<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Remote access multiple authentication in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/161428#M6087</link>
    <description>&lt;P&gt;I cannot define different authentication method based on your advise.&lt;/P&gt;&lt;P&gt;the problem is you can specify the LDAP Account unit and not the user group.&lt;/P&gt;&lt;P&gt;in addition the ldap account unit must unique for the same domain, otherwise you will have warning about multiple account unit refers to the same domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 07 Nov 2022 12:24:22 GMT</pubDate>
    <dc:creator>ggiordano</dc:creator>
    <dc:date>2022-11-07T12:24:22Z</dc:date>
    <item>
      <title>VPN Remote access multiple authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/160430#M6084</link>
      <description>&lt;P&gt;Hi mates&lt;/P&gt;&lt;P&gt;in some customers I have multiple authentication for the remote access vpn connection (client &amp;amp; mobile access unified).&lt;/P&gt;&lt;P&gt;normally the authentication is based on external LDAP servers and they need for discriminating internal users (SAML MFA) from external users (username/password + OTP).&lt;/P&gt;&lt;P&gt;The remote users have the decision which authentication method choose and it means the users could another authentication method and authenticate successfully&lt;/P&gt;&lt;P&gt;let me go in an example&lt;/P&gt;&lt;P&gt;users1 needs to connect to VPN (client or Mobile access)&lt;/P&gt;&lt;P&gt;users1 is internal user so he knows the authentication method must be the one defined for internal users (SAML MFA)&lt;/P&gt;&lt;P&gt;users1 is able to authenticate by the authentication method for external users as well.&lt;/P&gt;&lt;P&gt;I'd like to enforce some check where if internal user is trying to use the authentication method for external users, the authentication fails because the internal user is not entitle for that authentication method.&lt;/P&gt;&lt;P&gt;in other words, I'd like to assign the authentication method per LDAP users or LDAP user groups&lt;/P&gt;&lt;P&gt;do anyone know if it's possible?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 09:20:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/160430#M6084</guid>
      <dc:creator>ggiordano</dc:creator>
      <dc:date>2022-10-26T09:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access multiple authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/160494#M6085</link>
      <description>&lt;P&gt;Have you defined a single LDAP branch or do you have multiple LDAP branches defined on the Check Point side (one for internal users and one for external third parties)?&lt;BR /&gt;Because that will be required to set a different authentication scheme for different groups in AD.&lt;BR /&gt;This is configured in the gateway object under VPN Clients &amp;gt; Authentication &amp;gt; Multiple Authentication Client Settings.&lt;BR /&gt;In each setting, you specify the LDAP Branch the authentication type applies to.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18230iD2DF4438C33D83CD/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 18:43:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/160494#M6085</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-26T18:43:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access multiple authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/160500#M6086</link>
      <description>&lt;P&gt;I read what phoneboy responded and it makes total sense to me. Im not sure if there is a different way to achieve what you are looking for.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Oct 2022 20:42:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/160500#M6086</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-10-26T20:42:37Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote access multiple authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/161428#M6087</link>
      <description>&lt;P&gt;I cannot define different authentication method based on your advise.&lt;/P&gt;&lt;P&gt;the problem is you can specify the LDAP Account unit and not the user group.&lt;/P&gt;&lt;P&gt;in addition the ldap account unit must unique for the same domain, otherwise you will have warning about multiple account unit refers to the same domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Nov 2022 12:24:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-access-multiple-authentication/m-p/161428#M6087</guid>
      <dc:creator>ggiordano</dc:creator>
      <dc:date>2022-11-07T12:24:22Z</dc:date>
    </item>
  </channel>
</rss>

