<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2FA Configuration For Remote VPN Users in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/2FA-Configuration-For-Remote-VPN-Users/m-p/258133#M10862</link>
    <description>&lt;P&gt;For email MFA, the features is called DynamicID&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/DynamicID.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/DynamicID.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User based policies require Access Roles to be defined.&lt;BR /&gt;Access Roles are required to have user-specific policies, which generally requires enabling/configuring Identity Awareness, though I believe this can be done with local users as well.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Access-Roles.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Access-Roles.htm&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You can then create rules that permit access to the various roles.&lt;/P&gt;
&lt;P&gt;There isn't an "idle" timer, but there is a reauthentication timer set in Global Properties &amp;gt; Remote Access &amp;gt; Endpoint Connect&lt;/P&gt;
&lt;P&gt;To restrict (or allow) only specific countries for Remote Access:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Sep 2025 22:10:14 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-09-24T22:10:14Z</dc:date>
    <item>
      <title>2FA Configuration For Remote VPN Users</title>
      <link>https://community.checkpoint.com/t5/Endpoint/2FA-Configuration-For-Remote-VPN-Users/m-p/258091#M10860</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Here we are using CP R81.20 GW Cluster and R81.20 CP Management (Open Server). There is a request to configure VPN users from Checkpoint with the 2FA (Email Notifications). Following tasks need to be achieved from our side.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User Base Policies (Group wise or User Wise)&lt;/LI&gt;&lt;LI&gt;User Idle timeout&lt;/LI&gt;&lt;LI&gt;Preventing Geo Locations For VPN Users (Country Wise)&lt;/LI&gt;&lt;LI&gt;2FA should be enabled (Email Notification - Already has on-prem Email Relay)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Currently we have enabled below blades.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN CLIENT CONFIGURATION - 01.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31520iA9D9610BC9890E9F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN CLIENT CONFIGURATION - 01.png" alt="VPN CLIENT CONFIGURATION - 01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN CLIENT CONFIGURATION - AUTHENTICATION.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31521i65CB2D419A841EEC/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN CLIENT CONFIGURATION - AUTHENTICATION.png" alt="VPN CLIENT CONFIGURATION - AUTHENTICATION.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN CLIENT CONFIGURATION - CLIENTLESS VPN.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31525i7B516C1ACE222F6D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN CLIENT CONFIGURATION - CLIENTLESS VPN.png" alt="VPN CLIENT CONFIGURATION - CLIENTLESS VPN.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN CLIENT CONFIGURATION - OFFICE MODE.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31523iDAD50BB44DD013AD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN CLIENT CONFIGURATION - OFFICE MODE.png" alt="VPN CLIENT CONFIGURATION - OFFICE MODE.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN CLIENT CONFIGURATION - REMOTE ACCESS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31524i88D59CDB5A03E040/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN CLIENT CONFIGURATION - REMOTE ACCESS.png" alt="VPN CLIENT CONFIGURATION - REMOTE ACCESS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VPN CLIENT CONFIGURATION - SAML PORTAL SETTINGS.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31526iEC7052DFEA6663A5/image-size/medium?v=v2&amp;amp;px=400" role="button" title="VPN CLIENT CONFIGURATION - SAML PORTAL SETTINGS.png" alt="VPN CLIENT CONFIGURATION - SAML PORTAL SETTINGS.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ENABLED BLADES.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31522iAA3510388E14D57E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ENABLED BLADES.png" alt="ENABLED BLADES.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;       &lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;LI-PRODUCT title="remote-access" id="remote-access"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;LI-PRODUCT title="Remote Access VPN" id="remote-access-vpn"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 08:18:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/2FA-Configuration-For-Remote-VPN-Users/m-p/258091#M10860</guid>
      <dc:creator>scher</dc:creator>
      <dc:date>2025-09-24T08:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA Configuration For Remote VPN Users</title>
      <link>https://community.checkpoint.com/t5/Endpoint/2FA-Configuration-For-Remote-VPN-Users/m-p/258133#M10862</link>
      <description>&lt;P&gt;For email MFA, the features is called DynamicID&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/DynamicID.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Content/Topics-MABG/DynamicID.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;User based policies require Access Roles to be defined.&lt;BR /&gt;Access Roles are required to have user-specific policies, which generally requires enabling/configuring Identity Awareness, though I believe this can be done with local users as well.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Access-Roles.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuide/Content/Topics-SECMG/Access-Roles.htm&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;You can then create rules that permit access to the various roles.&lt;/P&gt;
&lt;P&gt;There isn't an "idle" timer, but there is a reauthentication timer set in Global Properties &amp;gt; Remote Access &amp;gt; Endpoint Connect&lt;/P&gt;
&lt;P&gt;To restrict (or allow) only specific countries for Remote Access:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Block-VPN-Traffic-by-Country/m-p/172695#M31396&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 22:10:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/2FA-Configuration-For-Remote-VPN-Users/m-p/258133#M10862</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-24T22:10:14Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA Configuration For Remote VPN Users</title>
      <link>https://community.checkpoint.com/t5/Endpoint/2FA-Configuration-For-Remote-VPN-Users/m-p/258919#M10880</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/89386"&gt;@scher&lt;/a&gt;&amp;nbsp;...hopefully what Phoneboy provided worked for you.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 15:21:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/2FA-Configuration-For-Remote-VPN-Users/m-p/258919#M10880</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-03T15:21:39Z</dc:date>
    </item>
  </channel>
</rss>

