<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MFA and secondary connect / Multi sites in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116588#M16441</link>
    <description>&lt;P&gt;Is this in take 102?&lt;BR /&gt;I have tried to look for the specific support in the release notes ..&lt;/P&gt;</description>
    <pubDate>Thu, 22 Apr 2021 06:48:38 GMT</pubDate>
    <dc:creator>Galb</dc:creator>
    <dc:date>2021-04-22T06:48:38Z</dc:date>
    <item>
      <title>MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115897#M16333</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;When implementing MFA and Radius authentication such as Dou/OKTA in a multi sites scenario.&lt;/P&gt;&lt;P&gt;is the user getting a separate MFA request for each gateway when accessing a resource that is behind it even when password caching is defined ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 07:12:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115897#M16333</guid>
      <dc:creator>Galb</dc:creator>
      <dc:date>2021-04-13T07:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115941#M16341</link>
      <description>&lt;P&gt;Yes.&amp;nbsp;&amp;nbsp; In our testing of MFA using MS Authenticator this was the case.&amp;nbsp; At this time I don't know if there is a resolution to this issue.&amp;nbsp; Deeper investigation into our setup showed that MS NPS (Radius Server) could not take into account any previous session information. So users saw Authenticator prompts everytime the VPN client connected to a Secondary Gateway.&lt;/P&gt;&lt;P&gt;I think mileage may vary depending on the radius server implementation as I know that some radius implementations can account for existing sessions and then by-pass the MFA request.&lt;/P&gt;&lt;P&gt;It would be great if CP could let us know what if anything is on the roadmap for this MFA use case.&amp;nbsp; I would certainly welcome a resolution.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 13:54:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115941#M16341</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2021-04-13T13:54:01Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115945#M16342</link>
      <description>&lt;P&gt;The challenge here is around the fact that each secondary GW is not aware of the second factor entered by the primary GW. In a RADIUS example the VPN treat the authentication as&amp;nbsp; black box and passes the challenges to the client till the RADIUS server is done.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So the options are:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. Make the RADIUS server aware of prior authentications and not prompt second factor&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Work towards having SAML based authentication in the client in order to leverage the IDP SSO.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 14:45:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115945#M16342</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2021-04-13T14:45:54Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115948#M16343</link>
      <description>&lt;P&gt;Well said.&amp;nbsp; Thanks.&lt;/P&gt;&lt;P&gt;When will number 2 above make it into a product release?&amp;nbsp; This seems the best direction forward.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Apr 2021 15:03:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/115948#M16343</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2021-04-13T15:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116011#M16353</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;I guess SAML can be the solution since RADIUS/RADIUS proxies can support session cookie to bypass the second MFA authentication.&lt;BR /&gt;But, which version of CP&amp;nbsp; and client support SAML..?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Apr 2021 12:53:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116011#M16353</guid>
      <dc:creator>Galb</dc:creator>
      <dc:date>2021-04-14T12:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116252#M16388</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;For general availability: The next R80.40 Jumbo should have the SAML capabilities (should be released before the end of the month) and the Client side GA should be released in the next few days.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For Customer Release - one is available through Solution Center for several months now.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 09:46:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116252#M16388</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2021-04-18T09:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116262#M16392</link>
      <description>&lt;P&gt;Thanks Tzvi&lt;/P&gt;&lt;P&gt;I will wait till the end of the month to test both&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 14:51:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116262#M16392</guid>
      <dc:creator>Galb</dc:creator>
      <dc:date>2021-04-18T14:51:35Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116263#M16393</link>
      <description>&lt;P&gt;Just one more question..&lt;BR /&gt;Is there a best practice&amp;nbsp; recommendation to implementing/not implementing "Secondary Connect"?&lt;BR /&gt;I think that secondary connect is a more "Slick" solution than routing the traffic via the STS..&lt;/P&gt;&lt;P&gt;But maybe I am wrong here?&lt;/P&gt;</description>
      <pubDate>Sun, 18 Apr 2021 15:25:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116263#M16393</guid>
      <dc:creator>Galb</dc:creator>
      <dc:date>2021-04-18T15:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116588#M16441</link>
      <description>&lt;P&gt;Is this in take 102?&lt;BR /&gt;I have tried to look for the specific support in the release notes ..&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 06:48:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116588#M16441</guid>
      <dc:creator>Galb</dc:creator>
      <dc:date>2021-04-22T06:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116611#M16443</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It should be in the next take following 102, it seems it had yet to be released. Stay tuned, since I understand it should be released shortly.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 09:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116611#M16443</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2021-04-22T09:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116661#M16457</link>
      <description>&lt;P&gt;Thank!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 16:02:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116661#M16457</guid>
      <dc:creator>Galb</dc:creator>
      <dc:date>2021-04-22T16:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116865#M16491</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;R80.40 JHF T114 was released with SAML support for RA IPsec VPN&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="SAML_RA_RN.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11515iD8474D1A69017472/image-size/medium?v=v2&amp;amp;px=400" role="button" title="SAML_RA_RN.jpg" alt="SAML_RA_RN.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 06:52:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116865#M16491</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2021-04-26T06:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: MFA and secondary connect / Multi sites</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116908#M16497</link>
      <description>&lt;P&gt;Thanks for the update!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Apr 2021 11:06:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/MFA-and-secondary-connect-Multi-sites/m-p/116908#M16497</guid>
      <dc:creator>Galb</dc:creator>
      <dc:date>2021-04-26T11:06:27Z</dc:date>
    </item>
  </channel>
</rss>

