<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Technology Partner News: Okta MFA for Check Point in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26849#M13199</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What problems are you running into? Anything unique about your configuration? thanks, bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 29 Jan 2019 21:02:21 GMT</pubDate>
    <dc:creator>DeletedUser</dc:creator>
    <dc:date>2019-01-29T21:02:21Z</dc:date>
    <item>
      <title>Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26845#M13195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="text-align: center;"&gt;&lt;A href="https://www.okta.com/integrations/MFA-for-VPN/checkpoint/"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70267_Okta-270x100px.png" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Happy to say that Okta has an &lt;A href="https://www.okta.com/integrations/MFA-for-VPN/checkpoint/"&gt;Okta-certified RADIUS app&lt;/A&gt; and posted&amp;nbsp;the integration guide with&amp;nbsp;Check Point on their website. A RADIUS integration is perhaps a small thing, but one thing notable about the integration is this authentication setting: Accept password and security token in the same login request. When MFA is required in the Okta policy and this is enabled, then a user must add a comma to the end of their password, followed by their second factor keyword (such as&amp;nbsp;a One-Time-Password from their Okta Verify app).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-2 j-img-centered j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70268_pastedImage_3.png" style="display: block; margin-left: auto; margin-right: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is helpful in some Check Point cases&amp;nbsp;where we don't support RADIUS access-challenge requests following the initial access-request to the RADIUS server. When there is an access-challenge, then our software needs to&amp;nbsp;handle this in an interactive exchange with the user like in this example from our Remote Access VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 j-img-centered jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70269_pastedImage_8.png" style="display: block; margin-left: auto; margin-right: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not all of our&amp;nbsp;clients support this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE class="j-table jiveBorder" style="border: 1px solid #c6c6c6;" width="100%"&gt;&lt;THEAD&gt;&lt;TR style="background-color: #efefef;"&gt;&lt;TH&gt;Client&lt;/TH&gt;&lt;TH style="text-align: center;"&gt;Supports Challenge-Response&lt;/TH&gt;&lt;/TR&gt;&lt;/THEAD&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Remote Access&lt;/TD&gt;&lt;TD style="text-align: center;"&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Mobile Access&lt;/TD&gt;&lt;TD style="text-align: center;"&gt;Yes&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Captive Portal&lt;/TD&gt;&lt;TD style="text-align: center;"&gt;Yes, in R80.20&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;SmartConsole&lt;/TD&gt;&lt;TD style="text-align: center;"&gt;No&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;Gaia OS&lt;/TD&gt;&lt;TD style="text-align: center;"&gt;No&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those cases where you want MFA and our software doesn't currently support access-challenge, then this is a convenient way to do MFA via adding the second factor in the initial access-request to the RADIUS server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 19:56:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26845#M13195</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-09-13T19:56:18Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26846#M13196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Funny thing is I remember working with some folks at Okta on this some time ago.&lt;/P&gt;&lt;P&gt;Glad to see it's a formally supported/documented thing now &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 21:59:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26846#M13196</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-13T21:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26847#M13197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Somehow I knew you had a hand in this &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; Thanks Dameon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 23:18:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26847#M13197</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2018-09-13T23:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26848#M13198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Has anyone been able to get this to work? I'm struggling with it.&amp;nbsp; Any help would be greatly appreciated.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2019 18:45:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26848#M13198</guid>
      <dc:creator>Christopher_Ric</dc:creator>
      <dc:date>2019-01-29T18:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26849#M13199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What problems are you running into? Anything unique about your configuration? thanks, bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2019 21:02:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26849#M13199</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-01-29T21:02:21Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26850#M13200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just get unknown user in the CP logs with any credentials that I input. No&lt;/P&gt;&lt;P&gt;logs are generated on the Okta side unless I use an invalid user that is&lt;/P&gt;&lt;P&gt;not in Okta. Nothing unique as far as configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2019 21:06:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26850#M13200</guid>
      <dc:creator>Christopher_Ric</dc:creator>
      <dc:date>2019-01-29T21:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26851#M13201</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you see the access-request in a tcpdump from CHKP to the Okta RADIUS agent? What CHKP client are you trying to login with?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2019 21:27:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26851#M13201</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-01-29T21:27:35Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26852#M13202</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting discovery with the tcpdump. If I use a user account that is&lt;/P&gt;&lt;P&gt;local to the check point user database I see the radius request and of&lt;/P&gt;&lt;P&gt;course that fails because its not in Okta. However if I use an Okta&lt;/P&gt;&lt;P&gt;username, I see an ldap request and no radius...Using Version VPN E80.82&lt;/P&gt;&lt;P&gt;endpoint client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2019 21:47:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26852#M13202</guid>
      <dc:creator>Christopher_Ric</dc:creator>
      <dc:date>2019-01-29T21:47:00Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26853#M13203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That helps, so something in the CHKP configuration that needs to be tweaked. To be sure the CHKP-Okta piece works, you can always set RADIUS as the auth method&amp;nbsp;in the user object where the user also exists in Okta. Not scalable, but some times nice to see something works &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To simplify things&amp;nbsp;you may want to ignore&amp;nbsp;RADIUS user group part&amp;nbsp;of the Okta docs and check your External User Profile settings.&lt;/P&gt;&lt;P&gt;.............&lt;/P&gt;&lt;P&gt;6. Navigate to SECURITY POLICIES and select Access Control. This displays Access Tools VPN Communities. Click on VPN Communities. Double click to open the RemoteAccess community and add the gateway object.&lt;/P&gt;&lt;P&gt;7. Click Participant User Groups and accept the default All Users.&lt;BR /&gt;8. Click OK to save the settings.&lt;BR /&gt;9. The option to create an External User Profile (generic*) is only available using the legacy SmartConsole Client. To launch legacy SmartDashboard go under "Manage &amp;amp; Settings" and select the "Configure in SmartDashboard" for the Mobile Access option&lt;/P&gt;&lt;P&gt;10. In the lower left corner click on the Users object. Right click on External User profile and select New External User profile -&amp;gt; Match all users.&lt;/P&gt;&lt;P&gt;11. Click Authentication and select RADIIUS as the authentication scheme. Select the RADIUS server configured above, for example MyRADIUS.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jan 2019 22:26:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26853#M13203</guid>
      <dc:creator>DeletedUser</dc:creator>
      <dc:date>2019-01-29T22:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26854#M13204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;9-11 has got me further...I'm seeing it hit Okta now, but for some reason&lt;/P&gt;&lt;P&gt;still fails. Checkpoint states radius servers not responding and okta&lt;/P&gt;&lt;P&gt;states authentication of user via radius: login failed. Not much detail.&lt;/P&gt;&lt;P&gt;Maybe I'll open a case with them and see what they have to say as well.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2019 12:21:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26854#M13204</guid>
      <dc:creator>Christopher_Ric</dc:creator>
      <dc:date>2019-01-30T12:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26855#M13205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Finally got it working. For the heck of it I decided to try changing the&lt;/P&gt;&lt;P&gt;radius secret and then it worked...Not sure if they have limitations on&lt;/P&gt;&lt;P&gt;characters or what, but I made it simpler. Thanks for your assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jan 2019 12:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/26855#M13205</guid>
      <dc:creator>Christopher_Ric</dc:creator>
      <dc:date>2019-01-30T12:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/98329#M13206</link>
      <description>&lt;P&gt;What about SandBlast Agent as the client? Do we support Okta/MFA for our Endpoint Security solution?&lt;/P&gt;
&lt;P&gt;In summary, I'm trying to understand if our FDE blade would support&amp;nbsp;preboot MFA without requesting the user for their credentials again for OS authentication. It doesn’t need to be Okta if we have any other MFA support for this purpose.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas will be much appreciated!&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Oct 2020 18:43:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/98329#M13206</guid>
      <dc:creator>KatiaCruz</dc:creator>
      <dc:date>2020-10-06T18:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Technology Partner News: Okta MFA for Check Point</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/197765#M13207</link>
      <description>&lt;P&gt;Do you remember what set of instructions you used for this. I am using the instructions from OKTA and it is just not working. Not getting a prompt for MFA on my vpn client&lt;/P&gt;</description>
      <pubDate>Sun, 12 Nov 2023 21:19:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Technology-Partner-News-Okta-MFA-for-Check-Point/m-p/197765#M13207</guid>
      <dc:creator>seanmc12</dc:creator>
      <dc:date>2023-11-12T21:19:11Z</dc:date>
    </item>
  </channel>
</rss>

