- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- SMB - disable default username and password authen...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SMB - disable default username and password authentication
Hello Checkmates,
I found very useful information here about the SMB appliances and how to start Remote-Access VPN with certificate authentication. I'm curious to know is there a why to disable the default username and password authentication?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are correct. On SMB appliances it is only possible with 3rd party products. You can use a Radius server which takes care of the 2FA for you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to clarify - Now remote users can connect with SecuRemote VPN or Capsule VPN client with either Username and Password authentication or certificates. I want to force the clients to use only certificates and disable the username- password authentication for VPN at all.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
These are the methods to configure remote access users on locally managed SMBs:
• Local users
• RADIUS users
• AD users
Certificates are accepted (if known).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The answer is easy: CP password has a length between 4 and 8 characters and may contain no spaces . In times of 2FA this is rather a weak solution...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, 2FA will be the best, but as I see it is not natively supported on SMB appliances and is possible only with 3rd party products, or I'm missing such solution from Checkpoint?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You are correct. On SMB appliances it is only possible with 3rd party products. You can use a Radius server which takes care of the 2FA for you.
