<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Configure Email-Based 2FA for Remote Access VPN Using Office 365 on Check Point Firewall in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257520#M10820</link>
    <description>&lt;P&gt;I'd have a look in&amp;nbsp;$CVPNDIR/log/cvpnd.elg to see if anything interesting is logged there.&lt;BR /&gt;Otherwise, I suggest TAC.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Sep 2025 17:03:33 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-09-17T17:03:33Z</dc:date>
    <item>
      <title>How to Configure Email-Based 2FA for Remote Access VPN Using Office 365 on Check Point Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257437#M10813</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;We are currently using a Check Point firewall for Remote Access VPN, and we would like to implement two-factor authentication (2FA) for our VPN users. We are using R82 and last jumbo has installed on it.&lt;/P&gt;&lt;P&gt;Instead of using SMS-based 2FA, we would prefer to use email-based verification. Since our organization uses Office 365 for email, we would like to send the 2FA codes to users via their Office 365 email addresses.&lt;/P&gt;&lt;P&gt;Has anyone implemented email-based 2FA for Remote Access VPN on Check Point before? Is this supported natively, or would we need a third-party integration or RADIUS solution? Any documentation, guides, or suggestions would be highly appreciated.&lt;/P&gt;&lt;P&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 06:53:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257437#M10813</guid>
      <dc:creator>Madmaks</dc:creator>
      <dc:date>2025-09-17T06:53:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Email-Based 2FA for Remote Access VPN Using Office 365 on Check Point Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257481#M10817</link>
      <description>&lt;P&gt;What authentication type are you using currently to authenticate the remote users?&lt;BR /&gt;You can send a second factor via email using DynamicID:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/DynamicID.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/DynamicID.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If you're using a SAML-based provider (Azure AD), the other factors should be implemented there.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 13:52:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257481#M10817</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-17T13:52:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Email-Based 2FA for Remote Access VPN Using Office 365 on Check Point Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257492#M10818</link>
      <description>&lt;P&gt;Currently, we are only using username and password for authentication via LDAP (Active Directory). In addition to this, we would like to implement 2FA by sending a code via email.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 14:15:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257492#M10818</guid>
      <dc:creator>Madmaks</dc:creator>
      <dc:date>2025-09-17T14:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Email-Based 2FA for Remote Access VPN Using Office 365 on Check Point Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257505#M10819</link>
      <description>&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; Summary of What I've Done:&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Created a local user&lt;/STRONG&gt; on the Check Point firewall.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Enabled &lt;STRONG&gt;Multi-Factor Authentication (MFA)&lt;/STRONG&gt; for that local user.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;On &lt;STRONG&gt;Office 365&lt;/STRONG&gt;, I generated an &lt;STRONG&gt;App Password&lt;/STRONG&gt; using the account vpn-mailer@yourdomain.com, as MFA is enabled for that account.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;I configured the &lt;STRONG&gt;Check Point email notification settings&lt;/STRONG&gt; using the following format:&lt;/P&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;mail:TO=&lt;SPAN class=""&gt;$EMAIL&lt;/SPAN&gt;;SSL_REQUIRED;SMTPSERVER=smtp://vpn-mailer@yourdomain.com:app_password_here@smtp.office365.com:587;FROM=sslvpn@yourdomain.com;BODY=&lt;SPAN class=""&gt;$RAWMESSAGE&lt;/SPAN&gt; &lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;I replaced app_password_here with the actual App Password generated from Microsoft 365.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The TO address is the email associated with the local user.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;I completed the configuration on the Check Point firewall side successfully.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;On the &lt;STRONG&gt;client side&lt;/STRONG&gt;, I'm using &lt;STRONG&gt;Check Point Endpoint Security&lt;/STRONG&gt; to connect via &lt;STRONG&gt;Remote Access VPN&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;During connection:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The &lt;STRONG&gt;username and password authentication works correctly&lt;/STRONG&gt; (using the local user).&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;After that, the &lt;STRONG&gt;endpoint client asks for the MFA response code&lt;/STRONG&gt; (OTP), which should be emailed to the user.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;HR /&gt;&lt;H3&gt;&lt;span class="lia-unicode-emoji" title=":cross_mark:"&gt;❌&lt;/span&gt; Problem:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The &lt;STRONG&gt;email containing the OTP code is never delivered&lt;/STRONG&gt; to the user's email inbox.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;No error is shown on the client; it just waits for the OTP.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The Check Point firewall is &lt;STRONG&gt;configured to send the OTP via Office 365 SMTP&lt;/STRONG&gt;, but it appears the email is either not being sent or not being delivered.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;In this case, which logs should I check on the Check Point side, what exactly should I look into, and how can I troubleshoot this issue?&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 15:28:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257505#M10819</guid>
      <dc:creator>Madmaks</dc:creator>
      <dc:date>2025-09-17T15:28:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Email-Based 2FA for Remote Access VPN Using Office 365 on Check Point Firewall</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257520#M10820</link>
      <description>&lt;P&gt;I'd have a look in&amp;nbsp;$CVPNDIR/log/cvpnd.elg to see if anything interesting is logged there.&lt;BR /&gt;Otherwise, I suggest TAC.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Sep 2025 17:03:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-Configure-Email-Based-2FA-for-Remote-Access-VPN-Using/m-p/257520#M10820</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-17T17:03:33Z</dc:date>
    </item>
  </channel>
</rss>

