September 20th-22nd, 2010!
3. Join Our CPUG Groups On LinkedIn and Facebook.  See Our Channel on YouTube.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register Projects FAQ Members List Social Groups Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 2009-11-27
Junior Member
 
Join Date: 2009-11-25
Posts: 6
Rep Power: 0
Razor has an average reputation (10+)
Default Extend the authentication timeout

We are having an issue to authenticate our remote users using SecureClient to vpn to our SecurePlatform R65 HFA 30 firewall.

When a user tries to connect they get the error below.
Checking network connectivity...
Preparing connection...
Connecting to gateway...
Gateway not responding Connection failed

This is because the RADIUS server behind the firewall is using time for extra authentication. The error message in the VPN log, says there is no respons from RADIUS. This is correct, because the RADIUS is busy also authenticating the user by other means, and will not answer before the final authentication is done.

The question is, how do I extend the timeout values in the CP VPN. I have attemted to extend the au_connection_timeout value to increase the timeout. This did not work. I attemted the same with ike_negotiation_timeout with the same result.

These values does not seem to have any effect even if i try to decrease the timeout values.


Any suggestions on what I should do next?
Reply With Quote
  #2 (permalink)  
Old 2009-12-08
Junior Member
 
Join Date: 2009-12-07
Posts: 1
Rep Power: 0
igore has an average reputation (10+)
Default Re: Extend the authentication timeout

In order to modify Radius timeouts, you can use the following attributes:

From the SmartCenter/CMA SmartDashboard got to 'Global Propertie' ==> 'SmartDashboard Customization' ==> Configure... ==> Firewall-1 ==> Authentication ==> RADIUS:
--------------------------------------------------------------------
- radius_connect_timeout (connection timeout)

- radius_retrant_timeout (timeout between retransmissions)

- radius_retrant_num (number of retransmissions)
--------------------------------------------------------------------

Hope it will help.
Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 23:22.


Powered by vBulletin® Version 3.8.5
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.5.1