Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Herschel_Liang
Collaborator
Jump to solution

Mobile access VPN authentication question

The client found SNX local user password complexity is low, but it seem that password length can set 8 characters at most. He want to know that is there exist increasing password length/complexity way? Can it be true? If no, 1. budget allow, which MFA way you recommend; 2. no budget, which MFA way you can suggest to increase secure for SNX? How to config?

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin
For local passwords, there is no way to change/increase complexity requirements aside from using "OS Password" authentication: https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a...
Then you can leverage Gaia's password length/complexity requirements.

External authentication servers would need to be leveraged for any sort of MFA.
One option is Google Authenticator, which can be set up with FreeRADIUS on any Linux server.
Here's a writeup on how to set that up: https://community.checkpoint.com/t5/General-Topics/MFA-with-Google-Authenticator/m-p/39456#M8416

Most of the other "paid" MFA options would also integrate via RADIUS.
Okta and Duo are two options I've seen write-ups on.

View solution in original post

0 Kudos
2 Replies
PhoneBoy
Admin
Admin
For local passwords, there is no way to change/increase complexity requirements aside from using "OS Password" authentication: https://community.checkpoint.com/t5/General-Topics/Supporting-more-Complex-Passwords-without-using-a...
Then you can leverage Gaia's password length/complexity requirements.

External authentication servers would need to be leveraged for any sort of MFA.
One option is Google Authenticator, which can be set up with FreeRADIUS on any Linux server.
Here's a writeup on how to set that up: https://community.checkpoint.com/t5/General-Topics/MFA-with-Google-Authenticator/m-p/39456#M8416

Most of the other "paid" MFA options would also integrate via RADIUS.
Okta and Duo are two options I've seen write-ups on.
0 Kudos
Herschel_Liang
Collaborator
Test successfully. Very nice.
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events