<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: EnableBlankRadiusAuth and OTP prompt in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245944#M2239</link>
    <description>&lt;P&gt;I see. Do you know if there's a specific reason for that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 08 Apr 2025 10:06:35 GMT</pubDate>
    <dc:creator>kamilazat</dc:creator>
    <dc:date>2025-04-08T10:06:35Z</dc:date>
    <item>
      <title>EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244154#M2231</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;
&lt;P&gt;We're testing a scheme where a Windows user would only enter username and then authenticate with a mail OTP from radius server. This is the first time we're going through something like this and I'm a bit confused. So let me try to describe what we did so far and maybe you can direct me to the right direction.&lt;/P&gt;
&lt;P&gt;First I set up Multiple Login Options:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29937i961B432D1D75C9D7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;1.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And then I configure Authentication factor for RADIUS. Here I clear the checkbox "Ask user for password" so that the user would only provide his username and then is only asked for the OTP he receives via email:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29938iF02D43D8F5E7ED82/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.png" alt="2.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;2.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Now, in Endpoint Security on the user PC, user enters his username and clicks connect:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29939i7E97BE5E2C4F135F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="3.png" alt="3.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;3.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The password prompt is greyed out (as in the image above) or completely nonexistent (below):&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29940i7E7618F7EC820562/image-size/medium?v=v2&amp;amp;px=400" role="button" title="4.png" alt="4.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;4.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;At this point gateway sends the Access-Request only when anything is entered. We tried entering the OTP code received by email and random characters. In all cases the connection gets reset.&lt;/P&gt;
&lt;P data-unlink="true"&gt;I found &lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Check-Point-Mobile-Firewall-1-authentication-screen-visible/td-p/185543" target="_self"&gt;this&lt;/A&gt; post, and tried &lt;A href="https://support.checkpoint.com/results/sk/sk167118" target="_self"&gt;sk167118&lt;/A&gt; but when EnableBlankRadiusAuth is set to 1, we don't even see the "Response" prompt. When we set the RADIUS server's policy to use OTP from the mobile app, everything works fine, the problem seems to be with email. And there are no issues with the connectivity between the gateway and the RADIUS server.&lt;/P&gt;
&lt;P data-unlink="true"&gt;Edit: I should've mentioned that EnableBlankRadiusAuth is still set to 1, but probably needs to be set back to 0. I'm not sure exactly what this does, though.&lt;/P&gt;
&lt;P data-unlink="true"&gt;I'm sure there's some confusion at some point but we couldn't pinpoint where it is so far.&lt;/P&gt;
&lt;P data-unlink="true"&gt;All help and ideas will be appreciated, as always &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-unlink="true"&gt;Cheers!&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 08:45:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244154#M2231</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-03-19T08:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244155#M2232</link>
      <description>&lt;P&gt;Open SR# with CP TAC to get this resolved asap !&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 09:12:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244155#M2232</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-03-19T09:12:59Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244161#M2233</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21294"&gt;@G_W_Albrecht&lt;/a&gt; Thanks for the recommendation. That will happen anyway if I can't find any answers &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But before doing that, I still want to ask. Would you think it's the RADIUS server if everything works with mobile OTP but fails with mail OTP? Or is it possible for CP to have issues somewhere?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 10:19:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244161#M2233</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-03-19T10:19:35Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244162#M2234</link>
      <description>&lt;P&gt;I have no idea at all ! Maybe an issue with the email server...&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 10:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244162#M2234</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-03-19T10:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244216#M2235</link>
      <description>&lt;P&gt;As far as I know, the only supported way to use RADIUS for MFA is to use a single prompt (user password + OTP on the same line).&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 14:51:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/244216#M2235</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-19T14:51:02Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245768#M2236</link>
      <description>&lt;P&gt;No sense, but.... did u try to enter password into response field?&lt;/P&gt;</description>
      <pubDate>Sat, 05 Apr 2025 20:52:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245768#M2236</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-04-05T20:52:42Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245821#M2237</link>
      <description>&lt;P&gt;Yes, the problem is the challenge is being sent 'after' we enter anything in the response field.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We're already in the process with TAC. Let's see what'll come out of it.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 08:00:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245821#M2237</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-04-07T08:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245860#M2238</link>
      <description>&lt;P&gt;We don't support challenge/response with RADIUS, which is what I assume the TAC will tell you.&lt;BR /&gt;You have to enter the password followed by the OTP code in the first dialog.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Apr 2025 15:19:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245860#M2238</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-07T15:19:17Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245944#M2239</link>
      <description>&lt;P&gt;I see. Do you know if there's a specific reason for that?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 10:06:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245944#M2239</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2025-04-08T10:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: EnableBlankRadiusAuth and OTP prompt</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245966#M2240</link>
      <description>&lt;P&gt;No idea, but it’s been this way for as long as I can remember.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Apr 2025 12:47:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/EnableBlankRadiusAuth-and-OTP-prompt/m-p/245966#M2240</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-08T12:47:22Z</dc:date>
    </item>
  </channel>
</rss>

