> Source: [sk184285](https://support.checkpoint.com/results/sk/sk184285)

# sk184285 - After Backup and Restore, Gaia Portal Enforces 2FA but Clish Allows Password-Only Login and do not Prompt for a 2FA Code

| Property | Value |
|----------|-------|
| Solution ID | sk184285 |
| Date Created | 2025-11-07 |
| Last Modified | 2026-09-10 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82, R81.20, R81.10 (EOS) |
| OS | Gaia |

## Symptoms

- * After restoring a Gaia system backup with Two-Factor Authentication (2FA) previously configured, the Gaia Portal enforces 2FA as expected.
* The clish (Command Line Interface shell) allows login with only a password and does not prompt for a 2FA verification code.
* This behavior contradicts the expected security policy, where both Gaia Portal and CLI shells (remote Secure Shell (SSH) / local console) should require 2FA after it is enabled.

## Cause

The Gaia backup process does not include the contents of the `/etc/2fa_keys/` directory by default.  
This directory stores user-specific 2FA configuration and key files required to enforce 2FA for CLI logins.  

When a system is restored from a backup (for example, after a factory reset), the missing `/etc/2fa_keys/*` files cause clish to revert to password-only authentication.  
The Gaia Portal continues enforcing 2FA because it uses a separate configuration source.  

This results in inconsistent authentication behavior and creates a potential security gap.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 44
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 126

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
