- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: OTP alternatives to SMS in CheckPoint Applianc...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
OTP alternatives to SMS in CheckPoint Appliances with 2FA
Hi CheckPoint guys,
Since it seems that sending SMS is a bad idea, since hackers can intercept received SMS messages, some customers are asking us for other two-factor methods.
Are there any future plans to integrate checkpoint gateways with OTP systems like Google Authenticator or similar?
I mean without having to setup an external RADIUS server that can be tuned to integrate with these tools.
Thank you all.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey,
Dynamic ID should work with emails too. Access to the users mailbox can be secured via https and Microsoft ActiveSync.
You could also try to use time-based OTP, but all solutions I know would require a external radius server.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which product are you talking about?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For example a CheckPoint 1570 Appliance. With R80.20.10, we already have the option to use Two-Factor Authentication via SMS (Locally Managed), and it works very well. But some customers always want to go one step further xD
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Mr. Ramirez,
I am trying to implement Two-Factor Authentication via SMS on my 1590 appliance(Locally managed). I got my API ID and everything but I am having the hardest time making work and Check Point tech support is having an even more difficult time. Would you be so kind to tell me who is your SMS provider and the DynamicID URL that was used?
Thanks in advance!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Then i would have posted the question in SMB Appliances and SMP instead 😉 Compared to the GAiA appliances there are many restrictions, and currently, SMS is the only 2FA for SMB.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, the post is now moved to SMB 🙂
