| CPUG | |
| The Check Point User Group | |
| A Resource For The Check Point Community. Fast. Useful. Independent. | |
|
| |||||||
![]() |
| | LinkBack | Thread Tools | Display Modes |
| |||
| Dear all, I'm new to this forum and unfortunately no network specialist at all but I would really appreciate your help on this topic: Three weeks ago, the VPN authentication process stopped working for several users from one day to another. Internet is working properly; Radius server authentificates the user but the gateway is not responding. According to our Firewall admins; they see the successfull authentication but afterwards the client doesn't send requests anymore... (We're using R60 HFA02 on all clients.) The problem seems to happen only with DSL/PPPoE connections... the VPN client is working properly via our internal LAN connection and also via mobile datacards (UMTS/HSDPA/GPRS). Do you have any ideas? Thank you very much for your help, Florian |
| |||
| One good way to start is to identify what changed 3 weeks ago. Are you sure the conditions under which you tested were exactly the same, like user, version, etc? Another angle is to try and understand what is shared by the user that can't authenticate and what differs from the ones that can. If it's only the lines, are they all from the same provider? Is it possible that they decided to block ESP? It's definitely worth it giving them a call and asking. |
| |||
| Thanks for your quick answer... Here are some more detailed information: .) users got different internet providers .) users got completely different hardware .) no changes made in the last years from our site .) already tried: re-installation + down- and upgrade of vpn software .) already tried: re-starting the radius servers .) already tried: disabeling the client firewall .) already tried: talking to internet provider = no changes made by them Thanks again, Florian |
| |||
| Hello, it seems, that we have a similar problem. I can connect with Username/Password with IKE over TCP and NAT-T enabled. Also on some Notebooks I can do this with certificates. When I turn off IKE over TCP and NAT-T it seems to work with Certificates with all notebooks. The problem is, that we have set the option IKE over TCP and NAT-T on all Clients and it worked like a charm for 2 years now. Also with R65 it worked, but from one day to the other it stopped working. I don't know what the issue can be. Greetz, Jan Kleinhans |
![]() |
| Thread Tools | |
| Display Modes | |
| |