- Products
- Learn
- Local User Groups
- Partners
- More
Access Control and Threat Prevention Best Practices
5 November @ 5pm CET / 11am ET
Ask Check Point Threat Intelligence Anything!
October 28th, 9am ET / 3pm CET
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
Spark Management Portal and More!
Hello,
We have configured Identity Provider Authentication for remote access vpn users.
When we login with Check Point Mobile App for Windows we have the following options.
What we want is to remove the "Standard" login option.
At Gateway Cluster Properties -> VPN clients -> Authentication -> Multiple Auth Clients Settings the configuration is the below.
Thank you
You can remove it from gateway properties, I cant recall what its called, I believe username/password, but will check later in the lab.
Andy
Hello,
I can remove the username/password. The MFA becomes default authentication method, but "Standard" still remains.
I can't find any tab to remove it.
Thanks
I believe this is what you need to uncheck.
Andy
Hi Andy,
I have already done this without success. The Authentication method at your screenshot is the legacy one. We have configure it as "Username and Password", does it matter?
Thanks
Which Authentication method is presented after choosing Standard ?
Can you please send screenshots of how thats configured? Please blur out any sensitive info. I know 100% this is possible, as I had done it before, just cant recall now exactly how...
Andy
Sure. The current one is the below.
I did uncheck the box, as below, but the "Standard" authentication method still appears at the mobile client
Here is what I just tested in the lab and worked fine, does NOT show standard in the list anywhere. I dont believe you would need to delete/re-create VPN site just for this, but to test that theory, you can have one user try and see result they get.
Kind regards,
Andy
Hello,
Based on your test the authentication method must be "Defined on user record (legacy)". Unfortunatelly I cannot change the authentication from "Username and password" and I will explain why.
We have connected more than one domains with the firewall. In these domains there are same sam account names (eg test@domain1, test@domain2 etc). In this case with authentication method "Defined on user record (legacy)", when a vpn user enters credentials at the Mobile app, search takes place only in one domain.
However, I tested with authentication "Username and Password" and it works only if site is recreated. It this case "Standard" authentication method is disapperared. It is ok for my case.
Thank you very much for the assistance.
In that case, maybe contact TAC and do remote session to find the best option. Its not really feasible to ask your users to delete/re-create the site. I know in the past, with one large cusotmer we have, couple of my colleagues had to do some modifications in trac.config file and push it via GPO to make things work.
Best regards,
Andy
Sure. It would be very helpful if the site has not to be recreated.
I will contact TAC and come back with solution.
Thanks
I think say if you had dozens of users, not a big deal, but if company has 100s of employees, its not a scalable "solution".
Let us know what TAC tells you.
Best regards,
Andy
Hello,
Sure, I will come back with feedback.
I more question please.
Can I restrict remote access vpn access from Capsule VPN for mobile (Android & IOS) based on username that users login?
This is because, when Identity provider authentication is selected, 2MFA is not working in R81.10. This is gonna be solved in take 113(it is not recommended right now).
Not that I know of. I would wait for jumbo to be recommended.
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
3 | |
3 | |
2 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Wed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesWed 22 Oct 2025 @ 11:00 AM (EDT)
Firewall Uptime, Reimagined: How AIOps Simplifies Operations and Prevents OutagesTue 28 Oct 2025 @ 11:00 AM (EDT)
Under the Hood: CloudGuard Network Security for Google Cloud Network Security Integration - OverviewAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY