- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I have the following requirement:
If I'm not mistaken machine authentication with Identity agent is only working with Kerberos.
But if Kerberos is active, also the user is authenticated using Kerberos und with that we are not using MFA to authenticate the user, as the Radius is skipped.
Any chance we get the machine identity using Kerberos and don't allow user logon with Kerberos to force Radius auth?
Are you refering to VPN authentication? Or do you want the user to authenticate to the gateway via MFA after logging into the OS?
The Identity Agent is designed as an SSO solution afaik, so i'd suggest you require the user to use MFA to login to the OS and then trust the credentials "transitively".
It has nothing to do with VPN.
I know that the identity agent can be used for SSO with Kerberos. But without it you can use any authentication but then the machine identity is not recognized.
Hence my question if it is possible to use only SSO with kerberos for machine identity but authenticate the user otherwise...
Thats interesting inquiry. Im not aware if you can configure that on basic settings via gateway auth methods, you may wish to contact TAC to confirm this 100%.
Seems like you might be able to change the default behavior here using the PDP Conciliation feature in R80.40+.
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
Currently requires a TAC case for the precise configuration.
Also paging @Royi_Priov in case he has a better idea.
PDP conciliation helps in distinguishing between different sources but in this case. It's only the agent. So I assume it will not help.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 18 | |
| 8 | |
| 7 | |
| 3 | |
| 3 | |
| 3 | |
| 3 | |
| 3 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY