- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone,
We are currently using a Check Point firewall for Remote Access VPN, and we would like to implement two-factor authentication (2FA) for our VPN users. We are using R82 and last jumbo has installed on it.
Instead of using SMS-based 2FA, we would prefer to use email-based verification. Since our organization uses Office 365 for email, we would like to send the 2FA codes to users via their Office 365 email addresses.
Has anyone implemented email-based 2FA for Remote Access VPN on Check Point before? Is this supported natively, or would we need a third-party integration or RADIUS solution? Any documentation, guides, or suggestions would be highly appreciated.
Thank you in advance!
What authentication type are you using currently to authenticate the remote users?
You can send a second factor via email using DynamicID: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_MobileAccess_AdminGuide/Cont...
If you're using a SAML-based provider (Azure AD), the other factors should be implemented there.
Currently, we are only using username and password for authentication via LDAP (Active Directory). In addition to this, we would like to implement 2FA by sending a code via email.
Created a local user on the Check Point firewall.
Enabled Multi-Factor Authentication (MFA) for that local user.
On Office 365, I generated an App Password using the account vpn-mailer@yourdomain.com, as MFA is enabled for that account.
I configured the Check Point email notification settings using the following format:
I replaced app_password_here with the actual App Password generated from Microsoft 365.
The TO address is the email associated with the local user.
I completed the configuration on the Check Point firewall side successfully.
On the client side, I'm using Check Point Endpoint Security to connect via Remote Access VPN.
During connection:
The username and password authentication works correctly (using the local user).
After that, the endpoint client asks for the MFA response code (OTP), which should be emailed to the user.
The email containing the OTP code is never delivered to the user's email inbox.
No error is shown on the client; it just waits for the OTP.
The Check Point firewall is configured to send the OTP via Office 365 SMTP, but it appears the email is either not being sent or not being delivered.
In this case, which logs should I check on the Check Point side, what exactly should I look into, and how can I troubleshoot this issue?
I'd have a look in $CVPNDIR/log/cvpnd.elg to see if anything interesting is logged there.
Otherwise, I suggest TAC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 8 | |
| 4 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY