<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Approve MS smartphone delay RADIUS in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245922#M41092</link>
    <description>&lt;P&gt;Why? if you don't mind me asking.&lt;/P&gt;</description>
    <pubDate>Tue, 08 Apr 2025 06:39:15 GMT</pubDate>
    <dc:creator>RemoteUser</dc:creator>
    <dc:date>2025-04-08T06:39:15Z</dc:date>
    <item>
      <title>Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245835#M41073</link>
      <description>&lt;P&gt;hello everyone, we are experiencing a problem with ms authentication on smartphone is taking about 20 seconds to do the approve... it used to take about 5 seconds, is there something checkpoint side we can check?&lt;BR /&gt;the vpngw is running R81.20 JH53&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 10:23:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245835#M41073</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-04-07T10:23:07Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245866#M41080</link>
      <description>&lt;P&gt;What's the actual authentication flow here where this step is required?&lt;BR /&gt;Have you checked with tcpdump to see which end is causing the delay?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 15:47:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245866#M41080</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-07T15:47:53Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245870#M41081</link>
      <description>&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;The VPN client request to Radius client&amp;nbsp;&lt;BR /&gt;Radius request to Primary AUthN (active directory)&lt;BR /&gt;And then to Multi-Factor Auth reuqest&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CKP &amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;NPS &amp;gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;AAD&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;How can i capture traffic, personally i've the same issue but if i disconnect from the vpn checkpoint i lost the session&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 16:13:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245870#M41081</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-04-07T16:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245881#M41083</link>
      <description>&lt;P&gt;This would most likely have to be captured on the gateway while you (or an affected user) are connecting via a VPN client.&lt;BR /&gt;It's also not clear where the MFA is coming from...is it a different authentication method you've configured?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 17:32:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245881#M41083</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-07T17:32:16Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245889#M41084</link>
      <description>&lt;P&gt;Azure MFA and Check Point VPN. The connections it's with Azure AD and the NPS extension for Azure MFA&lt;BR /&gt;if i want to collect tcpdumps myself how can i do it? if i disconnect to replicate the problem i also lose connectivity....&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 18:21:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245889#M41084</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-04-07T18:21:07Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245891#M41085</link>
      <description>&lt;P&gt;Please provide a screenshot of this portion of the relevant gateway/cluster object so I can understand how you have this configured on the Check Point side.&lt;BR /&gt;In general, if you're doing MFA with Azure AD, you should be using SAML instead of RADIUS.&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30157iF471CE25ED9E34A4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 18:30:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245891#M41085</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-07T18:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245895#M41086</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="certificate.png" style="width: 746px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30159iD9CAA5BE0B65A59D/image-size/large?v=v2&amp;amp;px=999" role="button" title="certificate.png" alt="certificate.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 18:47:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245895#M41086</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-04-07T18:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245899#M41088</link>
      <description>&lt;P&gt;Does Identity Provider refer to Azure AD?&lt;BR /&gt;Curious why you're doing RADIUS as a separate step here.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 19:52:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245899#M41088</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-07T19:52:48Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245921#M41091</link>
      <description>&lt;P&gt;Some unsolicited advice - seeing as you're already integrated with Entra (based on Identity Provider Entry) I would look to move away from Radius auth and its dependencies and move to straight SAML auth if at all possible.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 05:51:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245921#M41091</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-04-08T05:51:21Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245922#M41092</link>
      <description>&lt;P&gt;Why? if you don't mind me asking.&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 06:39:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245922#M41092</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-04-08T06:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Approve MS smartphone delay RADIUS</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245924#M41093</link>
      <description>&lt;P&gt;Don't mind at all.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;It's "cleaner".&lt;/LI&gt;
&lt;LI&gt;From an identity security perspective, we can pull in what Microsoft brings to the table in terms of conditional access, risk-based sign ins, impossible travel etc.&lt;/LI&gt;
&lt;LI&gt;We can do number matching as opposed to just approvals&lt;/LI&gt;
&lt;LI&gt;We can now Geo-restrict logins using conditional access policies, something that has been a big pain on check Point traditionally (for me at least).&lt;/LI&gt;
&lt;LI&gt;Integration works better in terms of access roles etc., no need for legacy objects&lt;/LI&gt;
&lt;LI&gt;We have the option to force 2nd factor every auth, or re-use existing session tokens for a seamless experience&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;That's off the top of my head, sure I'll be able to put down more if I think about it.&amp;nbsp; Of course every environment and use case is different, but the above has been true for us.&lt;/P&gt;
&lt;P&gt;-Ruan&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 06:55:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Approve-MS-smartphone-delay-RADIUS/m-p/245924#M41093</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-04-08T06:55:19Z</dc:date>
    </item>
  </channel>
</rss>

