CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3.
2. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-09-18
Junior Member
 
Join Date: 2007-09-17
Posts: 3
Rep Power: 0
darkid has an average reputation (10+)
Default RADIUS authentication help

Hi,
I'm trying to setup R61 to authenticate users through RADIUS. I followed all the instructions laid out in other threads but i'm still having some troubles.
I'm using an RSA SecurID box running Steel Belted Radius.

Authentication works if the user i'm trying to login with is defined both on the RSA box and on the SmartDashboard. However, when I create a generic* profile, it won't let me in anymore. I can see an actual Request being sent to the RADIUS server, and the RADIUS marks it as "Accepted"...so it's definitely getting the correct user info. But then all I get back at the SmartDashboard login is: "Authentication to Server 'x.x.x.x' failed."

Are there any RADIUS attributes I should be returning maybe?
Thanks for any help.
Reply With Quote
  #2 (permalink)  
Old 2007-09-23
Member
 
Join Date: 2005-09-04
Location: Perth
Posts: 40
Rep Power: 0
seanmac1904 has an average reputation (10+)
Default Re: RADIUS authentication help

Is your radius server returning any non-standard attributes ?

I found I needed to ignore a non-standard attribute that was required by my Telco's dial-in service that used our radius server

for me it was radus attribute 26 Ascend-Framed-IP

I set it under the global properties ->
smartdashboard customisation -> advanced button
under the firewall-1 -> authentication -> radius section

there is an option radius_ignore (i needed attribute 26)

cheers
Sean
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -7. The time now is 16:53.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0