Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
stefan_o
Participant

VPN defined on user record not enforced

Hi all!

We have this settings on our FW R81.20 for VPN-Clients:

image.png

Then i have this user, which needs Radius but also has a certificate:

image.png

Radius (duo proxy) is used for MFA only.

image.png

Now when i connect with a VPN-Client and use the certificate the connection is working - i would expect to be asked for the 2nd factor via radius. 

Am i getting something wrong?

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

I'm fairly certain that if you're using "defined on user record" only one authentication method is supported.
You need to set up the Multiple Login Options to specify both Certificate and RADIUS are required.

simonemantovani

Hello

I agree with @PhoneBoy if you want to use DUO MFA with Radius, you should create a specific authentication method in Multiple login option and follow this link to confnigure authenticatio: https://community.checkpoint.com/t5/SASE-and-Remote-Access/Configuring-Checkpoint-Remote-VPN-for-MFA...

I always configured VPN with MFA (DUO and Radius) following the above link.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events