<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote access MFA only work for users part of the Radius server domain in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/166883#M5758</link>
    <description>&lt;P&gt;Thanks Chris,&lt;/P&gt;&lt;P&gt;I tried to apply&amp;nbsp;&lt;SPAN&gt;sk122477 with no succes, I think I need to specify the user's domain on the vpn client and for now i'm not able to do it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have contacted my local support and will update this post when I get more information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jan 2023 08:29:47 GMT</pubDate>
    <dc:creator>Khay</dc:creator>
    <dc:date>2023-01-06T08:29:47Z</dc:date>
    <item>
      <title>Remote access MFA only work for users part of the Radius server domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/166584#M5756</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a NPS server with plugin for Azure AD MFA, this server is part of domain fr.xxx.lan&lt;/P&gt;&lt;P&gt;when a user part of fr.xxx.lan domain use the vpn client to connect, it work as exprected.&lt;/P&gt;&lt;P&gt;when another user (test-be) part of be.xxx.lan try to connect it fail the (user unknow)&lt;/P&gt;&lt;P&gt;If i check the NPS log I can see the&amp;nbsp;SAM-Account-Name and&amp;nbsp;Fully-Qualifed-User-Name with FR\test-be&lt;/P&gt;&lt;P&gt;I understand that the vpn client didnt send the domain information and the radius "fill the blank" with is own domain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually I can't authenticate (standard or radius authentication) with &lt;A href="mailto:username@domain" target="_blank"&gt;username@domain&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Is there a way to do so ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the way to solve my issue ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thansk for you help&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 14:06:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/166584#M5756</guid>
      <dc:creator>Khay</dc:creator>
      <dc:date>2023-01-03T14:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access MFA only work for users part of the Radius server domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/166593#M5757</link>
      <description>&lt;P&gt;Two suggestions to investigate further in consultation with TAC where required.&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;&lt;SPAN&gt;sk122477&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2. R81.10 JHF T79:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;PRJ-38144,&lt;/SPAN&gt;&lt;SPAN&gt;PRHF-22814&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Security Gateway&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;UPDATE: Added support for RADIUS UPN authentication with MS-CHAPv2. To use it, enable the registry configuration in ckp_regedit -a SOFTWARE/Checkpoint/VPN1 RADIUS_MSCHAPV2_UPN -n 1.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jan 2023 15:23:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/166593#M5757</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-01-03T15:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access MFA only work for users part of the Radius server domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/166883#M5758</link>
      <description>&lt;P&gt;Thanks Chris,&lt;/P&gt;&lt;P&gt;I tried to apply&amp;nbsp;&lt;SPAN&gt;sk122477 with no succes, I think I need to specify the user's domain on the vpn client and for now i'm not able to do it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have contacted my local support and will update this post when I get more information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 08:29:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/166883#M5758</guid>
      <dc:creator>Khay</dc:creator>
      <dc:date>2023-01-06T08:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access MFA only work for users part of the Radius server domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/167138#M5759</link>
      <description>&lt;P&gt;You can check a few other areas, depending on your configuration:&lt;/P&gt;
&lt;P&gt;1. Check your LDAP AU object to see what is the "domain name" in the configuration. &amp;nbsp;This is used to verify usernames in the directory.&lt;/P&gt;
&lt;P&gt;2. If you are using the newer Multiple Login Options on your gateway, check gateway properties -&amp;gt; VPN Clients -&amp;gt; Authentication and edit the login option being used. &amp;nbsp;In the User Directory section on the left, check what LDAP AU is being used as well as the user lookup value (sAMAccountName, userPrincipleName, etc.).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a customer with NPS and Azure AD/MFA plugin. &amp;nbsp;They have to use the UPN to login (&lt;A href="mailto:user@be.xxx.lan" target="_blank"&gt;test-be@be.xxx.lan&lt;/A&gt; in your example) and I also enabled UPN as the lookup method (as I noted in #2 above). &amp;nbsp;However, this depends on the LDAP AU domain name, too. &amp;nbsp;With Azure AD/MFA plugin, *ALL* requests are immediately forwarded to Azure AD from the NPS server (this is an Azure AD plugin requirement, which I learned the hard way). &amp;nbsp;From the implementation I helped configure, this required the UPN name and is dependent on the Azure AD directory.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can see further RADIUS lookup details with a vpn debug. &amp;nbsp;I would suggest you do this, too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 14:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/167138#M5759</guid>
      <dc:creator>Duane_Toler</dc:creator>
      <dc:date>2023-01-09T14:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access MFA only work for users part of the Radius server domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/167391#M5760</link>
      <description>&lt;P&gt;Thanks Duane,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you were right its working when I set the UPN setting and use it to login&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jan 2023 07:50:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-MFA-only-work-for-users-part-of-the-Radius-server/m-p/167391#M5760</guid>
      <dc:creator>Khay</dc:creator>
      <dc:date>2023-01-11T07:50:52Z</dc:date>
    </item>
  </channel>
</rss>

