> Source: [sk167118](https://support.checkpoint.com/results/sk/sk167118)

# sk167118 - When using RADIUS as a second factor without "Ask user for password", a response prompt is displayed despite not using RADIUS challenges.

| Property | Value |
|----------|-------|
| Solution ID | sk167118 |
| Date Created | 2020-06-02 |
| Last Modified | 2021-11-22 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |
| OS | Gaia |

## Symptoms

- * When using RADIUS as a second factor without "Ask user for password", a response prompt is displayed despite not using RADIUS in challenge mode.
* The prompt is shown even if the RADIUS did not return a reply at all.
* "Authenticating user 'X'. Please fill the required input. When using certificates as the first factor, you might see: " Certificate authentication completed successfully. password: Response: "

## Solution

This problem was fixed. The fix is included in:  

* [Jumbo Hotfix Accumulator for R81.10](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk175186) starting from Take 14
* **[R81](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk166715)**
* [Jumbo Hotfix Accumulator for R80.40 (Take 91 and above)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk165456)
* [Jumbo Hotfix Accumulator for R80.30 (Take 228 and above)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk153152)
* [Jumbo Hotfix Accumulator for R80.20 (Take 190 and above)](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk137592)

<br />

If you do not wish to upgrade, [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix. For faster resolution and verification please collect CPinfo files from the Security Management and Security Gateways involved in the case.  

For faster resolution and verification please collect [CPinfo](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk92739) files from the Security Management and Security Gateways involved in the case.   

**After the Hotfix is installed, you need to enable *EnableBlankRadiusAuth:***   

*ckp_regedit -a SOFTWARE/CheckPoint/VPN1 EnableBlankRadiusAuth -n 1*   

**and push policy** .  

**To check the value:**   

*ckp_regedit -p SOFTWARE/CheckPoint/VPN1 EnableBlankRadiusAuth*

<br />

**Related Solution:** [sk144932 - When Multiple Factor Authentication is configured with DynamicID , VPN clients receive 4 password prompts](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk144932).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
