- Products
- Learn
- Local User Groups
- Partners
- More
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
Introduction to Lakera:
Securing the AI Frontier!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
hello everyone, we are experiencing a problem with ms authentication on smartphone is taking about 20 seconds to do the approve... it used to take about 5 seconds, is there something checkpoint side we can check?
the vpngw is running R81.20 JH53
What's the actual authentication flow here where this step is required?
Have you checked with tcpdump to see which end is causing the delay?
The VPN client request to Radius client
Radius request to Primary AUthN (active directory)
And then to Multi-Factor Auth reuqest
CKP > NPS > AAD
How can i capture traffic, personally i've the same issue but if i disconnect from the vpn checkpoint i lost the session
This would most likely have to be captured on the gateway while you (or an affected user) are connecting via a VPN client.
It's also not clear where the MFA is coming from...is it a different authentication method you've configured?
Azure MFA and Check Point VPN. The connections it's with Azure AD and the NPS extension for Azure MFA
if i want to collect tcpdumps myself how can i do it? if i disconnect to replicate the problem i also lose connectivity....
Please provide a screenshot of this portion of the relevant gateway/cluster object so I can understand how you have this configured on the Check Point side.
In general, if you're doing MFA with Azure AD, you should be using SAML instead of RADIUS.
Does Identity Provider refer to Azure AD?
Curious why you're doing RADIUS as a separate step here.
Some unsolicited advice - seeing as you're already integrated with Entra (based on Identity Provider Entry) I would look to move away from Radius auth and its dependencies and move to straight SAML auth if at all possible.
Why? if you don't mind me asking.
Don't mind at all.
That's off the top of my head, sure I'll be able to put down more if I think about it. Of course every environment and use case is different, but the above has been true for us.
-Ruan
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
12 | |
12 | |
10 | |
7 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 |
Tue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Thu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY