Hello mates! Sorry for my compare to Cisco but i have long time experience with cisco and short time with checkpoint.
I need to grant access to inside networks thought remote access vpn for two user groups, one group need to use OTP and have extended access, and other group no need to use OTP but tey have retricted access to most inside resources except few hosts.
On cisco ASA I create two tunnel groups, one with AAA server (LDAP) and second AAA server (Radius which generate and send OTP and/or check entered OTP) and other tunnel-group with single AAA server (LDAP).
After this I enable tunnel-group list and user can select tunnel group from list.
How can I do simmilar functionality on Checkpoint?
Thank You!