Firewall-1

Re: [FW-1] Authentication schemes: RADIUS vs Checkpoint certificate

Subject: Re: [FW-1] Authentication schemes: RADIUS vs Checkpoint certificate
From: Lars Troen <Lars.Troen AT SIT DOT NO>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Date: Fri, 27 Jan 2006 23:27:08 +0100
 
> 
> Reinhard is partially correct.  Radius is "single-factor" 
> unless you are talking
>   RSA radius then it is "fwo-factor" because RSA radius uses 
> the PIN+passcode.
>    
RSA preferably uses SecurID in order to support rekeying. But you *may*
set it up to use Radius instead, but you rather not do it in case a
token gets out of synch. But cisco4ng *IS* still right. Most two factor
authenticators uses Radius as the primary protocol while some of them
might support others as well (tacacs).

Lars

=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================

<Prev in Thread] Current Thread [Next in Thread>