<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Agent - Auto Detecting gateway in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53491#M10664</link>
    <description>Hi Martin,&lt;BR /&gt;&lt;BR /&gt;look for "Transparent Kerberos SSO Authentication for Identity Agent" in the Idendity Awareness Administration Guide.</description>
    <pubDate>Wed, 15 May 2019 08:59:44 GMT</pubDate>
    <dc:creator>Andreas_Aust</dc:creator>
    <dc:date>2019-05-15T08:59:44Z</dc:date>
    <item>
      <title>Identity Agent - Auto Detecting gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53486#M10662</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Below is the situation at one of our customers.&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Instructions for installation of identity agent on a computer&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;During installation (computer - not user) enter the ip address of the Check Point gateway, at the prompt accept the certificate&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt; Export the registry values:&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;EM&gt;Windows Registry Editor Version 5.00&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;EM&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\IA]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"CurrentVersion"="1.0"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"GlobalConfigEnabled"=dword:00000001&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"DefaultGateway"="c.d.e.f"&amp;nbsp;&amp;lt;altered&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"DefaultGatewayEnabled"=dword:00000001&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"PredefinedPDPConnRBUsed"=dword:00000000&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"PTInstDir"="C:\\Program Files\\CheckPoint\\Identity Agent\\"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"CaptivePortalsList"="&lt;A href="https://206.111.120.194;https:/NAU-FWC-NLRTM.nautadutilh.com;" target="_blank"&gt;https://a.b.c.d;https://gateway.domain.com;&lt;/A&gt;"&amp;nbsp;&amp;lt;altered&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"ClientDeviceID"="{C3E40EC9-6F84-4006-B5F8-7A00000000029}"&amp;nbsp;&amp;lt;altered&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"IsFirstTimeActivation"=dword:00000000&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\IA\1.0]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"CurrentSP"="0"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"PKGPATH"="C:\\WINDOWS\\Installer\\1214087.msi"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"PRODDIR"="C:\\Program Files\\CheckPoint\\Identity Agent\\"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"PRODUCT_GUID"="{F419A0AD-95C8-400C-B519-F9800000C4}"&amp;nbsp;&amp;lt;altered&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\IA\1.0\SP0]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"CurrentMSP"="0"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\IA\1.0\SP0\MSP0]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"PRODUCT_GUID"="{F419A0AD-95C8-400C-B519-F9800000C4}" &amp;lt;altered&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\IA\Shortcuts]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Configuration"="1"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"DistrConfiguration"="1"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"IdentityAgent"="1"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\IA\TrustedGateways]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[HKEY_LOCAL_MACHINE\SOFTWARE\CheckPoint\IA\TrustedGateways\Gateway VPN Certificate]&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Fingerprint"="xxxx xxxxx xxxx xxxx xxxx"&amp;lt;altered&amp;gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"CertificateStatus"=dword:800b0109&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="3"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt; Use the custom agent tool to create a custom agent msi-file&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Installatiion custom agent on test computer&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt;Update the registry values on test computer&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt; Install custom agent on test computer&lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;&lt;EM&gt; Use a standard user account to log-in on test computer &lt;/EM&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The user should be able to login without a&amp;nbsp;login prompt from the Identity Agent, however we do get the loign prompt from the IA. To cache the credentials the following registry entry has been added:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Windows Registry Editor Version 5.00&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;&amp;nbsp;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;[HKEY_CURRENT_USER\Software\CheckPoint\IA\GatewaysData\10.110.101.62\AutomaticAthentication]&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;"UserAuthMethods"=dword:00000000&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;Now the first time we still get the login prompt but an added tickbox to allow credential saving, the next logon is automatic and no prompt is showing anymore.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The main question our customer has, can this first prompt also be overridden? My guess is that it cannot be done, but maybe someone has a idea how to do it?&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 07:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53486#M10662</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-05-15T07:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - Auto Detecting gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53491#M10664</link>
      <description>Hi Martin,&lt;BR /&gt;&lt;BR /&gt;look for "Transparent Kerberos SSO Authentication for Identity Agent" in the Idendity Awareness Administration Guide.</description>
      <pubDate>Wed, 15 May 2019 08:59:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53491#M10664</guid>
      <dc:creator>Andreas_Aust</dc:creator>
      <dc:date>2019-05-15T08:59:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - Auto Detecting gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53505#M10670</link>
      <description>Andreas,&lt;BR /&gt;All I can find there is Browser based login. This is not browser based.&lt;BR /&gt;</description>
      <pubDate>Wed, 15 May 2019 12:10:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53505#M10670</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-05-15T12:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - Auto Detecting gateway</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53512#M10674</link>
      <description>&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;Identity Awareness Administration Guide R80.30 Page 157 ff. In Short:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To configure AD for Kerberos:&lt;/P&gt;&lt;P&gt;1. Make a new user account (on page 149).&lt;/P&gt;&lt;P&gt;2. Open the command line (Start &amp;gt; Run &amp;gt; cmd).&lt;/P&gt;&lt;P&gt;3. Run: setspn -A ckp_pdp/&amp;lt;domain_full_dns_name&amp;gt; &amp;lt;username&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To see users associated with the principle name, run: setspn -Q ckp_pdp*/*&lt;/P&gt;&lt;P&gt;When done, configure an Account Unit (on page 150) in the SmartConsole, to use this account.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&lt;/P&gt;&lt;P&gt;-a&lt;/P&gt;</description>
      <pubDate>Wed, 15 May 2019 12:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-Auto-Detecting-gateway/m-p/53512#M10674</guid>
      <dc:creator>Andreas_Aust</dc:creator>
      <dc:date>2019-05-15T12:42:49Z</dc:date>
    </item>
  </channel>
</rss>

