<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about autentichation VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272384#M45643</link>
    <description>&lt;P&gt;So if i want to change the login option from DN to UPN i must do that under User Directories and not Login Option?&lt;BR /&gt;Right?&lt;/P&gt;</description>
    <pubDate>Tue, 03 Mar 2026 15:41:38 GMT</pubDate>
    <dc:creator>RemoteUser</dc:creator>
    <dc:date>2026-03-03T15:41:38Z</dc:date>
    <item>
      <title>Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272363#M45633</link>
      <description>&lt;P&gt;Hi mates,&lt;/P&gt;
&lt;P&gt;I have a question: is it possible to configure a VPN gateway so that it authenticates users based on PN (Principal Name) instead of DN (Distinguished Name)?&lt;/P&gt;
&lt;P&gt;If so, could you please advise how this can be configured?&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 14:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272363#M45633</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-03T14:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272371#M45634</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;did you try to look to the Multiple Login options within the authetication sectioni in VPN clients configuration for the gatreway?&lt;/P&gt;&lt;P&gt;You should be able to authenticate users through UPN, check it if it could solve your problem.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 14:58:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272371#M45634</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-03-03T14:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272376#M45636</link>
      <description>&lt;P&gt;From here right?&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DN.png" style="width: 435px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/33564i550C192E51782D96/image-size/large?v=v2&amp;amp;px=999" role="button" title="DN.png" alt="DN.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 15:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272376#M45636</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-03T15:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272377#M45637</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Go to VPN Clients -&amp;gt; Authentication.&lt;/P&gt;
&lt;P&gt;Add or Edit the Multiple Login Options. 'Username Password' might be there already.&lt;BR /&gt;Edit 'Username Password' and select 'User Directories' in the left pane.&lt;BR /&gt;&lt;BR /&gt;Below you can select the 'Common Lookup Type' and set this to UPN.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 15:22:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272377#M45637</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-03-03T15:22:16Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272379#M45638</link>
      <description>&lt;P&gt;What is the difference between logion options and user directories?&lt;BR /&gt;If i'm select Login Option and Edit the personal ertificate it's not the same thing? Or are two different things?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 15:30:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272379#M45638</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-03T15:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272380#M45639</link>
      <description>&lt;P&gt;It depends on how you want authenticate the user; in case of user directories the user is authenticated to an external authentication server; personal certificate means that you're trying to authenticate using a certificate.&lt;/P&gt;&lt;P&gt;In your case, what is the scenario?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 15:33:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272380#M45639</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-03-03T15:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272381#M45640</link>
      <description>&lt;P&gt;in my case is that the users coonect using CAPI certificate&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 15:35:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272381#M45640</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-03T15:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272383#M45642</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;The Login Option is what kind of authentication is supported. Personal Certificate, Username and Password or Dynamic ID.&amp;nbsp;&lt;BR /&gt;And in which order they must be placed.&lt;BR /&gt;&lt;BR /&gt;So Username and Password can be the first login option, followed by Dynamic ID.&lt;BR /&gt;&lt;BR /&gt;In User Directories, you configure what to look for when a user logs in. SAM Account name, DN or UPN.&lt;BR /&gt;&lt;BR /&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 15:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272383#M45642</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-03-03T15:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272384#M45643</link>
      <description>&lt;P&gt;So if i want to change the login option from DN to UPN i must do that under User Directories and not Login Option?&lt;BR /&gt;Right?&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 15:41:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272384#M45643</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-03T15:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272389#M45644</link>
      <description>&lt;P&gt;Yes, that's where I would start.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Mar 2026 16:01:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272389#M45644</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2026-03-03T16:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272518#M45678</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Just for your information, I reviewed the documentation:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;It explains that when selecting &lt;STRONG&gt;Personal Certificate&lt;/STRONG&gt; as a login option, you can configure what information the Security Gateway sends to the LDAP server to parse the certificate. By default, it uses the &lt;STRONG&gt;DN&lt;/STRONG&gt;, but it can also be configured to use the user’s &lt;STRONG&gt;email address&lt;/STRONG&gt; or &lt;STRONG&gt;serial number&lt;/STRONG&gt; instead.&lt;/P&gt;
&lt;P&gt;The documented steps are:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;
&lt;P&gt;In the &lt;STRONG&gt;Multiple Authentication Clients Settings&lt;/STRONG&gt; table on the &lt;EM&gt;Authentication&lt;/EM&gt; page, select a &lt;STRONG&gt;Personal_Certificate&lt;/STRONG&gt; entry and click &lt;STRONG&gt;Edit&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;In the &lt;STRONG&gt;Authentication Settings&lt;/STRONG&gt; section, under &lt;STRONG&gt;Fetch Username from&lt;/STRONG&gt;, select the information the Security Gateway should use to parse the certificate.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Click &lt;STRONG&gt;OK&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Install the policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;There is no mention of changes required in the user directories. Make sense?&lt;/P&gt;</description>
      <pubDate>Wed, 04 Mar 2026 19:39:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272518#M45678</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-04T19:39:29Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272539#M45685</link>
      <description>&lt;P&gt;Because, probably, it uses the default configuration in "user directories" that is Automatic Configuration (instead of selecting precisely which type of user directory to use).&lt;/P&gt;&lt;P&gt;In any case make sense, in case you could select Manual Configuration and select the LDAP users option, and also select the right LDAP Lookup Type (and for example select Email Address, that usually is the same as UPN).&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 08:07:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272539#M45685</guid>
      <dc:creator>simonemantovani</dc:creator>
      <dc:date>2026-03-05T08:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272618#M45696</link>
      <description>&lt;P&gt;Hey brother,&lt;/P&gt;
&lt;P&gt;Were you able to sort this out?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 17:12:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272618#M45696</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-05T17:12:15Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272625#M45699</link>
      <description>&lt;P data-end="10" data-start="0"&gt;Hi Andy,&lt;/P&gt;
&lt;P data-end="26" data-start="12"&gt;How are you?&lt;/P&gt;
&lt;P data-end="164" data-start="28"&gt;To be honest, I’m even more confused now. I reached out to TAC and they gave me a completely different answer, which is the following: (OpenOptional - UPN with Machine Certificate)&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Machine-Certificate.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 18:47:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272625#M45699</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-05T18:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272633#M45701</link>
      <description>&lt;P&gt;Im good! How are you?&lt;/P&gt;
&lt;P&gt;But wait, you dont want to do certificate auth, do you?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 20:20:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272633#M45701</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-05T20:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272634#M45702</link>
      <description>&lt;P&gt;i'm fine andy thank you.&lt;BR /&gt;let me explain:&lt;/P&gt;
&lt;P&gt;AUTHENTICATION in our case takes place in two ways: either through MFA or through CAPI certificate authentication.&lt;/P&gt;
&lt;P&gt;However, in this specific case, we want the Gateway to perform the user validation based on the UPN (User Principal Name) instead of the DN (Distinguished Name) when using CAPI certificate authentication.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 20:31:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272634#M45702</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-05T20:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272635#M45703</link>
      <description>&lt;P&gt;Ah, I get it now! So what TAC sent seems right, but I could not see in that link exact method you want to implement. Let me do some more research and see what I can find for you.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 20:43:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272635#M45703</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-05T20:43:09Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272636#M45704</link>
      <description>&lt;P&gt;in the link that i sent tac told me it's point 6&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2026 20:44:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272636#M45704</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-03-05T20:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Question about autentichation VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272637#M45705</link>
      <description>&lt;P&gt;Got it! I just ran this through AI and below is what it gave me:&lt;/P&gt;
&lt;P&gt;***************************************************************&lt;/P&gt;
&lt;ARTICLE class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" tabindex="-1" data-turn="assistant" data-scroll-anchor="false" data-testid="conversation-turn-2" data-turn-id="request-WEB:18ce2a0b-dc43-4a27-b4fd-f95d958394bb-0"&gt;
&lt;DIV class="text-base my-auto mx-auto [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" tabindex="-1"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;amp;]:mt-1" dir="auto" data-message-model-slug="gpt-5-3" data-message-id="91b1d9b4-594d-4efa-9ef6-d35face6fb78" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word dark markdown-new-styling"&gt;
&lt;H2 data-end="624" data-start="573" data-section-id="16cvack"&gt;Method: Configure UPN Mapping in the Certificate&lt;/H2&gt;
&lt;H3 data-end="672" data-start="626" data-section-id="krd33y"&gt;1. Ensure the certificate contains the UPN&lt;/H3&gt;
&lt;P data-end="763" data-start="673"&gt;The user certificate must include the &lt;STRONG data-end="756" data-start="711"&gt;UPN in the Subject Alternative Name (SAN)&lt;/STRONG&gt; field.&lt;/P&gt;
&lt;P data-end="780" data-start="765"&gt;Typical format:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Subject Alternative Name:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; Other Name: UPN=user@domain.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="921" data-start="853"&gt;If the certificate does not contain this, the gateway cannot map it.&lt;/P&gt;
&lt;HR data-end="926" data-start="923" /&gt;
&lt;H3 data-end="975" data-start="928" data-section-id="1k4hh77"&gt;2. Configure the Identity Source to Use UPN&lt;/H3&gt;
&lt;P data-end="996" data-start="976"&gt;In &lt;STRONG data-end="995" data-start="979"&gt;SmartConsole&lt;/STRONG&gt;:&lt;/P&gt;
&lt;OL data-end="1175" data-start="998"&gt;
&lt;LI data-end="1044" data-start="998" data-section-id="1vkyo50"&gt;
&lt;P data-end="1044" data-start="1001"&gt;Go to&lt;BR data-end="1009" data-start="1006" /&gt;&lt;STRONG data-end="1044" data-start="1012"&gt;Gateway → Identity Awareness&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1128" data-start="1046" data-section-id="57pnvn"&gt;
&lt;P data-end="1128" data-start="1049"&gt;Under &lt;STRONG data-end="1081" data-start="1055"&gt;Authentication Methods&lt;/STRONG&gt;, open the settings for &lt;STRONG data-end="1127" data-start="1105"&gt;Certificate (CAPI)&lt;/STRONG&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1175" data-start="1130" data-section-id="1eal935"&gt;
&lt;P data-end="1175" data-start="1133"&gt;Configure &lt;STRONG data-end="1167" data-start="1143"&gt;User Name Extraction&lt;/STRONG&gt; to use:&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Subject Alternative Name → UPN&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1228" data-start="1217"&gt;instead of:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Subject DN&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1253" data-start="1250" /&gt;
&lt;H3 data-end="1307" data-start="1255" data-section-id="1lmdzyy"&gt;3. Ensure AD Identity Source Supports UPN Lookup&lt;/H3&gt;
&lt;P data-end="1393" data-start="1308"&gt;Your &lt;STRONG data-end="1333" data-start="1313"&gt;Active Directory&lt;/STRONG&gt; identity source must allow lookup by &lt;STRONG data-end="1392" data-start="1371"&gt;userPrincipalName&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="1467" data-start="1395"&gt;This normally works automatically if the AD query account is configured.&lt;/P&gt;
&lt;HR data-end="1472" data-start="1469" /&gt;
&lt;H3 data-end="1513" data-start="1474" data-section-id="1vyawtx"&gt;4. Optional: Configure LDAP Mapping&lt;/H3&gt;
&lt;P data-end="1591" data-start="1514"&gt;If the gateway still attempts DN matching, verify the LDAP attribute mapping:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;userPrincipalName&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1631" data-start="1620"&gt;instead of:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;distinguishedName&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="1663" data-start="1660" /&gt;
&lt;H2 data-end="1703" data-start="1665" data-section-id="mwubsn"&gt;How the Flow Works After the Change&lt;/H2&gt;
&lt;OL data-end="1790" data-start="1705"&gt;
&lt;LI data-end="1737" data-start="1705" data-section-id="1j3tqs2"&gt;
&lt;P data-end="1737" data-start="1708"&gt;User connects to the gateway.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1769" data-start="1738" data-section-id="1xzfc3n"&gt;
&lt;P data-end="1769" data-start="1741"&gt;Client presents certificate.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1790" data-start="1770" data-section-id="10e7c10"&gt;
&lt;P data-end="1790" data-start="1773"&gt;Gateway extracts:&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;UPN = user@domain.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;OL start="4" data-end="1845" data-start="1823"&gt;
&lt;LI data-end="1845" data-start="1823" data-section-id="iiq2ac"&gt;
&lt;P data-end="1845" data-start="1826"&gt;Gateway queries AD:&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;(userPrincipalName=user@domain.com)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;OL start="5" data-end="1941" data-start="1892"&gt;
&lt;LI data-end="1941" data-start="1892" data-section-id="71a9yb"&gt;
&lt;P data-end="1941" data-start="1895"&gt;Identity Awareness maps the user successfully.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;HR data-end="1946" data-start="1943" /&gt;
&lt;H2 data-end="1969" data-start="1948" data-section-id="1tb54yh"&gt;Quick Verification&lt;/H2&gt;
&lt;P data-end="2020" data-start="1971"&gt;On the gateway CLI you can check identities with:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;pdp monitor all&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="2053" data-start="2051"&gt;or&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;pep show user all&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="2155" data-start="2086"&gt;This will show whether the username is being mapped as &lt;STRONG data-end="2154" data-start="2141"&gt;UPN or DN&lt;/STRONG&gt;.&lt;/P&gt;
&lt;HR data-end="2160" data-start="2157" /&gt;
&lt;P data-end="2348" data-start="2162"&gt;&lt;span class="lia-unicode-emoji" title=":light_bulb:"&gt;💡&lt;/span&gt; &lt;STRONG data-end="2179" data-start="2165"&gt;Important:&lt;/STRONG&gt;&lt;BR data-end="2182" data-start="2179" /&gt;Many issues occur because the certificate contains the &lt;STRONG data-end="2294" data-start="2237"&gt;UPN in SAN but the gateway still reads the Subject DN&lt;/STRONG&gt;, so confirming the &lt;STRONG data-end="2340" data-start="2314"&gt;SAN extraction setting&lt;/STRONG&gt; is key.&lt;/P&gt;
&lt;HR data-end="2353" data-start="2350" /&gt;
&lt;P data-end="2394" data-start="2355"&gt;&lt;span class="lia-unicode-emoji" title=":white_heavy_check_mark:"&gt;✅&lt;/span&gt; If you'd like, I can also show you:&lt;/P&gt;
&lt;UL data-is-only-node="" data-is-last-node="" data-end="2604" data-start="2395"&gt;
&lt;LI data-end="2468" data-start="2395" data-section-id="1ai44c5"&gt;
&lt;P data-end="2468" data-start="2397"&gt;the &lt;STRONG data-end="2449" data-start="2401"&gt;exact SmartConsole menu path and screenshots&lt;/STRONG&gt; for this setting&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-is-last-node="" data-end="2604" data-start="2469" data-section-id="1mjrcza"&gt;
&lt;P data-is-last-node="" data-end="2604" data-start="2471"&gt;the &lt;STRONG data-end="2512" data-start="2475"&gt;Check Point sk article references&lt;/STRONG&gt; that explain the UPN certificate mapping (these are not very obvious in the documentation).&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="z-0 flex min-h-[46px] justify-start"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;
&lt;ARTICLE class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-(--header-height)" dir="auto" tabindex="-1" data-turn="user" data-scroll-anchor="false" data-testid="conversation-turn-3" data-turn-id="5b29b164-b76f-47c0-a9c4-0a89871b5261"&gt;
&lt;DIV class="text-base my-auto mx-auto pt-12 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col" tabindex="-1"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;amp;]:mt-1" dir="auto" data-message-id="5b29b164-b76f-47c0-a9c4-0a89871b5261" data-message-author-role="user"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden items-end rtl:items-start"&gt;
&lt;DIV class="user-message-bubble-color corner-superellipse/1.1 relative rounded-[18px] px-4 py-1.5 data-[multiline]:py-3 max-w-[var(--user-chat-width,70%)]"&gt;
&lt;DIV class="whitespace-pre-wrap"&gt;yes please&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="z-0 flex justify-end"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;
&lt;ARTICLE class="text-token-text-primary w-full focus:outline-none [--shadow-height:45px] has-data-writing-block:pointer-events-none has-data-writing-block:-mt-(--shadow-height) has-data-writing-block:pt-(--shadow-height) [&amp;amp;:has([data-writing-block])&amp;gt;*]:pointer-events-auto scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" tabindex="-1" data-turn="assistant" data-scroll-anchor="true" data-testid="conversation-turn-4" data-turn-id="request-WEB:18ce2a0b-dc43-4a27-b4fd-f95d958394bb-1"&gt;
&lt;DIV class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)"&gt;
&lt;DIV class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" tabindex="-1"&gt;
&lt;DIV class="flex max-w-full flex-col gap-4 grow"&gt;
&lt;DIV class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal [.text-message+&amp;amp;]:mt-1" dir="auto" data-message-model-slug="gpt-5-3" data-message-id="c48f1abd-d95d-421c-b647-ed1455c1ac56" data-message-author-role="assistant"&gt;
&lt;DIV class="flex w-full flex-col gap-1 empty:hidden"&gt;
&lt;DIV class="markdown prose dark:prose-invert w-full wrap-break-word dark markdown-new-styling"&gt;
&lt;P data-end="150" data-start="0"&gt;Great — I’ll show you &lt;STRONG data-end="55" data-start="22"&gt;what it looks like in the GUI&lt;/STRONG&gt; and the &lt;STRONG data-end="113" data-start="64"&gt;relevant Check Point documentation references&lt;/STRONG&gt; so you can verify the configuration.&lt;/P&gt;
&lt;HR data-end="155" data-start="152" /&gt;
&lt;H1 data-end="208" data-start="157" data-section-id="1jqhz2m"&gt;1. SmartConsole Configuration (UPN instead of DN)&lt;/H1&gt;
&lt;P data-end="334" data-start="210"&gt;In &lt;STRONG data-end="254" data-start="213"&gt;&lt;SPAN class="whitespace-normal"&gt;Check Point SmartConsole&lt;/SPAN&gt;&lt;/STRONG&gt;, the setting is under the gateway’s &lt;STRONG data-end="333" data-start="291"&gt;Remote Access / Identity configuration&lt;/STRONG&gt;.&lt;/P&gt;
&lt;H3 data-end="344" data-start="336" data-section-id="yntunf"&gt;Path&lt;/H3&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Gateway Object&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; → Remote Access VPN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; → Authentication&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; → Login Options (Realm)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="520" data-start="448"&gt;Inside the &lt;STRONG data-end="483" data-start="459"&gt;Login Option / Realm&lt;/STRONG&gt; used for certificate authentication:&lt;/P&gt;
&lt;H3 data-end="557" data-start="522" data-section-id="14gn83k"&gt;Certificate Username Extraction&lt;/H3&gt;
&lt;P data-end="562" data-start="558"&gt;Set:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Fetch username from:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; Subject Alternative Name → UPN&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="639" data-start="628"&gt;Instead of:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Subject DN&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H3 data-end="681" data-start="661" data-section-id="126q44l"&gt;LDAP Lookup Type&lt;/H3&gt;
&lt;P data-end="734" data-start="682"&gt;Under &lt;STRONG data-end="708" data-start="688"&gt;User Directories&lt;/STRONG&gt; in the same Login Option:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Common Name Lookup Type:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; User-Principal-Name (UPN)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="810" data-start="799"&gt;instead of:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Distinguished Name&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="843" data-start="840" /&gt;
&lt;H1 data-end="883" data-start="845" data-section-id="40nshf"&gt;2. What the Certificate Must Contain&lt;/H1&gt;
&lt;P data-end="939" data-start="885"&gt;The certificate must include &lt;STRONG data-end="938" data-start="914"&gt;UPN in the SAN field&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="949" data-start="941"&gt;Example:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Subject:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; CN = John Doe&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Subject Alternative Name:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; Other Name: Principal Name = john.doe@company.com&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1094" data-start="1066"&gt;Authentication flow becomes:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Certificate → extract UPN from SAN&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;UPN = john.doe@company.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;LDAP query:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(userPrincipalName=john.doe@company.com)&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="1364" data-start="1221"&gt;UPN-based mapping relies on the &lt;STRONG data-end="1266" data-start="1253"&gt;SAN field&lt;/STRONG&gt;, which is the standard way to map certificates to AD users.&lt;/P&gt;
&lt;HR data-end="1369" data-start="1366" /&gt;
&lt;H1 data-end="1414" data-start="1371" data-section-id="qouzrk"&gt;3. Known Behavior / Gotcha in Check Point&lt;/H1&gt;
&lt;P data-end="1535" data-start="1416"&gt;There is a common issue where &lt;STRONG data-end="1503" data-start="1446"&gt;Identity Awareness / PDP still uses the default realm&lt;/STRONG&gt;, ignoring custom parsing rules.&lt;/P&gt;
&lt;P data-end="1555" data-start="1537"&gt;This happens when:&lt;/P&gt;
&lt;UL data-end="1657" data-start="1557"&gt;
&lt;LI data-end="1598" data-start="1557" data-section-id="1fan5s2"&gt;
&lt;P data-end="1598" data-start="1559"&gt;Login Option parsing rules were changed&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1657" data-start="1599" data-section-id="1kgumod"&gt;
&lt;P data-end="1657" data-start="1601"&gt;But the &lt;STRONG data-end="1657" data-start="1609"&gt;PDP still references the default "vpn" realm&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="1813" data-start="1659"&gt;This behavior is documented in Check Point bug tracking related to &lt;STRONG data-end="1774" data-start="1726"&gt;certificate parsing rules for UPN extraction&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P data-end="1830" data-start="1815"&gt;In those cases:&lt;/P&gt;
&lt;UL data-end="1911" data-start="1832"&gt;
&lt;LI data-end="1866" data-start="1832" data-section-id="17n1cmd"&gt;
&lt;P data-end="1866" data-start="1834"&gt;The gateway extracts the &lt;STRONG data-end="1866" data-start="1859"&gt;UPN&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="1911" data-start="1867" data-section-id="1f931tv"&gt;
&lt;P data-end="1911" data-start="1869"&gt;But LDAP lookup still happens using &lt;STRONG data-end="1911" data-start="1905"&gt;DN&lt;/STRONG&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="1916" data-start="1913" /&gt;
&lt;H1 data-end="1951" data-start="1918" data-section-id="yjww58"&gt;4. Debug Commands (Very Useful)&lt;/H1&gt;
&lt;P data-end="2010" data-start="1953"&gt;On the &lt;STRONG data-end="2001" data-start="1960"&gt;&lt;SPAN class="whitespace-normal"&gt;Check Point Gaia OS&lt;/SPAN&gt;&lt;/STRONG&gt; gateway:&lt;/P&gt;
&lt;H3 data-end="2038" data-start="2012" data-section-id="1p6cwz3"&gt;See extracted identity&lt;/H3&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;pdp monitor all&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H3 data-end="2096" data-start="2068" data-section-id="ih7ojy"&gt;Show authenticated users&lt;/H3&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;pep show user all&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;H3 data-end="2160" data-start="2128" data-section-id="4s21hp"&gt;Identity awareness debugging&lt;/H3&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute inset-x-4 top-12 bottom-4"&gt;
&lt;DIV class="pointer-events-none sticky z-40 shrink-0 z-1!"&gt;
&lt;DIV class="sticky bg-token-border-light"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;pdp debug on&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="2202" data-start="2187"&gt;Logs appear in:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;/var/log/pdp/&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;P data-end="2247" data-start="2227"&gt;Look for lines like:&lt;/P&gt;
&lt;DIV class="relative w-full mt-4 mb-1"&gt;
&lt;DIV class=""&gt;
&lt;DIV class="relative"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="h-full min-h-0 min-w-0"&gt;
&lt;DIV class="border border-token-border-light border-radius-3xl corner-superellipse/1.1 rounded-3xl"&gt;
&lt;DIV class="h-full w-full border-radius-3xl bg-token-bg-elevated-secondary corner-superellipse/1.1 overflow-clip rounded-3xl lxnfua_clipPathFallback"&gt;
&lt;DIV class="pointer-events-none absolute end-1.5 top-1 z-2 md:end-2 md:top-1"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="pt-3"&gt;
&lt;DIV class="relative z-0 flex max-w-full"&gt;
&lt;DIV id="code-block-viewer" class="q9tKkq_viewer cm-editor z-10 light:cm-light dark:cm-light flex h-full w-full flex-col items-stretch ͼk ͼy" dir="ltr"&gt;
&lt;DIV class="cm-scroller"&gt;
&lt;DIV class="cm-content q9tKkq_readonly"&gt;&lt;SPAN&gt;Extracted username from certificate: user@domain.com&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;LDAP lookup attribute: userPrincipalName&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;HR data-end="2355" data-start="2352" /&gt;
&lt;H1 data-end="2388" data-start="2357" data-section-id="1tc8if6"&gt;5. SK Articles Worth Checking&lt;/H1&gt;
&lt;P data-end="2494" data-start="2390"&gt;These are the most relevant &lt;STRONG data-end="2459" data-start="2418"&gt;&lt;SPAN class="whitespace-normal"&gt;Check Point Software Technologies&lt;/SPAN&gt;&lt;/STRONG&gt; knowledge articles for this topic:&lt;/P&gt;
&lt;UL data-end="2761" data-start="2496"&gt;
&lt;LI data-end="2548" data-start="2496" data-section-id="1jwaios"&gt;
&lt;P data-end="2548" data-start="2498"&gt;&lt;STRONG data-end="2509" data-start="2498"&gt;sk61060&lt;/STRONG&gt; – Certificate authentication with LDAP&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2627" data-start="2549" data-section-id="12l9yqk"&gt;
&lt;P data-end="2627" data-start="2551"&gt;&lt;STRONG data-end="2563" data-start="2551"&gt;sk172319&lt;/STRONG&gt; – Identity Awareness certificate authentication troubleshooting&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2703" data-start="2628" data-section-id="14ga5hh"&gt;
&lt;P data-end="2703" data-start="2630"&gt;&lt;STRONG data-end="2642" data-start="2630"&gt;sk174084&lt;/STRONG&gt; – Realm parsing rules ignored for certificate authentication&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-end="2761" data-start="2704" data-section-id="19gt3wj"&gt;
&lt;P data-end="2761" data-start="2706"&gt;&lt;STRONG data-end="2718" data-start="2706"&gt;sk113410&lt;/STRONG&gt; – VPN certificate authentication with LDAP&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;HR data-end="2766" data-start="2763" /&gt;
&lt;H1 data-end="2804" data-start="2768" data-section-id="8dr8x3"&gt;6. Quick Troubleshooting Checklist&lt;/H1&gt;
&lt;P data-end="2838" data-start="2806"&gt;If &lt;STRONG data-end="2830" data-start="2809"&gt;UPN mapping fails&lt;/STRONG&gt;, check:&lt;/P&gt;
&lt;P data-end="3072" data-start="2840"&gt;✔ Certificate SAN contains UPN&lt;BR data-end="2873" data-start="2870" /&gt;✔ Login Option extracts &lt;STRONG data-end="2910" data-start="2897"&gt;SAN → UPN&lt;/STRONG&gt;&lt;BR data-end="2913" data-start="2910" /&gt;✔ LDAP lookup type = &lt;STRONG data-end="2955" data-start="2934"&gt;userPrincipalName&lt;/STRONG&gt;&lt;BR data-end="2958" data-start="2955" /&gt;✔ Correct &lt;STRONG data-end="2992" data-start="2968"&gt;Login Option / Realm&lt;/STRONG&gt; used by gateway&lt;BR data-end="3011" data-start="3008" /&gt;✔ AD user attribute &lt;STRONG data-end="3052" data-start="3031"&gt;userPrincipalName&lt;/STRONG&gt; matches certificate&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/ARTICLE&gt;</description>
      <pubDate>Thu, 05 Mar 2026 20:46:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-autentichation-VPN/m-p/272637#M45705</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2026-03-05T20:46:25Z</dc:date>
    </item>
  </channel>
</rss>

