- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I need a little help. I want to apply a second authenticaiton factor to my C2S connections, actually the users connects to de VPN by Endpoint security VPN, they use their credentials from AD, now I want to set up a second factor using a RADIUS server that generates a token. Lets illustrate my scenario:
Scenario
So the thing I want and hope is, Client communicates with FW, FW asks AD server for identities, then FW asks RADIUS for token and thats it, so what I configured is this:
Configure a new multiple options, first username, then RADIUS
1st factor configuration
2nd factor configuration
AND! is not working, after authenticate with AD, it asks for a user, I thought it was the token but wasn't, dont know if this is the correct configuration, can you help me on how to start the troubleshooting?
I read that there is some configuration that let me use pass+token, but i cant make it works, or maybe configure.
Thanks in advance.
Hi,
so the vpn client is asking 1st for username and password, than for username and token/otp?
What solution do you use there? Where does that get it´s users, from AD? Do you see unsuccessful logins on the Radius Server?
is the Gateway defined as Radius Client on the server?
Are you able to authenticate with otp using tools like NTRadping on your local machine?
Daniel
Hi
so the vpn client is asking 1st for username and password, than for username and token/otp?
Asking for user/pass, then for a user, no more.
What solution do you use there? Where does that get it´s users, from AD? Do you see unsuccessful logins on the Radius Server?
A solution from NetIQ.
If you're talking about where the fw gets users, from AD, the Radius is just for generate the OTP, it should be getting users from de AD?
Cannot confirm at this moment the logins on radius server
is the Gateway defined as Radius Client on the server?
AFAIK, yes.
Are you able to authenticate with otp using tools like NTRadping on your local machine?
No response.
Thanks
Ok, when you then just enter the username again, you might get asked for the OTP, or something?
At NetIQ you have to configure a user store (they call it repository) to bind i.e. a token to a particular user. otherwise the solution cannot validate the token you entered. In most cases this solutions are using the Active Directory too. yes.
As I read, NetIQ is Linux based, you might want to check the logs mentioned here:
or here:
if you get any failed requests.
Are you able to check if Config on NetIQ is OK?
https://www.netiq.com/documentation/advanced-authentication-62/server-administrator-guide/data/t4399... (yes it is saying fortinet, but that should not be that important here) check point should be defined here as Radius Client. Doublecheck the Pre Shared Key/Secret. if this is incorrect, authentication fails too.
Ok, when you then just enter the username again, you might get asked for the OTP, or something?
No, it just says, wrong username or pass. From this point, what you're saying about bind a user with a token from NetIQ is a very very posible reason, let me check that.
THANKS
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY