- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Is it possible to setup MFA access to SmartDashboard? We would like to validate user with LDAP and then have RSA or DUO auth. I was thinking of using TACACS to handle the the MFA. Any suggestions are welcomed.
Thanks,
Bill
I was successful in setting up the MFA for SmartConsole with DUO. I utilized the DUO authentication proxy. I had to setup the RADIUS on the SmartConsole to point to the proxy. The proxy checks our AD credentials first. If the AD credentials pass, then the proxy will then utilize DUO for the second factor. I tested DUO with the push of ACCEPT or DENY to my mobile. Once accepted the console let me right on in.
Below is the link I followed to set it up.
Hope that helps!
The easiest way is probably proxying whatever your choice of MFA authentication is through RADIUS. We do this with RSA here and I know DUO has an option for an on-prem virtual appliance to allow RADIUS.
Once that is set up, you just need to add the RADIUS server in SmartConsole. Then, configure your administrators in SmartConsole to use RADIUS as their Authentication Method and select the RADIUS server you configured. Do an "Install Database" and you should be good to go!
Actually, that's a really good point and I glossed over the in your OP. I guess the answer is... no, it won't. It would allow you to use RSA/DUO as the primary authentication method. (Which was how I had misread your original quesiton). To that end, I'm honestly not 100% sure how that scenario might be accomplished. Sorry for the confusion 😞
Thanks Phoneboy,
I would be fine with the one authentication method and one password prompt. I figure the authentication method (RADIUS, TACACs) could then provide the 2nd authentication piece. In this case we ask for LDAP credentials for password prompt. When the password is authenticated, then a DUO push to mobile device. Not sure if a RADIUS proxy or TACACs could provide something like that.
I was successful in setting up the MFA for SmartConsole with DUO. I utilized the DUO authentication proxy. I had to setup the RADIUS on the SmartConsole to point to the proxy. The proxy checks our AD credentials first. If the AD credentials pass, then the proxy will then utilize DUO for the second factor. I tested DUO with the push of ACCEPT or DENY to my mobile. Once accepted the console let me right on in.
Below is the link I followed to set it up.
Hope that helps!
Hi Everyone,
We use our 2FA (DUO) as our authentication proxy which is working as the radius. This DUO is synced with AD for authentication. I have enabled mobile access and in my case, VPN traffic first comes to a gateway ---> Radius (Duo)----> AD and I am able to connect to the VPN.
What if I want to provide access to the users, based on AD users? I won't be able to do it, right? As I have pointed my authentication server as the radius so, the checkpoint is not synced with the AD and it doesn't have the AD users to allow it in the policy.
Hi Everyone,
Got the solution from this video posted in the Community 😊
https://community.checkpoint.com/t5/How-To-Videos/Check-Point-Mobile-Access-with-Duo-2FA-Authenticat...
Thanks a lot!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY