- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: IPSec MFA in Fedora 34
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
IPSec MFA in Fedora 34
Today I'm using Windows 10 to connect in my company VPN. This VPN use MFA in this way:
- I enter user/pass
- I receive SMS or Answer a secret question.
- I put sms code in checkpoint client , if I choose receive SMS.
- I'm connected.
Now I'm migration to Fedora 34, and I didn't found a way to connect to my vpn using MFA, I tried some solutions like: snx cli, snxconnect in python, install checkpoint using wine. But unhappy nothing worked.
Is possible using Fedora 34 (Linux in general) with MFA in Checkpoint VPN ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Your two options on Linux are SNX and StrongSWAN (the latter of which assumes R81+ gateways).
SNX doesn't support a multi-stage authentication.
Don't believe StrongSWAN does either.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, I don't have option, I need to use Windows or MacOS. 😞
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Read along here - https://strongswan.org/ ! StrongSwan supports MFA with IKEv2 Multiple Authentication Exchanges (RFC 4739). RADIUS is one possibility i saw mentioned.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How can I check if my company use Radius ? Unhappy I don't have access to this informations.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You really need to work with your IT folks on this.
They can place restrictions on the exact types of clients you’re allowed to use to connect to the gateway.
Believe their assistance will also be required to use StrongSWAN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I agree. But unhappy they said that Linux is not support nowdays.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why then the change to Fedora 34 ? If the company you are working for can not provide a VPN client for Fedora 34 they also can not tell you to migrate to that OS.
