<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Agent Untrusted Gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/183894#M33737</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm interested to get more feedback about this process.&lt;/P&gt;&lt;P&gt;We are also familiar with the Distributed Configuration which basically stored this info in the AD and avoid this Trust message&lt;/P&gt;&lt;P&gt;However when it's time to renew the certificate how do you proceed ?&lt;/P&gt;&lt;P&gt;We have about 65 GW where we need to change the certificate manually (no automation / api or script if I'm not wrong) ?&lt;/P&gt;&lt;P&gt;Also not able to add in advance the new Fingerprint (Not possible to have 2 registry key with same name) and same issue with the Distributed Configuratin. It doesn't allow to add a second certificate with the same FQDN and a different Fingerprint&lt;/P&gt;&lt;P&gt;Any idea ?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Tue, 13 Jun 2023 14:58:36 GMT</pubDate>
    <dc:creator>CP-NDA</dc:creator>
    <dc:date>2023-06-13T14:58:36Z</dc:date>
    <item>
      <title>Identity Agent Untrusted Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91140#M10861</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;I am using R80.10 on 23500 appliances.&lt;BR /&gt;I want use Identity Awareness Blade, actually almost everything working good expect Identity Agent SSL Certificate.&lt;BR /&gt;When I install identity agent on a Windows there is a Warning Message on status of agent.&lt;/P&gt;&lt;P&gt;My SSL certificate is looks like OK. If I click Trust everything working perfect. But while the installation like VPN is not sending any message to user for this trust relationship. It is just waiting in here, every user have to open up the status of agent and click Review after that click Trust. The users are do not know what is mouse so they can not do this clicking steps and we are talking about 20k active users.&lt;BR /&gt;Browser-Based Authentication works fine with same certificate.&lt;BR /&gt;My certificate is validated but I am still having this issue.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Ekran Resmi 2020-07-09 14.12.51.png" style="width: 663px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7217i2EDBC932E487360E/image-size/large?v=v2&amp;amp;px=999" role="button" title="Ekran Resmi 2020-07-09 14.12.51.png" alt="Ekran Resmi 2020-07-09 14.12.51.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 11:34:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91140#M10861</guid>
      <dc:creator>sukruozdemir</dc:creator>
      <dc:date>2020-07-10T11:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Untrusted Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91144#M10862</link>
      <description>&lt;P&gt;This is normal. Just press "Trust" and move on. Browser based CA trust is using a different repository. Agent's trust is relying on registry entry, which will be created when you press "Trust"&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 11:59:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91144#M10862</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-07-10T11:59:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Untrusted Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91145#M10863</link>
      <description>Hello Val&lt;BR /&gt;But my users are really bad using computer so thousands of them can not right click on agent, open up satus, click Review and click Trust.&lt;BR /&gt;Why it is not showing me a pop up while connecting or installing the agent for this trust relationship like Endpoint Security VPN.&lt;BR /&gt;Does every user in the world using Identity Agent have to click Trust?</description>
      <pubDate>Fri, 10 Jul 2020 12:06:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91145#M10863</guid>
      <dc:creator>sukruozdemir</dc:creator>
      <dc:date>2020-07-10T12:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Untrusted Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91152#M10864</link>
      <description>&lt;P&gt;You can prevent this problem for your users by predeploying the trust.&lt;/P&gt;&lt;P&gt;There are multiple ways to do so and Identity Awareness Admin Guide is showing you how.&lt;/P&gt;&lt;P&gt;For a very quick workaround for your 20k users: Deploy the following registry key using you client software management plattform (SCCM or something like that):&lt;/P&gt;&lt;P&gt;HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\CheckPoint\IA\TrustedGateways\...&lt;/P&gt;&lt;P&gt;Just copy the needed content of this hive key from a client, where the trust button is already pressed.&lt;/P&gt;&lt;P&gt;For the future, just bundle the needed registry keys with the agent installer. You can manipulate the agent installer msi file do include this trust. Just patch it using the IA config tool. See Identity Awareness Admin Guide for details.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jul 2020 13:02:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91152#M10864</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2020-07-10T13:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Untrusted Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91282#M10865</link>
      <description>This one is perfect.&lt;BR /&gt;I have learned lots of things , thanks to you.</description>
      <pubDate>Mon, 13 Jul 2020 06:13:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/91282#M10865</guid>
      <dc:creator>sukruozdemir</dc:creator>
      <dc:date>2020-07-13T06:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Untrusted Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/183894#M33737</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm interested to get more feedback about this process.&lt;/P&gt;&lt;P&gt;We are also familiar with the Distributed Configuration which basically stored this info in the AD and avoid this Trust message&lt;/P&gt;&lt;P&gt;However when it's time to renew the certificate how do you proceed ?&lt;/P&gt;&lt;P&gt;We have about 65 GW where we need to change the certificate manually (no automation / api or script if I'm not wrong) ?&lt;/P&gt;&lt;P&gt;Also not able to add in advance the new Fingerprint (Not possible to have 2 registry key with same name) and same issue with the Distributed Configuratin. It doesn't allow to add a second certificate with the same FQDN and a different Fingerprint&lt;/P&gt;&lt;P&gt;Any idea ?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2023 14:58:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Untrusted-Gateway/m-p/183894#M33737</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2023-06-13T14:58:36Z</dc:date>
    </item>
  </channel>
</rss>

