- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Firewall Uptime, Reimagined
How AIOps Simplifies Operations and Prevents Outages
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
when we want to enable secure ID authentication for checkpoint gateways we just need to copy the sdconf.rec file on the gateway on the CLI or do we need to configure through OPsec application also?
Checkpoint R80.10 security management doc says we just need to copy the file. But RSA doc insists to have an OPsec application configuration . can any one confirm on this?
Hi, an OPSEC application object wouldn't be needed for the SecurID configuration. Sounds like you're looking at an RSA doc for their SIEM product integration. Here's a link to RSA's SecurID Integration Guides with Check Point. Would follow this and the Check Point docs. hth, bob
can we enable Radius and SecureID auth together in checkpoint?
in the RSA doc, they mentioned to modify the settings in the global propriety :
"Select Manage>Policy>Global Properties.
7. Select Manage>Policy>Global Properties.
8. Select Smart Dashboard Customization from the list of options.
9. Under the Advanced Configuration option, select the Configure button.
10. Select FireWall-1 >Authentication>RADIUS from the left toolbar.
11. Modify the radius ignore setting changing the default value of “0” to “76”."
does this affect other Radius server properties configured on the MGMT
This is for authenticating users going through the Security Gateway, not for ones authenticating to it for Gaia SSH/WebUI.
Is the RADIUS server in question different from your SecurID server?
Most of the recent SecurID installs I've seen recently integrate through RADIUS instead of using sdconf.rec.
Either way, you should be able to do both.
Agree. is there any advantages using Radius over sdconf.rec
As far as I know, no significant differences.
Thanks. have you enabled MFA ( secure ID and Radius )for SSH/WEB logins for security gateways . or will it support?
If you want SecurID with SSH or Gaia WebUI, you have to configure it with RADIUS, not sdconf.rec.
The Gaia OS SSH/WebUI does not support the sdconf.rec method.
so If I use RADIUS client ( RSA) will it support both MFA for ssh/WEB?
Yes
will checkpoint 1200R Embeded Gaia will support RSA auth with Radius?
With RADIUS? Yes.
The sdconf.rec method is not supported on the SMB appliances.
I've tried to use RADIUS(RSA AM) server, the AD user can login into Dashboard/WebUI/CLI with SecurID Access Authenticator, but I've tried using RSA cloud radius authentication, cannot success to do so but SSL VPN and VPN client working fine with MFA(bio/push notification), did Check Point support login Dashboard/WebUI/CLI using RSA cloud radius?
Pretty sure our Dashboard/WebUI/CLI doesn't support the CHALLENGE-RESPONSE needed for MFA.
finally I used Microsoft NPS as proxy for RSA secure ID and it works for ssh/web logins for checkpoint firewalls
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 13 | |
| 7 | |
| 7 | |
| 6 | |
| 4 | |
| 3 | |
| 3 | |
| 3 | |
| 2 |
Tue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!Tue 28 Oct 2025 @ 12:30 PM (EDT)
Check Point & AWS Virtual Immersion Day: Web App ProtectionThu 30 Oct 2025 @ 03:00 PM (CET)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - EMEAThu 30 Oct 2025 @ 11:00 AM (EDT)
Tips and Tricks 2025 #15: Become a Threat Exposure Management Power User!Thu 30 Oct 2025 @ 02:00 PM (EDT)
Cloud Security Under Siege: Critical Insights from the 2025 Security Landscape - AMERAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY