<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using one external user profile for two different MFA connections in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/185149#M4776</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I tried what you said and managed to get this working on R81.20. Here are the steps if any one else wants to try it:&lt;/P&gt;&lt;P&gt;1) In Smart Dashboard, changed the external generic* profile authentication method from SecurID to Undefined&lt;/P&gt;&lt;P&gt;2) Then I created two authentication schemes for the VPN clients; one for SecurID and the second for Azure Identity Provider&lt;/P&gt;&lt;P&gt;3) The user can manually select the authentication in the Endpoint client and connect successfully to the chosen method&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 29 Jun 2023 09:06:31 GMT</pubDate>
    <dc:creator>tmnetsec</dc:creator>
    <dc:date>2023-06-29T09:06:31Z</dc:date>
    <item>
      <title>Using one external user profile for two different MFA connections</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/184656#M4774</link>
      <description>&lt;P&gt;Currently we have a MFA solution deployed using SecurID and this uses the external generic* authentication profile which has the SecurID option selected.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am now doing a PoC for Checkpoint VPN clients using SAML and Azure MFA as per &lt;A href="https://downloads.checkpoint.com/fileserver/SOURCE/direct/ID/125833/FILE/CP_R81.20_RemoteAccessVPN_AdminGuide.pdf" target="_blank"&gt;Remote Access VPN R81.20 Administration Guide (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The guide says that the SAML Identity Provider needs an external generic* authentication profile as well.&amp;nbsp;Can I change the authentication scheme in the existing generic* profile to Undefined that will allow the users to connect either using SecurID or Identity Provider?&amp;nbsp; Current options in the drop down in the authentication tab are undefined/SecurID/Identity Provider/RADIUS/etc. Using the multiple authentication options for the VPN client, the plan is to provide the VPN user the option to select SecurID or Azure MFA to connect to the VPN.&lt;/P&gt;&lt;P&gt;Is this possible with a single generic* external authentication profile?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2023 16:09:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/184656#M4774</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-06-23T16:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: Using one external user profile for two different MFA connections</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/184827#M4775</link>
      <description>&lt;P&gt;I'm fairly certain changing this to Undefined will break SecurID.&lt;BR /&gt;I'm not certain if SAML requires the setting in generic* to actually be "Undefined" or just that it merely exist.&lt;BR /&gt;If the latter, then it should work for both, but I'm not confident that it will work/be supported.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jun 2023 17:14:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/184827#M4775</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-26T17:14:06Z</dc:date>
    </item>
    <item>
      <title>Re: Using one external user profile for two different MFA connections</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/185149#M4776</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I tried what you said and managed to get this working on R81.20. Here are the steps if any one else wants to try it:&lt;/P&gt;&lt;P&gt;1) In Smart Dashboard, changed the external generic* profile authentication method from SecurID to Undefined&lt;/P&gt;&lt;P&gt;2) Then I created two authentication schemes for the VPN clients; one for SecurID and the second for Azure Identity Provider&lt;/P&gt;&lt;P&gt;3) The user can manually select the authentication in the Endpoint client and connect successfully to the chosen method&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 09:06:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/185149#M4776</guid>
      <dc:creator>tmnetsec</dc:creator>
      <dc:date>2023-06-29T09:06:31Z</dc:date>
    </item>
    <item>
      <title>Re: Using one external user profile for two different MFA connections</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/185167#M4777</link>
      <description>&lt;P&gt;Only caveat I see here is that you need to make sure you're not using the "legacy" (defined on user method) option.&lt;BR /&gt;Glad it works, however. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Jun 2023 13:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Using-one-external-user-profile-for-two-different-MFA/m-p/185167#M4777</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-06-29T13:39:27Z</dc:date>
    </item>
  </channel>
</rss>

