<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius Authentication on Check Point 1570 Appliance in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118435#M16780</link>
    <description>&lt;P&gt;Thats what I meant, sorry, worded it wrong : )&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2021 22:37:42 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-05-14T22:37:42Z</dc:date>
    <item>
      <title>Radius Authentication on Check Point 1570 Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118232#M16747</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have setup Radius authentication on a Check Point 1570 appliance with a backend FreeRadius server using local accounts.&lt;/P&gt;&lt;P&gt;Furthermore, the Radius server is also using Google Authenticator so that VPN users can use MFA when logging into the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The solution works fine as the user can enter their password + code and login.&lt;/P&gt;&lt;P&gt;A problem occurs when they set a password longer than 12 characters which would make the password a total of 18 characters with the 6 digit MFA code.&lt;/P&gt;&lt;P&gt;Testing has shown that it's not an issue with the FreeRadius server as it accepts the 12+6 password and it's not a problem with the Linux server as I can login via SSH with a password of 18 characters or more.&lt;/P&gt;&lt;P&gt;Bit more testing shows that when logging into the VPN with a password of 10 characters and 6 digit MFA code (16 in total), works fine. Anything more that this, then the firewall rejects the login with an authentication failure.&lt;/P&gt;&lt;P&gt;This indicates that the 1570 firewall is running Radius v1 where passwords are limited to 16 characters and not Radius 2 (as expected), which does have this issue. There is nothing in the Check Point documentation that indicates the above. As it is 2021, I cannot imagine why anyone would sell a product with an authentication protocol that was obsolete over 20 years ago.&lt;/P&gt;&lt;P&gt;Can anyone confirm this as it will cause a big issue as my company has a policy of 12 character minimum and the 6 digit MFA code will push this over the 16 character limit for Radius 1.&lt;/P&gt;&lt;P&gt;Thank You,&lt;/P&gt;&lt;P&gt;Gary&lt;/P&gt;</description>
      <pubDate>Wed, 12 May 2021 11:47:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118232#M16747</guid>
      <dc:creator>GaryJ</dc:creator>
      <dc:date>2021-05-12T11:47:19Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Authentication on Check Point 1570 Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118430#M16775</link>
      <description>&lt;P&gt;Unfortunately, it looks like on the SMB appliances, it's an RFE.&lt;BR /&gt;See the bottom of:&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk13740" target="_blank"&gt;&amp;nbsp;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk13740&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 22:22:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118430#M16775</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-14T22:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Authentication on Check Point 1570 Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118433#M16778</link>
      <description>&lt;P&gt;Sk phoneboy provided is actually a limitation. I never seen this problem on regular CP firewalls (5400, 6200...) for Radius auth, even with password 15-20 characters.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 22:32:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118433#M16778</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-14T22:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Authentication on Check Point 1570 Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118434#M16779</link>
      <description>&lt;P&gt;That's what the SK says: regular gateways support it, SMB ones do not.&lt;BR /&gt;No, don't know the reason for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 22:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118434#M16779</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-14T22:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Radius Authentication on Check Point 1570 Appliance</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118435#M16780</link>
      <description>&lt;P&gt;Thats what I meant, sorry, worded it wrong : )&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 22:37:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Radius-Authentication-on-Check-Point-1570-Appliance/m-p/118435#M16780</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-05-14T22:37:42Z</dc:date>
    </item>
  </channel>
</rss>

