- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check Point Remote Access Clients
Is Check Point IPSec-VPN Windows Client supported by RSA SecurID integration?
We have contacted RSA Support to validate this but can't seem to have a definite answer as they are relying/referencing only on the available documentation for Check Point (Check Point Remote Access Client - RSA SecurID Access Implementation Guide) which is SSL-VPN in RSA Ready list.
Appreciate the community response. Thank you!
- Tags:
- Community Thread
- Discussion
- Forum Thread
- Integration
- Integrations
- RSA SecurID
- RSA SecurID Access
- RSA SecurID Integration
- SecurID
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you are using R80.10, see Other Authentication Methods in the Check Point Remote Access VPN Admin Guide.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I have spent some hours integrating RSA CAS with a Checkpoint VPN, and have found some interesting conclusions, please see below.
According to the integration manual, you need to configure settings under "VPN Clients -> Authentication". But in some cases this is not available in the Smartconsole GUI, you need to first enable IPSec under "General Properties -> IPSec VPN"
In addition, for the Windows VPN client to work, it is necessary to enable "Ask user for password (will be used automatically answer the first)" under "VPN Clients -> Authentication" Settings button, otherwise the negotiation for the 2nd factor selection will fail, and you can only use the last valid factor for the user (either tokencode, push, biometrics, ...).
I think these points need to be included in the manual.
Kind Regards.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Nicanor Pulido - thanks very much for the feedback. Can you provide the Checkpoint version you are using?
Once I have that I can make sure your information is seen by our RSA Ready/Partner Engineering team.
Thanks,
Ted
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, sure.
The FW is a R80.10 and the VPN client version E82.50.
KR.
