- Products
- Learn
- Local User Groups
- Partners
- More
Introduction to Lakera:
Securing the AI Frontier!
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Is there any way to connect to an enterprise VPN using L2TP over IPSEC in combination with 2 factor authentication under a recent Linux Desktop Distribution like Ubuntu?
Ubuntu provides the package network-manager-l2tp-gnome that could work but I still do not manage to etablish a connection because there seems to be no 2FA handling.
Anyone has such a setup working?
We support use of strongSwan (Roadwarrier) and Libreswan 3.23, but not sure about 2FA
Thanks for your quick reply. I do consider myself as capable of configuring Libreswan but I do need to know if there is a chance for the 2FA (SMS token) part.
You would need to be able to enter the password in one go (fixed password plus your MFA code) if it were to work at all.
There is no handling for multi-stage authentication that I'm aware of.
I would approach your local Check Point office with your precise requirements.
What a pity. What we are using is multi-stage authentication as the token comes with a cell phone text message after having entered a password.
Are there any future plans for providing a CheckPoint Linux solution to cover this scenario? At least for Ubuntu and Fedora?
There are no plans to develop a native Linux VPN client.
Formal support for StrongSWAN is planned for R81 and I can’t say if it will include MFA support.
Recommend getting involved in the Production EA.
Existing formal support is limited to a customer release on R80.30.
The links Val provides above are community-developed instructions.
Using the Plugin L2TP with NetworkManager works also with 2FA. Make sure you use the latest Plugin version.
Configuration see here: https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494
I just verified it, I have a FreeIPA Server connected to the Check Point using LDAPS. On the FreeIPA all users have a password and OTP (it is included in FreeIPA). It also works if you have RSA Token or any Radius Connection combined with Active Directory etc.
But it won't work with SMS, or if you get the SMS before you initiate the connection which is very unlikely.
Unfortunately, we are using text messages (SMS) as the second factor. So this won't work for me.
We also try to use certificate based VPN connections with device certificates. The problem here is that our Checkpoint VPN teams knowledge is very limited when it comes to details.
There are many questions left such as:
General questions:
L2TP Questions:
Can I extract answers to these questions from the Windows or Android Checkpoint client? What do I need from our Checkpoint VPN team?
With L2TP over IPSec I don't use any Certificates at all.
General questions:
L2TP Questions:
For the Check Point configuration you can check here:
https://community.checkpoint.com/t5/Remote-Access-VPN/C2S-L2TP-over-IPSEC-Linux-VPN-with-R80-30-work...
For L2TP Configuration with Network Manager, see here:
https://community.checkpoint.com/t5/Remote-Access-VPN/L2TP-over-IPSec-Linux-VPN/m-p/48860#M1494
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Tue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureTue 07 Oct 2025 @ 10:00 AM (CEST)
Cloud Architect Series: AI-Powered API Security with CloudGuard WAFTue 30 Sep 2025 @ 08:00 AM (EDT)
Tips and Tricks 2025 #13: Strategic Cyber Assessments: How to Strengthen Your Security PostureThu 09 Oct 2025 @ 10:00 AM (CEST)
CheckMates Live BeLux: Discover How to Stop Data Leaks in GenAI Tools: Live Demo You Can’t Miss!Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY