Hi,
I have configured mobile access on my CP Gateway. I want the primary authentication for the SSL VPN users to be locally created 'Username and Password' on the Checkpoint GW and the secondary authentication to be 2FA (For eg. Duo). So, there will be 2 authentication factors 'Username and Password' and 'Radius'. Has anyone tried this?
For this, I have configured Multiple authentications on Mobile Access > Authentication. Please refer to the attached screenshot.
If the primary authentication was through Radius Server or AD, then it won't be a problem as I only have to select my Authentication method on Mobile Access as 'Radius' and my 2FA (Duo) would handle AD or Radius authentication and once verified, it generates a token or sends a push notification.