- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- MFA for admin access for checkpoint firewall on Ga...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
MFA for admin access for checkpoint firewall on Gaia and Smartconsole
Could anyone guide me with steps for implementing best approach of MFA for checkpoint firewalls (only for admin access on Gaia and smartconsole R81.10) for an azure platform.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, because the entire authentication flow happens in Azure AD (which supports MFA).
Like I said, the Gaia OS does not support integration with SAML, only RADIUS or TACACS.
Which means you need a Windows NPS server set up with the appropriate plugin: https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/auth-radius
You can actually use RADIUS for both SmartConsole and Gaia OS in R81.10.
The "MFA" would be entered in after your fixed password in both cases.
The user experience of the SAML-based approach is much better.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Integration with RADIUS is explained in the various guides:
- Gaia OS: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_AdminGuide/Topics-GAG/R...
- SmartConsole: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuid...
Refer to the appropriate Microsoft documentation to configure the NPS Server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What is your identity source here?
If it's Azure AD, then you cannot authenticate to the Gaia OS using this method, only RADIUS or TACACS are supported.
SmartConsole supports integration with Azure AD from R81.20: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It is Azure AD for authentication. Would this SAML authentication with Azure suffice my MFA requirement for admin logins on Smartconsole and Gaia portal ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, because the entire authentication flow happens in Azure AD (which supports MFA).
Like I said, the Gaia OS does not support integration with SAML, only RADIUS or TACACS.
Which means you need a Windows NPS server set up with the appropriate plugin: https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/auth-radius
You can actually use RADIUS for both SmartConsole and Gaia OS in R81.10.
The "MFA" would be entered in after your fixed password in both cases.
The user experience of the SAML-based approach is much better.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you so much for your response! Is there any documentation for the steps that can be followed to implement the MFA for both smartconsole and Gaia using RADIUS and Azure AD.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Integration with RADIUS is explained in the various guides:
- Gaia OS: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_Gaia_AdminGuide/Topics-GAG/R...
- SmartConsole: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_SecurityManagement_AdminGuid...
Refer to the appropriate Microsoft documentation to configure the NPS Server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi , we have tried to get this working for Gaia R81.20 (using NPS and NPS plugin) , works fine for our other clients (Cisco routers etc) , but Checkpoint Gaia (Web/shh/console) does not. I raised an SR and TAC informed me it wasn't supported .
Interested in what you mean in your comment The "MFA" would be entered in after your fixed password in both cases". As neither the Web Gui or SSH session display a separate input page , do you mean you put it all in one go, i.e. password and MFA code on same line when entering the password, do you have to use any separators or do you mean something else entirely ?
thanks Neal
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, you have to enter both the password and your MFA code in the same field.
The MFA code should be entered directly after the password, as I recall.
