<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MFA for some VPN users in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141310#M7221</link>
    <description>&lt;P&gt;Correct, Im pretty sure you cannot do that, unless you use one generic auth method, in which case users wont have a choice. There might be some way of doing this by modifying trac.defaults file, but I would confirm with TAC, to be certain.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Sat, 12 Feb 2022 12:32:32 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-02-12T12:32:32Z</dc:date>
    <item>
      <title>MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141272#M7213</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We've enabled MFA with SMS provider in the Remote Access VPN of one of our end customers. Everything is working fine, but our customer wants to know if it is possible to disable the MFA for a particular User or a particular Group of Users.&lt;/P&gt;&lt;P&gt;Our users are internal on the Check Point Gateways, so we don't have an Active Directory server to validate the users credentials. We have the MFA configured with Username and Password + SMS Provider for all the internal users. We would like to have a particular user (Failsafe user, if the SMS Provider fails) without MFA. Is it possible?&lt;/P&gt;&lt;P&gt;Thanks in advance for your help.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 14:21:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141272#M7213</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2022-02-11T14:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141281#M7214</link>
      <description>&lt;P&gt;If you are not using AD to validate users and they are all local, sounds like the only way to do this would be to modify the individual user by modifying auth method once you edit the user in dashboard.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 16:26:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141281#M7214</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-11T16:26:57Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141282#M7215</link>
      <description>&lt;P&gt;Hi the_rock,&lt;/P&gt;&lt;P&gt;But how can I differentiate the users that will require MFA on the VPN from users that will not need that with the auth method?&lt;/P&gt;&lt;P&gt;I'm not following when you say that I can achieve this with auth method.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 16:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141282#M7215</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2022-02-11T16:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141286#M7216</link>
      <description>&lt;P&gt;No problem, Im simply referring to below when you edit the user in smart console.&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_b3865968f6a0fcthe_rock_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_b3865968f6a0fcthe_rock_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15367i0ED9F7D01EB66562/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 16:57:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141286#M7216</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-11T16:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141288#M7217</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I know the place of the configuration on the Smart Console.&lt;/P&gt;&lt;P&gt;But I think that will still not help me to achieve what the end customer wants. So, let says that we have User_A and User_B, both of them local within the Gateways and with priviledges to login on the Remote Access VPN. Then, I want that the User_A only can connect on the VPN with his credentials (Username and Password) on the Authentication Profile with MFA, but not on the Authentication Profile without MFA. Also, I want that the User_B can connect in both of the Authentication Profiles with or without MFA.&lt;/P&gt;&lt;P&gt;I hope I explained better what we need. And sorry If I was not clear on the first place.&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 17:18:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141288#M7217</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2022-02-11T17:18:27Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141289#M7218</link>
      <description>&lt;P&gt;Message me privately, lets do remote session.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 17:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141289#M7218</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-11T17:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141292#M7219</link>
      <description>&lt;P&gt;If you are referring to below setting, that has to be changed manually, UNLESS you use just one generic auth method on gateway&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15368iCD4B6BB0900990E2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Fri, 11 Feb 2022 18:01:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141292#M7219</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-11T18:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141305#M7220</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That is exactly what I'm talking about. So, at the end of the day, the end users will always have the possibility to change that option, because we've two possible options for the authentication (Username/Password only, Username/Password + SMS).&lt;/P&gt;&lt;P&gt;As far as I known, I cannot disable that option in the VPN client of the end users. Also, I cannot avoid centrally that a end user successfully login in both authentication schemes.&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 12 Feb 2022 09:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141305#M7220</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2022-02-12T09:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: MFA for some VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141310#M7221</link>
      <description>&lt;P&gt;Correct, Im pretty sure you cannot do that, unless you use one generic auth method, in which case users wont have a choice. There might be some way of doing this by modifying trac.defaults file, but I would confirm with TAC, to be certain.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 12 Feb 2022 12:32:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-for-some-VPN-users/m-p/141310#M7221</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-12T12:32:32Z</dc:date>
    </item>
  </channel>
</rss>

