< Back
You are here:

HOW TO CONFIGURE OCTOPUS AUTHENTICATOR FOR CHECK POINT VPN

Preface

This document describes the configurations required for RADIUS integration between the Octopus Authenticator and Check Point VPN Connection.

Octopus Authenticator RADIUS Service Configuration

  • Login to Octopus Authenticator Management Console
  • Select Services from the left pane
  • Select Add Service
  • Click RADIUS service template

Tab-1: General Information

The following field and values are displayed

Field name Field value
Service name Check Point VPN
Issuer Check Point
Description Check Point VPN client Authentication
Service status Enable
Display icon

Tab-2: Parameters

The following fields and values are displayed

Field name Field value
Login Login authentication method for Check Point VPN
RADIUS key name NAS-IP- Address
RADIUS key value <Check Point Server IP address or 0.0.0.0>
+ Add additional parameter Do not add any parameters

Tab-3: Sign On

The following fields and values are displayed

Field name Field value
Multi Factor Authentication (MFA) Off (default)
Sign on Method RADIUS
Secret <Check Point RADIUS Secret code>
Custom Message Check Point VPN authentication

Step-4: Users

To configure the users of the service

  • Select users either from “Local Users” or “LDAP Users” lists
  • You can select either:
    • A group of users to import, by clicking on the dot next to one of the folders
    • An individual user to import, by clicking on the dot next to that user

The corresponding dot will then be colored blue. When you select only some of the users in the group,
the dot adjacent to the group will be colored partially.

After saving the settings, the selected users will be enrolled in the service.

  • Click “Save Settings

Check Point VPN RADIUS Configuration

  • Login to your Check Point VPN server console

  • From System dashboard page Select VPN tab

  • Under VPN page select Authentication Servers

  • Under RADIUS Servers click to open Primary Radius Server configuration and enter:
    • IP address: Your Octopus Authenticator Server IP address or name
    • Port: In Octopus Authenticator Management console -> System settings -> Services settings -> copy RADIUS port value
    • Shared Secret: In Octopus Authenticator Management console -> System settings -> Services settings -> Show and copy RADIUS secret value
    • Timeout (in seconds): 60

  • Click “Apply

Check Point VPN Client Configuration

Prerequisite

  • Download and install Check Point VPN client (also known as Capsule)

  • Under Windows Settings Select Network & Internet settings

  • Select VPN

  • Add VPN connection

  • Enter VPN connection configuration:
    • VPN provider
    • VPN connection name
    • VPN Server name or IP

  • Click “Save