Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Hllrdm
Contributor

Blocking two-factor authentication on Check Point Mobile

We have dual user authentication configured through an external SMS gateway that sends SMS messages to pass the second authentication for access via Check Point Mobile.
We need to restrict SMS texting to users who are not in the LDAP Remote Users group.

We explicitly set the LDAP group in the Access Role, User Group, LDAP Group in the Check Point rule, and we also specified the LDAP group in the Remote Access object.

But users still get text messages and after entering a text message, access via Check Point Mobile disappears "Negotiation with site failed". Is there an option at Check Point to check the LDAP group first and if the user is found in the LDAP group, then an SMS message is sent to him afterwards?

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

You need to define multiple login options: one that just does the LDAP lookup, and one that does both LDAP plus SMS.
The client will be able to choose which authentications scheme to use.
Refer to the Configuring Multiple Log-in Options section of: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_MobileAccess_AdminGuide/Topi...

Hllrdm
Contributor

We only need to use two-factor authorization. The first factor is LDAP, the second SMS.
No LDAP/two-factor authentication option.
Is this option available to solve the original problem?

0 Kudos
PhoneBoy
Admin
Admin

I suspect it may be trying both authentication methods and only confirming you matched both at the end.
It's possible this is a bug and you should contact the TAC.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events