<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/122264#M22656</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can you please advise which R80.40 HF supports longer than 8 character "Internal Password"? I've made a recent R80.40 deployment and that limitation is still present. Same for the R80.40 demo version.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 26 Jun 2021 15:21:57 GMT</pubDate>
    <dc:creator>Herold</dc:creator>
    <dc:date>2021-06-26T15:21:57Z</dc:date>
    <item>
      <title>Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30099#M6132</link>
      <description>&lt;P&gt;Often in smaller setups where a central authentication server is not used, organizations may wish to use "Check Point Passwords" to authenticate users (also called Internal Password or FireWall-1 Password).&lt;BR /&gt;These passwords are &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114536" target="_self"&gt;limited to 8 characters or less&lt;/A&gt;&amp;nbsp;prior to R81.&lt;BR /&gt;This is by design as it's best practice to use a centrally managed authentication source (like RADIUS/TACACS+ or even AD) and "Internal Password" is more meant for demos/testing.&lt;BR /&gt;However, some organizations do not want to maintain a central authentication server.&lt;/P&gt;
&lt;P&gt;However, there is a little known feature that you can use to support longer, stronger passwords without resorting to a centrally managed authentication server.&lt;BR /&gt;&lt;SPAN style="font-family: inherit;"&gt;That is to define users using "OS Password" authentication.&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: inherit;"&gt;What that tells the gateway is to authenticate to the underlying OS (in this case Gaia), which supports longer, stronger passwords.&lt;BR /&gt;&lt;/SPAN&gt;See screenshot below:&lt;/P&gt;
&lt;P&gt;&lt;IMG style="width: auto; height: auto;" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63121_pastedImage_1.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Obviously, you don't want to give typical users access to the WebUI of Gaia to review or change the configuration.&lt;BR /&gt;This is where Gaia's robust Role-Based Access comes in.&lt;BR /&gt;You should create a role that only allows them to do one thing: change their user account password.&lt;BR /&gt;Which is actually an enhancement compared to Check Point Passwords &lt;IMG class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" border="0" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: inherit;"&gt;Assign that new role to users as you create them.&lt;BR /&gt;&lt;/SPAN&gt;Screenshot of what the role looks like in the Gaia WebUI below:&lt;/P&gt;
&lt;P&gt;&lt;IMG style="width: 620px; height: 319px;" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63122_pastedImage_2.png" border="0" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The main caveat to this approach is each (physical) gateway will need to have the user defined in Gaia.&lt;BR /&gt;This means in a cluster, both members will need to have the user defined (unless you're using Cloning Groups).&lt;BR /&gt;This also means, if you have multiple gateways/clusters, end users will need to change their passwords on each gateway/cluster.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;NOTE&lt;/STRONG&gt;: I've only done perfunctory testing of this, and it may have some other caveats that I haven't outlined here.&lt;BR /&gt;I recommend thoroughly testing this before you deploy in production.&lt;BR /&gt;Feedback is welcome.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Edit&lt;/STRONG&gt;: Added note about R81 supporting longer passwords (and removed the fact R80.40 may have supported this).&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 16:33:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30099#M6132</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-26T16:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30100#M6133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great tip Dameon!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 16 Feb 2018 13:51:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30100#M6133</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2018-02-16T13:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30101#M6134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That’s a good improvement.&lt;/P&gt;&lt;P&gt;if you also rely on cloning groups you may have users&amp;nbsp;synced between cluster members which helps to maintain them.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 20 Feb 2018 22:33:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30101#M6134</guid>
      <dc:creator>Pedro_Boavida</dc:creator>
      <dc:date>2018-02-20T22:33:42Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30102#M6135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very true, thus the comment I made above about Cluster Sync.&lt;/P&gt;&lt;P&gt;I guess I meant cloning groups...will fix &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Feb 2018 00:12:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/30102#M6135</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-21T00:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/68630#M14004</link>
      <description>Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;, does this work with Remote IPSEC VPN User on multifactor authentication, OS password plus Raduis (vasco token)? Thanks</description>
      <pubDate>Wed, 27 Nov 2019 11:20:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/68630#M14004</guid>
      <dc:creator>dale_shang</dc:creator>
      <dc:date>2019-11-27T11:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/68706#M14012</link>
      <description>Haven’t tried it personally.</description>
      <pubDate>Wed, 27 Nov 2019 17:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/68706#M14012</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-27T17:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/68735#M14017</link>
      <description>&lt;P&gt;Any suggestion / recommendation on how to achieve 2FA, we have Vasco Token. Challenge/goal that the 1st factor should give Remote Users the option to change 1st password by themselves. Thank you again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Dale&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2019 04:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/68735#M14017</guid>
      <dc:creator>dale_shang</dc:creator>
      <dc:date>2019-11-28T04:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/97822#M19167</link>
      <description>&lt;P&gt;Looks like R80.40 (possibly with JHF) supports longer than 8 character "Internal Password" passwords.&lt;BR /&gt;Updated the original post to reflect this.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:20:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/97822#M19167</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-09-29T15:20:06Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/122264#M22656</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Can you please advise which R80.40 HF supports longer than 8 character "Internal Password"? I've made a recent R80.40 deployment and that limitation is still present. Same for the R80.40 demo version.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 15:21:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/122264#M22656</guid>
      <dc:creator>Herold</dc:creator>
      <dc:date>2021-06-26T15:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: Supporting more Complex Passwords without using a RADIUS/TACACS+ Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/122269#M22657</link>
      <description>&lt;P&gt;Turns out I was incorrect above.&lt;BR /&gt;The limitation is actually lifted in R81:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114536&amp;amp;partition=Advanced&amp;amp;product=SmartConsole" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114536&amp;amp;partition=Advanced&amp;amp;product=SmartConsole&lt;/A&gt;&lt;BR /&gt;Will edit my post above.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 16:29:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a-RADIUS-TACACS/m-p/122269#M22657</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-26T16:29:40Z</dc:date>
    </item>
  </channel>
</rss>

