<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216882#M10753</link>
    <description>&lt;P&gt;Regarding Microsoft Authenticator I'm not 100% sure because I didn't use it but I believe that it can be used as regular OTP like Google Authenticator.&lt;/P&gt;&lt;P&gt;From Check Point's documentation:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;You can use either the Microsoft Authenticator or the Google Authenticator"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So... it should work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I use neither ... because I like FreeOTP &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This 2FA provided in R81.10.07 was only for ... Remote Access. 2FA for mgmt access was introduced in R81.10.10.&lt;/P&gt;&lt;P&gt;So in case you want it for RA, which I believe is the case, you can use it since R81.10.07.&lt;/P&gt;&lt;P&gt;m.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2024 19:51:33 GMT</pubDate>
    <dc:creator>marcyn</dc:creator>
    <dc:date>2024-06-07T19:51:33Z</dc:date>
    <item>
      <title>Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169897#M8143</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;&lt;P&gt;There are couple of topics on this community regarding 2FA via radius on Sparks.&lt;BR /&gt;A few of you noticed an issue with Spark and radius with fw older then R81.10.&lt;BR /&gt;It was due to Spark below R81.10 supports only radius 1.0.&lt;BR /&gt;From R81.10 it supports radius 2.0 and issues with passwords longer then 16 characters should be gone.&lt;/P&gt;&lt;P&gt;Well ... as far as I see not entirely &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;On last Saturday I was configuring my new Spark 1570.&lt;BR /&gt;Because I'm a huge fan of 2FA it was pretty sure that I will configure radius.&lt;BR /&gt;So I did it ... and faced an issue.&lt;/P&gt;&lt;P&gt;I have R81.10.05 (996001002) and it's locally mgmt.&lt;BR /&gt;On radius server I have user with password longer then 10 characters (+6 OTP = 16) ...&lt;BR /&gt;I had no issues with logging in to mgmt portal, but I was not able to log in using the same user to VPN (wrong credentials).&lt;BR /&gt;After some diggings I noticed in radius logs something like that as password "1234567890abcdef\12\34\56\23" - so soon after exactly 16 characters there is "a mess" - which is exactly the same as it looks like with radius 1.0.&lt;/P&gt;&lt;P&gt;It looks like Spark supports radius 2.0 but not for VPN (here it is still radius 1.0 constraint) &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Falks from R&amp;amp;D maybe you can take a look at this ?&lt;/P&gt;&lt;P&gt;--&lt;BR /&gt;Best&lt;BR /&gt;m.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 12:13:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169897#M8143</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2023-02-01T12:13:57Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169941#M8147</link>
      <description>&lt;P&gt;Did you report this via TAC and have an SR number that can be shared for follow-up?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 15:29:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169941#M8147</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-01T15:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169943#M8148</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Not yet. First I wanted to know if anyone else from community faced this issue as well.&lt;/P&gt;&lt;P&gt;If not I will direct this to TAC.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;m.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 15:44:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169943#M8148</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2023-02-01T15:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169983#M8153</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;¿Have you configured the Radius Server with version 2.0?&lt;/P&gt;&lt;P&gt;It&amp;nbsp; must be done in cli "set radius server"&amp;nbsp; --&amp;nbsp; &amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/set-radius-server.htm?Highlight=radius" target="_blank"&gt;set radius-server (checkpoint.com)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope it helps.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 19:36:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169983#M8153</guid>
      <dc:creator>Eduardo_Eiros</dc:creator>
      <dc:date>2023-02-01T19:36:22Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169984#M8154</link>
      <description>&lt;P&gt;Hi Eduardo,&lt;/P&gt;&lt;P&gt;Jackpot ! This fixed the issue.&lt;/P&gt;&lt;P&gt;It's very very interesting that regarding having version 1 (taken from show radius-server command) it worked fine with web access to mgmt portal with password longer then 16 characters &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Because of that I didn't even consider that there could be need to change any setting regarding to radiu from cli. If it worked with longer passwords for web it was clear to me that it us version 2 &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;To be honest I completely don't get it why it worked for web login ... but it is not as important, as that it now works for vpn as well, after manual change of version from cli.&lt;/P&gt;&lt;P&gt;Thank you, case closed.&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;m.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 19:55:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/169984#M8154</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2023-02-01T19:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/170027#M8155</link>
      <description>&lt;P&gt;Further to this I've asked internally that we consider the following related enhancements for future versions.&lt;/P&gt;
&lt;P&gt;- Radius 2.0 as default&lt;/P&gt;
&lt;P&gt;- Version selection via the Web UI.&lt;/P&gt;
&lt;P&gt;If this is important for you please follow-up with your local SE accordingly as an RFE - thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 05:45:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/170027#M8155</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-02-02T05:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216860#M10748</link>
      <description>&lt;P&gt;Would you by any chance be using DUO mfa for the spark? im seeing same issues with Radius authentication&lt;BR /&gt;I can do ad authentication without aproblem but not radius&amp;nbsp;@ Duo&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 16:59:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216860#M10748</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-06-07T16:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216862#M10749</link>
      <description>&lt;P&gt;Hi&amp;nbsp;skandshus,&lt;/P&gt;&lt;P&gt;No, this was FreeRadius.&lt;/P&gt;&lt;P&gt;Now I even don't use it anymore as 2FA is inside Gaia Embedded fw.&lt;/P&gt;&lt;P&gt;If you see the same issue that I had ... it should be because of Radius version 1. If you've already changed this version to 2 on Spark side then probably it's something else on Duo side.&lt;/P&gt;&lt;P&gt;m.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 17:15:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216862#M10749</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-06-07T17:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216873#M10750</link>
      <description>&lt;P&gt;How so i 2FA inside embedded? are you talking about the sms feature they got?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 18:40:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216873#M10750</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-06-07T18:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216874#M10751</link>
      <description>&lt;P&gt;2FA via e-mail and sms has been around for several years, but in fw R81.10.07 Check Point added another 2FA based on OTP like GoogleAuthenticator, Microsoft Authenticator, etc.&lt;/P&gt;&lt;P&gt;Before R81.10.07 we had to use some external mechanisms like linux with freeradius and google authenticator to have OTP ... but since R81.10.07 google authenticator "server" is included in Spark's fw.&lt;/P&gt;&lt;P&gt;Take a look at this:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk179615" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk179615&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Of course now there is no sense to use R81.10.07 ... R81.10.08 is better ... and even best in my opinion R81.10.10 where we also have 2FA for web gui and "nicer" gui &lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt;&lt;/P&gt;&lt;P&gt;m.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 18:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216874#M10751</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-06-07T18:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216877#M10752</link>
      <description>&lt;P&gt;LOL i havent ever gotten back to that. i remeber when it was only sms, and then after that, ive never visited that again&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now i see we can do Email too &amp;amp; google authenticator.&lt;/P&gt;
&lt;P&gt;Are you sure Microsoft Authenticator is working too? i guess its not microsoft-365 integration but a regular OTP if you use Microsoft? right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to be clear. is this ONLY for administration login? the MFA cant be used for remote access?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 19:36:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216877#M10752</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-06-07T19:36:59Z</dc:date>
    </item>
    <item>
      <title>Re: Spark R81.10 and support for Radius 2.0 .... well not entirely true</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216882#M10753</link>
      <description>&lt;P&gt;Regarding Microsoft Authenticator I'm not 100% sure because I didn't use it but I believe that it can be used as regular OTP like Google Authenticator.&lt;/P&gt;&lt;P&gt;From Check Point's documentation:&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;You can use either the Microsoft Authenticator or the Google Authenticator"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So... it should work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I use neither ... because I like FreeOTP &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This 2FA provided in R81.10.07 was only for ... Remote Access. 2FA for mgmt access was introduced in R81.10.10.&lt;/P&gt;&lt;P&gt;So in case you want it for RA, which I believe is the case, you can use it since R81.10.07.&lt;/P&gt;&lt;P&gt;m.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2024 19:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-R81-10-and-support-for-Radius-2-0-well-not-entirely-true/m-p/216882#M10753</guid>
      <dc:creator>marcyn</dc:creator>
      <dc:date>2024-06-07T19:51:33Z</dc:date>
    </item>
  </channel>
</rss>

