- Products
- Learn
- Local User Groups
- Partners
- More
Stop Babysitting Rules.
Go Agentic
Step Into the Future of
AI-Powered Cyber Security
Bridge the CAASM Gap
with Exposure Management
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
Call For Papers
Your Expertise. Our Stage
CheckMates Go:
CheckMates Fest
Could anyone guide me with steps for implementing best approach of MFA for checkpoint firewalls (only for admin access on Gaia and smartconsole R81.10) for an azure platform.
We've added support for MFA for Gaia OS (WebUI, clish and API) in R82 as well as R81.20 JHF 96 and above.
The MFA is TOTP clients like Google/Microsoft Authenticator.
More details: https://support.checkpoint.com/results/sk/sk181854
I realize that you also asked about SmartConsole and MFA, which is very different.
From R81.20, you can use a SAML provider (Entra ID): https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
In earlier releases, or without his is supported provided your MFA source is reachable via RADIUS or TACACS.
Note that you will only get a single password prompt, which means you enter your password plus MFA code in the same box.
What is your identity source here?
If it's Azure AD, then you cannot authenticate to the Gaia OS using this method, only RADIUS or TACACS are supported.
SmartConsole supports integration with Azure AD from R81.20: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
It is Azure AD for authentication. Would this SAML authentication with Azure suffice my MFA requirement for admin logins on Smartconsole and Gaia portal ?
Yes, because the entire authentication flow happens in Azure AD (which supports MFA).
Like I said, the Gaia OS does not support integration with SAML, only RADIUS or TACACS.
Which means you need a Windows NPS server set up with the appropriate plugin: https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/auth-radius
You can actually use RADIUS for both SmartConsole and Gaia OS in R81.10.
The "MFA" would be entered in after your fixed password in both cases.
The user experience of the SAML-based approach is much better.
Thank you so much for your response! Is there any documentation for the steps that can be followed to implement the MFA for both smartconsole and Gaia using RADIUS and Azure AD.
Integration with RADIUS is explained in the various guides:
Refer to the appropriate Microsoft documentation to configure the NPS Server.
Hi , we have tried to get this working for Gaia R81.20 (using NPS and NPS plugin) , works fine for our other clients (Cisco routers etc) , but Checkpoint Gaia (Web/shh/console) does not. I raised an SR and TAC informed me it wasn't supported .
Interested in what you mean in your comment The "MFA" would be entered in after your fixed password in both cases". As neither the Web Gui or SSH session display a separate input page , do you mean you put it all in one go, i.e. password and MFA code on same line when entering the password, do you have to use any separators or do you mean something else entirely ?
thanks Neal
Yes, you have to enter both the password and your MFA code in the same field.
The MFA code should be entered directly after the password, as I recall.
Hi, are there any new options with R82? Also, since MFA is 90% effective, to get to 99.9% now we're being asked for phishing resistant MFA. Maybe a user certificate on a Yubikey would work? RE: admin access to Gaia, command line, LOM, and/or smartconsole.
We've added support for MFA for Gaia OS (WebUI, clish and API) in R82 as well as R81.20 JHF 96 and above.
The MFA is TOTP clients like Google/Microsoft Authenticator.
More details: https://support.checkpoint.com/results/sk/sk181854
I realize that you also asked about SmartConsole and MFA, which is very different.
From R81.20, you can use a SAML provider (Entra ID): https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
In earlier releases, or without his is supported provided your MFA source is reachable via RADIUS or TACACS.
Note that you will only get a single password prompt, which means you enter your password plus MFA code in the same box.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 18 | |
| 9 | |
| 9 | |
| 8 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 |
Fri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesTue 02 Jun 2026 @ 10:00 AM (AEST)
The Cloud Architect Series: Check Point WAF. The next generation of AI-Powered Protection - APACTue 02 Jun 2026 @ 06:00 PM (IDT)
Under the Hood | Check Point SASE: Identity Integration & Access Policy Design Best PracticesThu 04 Jun 2026 @ 02:00 PM (CEST)
Deep Dive Webinar: New CloudGuard GWLB Deployment Without NAT Gateways - EuropeFri 29 May 2026 @ 09:00 AM (EDT)
Caracas: Executive Breakfast: Innovación en Ciberseguridad – IA y Threat IntelligenceAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY