<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN client with sms MFA in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247634#M10522</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;the radius challenge/accept is sent when using MS authenticator. Why would the same process via SMS block somewhere?&lt;/P&gt;</description>
    <pubDate>Tue, 29 Apr 2025 13:03:42 GMT</pubDate>
    <dc:creator>AlainC</dc:creator>
    <dc:date>2025-04-29T13:03:42Z</dc:date>
    <item>
      <title>VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247509#M10514</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've MFA via Microsoft Authenticator setup for my VPN users. This works fine. Users get an extra window from the VPN client to insert their code and the connection is established.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I was testing the same process, but now with SMS as MFA. Strangely enough, the SMS is received on the smartphone, but an extra window from the VPN client, to insert the code from the sms, does not appear. I get wrong user or password.&lt;/P&gt;&lt;P&gt;FYI&lt;/P&gt;&lt;P&gt;I use a third party MFA solution and MS NPS.&lt;/P&gt;&lt;P&gt;My VPN client is v88.70&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea where to look (VPN client, MFA solution, NPS, Checkpoint firewall/vpn, etc...)?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 11:47:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247509#M10514</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-28T11:47:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247510#M10515</link>
      <description>&lt;P&gt;What do logs show?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 12:24:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247510#M10515</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-28T12:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247546#M10520</link>
      <description>&lt;P&gt;The 3rd party server needs to send a RADIUS Access-Challenge to the NPS server. &amp;nbsp;If your 3rd party service isn't providing that, then the VPN client will never see that from the NPS server to present the extra login prompt.&lt;/P&gt;
&lt;P&gt;With SMS (and voice/call), this usually doesn't work, as the two services are out-of-band of each other (the RADIUS server is effectively hanging while waiting on the 3rd party to respond).&lt;/P&gt;
&lt;P&gt;If you believe it should be working, then you'll need to run a VPN debug on the gateway to watch the RADIUS session between the gateway and the NPS server.&lt;/P&gt;
&lt;P&gt;For a quick debug, you can just do a "tcpdump -xXvv -nni &amp;lt;interface facing the RADIUS server&amp;gt; port 1812" and look at the RADIUS packet decode (access-accept and access-challenge is what you want to see). &amp;nbsp;If the tcpdump isn't helpful, then you'll need a VPN debug.&lt;/P&gt;
&lt;P&gt;Regardless, I wouldn't expect this work.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Apr 2025 23:18:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247546#M10520</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-04-28T23:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247633#M10521</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;just been hanging 2 hours in a call with MFA soft provider, digging through logs. All seems fine here.&lt;/P&gt;&lt;P&gt;Can you specify which logs to check and where?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 13:02:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247633#M10521</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-29T13:02:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247634#M10522</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;the radius challenge/accept is sent when using MS authenticator. Why would the same process via SMS block somewhere?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 13:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247634#M10522</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-29T13:03:42Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247635#M10523</link>
      <description>&lt;P&gt;still in the complete dark here... finding the root is a first step:&lt;/P&gt;&lt;P&gt;MFA soft (i don't think so)&lt;/P&gt;&lt;P&gt;NPS ( i don't think so)&lt;/P&gt;&lt;P&gt;SMS gateway&lt;/P&gt;&lt;P&gt;VPN&lt;/P&gt;&lt;P&gt;VPN client&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 13:05:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247635#M10523</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-29T13:05:52Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247638#M10524</link>
      <description>&lt;P&gt;I meant smart console logs...&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 13:12:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247638#M10524</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T13:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247639#M10525</link>
      <description>&lt;P&gt;Is the gateway still using NPS as the RADIUS server, or a different RADIUS server? &amp;nbsp;Check tcpdump (or cppcap) on the gateway for RADIUS connections (port 1812) to see if the RADIUS messages are being exchanged as you expect. &amp;nbsp;If they are, then you need to run a VPN debug on the gateway and look in $FWDIR/log/vpnd.elg.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 13:15:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247639#M10525</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-04-29T13:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247667#M10526</link>
      <description>&lt;P&gt;I was able to pinpoint the problem... a faulty return code received on the MFA server from our SMS gateway. Nothing to do with Checkpoint!&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reactions!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 15:46:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247667#M10526</guid>
      <dc:creator>AlainC</dc:creator>
      <dc:date>2025-04-29T15:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247669#M10527</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 15:49:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247669#M10527</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-29T15:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: VPN client with sms MFA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247673#M10528</link>
      <description>&lt;P&gt;Excellent! Good hunting!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Apr 2025 15:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/VPN-client-with-sms-MFA/m-p/247673#M10528</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2025-04-29T15:57:18Z</dc:date>
    </item>
  </channel>
</rss>

