<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 2FA with SMB 1500 (R80.20.30) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127137#M8160</link>
    <description>&lt;P&gt;Yes, it makes sense, therefore it seems sk137732 would apply.&lt;/P&gt;</description>
    <pubDate>Mon, 16 Aug 2021 20:21:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-08-16T20:21:59Z</dc:date>
    <item>
      <title>2FA with SMB 1500 (R80.20.30)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127048#M8155</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Are there any "workarounds"/solution(s) for the following scenario?&lt;BR /&gt;Appliance: SMB 1550 with R80.20.30.&lt;BR /&gt;On-premise 2FA Appliance (based on FreeRadius)&lt;BR /&gt;&lt;U&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/U&gt;&lt;BR /&gt;We've successfully integrated 2FA/Radius appliance with AD and it "pulls" through the relevant VPN users group via FilterID.&lt;BR /&gt;When we have Radius/2FA server defined as the ONLY Authentication Server, the VPN users successfully authenticate with OTP.&lt;BR /&gt;Once we add the AD server, 2FA does not work. (even if we create a dummy AD group for the 1550 to read)&lt;BR /&gt;We do, however, need the AD server for building specific rules in the Access Policy.&lt;BR /&gt;&lt;BR /&gt;Any suggestions/advice would be greatly appreciated.&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 09:34:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127048#M8155</guid>
      <dc:creator>SaxMan</dc:creator>
      <dc:date>2021-08-16T09:34:04Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA with SMB 1500 (R80.20.30)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127051#M8156</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk137732 ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 09:52:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127051#M8156</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-08-16T09:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA with SMB 1500 (R80.20.30)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127066#M8157</link>
      <description>&lt;P&gt;Thanks a million.&lt;BR /&gt;Yip.&lt;BR /&gt;Read through that doc/SK - I just thought there might be a chance of someone on the community successfully implementing it (with AD, of course)&lt;BR /&gt;The 2FA solution works with other SMB brands(with AD + Radius) so we're trying to compete with our CheckPoint POV/POCs.&lt;BR /&gt;Thank you for the prompt feedback.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 11:52:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127066#M8157</guid>
      <dc:creator>SaxMan</dc:creator>
      <dc:date>2021-08-16T11:52:52Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA with SMB 1500 (R80.20.30)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127111#M8158</link>
      <description>&lt;P&gt;But&amp;nbsp;&lt;SPAN&gt;sk137732 is for locally managed SMB and you’re talking about using Access Roles in rules.&lt;BR /&gt;Is this a centrally managed SMB?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 15:29:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127111#M8158</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-16T15:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA with SMB 1500 (R80.20.30)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127127#M8159</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;Thanks for the response.&lt;BR /&gt;&lt;BR /&gt;Locally managed 1500.&lt;BR /&gt;My original post should've read:&lt;BR /&gt;On the 1500 we want to use AD to define&amp;nbsp;&lt;STRONG&gt;rules&lt;/STRONG&gt; under &lt;STRONG&gt;Access Policy -&amp;gt; Policy&amp;nbsp;&lt;/STRONG&gt;&lt;BR /&gt;(example: Outgoing - Source: (AD Group)marketing -&amp;gt; Dest:internet -&amp;gt; Service:Facebook Business -&amp;gt; Action: accept -&amp;gt; Log)&lt;BR /&gt;&lt;BR /&gt;The Radius server will sync with AD and filter out the VPN users and do the 2FA&lt;BR /&gt;So ideally, have both AD and Radius configured under &lt;STRONG&gt;Authentication Servers&lt;BR /&gt;&lt;/STRONG&gt;(right now we have to remove AD from the Auth Servers list, and then 2FA works 100%)&lt;BR /&gt;&lt;BR /&gt;I hope this makes sense?&lt;BR /&gt;&lt;BR /&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 19:01:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127127#M8159</guid>
      <dc:creator>SaxMan</dc:creator>
      <dc:date>2021-08-16T19:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA with SMB 1500 (R80.20.30)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127137#M8160</link>
      <description>&lt;P&gt;Yes, it makes sense, therefore it seems sk137732 would apply.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 20:21:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127137#M8160</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-16T20:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA with SMB 1500 (R80.20.30)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127140#M8161</link>
      <description>&lt;P&gt;Great stuff.&lt;BR /&gt;Thanks.&lt;BR /&gt;&lt;BR /&gt;So, here's the Million Dollar question:&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;BR /&gt;Any chance that there &lt;STRONG&gt;might&lt;/STRONG&gt;&amp;nbsp;be a solution/enhancement on a roadmap soon?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Aug 2021 20:44:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-with-SMB-1500-R80-20-30/m-p/127140#M8161</guid>
      <dc:creator>SaxMan</dc:creator>
      <dc:date>2021-08-16T20:44:14Z</dc:date>
    </item>
  </channel>
</rss>

