<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R82 DynamicID via Email (SMTP) – Configuration Tips and Key Considerations in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276215#M105129</link>
    <description>&lt;P&gt;Excellent!&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2026 21:12:29 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2026-04-28T21:12:29Z</dc:date>
    <item>
      <title>R82 DynamicID via Email (SMTP) – Configuration Tips and Key Considerations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276214#M105128</link>
      <description>&lt;P&gt;Configuring MFA is something essential nowadays, and its setup should be intuitive. When I tried to find where to configure the email string for SMTP Relay, I noticed that in SmartConsole R82 it is extremely hidden, and placed in a section that, in my opinion, does not make much sense. It should be simpler and ideally located within the Gateway properties under &lt;STRONG&gt;Authentication &amp;gt; Dynamic ID&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Below, I’ll show where this configuration is located. This can serve as a useful reference for others trying to configure it, and also as a suggestion for the Check Point team to improve this in future SmartConsole versions, making MFA settings more intuitive.&lt;BR /&gt;&lt;BR /&gt;The &lt;STRONG&gt;“SMS provider and email”&lt;/STRONG&gt; option is locked under DynamicID Settings. Below I will show where this configuration is located.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="israelfds95_0-1777408925061.png" style="width: 920px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34133iD33CD1E8F702641C/image-dimensions/920x674?v=v2" width="920" height="674" role="button" title="israelfds95_0-1777408925061.png" alt="israelfds95_0-1777408925061.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Go to &lt;STRONG&gt;“Manage &amp;amp; Settings” &amp;gt; Blades &amp;gt; Mobile Access &amp;gt; Capsule Workspace Settings&lt;BR /&gt;&lt;BR /&gt;NOTE: In my opinion, it does not make sense for this configuration to be so hidden, especially within Capsule Workspace settings, which are expected to be deprecated.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="israelfds95_1-1777408925071.png" style="width: 864px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34131i28EE23CE3949DBAF/image-dimensions/864x596?v=v2" width="864" height="596" role="button" title="israelfds95_1-1777408925071.png" alt="israelfds95_1-1777408925071.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Go to &lt;STRONG&gt;“Multiple Authentication”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="israelfds95_2-1777408925075.png" style="width: 886px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34132iB45F9456AF6FE496/image-dimensions/886x534?v=v2" width="886" height="534" role="button" title="israelfds95_2-1777408925075.png" alt="israelfds95_2-1777408925075.png" /&gt;&lt;/span&gt;In the &lt;STRONG&gt;“Client Authentication”&lt;/STRONG&gt; window &amp;gt; &lt;STRONG&gt;DynamicID Settings&lt;/STRONG&gt;, enable the option:&lt;BR /&gt;&lt;STRONG&gt;“Challenge users to provide the DynamicID one-time password sent to their email account or mobile device via SMS”&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Add the SMTP information string in the “SMS provider and email” field.&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="israelfds95_3-1777408925094.png" style="width: 918px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34136i951F506199B897A4/image-dimensions/918x698?v=v2" width="918" height="698" role="button" title="israelfds95_3-1777408925094.png" alt="israelfds95_3-1777408925094.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;NOTE:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regarding this string, it is important to validate the following SMTP information:&lt;/P&gt;
&lt;P&gt;For email-based multi-factor authentication, you will need the following SMTP details:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;SMTP Server Address&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Example:&lt;BR /&gt;smtp.office365.com&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Connection Type&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;You need to determine:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;SMTP without TLS → smtp://&lt;/LI&gt;
&lt;LI&gt;SMTP with TLS (STARTTLS) → smtp:// + SSL_REQUIRED&lt;/LI&gt;
&lt;LI&gt;SMTP with direct SSL → smtps://&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Port&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;25 → Relay / no TLS or STARTTLS&lt;/LI&gt;
&lt;LI&gt;587 → STARTTLS (most commonly used today)&lt;/LI&gt;
&lt;LI&gt;465 → SMTPS&lt;/LI&gt;
&lt;/UL&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;Authentication&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Key question:&lt;/P&gt;
&lt;P&gt;Does the SMTP server require a username and password?&lt;/P&gt;
&lt;P&gt;If the SMTP server does &lt;STRONG&gt;not&lt;/STRONG&gt; require authentication, you can use a string similar to the example below:&lt;/P&gt;
&lt;P&gt;mail:TO=$EMAIL;SMTPSERVER=system.mail.com;FROM=no-reply@domain.com;BODY=$RAWMESSAGE&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is an older SK that can be used as a reference:&lt;BR /&gt;&lt;STRONG&gt;"sk144712 - How to enable SMTP authentication or TLS-SMTP for DynamicID"&lt;/STRONG&gt;, which mentions that:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;"Dynamic ID with an SMTP server that requires username and password for authentication is supported."&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then go back to the Security Gateway or Cluster properties, navigate to &lt;STRONG&gt;VPN Clients&lt;/STRONG&gt; or &lt;STRONG&gt;Mobile Access &amp;gt; Authentication&lt;/STRONG&gt;, and configure &lt;STRONG&gt;Multiple Login Options&lt;/STRONG&gt;, adding the first option and then DynamicID as the second.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="israelfds95_4-1777408925101.png" style="width: 923px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34134i2332490BACDA8083/image-dimensions/923x692?v=v2" width="923" height="692" role="button" title="israelfds95_4-1777408925101.png" alt="israelfds95_4-1777408925101.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Edit DynamicID as shown below if you want to use "Send Email" only.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="israelfds95_5-1777408925112.png" style="width: 910px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34135i1EDA53B786E7EF33/image-dimensions/910x635?v=v2" width="910" height="635" role="button" title="israelfds95_5-1777408925112.png" alt="israelfds95_5-1777408925112.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Configure the &lt;STRONG&gt;“User Directories”&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="israelfds95_6-1777408925115.png" style="width: 1009px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/34137i89F57B09D3148B41/image-dimensions/1009x898?v=v2" width="1009" height="898" role="button" title="israelfds95_6-1777408925115.png" alt="israelfds95_6-1777408925115.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 20:46:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276214#M105128</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2026-04-28T20:46:46Z</dc:date>
    </item>
    <item>
      <title>Re: R82 DynamicID via Email (SMTP) – Configuration Tips and Key Considerations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276215#M105129</link>
      <description>&lt;P&gt;Excellent!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2026 21:12:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276215#M105129</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-04-28T21:12:29Z</dc:date>
    </item>
    <item>
      <title>Re: R82 DynamicID via Email (SMTP) – Configuration Tips and Key Considerations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276262#M105130</link>
      <description>&lt;P&gt;Great content, I believe it's very relevant to the community.&lt;BR /&gt;&lt;BR /&gt;Best.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 14:03:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276262#M105130</guid>
      <dc:creator>WiliRGasparetto</dc:creator>
      <dc:date>2026-04-29T14:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: R82 DynamicID via Email (SMTP) – Configuration Tips and Key Considerations</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276268#M105131</link>
      <description>&lt;P&gt;Nicely done!&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 20:27:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R82-DynamicID-via-Email-SMTP-Configuration-Tips-and-Key/m-p/276268#M105131</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-29T20:27:47Z</dc:date>
    </item>
  </channel>
</rss>

