Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Eric_Smith
Participant
Jump to solution

Unique Radius Situation

I have a scenario where we need to have RADIUS Authentication for access to CLI and WEBUI for Firewalls and the SMS.

The Scenario requires that Multiple Companies be able to access the CLI and WebUI using different RADIUS Servers.

I know that for example in Smart Console you can create a user and then Select the Authentication method as RADIUS and point to a specific radius server. For Example -- Testuser1 can Authenticate using Radius Server 10.1.1.1 and Test User 2 can Authenticate using Radius Server 172.16.1.2

Is there a way to do this for CLI and WEBUI access? 

In the Gaia WebUI under User Management -> Authentication Servers, it appears that you can only add one Authentication Server and then only by Priority.

What I am looking for is to allow Company users to access the WebUI and CLI using an Internal RADIUS Server and Support Users to access it using a different Radius Server. Is this possible, is there a better way to go about configuring this?

0 Kudos
2 Solutions

Accepted Solutions
Bob_Zimmerman
Authority
Authority

It's possible at a technical level. Check Point's OS is based on Red Hat Enterprise Linux, and it uses pam_radius for OS-level RADIUS authentication. Significant RADIUS config isn't supported, but it works.

View solution in original post

(1)
PhoneBoy
Admin
Admin

Like @Bob_Zimmerman said, the underlying OS should support this through PAM configuration.
However, it's not something we formally support.
Might be worth an RFE with your local Check Point office.

View solution in original post

5 Replies
the_rock
Legend
Legend

Personally, dont believe thats possible, but I could be wrong. Maybe someone else can confirm.

Andy

0 Kudos
Bob_Zimmerman
Authority
Authority

It's possible at a technical level. Check Point's OS is based on Red Hat Enterprise Linux, and it uses pam_radius for OS-level RADIUS authentication. Significant RADIUS config isn't supported, but it works.

(1)
Chris_Atkinson
Employee Employee
Employee

I've seen similar done in the past using an intermediate Radius proxy that forwards to the correct radius server based on domain/realm.

CCSM R77/R80/ELITE
0 Kudos
the_rock
Legend
Legend

It sure is very interesting question...if there is an sk or document how to do this, would be great to share it.

Andy

PhoneBoy
Admin
Admin

Like @Bob_Zimmerman said, the underlying OS should support this through PAM configuration.
However, it's not something we formally support.
Might be worth an RFE with your local Check Point office.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events