<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic External access to internal RDS gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/External-access-to-internal-RDS-gateway/m-p/152921#M25558</link>
    <description>&lt;P&gt;Good evening,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firstly, apologies if I've attached this to the wrong board!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking at how we can use our R80.40 cluster to control external 3rd party access to our internal RDS gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to integrate the solution to AAD for authentication/MFA using SAML. Browser Based Authentication seems like a good way to go with this, but I'm not sure how the gateway would handle the traffic. For example, if user A authenticates to the gateway from IP x.x.x.x, is user B also forced to authenticate if they connect to our gateway from the same IP? Our concern is if two users happen to connect to the gateway from the same remote location which is being NAT'd behind the same public IP, are both users forced to authenticate? Or does one authentication request from that source IP consequently allow traffic from any other hosts NAT'd behind the same IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, are there any other solutions for this remote access that can integrate with AAD using SAML on an R80.40 gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As always, any advice would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aaron.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Jul 2022 19:04:23 GMT</pubDate>
    <dc:creator>AaronCP</dc:creator>
    <dc:date>2022-07-13T19:04:23Z</dc:date>
    <item>
      <title>External access to internal RDS gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/External-access-to-internal-RDS-gateway/m-p/152921#M25558</link>
      <description>&lt;P&gt;Good evening,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firstly, apologies if I've attached this to the wrong board!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are looking at how we can use our R80.40 cluster to control external 3rd party access to our internal RDS gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We would like to integrate the solution to AAD for authentication/MFA using SAML. Browser Based Authentication seems like a good way to go with this, but I'm not sure how the gateway would handle the traffic. For example, if user A authenticates to the gateway from IP x.x.x.x, is user B also forced to authenticate if they connect to our gateway from the same IP? Our concern is if two users happen to connect to the gateway from the same remote location which is being NAT'd behind the same public IP, are both users forced to authenticate? Or does one authentication request from that source IP consequently allow traffic from any other hosts NAT'd behind the same IP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, are there any other solutions for this remote access that can integrate with AAD using SAML on an R80.40 gateway?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As always, any advice would be greatly appreciated!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Aaron.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jul 2022 19:04:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/External-access-to-internal-RDS-gateway/m-p/152921#M25558</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-07-13T19:04:23Z</dc:date>
    </item>
    <item>
      <title>Re: External access to internal RDS gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/External-access-to-internal-RDS-gateway/m-p/152932#M25559</link>
      <description>&lt;P&gt;Browser Based Authentication is really only for internal hosts, not necessarily external ones.&lt;BR /&gt;And, in your case, if one person authenticates from a specific IP, all users who appear to be coming from that IP would also be allowed.&lt;/P&gt;
&lt;P&gt;A better solution from a remote site would be something like Mobile Access Blade, which would authenticate each user.&lt;BR /&gt;This should be able to integrate with AAD via SAML authentication.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2022 02:04:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/External-access-to-internal-RDS-gateway/m-p/152932#M25559</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-14T02:04:16Z</dc:date>
    </item>
  </channel>
</rss>

