- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello
When implementing MFA and Radius authentication such as Dou/OKTA in a multi sites scenario.
is the user getting a separate MFA request for each gateway when accessing a resource that is behind it even when password caching is defined ?
Thanks
Yes. In our testing of MFA using MS Authenticator this was the case. At this time I don't know if there is a resolution to this issue. Deeper investigation into our setup showed that MS NPS (Radius Server) could not take into account any previous session information. So users saw Authenticator prompts everytime the VPN client connected to a Secondary Gateway.
I think mileage may vary depending on the radius server implementation as I know that some radius implementations can account for existing sessions and then by-pass the MFA request.
It would be great if CP could let us know what if anything is on the roadmap for this MFA use case. I would certainly welcome a resolution.
The challenge here is around the fact that each secondary GW is not aware of the second factor entered by the primary GW. In a RADIUS example the VPN treat the authentication as black box and passes the challenges to the client till the RADIUS server is done.
So the options are:
1. Make the RADIUS server aware of prior authentications and not prompt second factor
2. Work towards having SAML based authentication in the client in order to leverage the IDP SSO.
Well said. Thanks.
When will number 2 above make it into a product release? This seems the best direction forward.
Thanks
I guess SAML can be the solution since RADIUS/RADIUS proxies can support session cookie to bypass the second MFA authentication.
But, which version of CP and client support SAML..?
Hi,
For general availability: The next R80.40 Jumbo should have the SAML capabilities (should be released before the end of the month) and the Client side GA should be released in the next few days.
For Customer Release - one is available through Solution Center for several months now.
Thanks Tzvi
I will wait till the end of the month to test both
Just one more question..
Is there a best practice recommendation to implementing/not implementing "Secondary Connect"?
I think that secondary connect is a more "Slick" solution than routing the traffic via the STS..
But maybe I am wrong here?
Is this in take 102?
I have tried to look for the specific support in the release notes ..
Hi,
It should be in the next take following 102, it seems it had yet to be released. Stay tuned, since I understand it should be released shortly.
Thanks
Thank!
Hello,
R80.40 JHF T114 was released with SAML support for RA IPsec VPN
Thanks for the update!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 14 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY