CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2006-09-05
karimi karimi is offline
Member
 
Join Date: 2005-08-22
Posts: 54
Rep Power: 3
karimi has an average reputation (10+)
Default SecuRemote w/ RADIUS Authentication issue

Hello,

I have my administrator user using RADIUS and authenticating to SmartDashboard with no problems.

When I change one of the securremote users Auth method from Firewall-1 Password to "RADIUS", when the user logs on with the SecureRemote client, they get "Authentication Failed: Username + Password".

Do I have to delete and recreate the Site in SecuRemote, or am I missing something?

Thanks

~m
Reply With Quote
  #2 (permalink)  
Old 2006-09-05
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecuRemote w/ RADIUS Authentication issue

You shouldn't as long as the username matches the radius username. Do you see anything in the logs? Maybe turing on IKE debugging would show you something vpn debug ikeon
Reply With Quote
  #3 (permalink)  
Old 2006-09-05
karimi karimi is offline
Member
 
Join Date: 2005-08-22
Posts: 54
Rep Power: 3
karimi has an average reputation (10+)
Default Re: SecuRemote w/ RADIUS Authentication issue

Strangely I get "Wrong username/password: IKE Failed". If I change it back to "Firewall-1 Username" then everything works fine.

RADIUS works for Administrator users to the same radius server.. so i'm unsure what is failing in secure-remote.

I don't see anything in the logs indicating a drop
Reply With Quote
  #4 (permalink)  
Old 2006-09-06
chillyjim chillyjim is offline
Senior Member
 
Join Date: 2005-08-29
Location: Upstate NY
Posts: 1,598
Rep Power: 4
chillyjim has an average reputation (10+)
Send a message via AIM to chillyjim Send a message via Skype™ to chillyjim
Default Re: SecuRemote w/ RADIUS Authentication issue

Check your RADIUS logs and make sure you have the gateway defined as a "NAS" device (define all the interfaces just to be safe).
Reply With Quote
  #5 (permalink)  
Old 2006-09-06
aqw789 aqw789 is offline
Junior Member
 
Join Date: 2006-08-31
Posts: 10
Rep Power: 0
aqw789 has an average reputation (10+)
Default Re: SecuRemote w/ RADIUS Authentication issue

- Define a Radius server - Object tree --> Servers / Radius
(Name: Enter the host name, Host:Select Radius server, Enter Shared secret to authenticate with the Radius server)

- Define the users in the FW user DB or use external user profiles.

- Create a user group for the Radius users and add them to this group. If you are using external user profiles, they should also be added to this group.

!!! Encryption tab: This should be configured for SecureClient and IKE

- authentication tab: Select the Radius server or group

- Authentication tab: Allow Radius authentication on the gateway.

- Authentication tab of Gateway:You need to add the Radius user groups to the Policy server group if you use a policy server.

- Remote Access Community: Add the Radius group to the user groups in the Remote Access Community.
!!! Don't forget your Remote Access rule. Create it or if it's already there upload the policy to the enforcement module to activate your changes.

HTH.
Reply With Quote
  #6 (permalink)  
Old 2006-09-06
karimi karimi is offline
Member
 
Join Date: 2005-08-22
Posts: 54
Rep Power: 3
karimi has an average reputation (10+)
Default Re: SecuRemote w/ RADIUS Authentication issue

The RADIUS works fine for SmartDashboard admins, it just doesn't work for SecuRemote users.

I checked the log, and the error I get is:

"Client Encryption: RADIUS Servers not responding..."

If this is an issue with Microsoft IAS, why does RADIUS work with SmartDashboard users?

~k
Reply With Quote
  #7 (permalink)  
Old 2006-09-06
karimi karimi is offline
Member
 
Join Date: 2005-08-22
Posts: 54
Rep Power: 3
karimi has an average reputation (10+)
Default Re: SecuRemote w/ RADIUS Authentication issue

Hi Folks

It works now.

1) Changed MS Auth to PAP on IAS
2) Added 2 entries for both Firewalls in Cluster to Microsoft IAS
3) Duplicated same shared-secret for RADIUS server object and 3 Clients in IAS.
4) Using NGX SecureRemote/SecureClient

It's working now. If anyone wants a detailed document on how to do this, email me and I'll send it.
Reply With Quote
  #8 (permalink)  
Old 2006-11-28
Alfa.Ma@kinectrics.com Alfa.Ma@kinectrics.com is offline
Junior Member
 
Join Date: 2006-11-28
Posts: 1
Rep Power: 0
Alfa.Ma@kinectrics.com has an average reputation (10+)
Default Re: SecuRemote w/ RADIUS Authentication issue

Karima,
Thanks for sending the document to me so fast. But I need the document on setting up the Microsoft IAS server as radius server for SecureClient authentication. I need a radius server so my ntwork support can use it fot network management.
Please send it to alfa.ma@kinectrics.com.
Thanks in advance.

Alf
Reply With Quote
  #9 (permalink)  
Old 2007-02-05
giulitn giulitn is offline
Junior Member
 
Join Date: 2005-12-14
Posts: 19
Rep Power: 0
giulitn has an average reputation (10+)
Default Re: SecuRemote w/ RADIUS Authentication issue

Quote:
Originally Posted by karimi View Post
Hi Folks

It works now.

1) Changed MS Auth to PAP on IAS
2) Added 2 entries for both Firewalls in Cluster to Microsoft IAS
3) Duplicated same shared-secret for RADIUS server object and 3 Clients in IAS.
4) Using NGX SecureRemote/SecureClient

It's working now. If anyone wants a detailed document on how to do this, email me and I'll send it.
Please, could you send me also how you succed?
I'm working on it and i'm successfully using IAS for wireless authentication.
Bye.
Reply With Quote
  #10 (permalink)  
Old 2007-12-30
vinayakk06 vinayakk06 is offline
Junior Member
 
Join Date: 2007-10-22
Posts: 3
Rep Power: 0
vinayakk06 has an average reputation (10+)
Default Re: SecuRemote w/ RADIUS Authentication issue

heyy frnds,

can you pls email me the steps you have taken to solve the problem for the error: Radius authentication failed and wrong user name and password.

My email id is vinayakk06@yahoo.co.in

Thanks in advance.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:09.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0