<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Duo setup with VPN remote access in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97539#M11029</link>
    <description>&lt;P&gt;Thanks, is there a way to perform a push option without using the "Password,push"&amp;nbsp;&lt;/P&gt;&lt;P&gt;I find it quite annoying and I would be happy to allow a seamless and cleaner user experience to our users&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 25 Sep 2020 13:34:41 GMT</pubDate>
    <dc:creator>Shahar_Grober</dc:creator>
    <dc:date>2020-09-25T13:34:41Z</dc:date>
    <item>
      <title>Duo setup with VPN remote access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/87958#M11024</link>
      <description>&lt;P&gt;My goal is to primary auth the user with LDAP then second auth with a duo push. Although the confusing part is there is RADIUS configuration required, even though I only want to use LDAP w/ Duo. Not sure I understand why but any configuration examples would be helpful!!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is mine today:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ad_client]&lt;BR /&gt;host=1.2.3.4 (AD server IP)&lt;BR /&gt;service_account_username=ad-admin&lt;BR /&gt;service_account_password=ad-admin-password&lt;BR /&gt;search_dn=DC=domain,DC=com&lt;BR /&gt;security_group_dn="CN=Duo Checkpoint VPN,OU=Groups,DC=domain,DC=com"&lt;/P&gt;&lt;P&gt;[radius_server_auto]&lt;BR /&gt;ikey=ikey_from_duo_console&lt;BR /&gt;skey=skey_from_duo_console&lt;BR /&gt;api_host=api-123456789.duosecurity.com&lt;BR /&gt;radius_ip_1=checkpoint_gw1&lt;BR /&gt;radius_ip_2=checkpoint_gw2&lt;BR /&gt;radius_secret_1=secret1&lt;BR /&gt;radius_secret_2=secret2&lt;BR /&gt;client=ad_client&lt;BR /&gt;port=1812&lt;BR /&gt;failmode=secure&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am seeing the firewall logs that the radius server is not responding, but I am guess that just means it cannot properly authenticate my account. I know network-wise the gateways can reach the Duo proxy server.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jun 2020 18:16:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/87958#M11024</guid>
      <dc:creator>Tim_McColgan</dc:creator>
      <dc:date>2020-06-10T18:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Duo setup with VPN remote access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/88474#M11025</link>
      <description>Have you followed the guide Duo has for this? &lt;A href="https://duo.com/docs/checkpoint" target="_blank"&gt;https://duo.com/docs/checkpoint&lt;/A&gt;</description>
      <pubDate>Sun, 14 Jun 2020 07:52:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/88474#M11025</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-06-14T07:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: Duo setup with VPN remote access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/91478#M11026</link>
      <description>&lt;P&gt;I did, after a few tweaks I am up and working. Crazy enough, my fix was to remove the double quotes from the security dn.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;security_group_dn=CN=Duo Checkpoint VPN,OU=Groups,DC=domain,DC=com&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 13:46:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/91478#M11026</guid>
      <dc:creator>Tim_McColgan</dc:creator>
      <dc:date>2020-07-14T13:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: Duo setup with VPN remote access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97530#M11027</link>
      <description>&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;did you manage to get the Duo work with Push instead of OTP?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 10:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97530#M11027</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2020-09-25T10:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Duo setup with VPN remote access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97538#M11028</link>
      <description>Yes!</description>
      <pubDate>Fri, 25 Sep 2020 13:26:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97538#M11028</guid>
      <dc:creator>Tim_McColgan</dc:creator>
      <dc:date>2020-09-25T13:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: Duo setup with VPN remote access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97539#M11029</link>
      <description>&lt;P&gt;Thanks, is there a way to perform a push option without using the "Password,push"&amp;nbsp;&lt;/P&gt;&lt;P&gt;I find it quite annoying and I would be happy to allow a seamless and cleaner user experience to our users&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 13:34:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97539#M11029</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2020-09-25T13:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Duo setup with VPN remote access</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97543#M11030</link>
      <description>&lt;P&gt;Yes, in the [radius_server_auto] portion of your&amp;nbsp;authproxy.cfg file you would just add this:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;factors = push&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can add many factors to it, but I prefer and only use push.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Sep 2020 14:07:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Duo-setup-with-VPN-remote-access/m-p/97543#M11030</guid>
      <dc:creator>Tim_McColgan</dc:creator>
      <dc:date>2020-09-25T14:07:14Z</dc:date>
    </item>
  </channel>
</rss>

