- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Could anyone guide me with steps for implementing best approach of MFA for checkpoint firewalls (only for admin access on Gaia and smartconsole R81.10) for an azure platform.
We've added support for MFA for Gaia OS (WebUI, clish and API) in R82 as well as R81.20 JHF 96 and above.
The MFA is TOTP clients like Google/Microsoft Authenticator.
More details: https://support.checkpoint.com/results/sk/sk181854
I realize that you also asked about SmartConsole and MFA, which is very different.
From R81.20, you can use a SAML provider (Entra ID): https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
In earlier releases, or without his is supported provided your MFA source is reachable via RADIUS or TACACS.
Note that you will only get a single password prompt, which means you enter your password plus MFA code in the same box.
What is your identity source here?
If it's Azure AD, then you cannot authenticate to the Gaia OS using this method, only RADIUS or TACACS are supported.
SmartConsole supports integration with Azure AD from R81.20: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
It is Azure AD for authentication. Would this SAML authentication with Azure suffice my MFA requirement for admin logins on Smartconsole and Gaia portal ?
Yes, because the entire authentication flow happens in Azure AD (which supports MFA).
Like I said, the Gaia OS does not support integration with SAML, only RADIUS or TACACS.
Which means you need a Windows NPS server set up with the appropriate plugin: https://learn.microsoft.com/en-us/azure/active-directory/fundamentals/auth-radius
You can actually use RADIUS for both SmartConsole and Gaia OS in R81.10.
The "MFA" would be entered in after your fixed password in both cases.
The user experience of the SAML-based approach is much better.
Thank you so much for your response! Is there any documentation for the steps that can be followed to implement the MFA for both smartconsole and Gaia using RADIUS and Azure AD.
Integration with RADIUS is explained in the various guides:
Refer to the appropriate Microsoft documentation to configure the NPS Server.
Hi , we have tried to get this working for Gaia R81.20 (using NPS and NPS plugin) , works fine for our other clients (Cisco routers etc) , but Checkpoint Gaia (Web/shh/console) does not. I raised an SR and TAC informed me it wasn't supported .
Interested in what you mean in your comment The "MFA" would be entered in after your fixed password in both cases". As neither the Web Gui or SSH session display a separate input page , do you mean you put it all in one go, i.e. password and MFA code on same line when entering the password, do you have to use any separators or do you mean something else entirely ?
thanks Neal
Yes, you have to enter both the password and your MFA code in the same field.
The MFA code should be entered directly after the password, as I recall.
Hi, are there any new options with R82? Also, since MFA is 90% effective, to get to 99.9% now we're being asked for phishing resistant MFA. Maybe a user certificate on a Yubikey would work? RE: admin access to Gaia, command line, LOM, and/or smartconsole.
We've added support for MFA for Gaia OS (WebUI, clish and API) in R82 as well as R81.20 JHF 96 and above.
The MFA is TOTP clients like Google/Microsoft Authenticator.
More details: https://support.checkpoint.com/results/sk/sk181854
I realize that you also asked about SmartConsole and MFA, which is very different.
From R81.20, you can use a SAML provider (Entra ID): https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_SecurityManagement_AdminGuid...
In earlier releases, or without his is supported provided your MFA source is reachable via RADIUS or TACACS.
Note that you will only get a single password prompt, which means you enter your password plus MFA code in the same box.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
21 | |
15 | |
6 | |
6 | |
4 | |
3 | |
3 | |
3 | |
2 | |
2 |
Tue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewTue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY