I like this feature out of Check Point. Two factor authentication, which you can do with most firewalls, is pretty cool. But I like that the Check Point will also generate you a one time password and send it to you for a second authentication method. Their documentation is terrible, but here is how to set it up.
Go to your Mobile Access blade and add your Check Point firewall in. Then, go down to the box circled above, and put in this string in the SMS provider and Email settings after you check the box for "challenge users...":
mail:TO=$EMAIL;SMTPSERVER=smtp.companyname.com;FROM=support@companyname.com;BODY=$RAWMESSAGE
Once you have configured this and you allow SSLVPN user access, the user will login successfully and then be sent a one time password. The email (in this case) will look like this:
Its not too hard to setup, but again, Check Points documentation is pretty terrible when it comes to this. But still a cool feature.
This is the retired Shane Killen personal blog, an IT technical blog about configs and topics related to the Network and Security Engineer working with Cisco, Brocade, Check Point, and Palo Alto and Sonicwall. I hope this blog serves you well. -- May The Lord bless you and keep you. May He shine His face upon you, and bring you peace.
Subscribe to:
Post Comments (Atom)
Hi. I have this configured...but can't seem to get TFA to work with the installed mobile access client.
ReplyDeleteAny thoughts?
Rob
Been a while since I did that. Not sure right off. May be a TAC call.
Deleteit's not really 2FA in an email and should be setup as SMS for 2FA.
ReplyDelete