<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic 2FA and L2TP/IPSEC under Linux in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94343#M9986</link>
    <description>&lt;P&gt;Is there any way to connect to an enterprise VPN using L2TP over IPSEC in combination with 2 factor authentication under a recent Linux Desktop Distribution like Ubuntu?&lt;BR /&gt;&lt;BR /&gt;Ubuntu provides the package network-manager-l2tp-gnome that could work but I still do not manage to etablish a connection because there seems to be no 2FA handling.&lt;/P&gt;&lt;P&gt;Anyone has such a setup working?&lt;/P&gt;</description>
    <pubDate>Mon, 17 Aug 2020 11:50:19 GMT</pubDate>
    <dc:creator>ronzo</dc:creator>
    <dc:date>2020-08-17T11:50:19Z</dc:date>
    <item>
      <title>2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94343#M9986</link>
      <description>&lt;P&gt;Is there any way to connect to an enterprise VPN using L2TP over IPSEC in combination with 2 factor authentication under a recent Linux Desktop Distribution like Ubuntu?&lt;BR /&gt;&lt;BR /&gt;Ubuntu provides the package network-manager-l2tp-gnome that could work but I still do not manage to etablish a connection because there seems to be no 2FA handling.&lt;/P&gt;&lt;P&gt;Anyone has such a setup working?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 11:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94343#M9986</guid>
      <dc:creator>ronzo</dc:creator>
      <dc:date>2020-08-17T11:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94351#M9987</link>
      <description>&lt;P&gt;We support use of&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/C2S-strongSwan-Roadwarrior-and-R80-30-working/m-p/67619#M2157" target="_self"&gt;strongSwan (Roadwarrier)&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;and&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/C2S-Libreswan-3-23-Roadwarrior-and-R80-30-working/m-p/67129#M2129" target="_self"&gt;Libreswan 3.23&lt;/A&gt;, but not sure about 2FA&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 12:44:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94351#M9987</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-08-17T12:44:53Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94352#M9988</link>
      <description>&lt;P&gt;Thanks for your quick reply. I do consider myself as capable of configuring Libreswan but I do need to know if there is a chance for the 2FA (SMS token) part.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 12:52:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94352#M9988</guid>
      <dc:creator>ronzo</dc:creator>
      <dc:date>2020-08-17T12:52:47Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94390#M9989</link>
      <description>&lt;P&gt;You would need to be able to enter the password in one go (fixed password plus your MFA code) if it were to work at all.&lt;BR /&gt;There is no handling for multi-stage authentication that I'm aware of.&lt;BR /&gt;I would approach your local Check Point office with your precise requirements.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 15:33:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94390#M9989</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-17T15:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94392#M9990</link>
      <description>&lt;P&gt;What a pity. What we are using is multi-stage authentication as the token comes with a cell phone text message after having entered a password.&lt;/P&gt;&lt;P&gt;Are there any future plans for providing a CheckPoint Linux solution to cover this scenario? At least for Ubuntu and Fedora?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 15:43:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94392#M9990</guid>
      <dc:creator>ronzo</dc:creator>
      <dc:date>2020-08-17T15:43:24Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94403#M9991</link>
      <description>&lt;P&gt;There are no plans to develop a native Linux VPN client.&lt;BR /&gt;Formal support for StrongSWAN is planned for R81 and I can’t say if it will include MFA support.&lt;BR /&gt;Recommend getting involved in the Production EA.&lt;/P&gt;
&lt;P&gt;Existing formal support is limited to a customer release on R80.30.&lt;BR /&gt;The links Val provides above are community-developed instructions.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2020 18:29:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/94403#M9991</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-17T18:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/103429#M9992</link>
      <description>&lt;P&gt;Using the Plugin L2TP with NetworkManager works also with 2FA. Make sure you use the latest Plugin version.&lt;/P&gt;&lt;P&gt;Configuration see here: &lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I just verified it, I have a FreeIPA Server connected to the Check Point using LDAPS. On the FreeIPA all users have a password and OTP (it is included in FreeIPA). It also works if you have RSA Token or any Radius Connection combined with Active Directory etc.&lt;/P&gt;&lt;P&gt;But it won't work with SMS, or if you get the SMS before you initiate the connection which is very unlikely.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 13:33:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/103429#M9992</guid>
      <dc:creator>Soeren_Rothe</dc:creator>
      <dc:date>2020-11-26T13:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/103434#M9993</link>
      <description>&lt;P&gt;Unfortunately, we are using text messages (SMS) as the second factor. So this won't work for me.&lt;/P&gt;&lt;P&gt;We also try to use certificate based VPN connections with device certificates. The problem here is that our Checkpoint VPN teams knowledge is very limited when it comes to details.&lt;/P&gt;&lt;P&gt;There are many questions left such as:&lt;/P&gt;&lt;P&gt;General questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Do we use certificates for both? The VPN (ipsec) connection itself and L2TP?&lt;/LI&gt;&lt;LI&gt;Would the most recent Fedora release be sufficient to establish a VPN connection or does one of the components (Network Manager L2TP plugin, Strongswan, ???) lack something?&lt;/LI&gt;&lt;LI&gt;In order to debug would it not be better to use StrongSwan cli instead of l2tp-network-manager-gnome?&lt;/LI&gt;&lt;LI&gt;I read something about the VPN gateway certificate. That I need it whenever I do not use the official Checkpoint client. True?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;L2TP Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What is the Remote ID?&lt;/LI&gt;&lt;LI&gt;What the hell do i put in the phase 1 and phase 2 algorithm field?&lt;/LI&gt;&lt;LI&gt;Which lifetimes should I set?&lt;/LI&gt;&lt;LI&gt;Which checkboxes should be set?&lt;/LI&gt;&lt;LI&gt;Which L2TP-PPP options should be set?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Can I extract answers to these questions from the Windows or Android Checkpoint client? What do I need from our Checkpoint VPN team?&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 13:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/103434#M9993</guid>
      <dc:creator>ronzo</dc:creator>
      <dc:date>2020-11-26T13:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: 2FA and L2TP/IPSEC under Linux</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/103447#M9994</link>
      <description>&lt;P&gt;With L2TP over IPSec I don't use any Certificates at all.&amp;nbsp;&lt;/P&gt;&lt;P&gt;General questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Do we use certificates for both? The VPN (ipsec) connection itself and L2TP?&lt;UL&gt;&lt;LI&gt;No Certificates at all.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Would the most recent Fedora release be sufficient to establish a VPN connection or does one of the components (Network Manager L2TP plugin, Strongswan, ???) lack something?&lt;UL&gt;&lt;LI&gt;Can you tell me the Network Manager L2TP Plugin Version? Should be greater than 1.7.2&lt;/LI&gt;&lt;LI&gt;StrongSwan works too, but the documentation I wrote in Checkmates uses Libreswan and L2TP. Try Libreswan.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;In order to debug would it not be better to use StrongSwan cli instead of l2tp-network-manager-gnome?&lt;UL&gt;&lt;LI&gt;Of course, but you can also check the logs. L2TP and IPSec is very complicated to run on cli. I don't recommend it, see here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/C2S-L2TP-over-IPSEC-Linux-VPN-with-R80-30-working/m-p/68069#M2175" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/C2S-L2TP-over-IPSEC-Linux-VPN-with-R80-30-working/m-p/68069#M2175&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;I read something about the VPN gateway certificate. That I need it whenever I do not use the official Checkpoint client. True?&lt;UL&gt;&lt;LI&gt;For L2TP over IPSec you don't need it.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;L2TP Questions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;What is the Remote ID?&lt;UL&gt;&lt;LI&gt;This is the Main IP of the Gateway, this works for me&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;What the hell do i put in the phase 1 and phase 2 algorithm field?&lt;UL&gt;&lt;LI&gt;Make sure this is enabled on the GW. This is an example for Libreswan&lt;UL&gt;&lt;LI&gt;Phase1: AES256-SHA256 and DH14&lt;UL&gt;&lt;LI&gt;aes256-sha256-modp2048&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Phase2: AES128-SHA256 (no PFS)&lt;UL&gt;&lt;LI&gt;aes128-sha256&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Which lifetimes should I set?&lt;UL&gt;&lt;LI&gt;Phase1: 8h (depends on the settings of the GW, see Global Properties - Remote Access - Endpoint Connect - Re-Authentication every: 720m)&lt;/LI&gt;&lt;LI&gt;Phase2: 1h&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Which checkboxes should be set?&lt;UL&gt;&lt;LI&gt;Disable PFS must be checked&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Which L2TP-PPP options should be set?&lt;UL&gt;&lt;LI&gt;enable PAP,&lt;/LI&gt;&lt;LI&gt;disable CHAP,MSCHAP, MSCHAPv2, EAP&lt;/LI&gt;&lt;LI&gt;leave the rest&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;For the Check Point configuration you can check here:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/C2S-L2TP-over-IPSEC-Linux-VPN-with-R80-30-working/m-p/68069#M2175" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/C2S-L2TP-over-IPSEC-Linux-VPN-with-R80-30-working/m-p/68069#M2175&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For L2TP Configuration with Network Manager, see here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 14:19:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/2FA-and-L2TP-IPSEC-under-Linux/m-p/103447#M9994</guid>
      <dc:creator>Soeren_Rothe</dc:creator>
      <dc:date>2020-11-26T14:19:12Z</dc:date>
    </item>
  </channel>
</rss>

