<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICA Management Tool in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14676#M96295</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition, I do have SSL enabled. Should I disable it as you said above?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Apr 2018 12:46:59 GMT</pubDate>
    <dc:creator>Jack_Prenderga1</dc:creator>
    <dc:date>2018-04-12T12:46:59Z</dc:date>
    <item>
      <title>ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14673#M96292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try create and download certificates, or edit the CA settings, I get this&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The URL you requested could not be found on this server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is when I am connected to the ICA management tool on 18265.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any advice?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 11:07:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14673#M96292</guid>
      <dc:creator>Jack_Prenderga1</dc:creator>
      <dc:date>2018-04-12T11:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14674#M96293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The&lt;STRONG&gt; ICA Management Tool&lt;/STRONG&gt; is disabled by default. You can &lt;STRONG&gt;enable it&lt;/STRONG&gt; on the CLI of your SmartCenter Server.&lt;/P&gt;&lt;P&gt;Example: &lt;STRONG&gt;cpca_client set_mgmt_tool on -no_ssl&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Access the WebUI of your ICA Management Tool via :&lt;STRONG&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://" rel="nofollow"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;ip-of-your-smartcenter&amp;gt;:18265&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;cpca_client [-d] set_mgmt_tool on|off [-p &amp;lt;ca_port&amp;gt;] [-no_ssl]&lt;BR /&gt;[-a|-u "administrator|user DN" ... ]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; * on starts the ICA Management Tool (on port 18265)&lt;BR /&gt;&amp;nbsp; * off stops the ICA Management Tool&lt;BR /&gt;&amp;nbsp; * -p specifies a different port to access the ICA Management Tool&lt;BR /&gt;&amp;nbsp; * -no_ssl starts the ICA Management Tool on http instead of https&lt;BR /&gt;&amp;nbsp; * -a "administrator DN"&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Sample screenshot:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="" src="https://indeni.com/wp-content/uploads/2015/08/download-59.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If your issue remains, try to work on CLI only by using the following commands:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cpca_client lscert&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cpca_client create_cert&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;cpca_client revoke_cert&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:37:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14674#M96293</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-04-12T12:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14675#M96294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Danny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is enabled. I can connect to the tool, and get the same pages as you provided. Whenever I try download a certificate, it comes up the error above. A few other parts to the site display the same error too.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if I did it via clish, how would I download the cert? Or retrieve it?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:46:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14675#M96294</guid>
      <dc:creator>Jack_Prenderga1</dc:creator>
      <dc:date>2018-04-12T12:46:28Z</dc:date>
    </item>
    <item>
      <title>Re: ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14676#M96295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In addition, I do have SSL enabled. Should I disable it as you said above?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:46:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14676#M96295</guid>
      <dc:creator>Jack_Prenderga1</dc:creator>
      <dc:date>2018-04-12T12:46:59Z</dc:date>
    </item>
    <item>
      <title>Re: ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14677#M96296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's what I suggested to try. May I ask what you are trying to do with the ICA Management Tool that SmartDashboard can't?&lt;/P&gt;&lt;P&gt;You would copy certs off your SmartCenter's CLI &lt;A _jive_internal="true" href="https://community.checkpoint.com/thread/5574-howto-creating-an-scpuser-account-on-gaia-clish"&gt;via scp of course.&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 12:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14677#M96296</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-04-12T12:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14678#M96297</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You maybe able to help me here actually.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am setting up the authentication for mobile remote access. I want all corporate machines, connection to the IPSEC VPN to have a personal certificate, and also RADIUS auth.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know there is an option under multiple auth for cert+user and password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the 'personal certificate' part needs to be created by the internal CA, hence why I am trying to log into the ICA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I doing this wrong? I want 1 generic certificate that I can generate and deploy via group policy to all corporate machines, so non-corporate machines can not connect, regardless if they can authenticate via RADIUS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Would this work?&lt;/P&gt;&lt;P&gt;2) Is this the best way to do it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Danny - your help is appreciated. I feel like I am running around in circles at the moment.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:17:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14678#M96297</guid>
      <dc:creator>Jack_Prenderga1</dc:creator>
      <dc:date>2018-04-12T13:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14679#M96298</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Typically you'd create personal certificates within SmartDashboard within the User Properties of your User Accounts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="64584" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64584_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:27:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14679#M96298</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-04-12T13:27:51Z</dc:date>
    </item>
    <item>
      <title>Re: ICA Management Tool</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14680#M96299</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Okay, I have a question for you then.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, as above, we need a certificate for machines, not users. We may have multiple users over the year using the same corporate laptop. We need 1 certificate we can deploy across all corporate machines, so its locked and stored there, and deployed via group policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I did it that way, through SmartDashboard, how could I create 1 generic one for machines, and not tie it to single users? We have over 4000 employees, and 3000 corporate laptops. Obviously it would be impossible deploy a certificate for every user, or every machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1 generic one would do the trick. Any clues?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:34:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/ICA-Management-Tool/m-p/14680#M96299</guid>
      <dc:creator>Jack_Prenderga1</dc:creator>
      <dc:date>2018-04-12T13:34:19Z</dc:date>
    </item>
  </channel>
</rss>

