> Source: [sk98874](https://support.checkpoint.com/results/sk/sk98874)

# sk98874 - RADIUS user cannot log in to Gaia Portal or SSH 

| Property | Value |
|----------|-------|
| Solution ID | sk98874 |
| Date Created | 2014-03-17 |
| Last Modified | 2021-11-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * RADIUS user cannot log in to Gaia Portal or SSH.  

* The `/var/log/messages` file shows the following when RADIUS user logs in over SSH:  

  `xpand[4174]: admin localhost t +volatile:mrma:users:user:test_user:su t `  
  `
  sshd[26810]: pam_radius_auth: Non local user 'test_user' will be in 'superusr' and have root access`  
  `
  xpand[4174]: test_user localhost t -volatile:set_clish_flag `  
  `
  clish[26812]: user logged from test_user`  
  `
  clish[26812]: User not logged in. He has no configured role.`  
  `
  xpand[4174]: test_user localhost t -volatile:mrma:users:user:test_user`  
  ` 
  xpand[4174]: test_user localhost t -volatile:mrma:users:user:test_user:access_mechanism:CLI `  
  `
  xpand[4174]: test_user localhost t -volatile:mrma:users:user:test_user:access_mechanism:Web `  
  `
  xpand[4174]: test_user localhost t -volatile:mrma:users:user:test_user:pid `  
  `
  xpand[4174]: test_user localhost t -volatile:mrma:users:user:test_user:role:radius-group-any `  
  ` 
  xpand[4174]: test_user localhost t -volatile:mrma:users:user:test_user:role:radius-group-any:domainname:default `  
  ` 
  xpand[4174]: test_user localhost t -volatile:mrma:users:user:test_user:su `  
  `
  clish[26812]: User test_user logged out due to an error from CLI shell`  
  `
  sshd[26810]: Received disconnect from x.x.x.x: 11: disconnected by user`  
  `
  sshd[26765]: pam_unix(sshd:session): session closed for user test_user`  

* The `/var/log/messages` file shows the following when RADIUS user logs in Gaia Portal:  

  `httpauth: pam_radius_auth: Got response from RADIUS server`  
  `
  cp_radius_helper_1: Non-local user 'test_user' given role 'radius-group-any' (if that exists)`  
  `
  cp_radius_helper_1: Non-local user 'test_user' given role 'radius-group-any' (if that exists)`  
  `
  cp_radius_helper_1: Can't handle ':' or '\' in role name 'radius-group-XXX:XXXXX' for user test_user`  
  `
  xpand[4174]: nobody localhost t +volatile:mrma:users:user:test_user:pid 29873 `  
  `
  xpand[4174]: nobody localhost t +volatile:pid:29873 test_user `  
  `
  xpand[4174]: nobody localhost t +volatile:ppid:29873 0 `  
  `
  xpand[4174]: nobody localhost t +volatile:set_clish_flag t `  
  `
  xpand[4174]: nobody localhost t +volatile:mrma:users:user:test_user:access_mechanism:Web t `  
  `
  xpand[4174]: nobody localhost t +volatile:mrma:users:user:test_user:access_mechanism:CLI t `  
  `
  xpand[4174]: nobody localhost t +volatile:mrma:users:user:test_user t `  
  `
  xpand[4174]: nobody localhost t +volatile:mrma:users:user:test_user:role:radius-group-any t `  
  `
  xpand[4174]: nobody localhost t +volatile:mrma:users:user:test_user:role:radius-group-any:domainname:default t `  
  `
  xpand[4174]: nobody localhost t +volatile:mrma:users:user:test_user:su t `  
  `
  httpauth: pam_radius_auth: Non local user 'test_user' will be in 'superusr' and have root access`  
  `
  httpd2: User not logged in. He has no configured role.`  

* '`You are not configured for web access`' message in Gaia Portal.  

* RADIUS user can login via SSH but RADIUS user login to Gaia WebUI does not work:  

  Gaia Portal shows error: Permission Denied

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
