- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Is there any way to connect to an enterprise VPN using L2TP over IPSEC in combination with 2 factor authentication under a recent Linux Desktop Distribution like Ubuntu?
Ubuntu provides the package network-manager-l2tp-gnome that could work but I still do not manage to etablish a connection because there seems to be no 2FA handling.
Anyone has such a setup working?
We support use of strongSwan (Roadwarrier) and Libreswan 3.23, but not sure about 2FA
Thanks for your quick reply. I do consider myself as capable of configuring Libreswan but I do need to know if there is a chance for the 2FA (SMS token) part.
You would need to be able to enter the password in one go (fixed password plus your MFA code) if it were to work at all.
There is no handling for multi-stage authentication that I'm aware of.
I would approach your local Check Point office with your precise requirements.
What a pity. What we are using is multi-stage authentication as the token comes with a cell phone text message after having entered a password.
Are there any future plans for providing a CheckPoint Linux solution to cover this scenario? At least for Ubuntu and Fedora?
There are no plans to develop a native Linux VPN client.
Formal support for StrongSWAN is planned for R81 and I can’t say if it will include MFA support.
Recommend getting involved in the Production EA.
Existing formal support is limited to a customer release on R80.30.
The links Val provides above are community-developed instructions.
Using the Plugin L2TP with NetworkManager works also with 2FA. Make sure you use the latest Plugin version.
Configuration see here: https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494
I just verified it, I have a FreeIPA Server connected to the Check Point using LDAPS. On the FreeIPA all users have a password and OTP (it is included in FreeIPA). It also works if you have RSA Token or any Radius Connection combined with Active Directory etc.
But it won't work with SMS, or if you get the SMS before you initiate the connection which is very unlikely.
Unfortunately, we are using text messages (SMS) as the second factor. So this won't work for me.
We also try to use certificate based VPN connections with device certificates. The problem here is that our Checkpoint VPN teams knowledge is very limited when it comes to details.
There are many questions left such as:
General questions:
L2TP Questions:
Can I extract answers to these questions from the Windows or Android Checkpoint client? What do I need from our Checkpoint VPN team?
With L2TP over IPSec I don't use any Certificates at all.
General questions:
L2TP Questions:
For the Check Point configuration you can check here:
https://community.checkpoint.com/t5/Remote-Access-VPN/C2S-L2TP-over-IPSEC-Linux-VPN-with-R80-30-work...
For L2TP Configuration with Network Manager, see here:
https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY