<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change VPN client authentication option in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/244023#M40743</link>
    <description>&lt;P&gt;Yep using SAML and that part is working very well.&lt;/P&gt;
&lt;P&gt;Automating re-creating the sites with&amp;nbsp;update_config_tool seems to be going well when manually testing.&amp;nbsp; Need to wrap it inside a PS script then test it as part of push job in Harmony Endpoint today and see where that brings me.&lt;/P&gt;
&lt;P&gt;Will share my learnings here if / when I get it going.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Mar 2025 05:39:15 GMT</pubDate>
    <dc:creator>Ruan_Kotze</dc:creator>
    <dc:date>2025-03-18T05:39:15Z</dc:date>
    <item>
      <title>Change VPN client authentication option</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/243812#M40711</link>
      <description>&lt;P&gt;Hi CheckMates,&lt;/P&gt;
&lt;P&gt;We are transitioning our VPN to authentication via Entra, primarily to enforce MFA.&lt;/P&gt;
&lt;P&gt;My question relates to migrating the client settings. Is there a way to accomplish this by manipulating the Authentication settings on the gateway? What I have done is made the MFA option the first priority in the Multiple Authentication Options list.&lt;/P&gt;
&lt;P&gt;On the client side this results in the MFA option being labelled as the default, but it seems that regardless of that the client just uses the last succesful authentication method.&lt;/P&gt;
&lt;P&gt;Is there anything we can do to flip the clients over to the MFA login option without needing to touch the client?&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Fri, 14 Mar 2025 12:06:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/243812#M40711</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-03-14T12:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: Change VPN client authentication option</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/243984#M40735</link>
      <description>&lt;P&gt;You're using SAML, correct?&lt;BR /&gt;As I recall, this requires deleting and re-adding the site.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 18:40:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/243984#M40735</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-03-17T18:40:26Z</dc:date>
    </item>
    <item>
      <title>Re: Change VPN client authentication option</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/244005#M40740</link>
      <description>&lt;P&gt;I see what Phoneboy is saying. I recall while ago thats what one of the customers I was helping had to do. Not sure if there is better method these days.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 22:31:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/244005#M40740</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-03-17T22:31:17Z</dc:date>
    </item>
    <item>
      <title>Re: Change VPN client authentication option</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/244023#M40743</link>
      <description>&lt;P&gt;Yep using SAML and that part is working very well.&lt;/P&gt;
&lt;P&gt;Automating re-creating the sites with&amp;nbsp;update_config_tool seems to be going well when manually testing.&amp;nbsp; Need to wrap it inside a PS script then test it as part of push job in Harmony Endpoint today and see where that brings me.&lt;/P&gt;
&lt;P&gt;Will share my learnings here if / when I get it going.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Mar 2025 05:39:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Change-VPN-client-authentication-option/m-p/244023#M40743</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2025-03-18T05:39:15Z</dc:date>
    </item>
  </channel>
</rss>

