- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi everyone,
We have been using Client Auth in our firewall policies just about forever. These rules are used to limit exposure to our most critical assets by requiring MFA (we use SecurID as the authenticator) before a user can access certain assets. These assets have a variety of different access methods - https, ssh, and a number of "non-standard" ports/interfaces.
I have heard the rumblings that Client Auth will someday go away, and I need an alternative that meets the following:
1. Requires MFA (SecurID) on part of the user
2. Supports protecting hosts that are not a web server/site
Captive portal looks like it could meet the first objective (leveraging Radius) but not the second. Any other suggestions? Am I missing an option?
Thanks,
Dave
Client Auth is called legacy authentication for a reason. It is not developed for quite a few years. Moreover, legacy authentication is really bad for performance, as it disables acceleration templates.
What you want to do is to use Identity Awareness. If client based, it covers both your points transparently. If you do not want to install IA clients, or if those PCs your users are accessing from are unmanaged, users can sign into IA portal before accessing protected assets.
Thanks Val,
We do use IA awareness (via AD Query) to control access to certain resources. We still use Client Auth because we can require a user to use MFA before accessing our most critical resources (and honestly, because IA has not been 100% reliable). If I can replicate this with Captive Portal, I will use that, but from what I see in the documentation:
Captive Portal is a simple method that authenticates users with a web interface. When users try to access a protected web resource, they enter authentication information in a form that shows in their web browser.
My bolding. Does this mean Captive Portal only works when trying to access something via http/https?
Thanks
Dave
As Dameon already answered, and mentioned before him :-), for non-Web services you will have to authenticate on Captive Portal explicitly.
Perfect, that's the answer I was hoping for. Thanks PhoneBoy (and everyone else who provided help).
Dave
One follow up question --
Since we already use IA with AD Query, can AD Query to be used for certain IA rules, and for other rules can I force the use of manual Captive Portal (and RADIUS, with which I can leverage our SecurID MFA) for other rules?
Thanks
Dave
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 13 | |
| 8 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolFri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY