- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Good Day to all,
we currently have our checkpoint endpoint vpn authentication which uses username, password and dynamicid which sends an sms to the user in order to complete the logon.
We would like to change the dynamicid portion to Microsoft's two factor authentication. I am aware that a radius server is needed for this, however is there an sk or guide which can help us out on how checkpoint can be configured for this?
Thanks in advance.
Which version are you using? Here are the r80.10 guides:
Further to the relevant sections of the admin guide please see:
sk114263: Can an Azure Multi-Factor Authentication Server be used as a RADIUS server for Mobile Access authentication?
Thank you for your guides will have a look at them.
Hello, curious if you succeeded in this configuration. I am on it as well with the aim of replacing an RSA AuthMgr.
Simo
Hi sorry for the late reply, we still haven't got on it yet but will let you know once we get it up and running.
Hello
Did you finally configure it?
BR,
Kostas
Hello,
fyi this setup implies:
1) download a RADIUS proxy VM from Microsoft and configure it to talk to our Azure tenancy MFA instance
2) point checkpoint to that internal RADIUS proxy as a MFA provider
I was expecting a more direct connection i.e. Checkpoint to my Azure MFA tenancy directly, but it is not the case.
I have not yet investigated aspects like: how does the system behave if Azure MFA is down or not reachable etc? Are there emergency connection procedures etc?
Best regards,
Simone
Hello Simone
Can you please kindly share checkpoint configuration and NPS configuration or some hints?
As concerns emergency procedure you could configure another Login option on checkpoint vpn client with one factor authentication.
BR,
Kostas
does Checkpoint support Azure mfa in the way it does for example duo ?
any help is appreciated
Thanks
Tom
See if this post can help you.
Good luck.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY