<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Clarification Authentication for Remote Access VPN in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276292#M46111</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;thank you, can i ask What is the difference between?&amp;nbsp;If I change from DN to UPN, for example, do both need to be set to UPN?&lt;/P&gt;
&lt;UL data-start="537" data-end="662"&gt;
&lt;LI data-section-id="qqeyon" data-start="537" data-end="613"&gt;&lt;STRONG data-start="539" data-end="611"&gt;VPN Clients &amp;gt; Personal Certificate (Edit) &amp;gt; Fetch username from: x&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-section-id="1d408xm" data-start="614" data-end="662"&gt;&lt;STRONG data-start="616" data-end="660"&gt;User Directories &amp;gt; LDAP Lookup Type: x&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Apr 2026 06:15:37 GMT</pubDate>
    <dc:creator>RemoteUser</dc:creator>
    <dc:date>2026-04-30T06:15:37Z</dc:date>
    <item>
      <title>Clarification Authentication for Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276078#M46086</link>
      <description>&lt;P data-end="68" data-start="57"&gt;Hi mates,&lt;/P&gt;
&lt;P data-end="99" data-start="70"&gt;Hope you’re all doing well!&lt;/P&gt;
&lt;P data-end="255" data-start="101"&gt;I have a doubt that came up while testing a task requested by the customer: making the gateway perform authentication lookup based on UPN instead of DN.&lt;/P&gt;
&lt;P data-end="456" data-start="257"&gt;I ran some tests by creating a user with a CAPI certificate and then moving the user between different OUs. The authentication still works correctly, which is exactly the behavior I was aiming for.&lt;/P&gt;
&lt;P data-end="536" data-start="458"&gt;This was configured on the &lt;STRONG data-end="514" data-start="485"&gt;VPN Client Authentication&lt;/STRONG&gt; side, specifically:&lt;/P&gt;
&lt;UL data-end="662" data-start="537"&gt;
&lt;LI data-end="613" data-start="537" data-section-id="qqeyon"&gt;&lt;STRONG data-end="611" data-start="539"&gt;VPN Clients &amp;gt; Personal Certificate (Edit) &amp;gt; Fetch username from: UPN&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-end="662" data-start="614" data-section-id="1d408xm"&gt;&lt;STRONG data-end="660" data-start="616"&gt;User Directories &amp;gt; LDAP Lookup Type: UPN&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-end="716" data-start="664"&gt;I’ve also attached some screenshots for reference.&lt;/P&gt;
&lt;P data-end="900" data-start="718"&gt;My question is: since users connect via Remote Access Client, do I also need to configure the authentication method under &lt;STRONG data-end="857" data-start="840"&gt;Mobile Access&lt;/STRONG&gt;, or is it not relevant in this scenario?&lt;/P&gt;
&lt;P data-end="1018" data-start="902"&gt;If anyone could clarify the differences between these two authentication methods, it would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Apr 2026 07:11:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276078#M46086</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-04-26T07:11:14Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Authentication for Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276270#M46109</link>
      <description>&lt;P&gt;The settings in question are only relevant to how the gateway looks up the user information sent by the client.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DN refers to a precise object in the LDAP directory.&lt;BR /&gt;UPN is the login name of the user.&lt;/P&gt;
&lt;P&gt;Unless you use the Mobile Access portal, you shouldn't need to configure anything there.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Apr 2026 20:40:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276270#M46109</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-29T20:40:51Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Authentication for Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276292#M46111</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;thank you, can i ask What is the difference between?&amp;nbsp;If I change from DN to UPN, for example, do both need to be set to UPN?&lt;/P&gt;
&lt;UL data-start="537" data-end="662"&gt;
&lt;LI data-section-id="qqeyon" data-start="537" data-end="613"&gt;&lt;STRONG data-start="539" data-end="611"&gt;VPN Clients &amp;gt; Personal Certificate (Edit) &amp;gt; Fetch username from: x&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI data-section-id="1d408xm" data-start="614" data-end="662"&gt;&lt;STRONG data-start="616" data-end="660"&gt;User Directories &amp;gt; LDAP Lookup Type: x&lt;BR /&gt;&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 06:15:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276292#M46111</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-04-30T06:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: Clarification Authentication for Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276332#M46113</link>
      <description>&lt;P&gt;I would set them both to use this value, yes.&lt;BR /&gt;Not exactly sure where "User Directory" is still used (it's a legacy feature).&lt;/P&gt;</description>
      <pubDate>Thu, 30 Apr 2026 15:13:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Clarification-Authentication-for-Remote-Access-VPN/m-p/276332#M46113</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-04-30T15:13:48Z</dc:date>
    </item>
  </channel>
</rss>

