<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN defined on user record not enforced in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-defined-on-user-record-not-enforced/m-p/274985#M14438</link>
    <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;We have this settings on our FW R81.20 for VPN-Clients:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 706px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33951iD0A312584D0E09EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then i have this user, which needs Radius but also has a certificate:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 525px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33952i83240624CC7A4D33/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Radius (duo proxy) is used for MFA only.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 496px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33953iCCEA876392522DF2/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now when i connect with a VPN-Client and use the certificate the connection is working - i would expect to be asked for the 2nd factor via radius.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am i getting something wrong?&lt;/P&gt;</description>
    <pubDate>Tue, 07 Apr 2026 11:25:11 GMT</pubDate>
    <dc:creator>stefan_o</dc:creator>
    <dc:date>2026-04-07T11:25:11Z</dc:date>
    <item>
      <title>VPN defined on user record not enforced</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-defined-on-user-record-not-enforced/m-p/274985#M14438</link>
      <description>&lt;P&gt;Hi all!&lt;/P&gt;&lt;P&gt;We have this settings on our FW R81.20 for VPN-Clients:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 706px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33951iD0A312584D0E09EC/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then i have this user, which needs Radius but also has a certificate:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 525px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33952i83240624CC7A4D33/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Radius (duo proxy) is used for MFA only.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 496px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33953iCCEA876392522DF2/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now when i connect with a VPN-Client and use the certificate the connection is working - i would expect to be asked for the 2nd factor via radius.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am i getting something wrong?&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 11:25:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-defined-on-user-record-not-enforced/m-p/274985#M14438</guid>
      <dc:creator>stefan_o</dc:creator>
      <dc:date>2026-04-07T11:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN defined on user record not enforced</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-defined-on-user-record-not-enforced/m-p/274998#M14441</link>
      <description>&lt;P&gt;I'm fairly certain that if you're using "defined on user record" only one authentication method is supported.&lt;BR /&gt;You need to set up the Multiple Login Options to specify both Certificate and RADIUS are required.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 14:54:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-defined-on-user-record-not-enforced/m-p/274998#M14441</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-07T14:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: VPN defined on user record not enforced</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-defined-on-user-record-not-enforced/m-p/274999#M14442</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;
&lt;P&gt;I agree with&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;if you want to use DUO MFA with Radius, you should create a specific authentication method in Multiple login option and follow this link to confnigure authenticatio:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/SASE-and-Remote-Access/Configuring-Checkpoint-Remote-VPN-for-MFA/td-p/197812" target="_blank"&gt;https://community.checkpoint.com/t5/SASE-and-Remote-Access/Configuring-Checkpoint-Remote-VPN-for-MFA/td-p/197812&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I always configured VPN with MFA (DUO and Radius) following the above link.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2026 14:59:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-defined-on-user-record-not-enforced/m-p/274999#M14442</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-04-07T14:59:22Z</dc:date>
    </item>
  </channel>
</rss>

