<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Two factor authentication in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62634#M11981</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so the vpn client is asking 1st for username and password, than for username and token/otp?&lt;/P&gt;&lt;P&gt;What solution do you use there? Where does that get it´s users, from AD? Do you see unsuccessful logins on the Radius Server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;is the Gateway defined as Radius Client on the server?&lt;/P&gt;&lt;P&gt;Are you able to authenticate with otp using tools like NTRadping on your local machine?&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
    <pubDate>Thu, 12 Sep 2019 14:59:05 GMT</pubDate>
    <dc:creator>Nüüül</dc:creator>
    <dc:date>2019-09-12T14:59:05Z</dc:date>
    <item>
      <title>Two factor authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62632#M11980</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need a little help. I want to apply a second authenticaiton factor to my C2S connections, actually the users connects to de VPN by Endpoint security VPN, they use their credentials from AD, now I want to set up a second factor using a RADIUS server that generates a token. Lets illustrate my scenario:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Scenario" style="width: 680px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2514i53D41DC266D739C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="azte.png" alt="Scenario" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;Scenario&lt;/span&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the thing I want and hope is, Client communicates with FW, FW asks AD server for identities, then FW asks RADIUS for token and thats it, so what I configured is this:&lt;/P&gt;&lt;P&gt;Configure a new multiple options, first username, then RADIUS&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azte2.png" style="width: 740px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2515i80DC479E2EC82A9B/image-size/large?v=v2&amp;amp;px=999" role="button" title="azte2.png" alt="azte2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;1st factor configuration&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azte3.png" style="width: 527px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2516iB4B153FA3EDC8685/image-size/large?v=v2&amp;amp;px=999" role="button" title="azte3.png" alt="azte3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;2nd factor configuration&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="azte4.png" style="width: 530px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/2518iDE49941D094A44EB/image-size/large?v=v2&amp;amp;px=999" role="button" title="azte4.png" alt="azte4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;AND! is not working, after authenticate with AD, it asks for a user, I thought it was the token but wasn't, dont know if this is the correct configuration, can you help me on how to start the troubleshooting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I read that there is some configuration that let me use pass+token, but i cant make it works, or maybe configure.&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 14:52:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62632#M11980</guid>
      <dc:creator>Oscar_David_Gom</dc:creator>
      <dc:date>2019-09-12T14:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Two factor authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62634#M11981</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so the vpn client is asking 1st for username and password, than for username and token/otp?&lt;/P&gt;&lt;P&gt;What solution do you use there? Where does that get it´s users, from AD? Do you see unsuccessful logins on the Radius Server?&amp;nbsp;&lt;/P&gt;&lt;P&gt;is the Gateway defined as Radius Client on the server?&lt;/P&gt;&lt;P&gt;Are you able to authenticate with otp using tools like NTRadping on your local machine?&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 14:59:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62634#M11981</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2019-09-12T14:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Two factor authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62637#M11982</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;so the vpn client is asking 1st for username and password, than for username and token/otp?&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Asking for user/pass, then for a user, no more.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;What solution do you use there? Where does that get it´s users, from AD? Do you see unsuccessful logins on the Radius Server?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;A solution from NetIQ. &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If you're talking about where the fw gets users, from AD, the Radius is just for generate the OTP, it should be getting users from de AD?&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cannot confirm at this moment the logins on radius server&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;is the Gateway defined as Radius Client on the server?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;AFAIK, yes.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Are you able to authenticate with otp using tools like NTRadping on your local machine?&lt;/P&gt;&lt;P&gt;&lt;EM&gt;No response.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 15:26:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62637#M11982</guid>
      <dc:creator>Oscar_David_Gom</dc:creator>
      <dc:date>2019-09-12T15:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: Two factor authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62640#M11983</link>
      <description>&lt;P&gt;Ok, when you then just enter the username again, you might get asked for the OTP, or something?&lt;/P&gt;&lt;P&gt;At NetIQ you have to configure a user store (they call it repository) to bind i.e. a token to a particular user. otherwise the solution cannot validate the token you entered. In most cases this solutions are using the Active Directory too. yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As I read, NetIQ is Linux based, you might want to check the logs mentioned here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.netiq.com/documentation/advanced-authentication-62/install-upgrade-guide/data/t45y9mnldg39.html" target="_blank"&gt;https://www.netiq.com/documentation/advanced-authentication-62/install-upgrade-guide/data/t45y9mnldg39.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;or here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.netiq.com/documentation/advanced-authentication-62/helpdesk-administrator-guide/data/monitoring_user_report.html" target="_blank"&gt;https://www.netiq.com/documentation/advanced-authentication-62/helpdesk-administrator-guide/data/monitoring_user_report.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;if you get any failed requests.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you able to check if Config on NetIQ is OK?&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.netiq.com/documentation/advanced-authentication-62/server-administrator-guide/data/t43991ne372u.html" target="_blank"&gt;https://www.netiq.com/documentation/advanced-authentication-62/server-administrator-guide/data/t43991ne372u.html&lt;/A&gt; (yes it is saying fortinet, but that should not be that important here) check point should be defined here as Radius Client. Doublecheck the Pre Shared Key/Secret. if this is incorrect, authentication fails too.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 16:22:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62640#M11983</guid>
      <dc:creator>Nüüül</dc:creator>
      <dc:date>2019-09-12T16:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Two factor authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62655#M11984</link>
      <description>&lt;P&gt;&lt;EM&gt;Ok, when you then just enter the username again, you might get asked for the OTP, or something?&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;No, it just says, wrong username or pass. From this point, what you're saying about bind a user with a token from NetIQ is a very very posible reason, let me check that.&lt;BR /&gt;&lt;BR /&gt;THANKS&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2019 18:32:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Two-factor-authentication/m-p/62655#M11984</guid>
      <dc:creator>Oscar_David_Gom</dc:creator>
      <dc:date>2019-09-12T18:32:50Z</dc:date>
    </item>
  </channel>
</rss>

