- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
when we want to enable secure ID authentication for checkpoint gateways we just need to copy the sdconf.rec file on the gateway on the CLI or do we need to configure through OPsec application also?
Checkpoint R80.10 security management doc says we just need to copy the file. But RSA doc insists to have an OPsec application configuration . can any one confirm on this?
Hi, an OPSEC application object wouldn't be needed for the SecurID configuration. Sounds like you're looking at an RSA doc for their SIEM product integration. Here's a link to RSA's SecurID Integration Guides with Check Point. Would follow this and the Check Point docs. hth, bob
can we enable Radius and SecureID auth together in checkpoint?
in the RSA doc, they mentioned to modify the settings in the global propriety :
"Select Manage>Policy>Global Properties.
7. Select Manage>Policy>Global Properties.
8. Select Smart Dashboard Customization from the list of options.
9. Under the Advanced Configuration option, select the Configure button.
10. Select FireWall-1 >Authentication>RADIUS from the left toolbar.
11. Modify the radius ignore setting changing the default value of “0” to “76”."
does this affect other Radius server properties configured on the MGMT
This is for authenticating users going through the Security Gateway, not for ones authenticating to it for Gaia SSH/WebUI.
Is the RADIUS server in question different from your SecurID server?
Most of the recent SecurID installs I've seen recently integrate through RADIUS instead of using sdconf.rec.
Either way, you should be able to do both.
Agree. is there any advantages using Radius over sdconf.rec
As far as I know, no significant differences.
Thanks. have you enabled MFA ( secure ID and Radius )for SSH/WEB logins for security gateways . or will it support?
If you want SecurID with SSH or Gaia WebUI, you have to configure it with RADIUS, not sdconf.rec.
The Gaia OS SSH/WebUI does not support the sdconf.rec method.
so If I use RADIUS client ( RSA) will it support both MFA for ssh/WEB?
Yes
will checkpoint 1200R Embeded Gaia will support RSA auth with Radius?
With RADIUS? Yes.
The sdconf.rec method is not supported on the SMB appliances.
I've tried to use RADIUS(RSA AM) server, the AD user can login into Dashboard/WebUI/CLI with SecurID Access Authenticator, but I've tried using RSA cloud radius authentication, cannot success to do so but SSL VPN and VPN client working fine with MFA(bio/push notification), did Check Point support login Dashboard/WebUI/CLI using RSA cloud radius?
Pretty sure our Dashboard/WebUI/CLI doesn't support the CHALLENGE-RESPONSE needed for MFA.
finally I used Microsoft NPS as proxy for RSA secure ID and it works for ssh/web logins for checkpoint firewalls
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
19 | |
6 | |
6 | |
5 | |
4 | |
3 | |
3 | |
2 | |
2 | |
2 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY