This section describes how to integrate Check Point Gateway Identity Awareness with RSA Authentication Manager using RADIUS.
Configure RSA Authentication Manager
Perform these steps to configure RSA Authentication Manager using Radius.
Procedure
- Log in to Security Console.
- Go to RADIUS > RADIUS Servers and make a note of the IP address of the selected RADIUS server.
- Go to RADIUS > RADIUS Clients > Add New.
- On the Add RADIUS Client page enter the following details:
-
- Client Name: Enter a descriptive name for the Radius client.
- IPv4 Address: Enter the IP address of the Radius client.
- Make / Model: Select CheckPoint from the drop-down menu.
- Shared Secret: Create and enter a secure shared secret. This secret will be used for secure communication between the Radius client and the Radius server.
- Click Save & Create Associated RSA Agent.
- Click Save.
- Confirm by clicking Yes, Save Agent.
Notes
- RSA Authentication Manager RADIUS server listens on ports UDP 1645 and UDP 1812.
- The relationship of agent host record to RADIUS client in the Authentication Manager can 1 to 1, 1 to many or 1 to all (global).
- Shared Secret must be an alphanumeric string between 1 and 31 characters in length and is case-sensitive.
Configure Check Point Identity Awareness
Perform these steps to configure RSA Authentication Manager using Check Point Identity Awareness.
Procedure
- Log in to Check Point SmartConsole desktop application with admin credentials.
- From the left pane, go to Gateways & Servers tab.
- Double click the required deployed Check Point Gateway.
- In General properties of the gateway, ensure that Identity Awareness is enabled.
Note: If Identity Awareness is not enabled, follow the prompt to enable the service. During this process, the Identity Awareness portal URL will be configured, and end users will be redirected to it when Identity Awareness is triggered by the configured policies.
- In the Gateway & Servers tab, click New > More > Server > RADIUS.
- In the RADIUS Server window, go to Host choose the RADIUS server host.
Note: If the RADIUS server host is not yet configured in the dropdown list, create a new host by entering the Identity Router Management Interface IP address obtained from the RSA. Then, select the RADIUS service, which uses port 1812, and enter the shared secret that was configured in the RSA.
- In SmartConsole, click the Gateways & Servers panel.
- Open the Security Gateway object. In the left pane, click Identity Awareness, enable Browser-Based Authentication and select Settings.
- In the Access Settings, choose how end users will access this portal from to the following options:
- All interfaces
- Internal interfaces
- Firewall policy
- In Authentication Settings, select RADIUS as the Authentication Method.
- Select the RADIUS server configured previously from the dropdown menu.
- In the User Directories section, enter the following information:
-
- Internal users: In this configuration, the users authenticated against RSA must exist locally on the Check Point SmartConsole for authentication.
- LDAP users: In this configuration, the users authenticated against RSA must exist on a remote Active Directory server. Check Point must be configured to connect to it successfully to fetch the users according to the LDAP lookup for authentication.
Note: You must select the LDAP Lookup Type as mail.
-
- External user profiles: This configuration relies on users existing outside of Check Point and LDAP. However, you must create an external user profile to authenticate users correctly.
- In the Gateways & Servers main tab,
- Go to Global properties > Advanced > Configure > FireWall-1 > Authentication > RADIUS.
- Configure the values as shown in the following figure.
- In SmartConsole, click Publish.
- Select the applicable policy, and choose Access Control.
- Click Install to apply the Policy.
The configuration is complete.
Return to Main page
Related Articles
Check Point Gateway Identity Awareness- SAML Relying Party Configuration for Cloud Authentication Service - RSA Ready Impl… 27Number of Views Check Point Gateway - RSA Ready Implementation Guide 94Number of Views Check Point Gateway Identity Awareness - RADIUS Configuration for Cloud Authentication Service - RSA Ready Implementation … 40Number of Views Check Point Gateway Mobile Access Portal - RADIUS Configuration for Cloud Authentication Service - RSA Ready Implementatio… 25Number of Views Check Point Gateway Mobile Access Portal - RADIUS Configuration for Authentication Manager - RSA Ready Implementation Guide 43Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Release Notes for RSA Authentication Manager 8.8 RSA Authentication Manager 8.9 Release Notes (January 2026) Supported On-Demand Authentication (ODA) SMS providers for use with RSA Authentication Manager 8.x Deploying RSA Authenticator 6.2.2 for Windows Using DISM