<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote access using Active Directory with Radius/Duo authentication in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/121913#M8397</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would like to know how we can enable remote access VPNs for all the users configured on our AD server. The users should be able to authenticate using the Duo/Radius server we have already in place.&lt;/P&gt;&lt;P&gt;Current setup as below: -&lt;/P&gt;&lt;P&gt;1. Create the User on smartconsole and configure authentication as Duo&lt;/P&gt;&lt;P&gt;2. Create Duo accounts&lt;/P&gt;&lt;P&gt;3. User login to their endpoint security client using AD credentials, receives a Duo push and authneticate themselves and connect the VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want it to change so that the VPN user creation on the smartconsole is not required. Every new user in the AD should have the remote access VPN with duo authentication enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anish&lt;/P&gt;</description>
    <pubDate>Wed, 23 Jun 2021 11:04:38 GMT</pubDate>
    <dc:creator>anishtholath</dc:creator>
    <dc:date>2021-06-23T11:04:38Z</dc:date>
    <item>
      <title>Remote access using Active Directory with Radius/Duo authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/121913#M8397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I would like to know how we can enable remote access VPNs for all the users configured on our AD server. The users should be able to authenticate using the Duo/Radius server we have already in place.&lt;/P&gt;&lt;P&gt;Current setup as below: -&lt;/P&gt;&lt;P&gt;1. Create the User on smartconsole and configure authentication as Duo&lt;/P&gt;&lt;P&gt;2. Create Duo accounts&lt;/P&gt;&lt;P&gt;3. User login to their endpoint security client using AD credentials, receives a Duo push and authneticate themselves and connect the VPN&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We want it to change so that the VPN user creation on the smartconsole is not required. Every new user in the AD should have the remote access VPN with duo authentication enabled.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anish&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 11:04:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/121913#M8397</guid>
      <dc:creator>anishtholath</dc:creator>
      <dc:date>2021-06-23T11:04:38Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access using Active Directory with Radius/Duo authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/122231#M8398</link>
      <description>&lt;P&gt;What you need to create is an External User Profile.&lt;BR /&gt;Which isn't obvious because SmartConsole does not have this option.&lt;BR /&gt;It needs to be done with the legacy SmartDashboard client as described here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114797" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114797&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jun 2021 21:50:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/122231#M8398</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-25T21:50:51Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access using Active Directory with Radius/Duo authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/122239#M8399</link>
      <description>&lt;P&gt;Pretty simple. All you have to do is make sure that under gateway properties, vpn office mode, authentication -&amp;gt; and then under settings there, choose radius and select radius server you configured. As long as your radius communicates fine with the gateway, thats all you really need. Now, there is a document for radius auth with vpn clients (attached here). Phoneboy is correct as far as external user profile, but I can tell you that I never had to do that myself for Radius auth and worked fine every time. Message me privately if you wish and happy to do remote session to show you.&lt;/P&gt;</description>
      <pubDate>Sat, 26 Jun 2021 01:31:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/122239#M8399</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-26T01:31:30Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access using Active Directory with Radius/Duo authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/123338#M8400</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Is there a detailed documentation on how to do this? What am i supposed to do with the external user profile?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 14:45:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/123338#M8400</guid>
      <dc:creator>anishtholath</dc:creator>
      <dc:date>2021-07-08T14:45:43Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access using Active Directory with Radius/Duo authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/123341#M8401</link>
      <description>&lt;P&gt;Hi, we already have radius configured which we are using to authenticate the vpn clients. what i want is to remove the necessity of creating the users on the firewall and instead let all the AD users connect using vpn clients and authenticate using duo/radius.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 14:46:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/123341#M8401</guid>
      <dc:creator>anishtholath</dc:creator>
      <dc:date>2021-07-08T14:46:55Z</dc:date>
    </item>
    <item>
      <title>Re: Remote access using Active Directory with Radius/Duo authentication</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/123343#M8402</link>
      <description>&lt;P&gt;Did you set duo up to have your AD users in correctly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://duo.com/docs/checkpoint" target="_blank"&gt;https://duo.com/docs/checkpoint&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because what you are describing is how it just usually works, if you follow that explication.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 14:51:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-access-using-Active-Directory-with-Radius-Duo/m-p/123343#M8402</guid>
      <dc:creator>Institut_fuer_R</dc:creator>
      <dc:date>2021-07-08T14:51:46Z</dc:date>
    </item>
  </channel>
</rss>

