<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2FA for ssl VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248647#M1992</link>
    <description>&lt;P&gt;Hi, hard situation. Low cost, not so beautiful, but certificate based VPN can be the solution.&lt;/P&gt;
&lt;P&gt;Page 40:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Digital User Certificates&lt;BR /&gt;Digital Certificates are the most recommended and manageable method for authentication.&lt;BR /&gt;Both parties present certificates as a means of proving their identity. Both parties verify that the&lt;BR /&gt;peer's certificate is valid (i.e. that it was signed by a known and trusted CA, and that the&lt;BR /&gt;certificate has not expired or been revoked).&lt;BR /&gt;Digital certificates are issued either by Check Point's Internal Certificate Authority or third-party&lt;BR /&gt;PKI solutions. Check Point's ICA is tightly integrated with VPN and is the easiest way to&lt;BR /&gt;configure a Remote Access VPN. The ICA can issue certificates both to Security Gateways&lt;BR /&gt;(automatically) and to remote users (generated or initiated).&lt;BR /&gt;Generate digital certificates easily in SmartConsole &amp;gt; Security Policies &amp;gt; Access Tools &amp;gt;&lt;BR /&gt;Client Certificates.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/CP_R81.20_RemoteAccessVPN_AdminGuide.pdf" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/CP_R81.20_RemoteAccessVPN_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 12 May 2025 11:38:00 GMT</pubDate>
    <dc:creator>AkosBakos</dc:creator>
    <dc:date>2025-05-12T11:38:00Z</dc:date>
    <item>
      <title>2FA for ssl VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248642#M1991</link>
      <description>&lt;P&gt;Hai&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of the client needs to enable 2FA, MFA for ssl vpn&amp;nbsp; checkpoint for 15 users .&lt;/P&gt;&lt;P&gt;Client got on premise AD and no radius server.&lt;/P&gt;&lt;P&gt;Please provide a recommended solution, and what components required for that solution, like radius server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248642#M1991</guid>
      <dc:creator>kevin100</dc:creator>
      <dc:date>2025-05-12T11:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA for ssl VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248647#M1992</link>
      <description>&lt;P&gt;Hi, hard situation. Low cost, not so beautiful, but certificate based VPN can be the solution.&lt;/P&gt;
&lt;P&gt;Page 40:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Digital User Certificates&lt;BR /&gt;Digital Certificates are the most recommended and manageable method for authentication.&lt;BR /&gt;Both parties present certificates as a means of proving their identity. Both parties verify that the&lt;BR /&gt;peer's certificate is valid (i.e. that it was signed by a known and trusted CA, and that the&lt;BR /&gt;certificate has not expired or been revoked).&lt;BR /&gt;Digital certificates are issued either by Check Point's Internal Certificate Authority or third-party&lt;BR /&gt;PKI solutions. Check Point's ICA is tightly integrated with VPN and is the easiest way to&lt;BR /&gt;configure a Remote Access VPN. The ICA can issue certificates both to Security Gateways&lt;BR /&gt;(automatically) and to remote users (generated or initiated).&lt;BR /&gt;Generate digital certificates easily in SmartConsole &amp;gt; Security Policies &amp;gt; Access Tools &amp;gt;&lt;BR /&gt;Client Certificates.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/CP_R81.20_RemoteAccessVPN_AdminGuide.pdf" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/CP_R81.20_RemoteAccessVPN_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:38:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248647#M1992</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-05-12T11:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA for ssl VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248650#M1993</link>
      <description>&lt;P&gt;Hai thanks for the reply, will Duo 2fa work with checkpoint ssl VPN&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:50:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248650#M1993</guid>
      <dc:creator>kevin100</dc:creator>
      <dc:date>2025-05-12T11:50:34Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA for ssl VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248652#M1994</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/108557"&gt;@kevin100&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought that you don't want to invest any money.&lt;/P&gt;
&lt;P&gt;If yes, the Cisco DUO is the one of the best and cheapest solution for this. I have experience with that, it works, as expected!&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:53:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248652#M1994</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-05-12T11:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA for ssl VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248653#M1995</link>
      <description>&lt;P&gt;Dear Akos&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the info, do this solution setup need a separate radius server?&lt;/P&gt;&lt;P&gt;Also hope checkpoint ssl vpn works with laptops&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 11:57:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248653#M1995</guid>
      <dc:creator>kevin100</dc:creator>
      <dc:date>2025-05-12T11:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA for ssl VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248661#M1996</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/108557"&gt;@kevin100&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A small connector tool is needed for the Cisco DUO. It must be installed locally.&lt;/P&gt;
&lt;P&gt;SSL VPN ha browsed dependencies. It should work with laptop, of course,&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 12:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248661#M1996</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-05-12T12:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA for ssl VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248663#M1997</link>
      <description>&lt;P&gt;Yea, DUO works 100%. I know few customers who use it without any issues.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 12 May 2025 13:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-for-ssl-VPN/m-p/248663#M1997</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-05-12T13:07:37Z</dc:date>
    </item>
  </channel>
</rss>

