Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ildar07
Explorer
Jump to solution

Second factor from Radius (MFA)

Hello.

We have Checkpoint on R77.30. And we want to use multi factor authentication for endpoint VPN clients.

We already have MFA with ASA. MFA based on freeradius with LinOTP. It work fine on ASA: with first factor VPN user input AD credentials and radius check user in AD, and if user is checked radius send challinge response - user see another window. He enter TOTP pin and get authorize.

But when we use same server for checkpoint - it dont work. Second window do not appear. It is looks like checkpoint do not understand "Access-Challenge" from Radius server. This is true?

0 Kudos
2 Solutions

Accepted Solutions
the_rock
Legend
Legend

It does work, I used it before. But again, you are on totally unsupported version, so you would not be able to get any TAC help if needed.

Andy

View solution in original post

0 Kudos
PhoneBoy
Admin
Admin

If the user enters their password followed by the MFA code in the password field, it should work.
An "Access Challenge" prompt in RADIUS is currently not supported.

View solution in original post

5 Replies
the_rock
Legend
Legend

R77.30, hope you know its long time not supported. But, lets see if we can help. Can you send some screenshot of the config for this?

Andy

0 Kudos
Ildar07
Explorer

Configurations is very simple. I use Radius server for Authentication VPN Users in VPN settings. And I just want to know: does the checkpoint understand "Access-Challenge" from Radius server?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

In some configurations you need to append the password+code together.

Again R77.30 is EOL.

 

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

It does work, I used it before. But again, you are on totally unsupported version, so you would not be able to get any TAC help if needed.

Andy

0 Kudos
PhoneBoy
Admin
Admin

If the user enters their password followed by the MFA code in the password field, it should work.
An "Access Challenge" prompt in RADIUS is currently not supported.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events