<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Steps for using Third party CA for IPSEC Remote access VPN (Endpoint security client) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Steps-for-using-Third-party-CA-for-IPSEC-Remote-access-VPN/m-p/85117#M10431</link>
    <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;Need your support !&lt;/P&gt;&lt;P&gt;i need to use third party CA in Remote access VPN.&lt;/P&gt;&lt;P&gt;The remote Access vpn is already configured and working, but now we want to use Certificate along with username and password authentication for users connecting via endpoint security client.&lt;/P&gt;&lt;P&gt;The user database resides on AD Ldap,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i need steps by step process (from creating CA, CSR , and importing) how to get this working,&amp;nbsp;&lt;/P&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;how to ADD the trusted Ca on Dashboard, whether we have to create root CA or sub-CA from openssl&amp;nbsp; ?&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Or directly create CSR from firewall itself at first by "&lt;STRONG&gt;cpopenssl req -new -out &amp;lt;CERT.CSR&amp;gt; -keyout &amp;lt;KEYFILE.KEY&amp;gt; -config $CPDIR/conf/openssl.cnf"&amp;nbsp; &amp;nbsp;?&amp;nbsp; and send CSR to CA to sign ?&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Users are on AD using LDAP account unit, for this do i have create a "user template " and enable Encryotion&amp;gt;enable IKE private key .&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;is anyone done this requirement and created a document for reference.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any help would be appreciated.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2020 22:22:44 GMT</pubDate>
    <dc:creator>vivekumar1988</dc:creator>
    <dc:date>2020-05-13T22:22:44Z</dc:date>
    <item>
      <title>Steps for using Third party CA for IPSEC Remote access VPN (Endpoint security client)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Steps-for-using-Third-party-CA-for-IPSEC-Remote-access-VPN/m-p/85117#M10431</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;Need your support !&lt;/P&gt;&lt;P&gt;i need to use third party CA in Remote access VPN.&lt;/P&gt;&lt;P&gt;The remote Access vpn is already configured and working, but now we want to use Certificate along with username and password authentication for users connecting via endpoint security client.&lt;/P&gt;&lt;P&gt;The user database resides on AD Ldap,&amp;nbsp;&lt;/P&gt;&lt;P&gt;i need steps by step process (from creating CA, CSR , and importing) how to get this working,&amp;nbsp;&lt;/P&gt;&lt;OL class="lia-list-style-type-lower-alpha"&gt;&lt;LI&gt;how to ADD the trusted Ca on Dashboard, whether we have to create root CA or sub-CA from openssl&amp;nbsp; ?&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;Or directly create CSR from firewall itself at first by "&lt;STRONG&gt;cpopenssl req -new -out &amp;lt;CERT.CSR&amp;gt; -keyout &amp;lt;KEYFILE.KEY&amp;gt; -config $CPDIR/conf/openssl.cnf"&amp;nbsp; &amp;nbsp;?&amp;nbsp; and send CSR to CA to sign ?&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Users are on AD using LDAP account unit, for this do i have create a "user template " and enable Encryotion&amp;gt;enable IKE private key .&lt;/STRONG&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;STRONG&gt;is anyone done this requirement and created a document for reference.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Any help would be appreciated.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Thanks&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 22:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Steps-for-using-Third-party-CA-for-IPSEC-Remote-access-VPN/m-p/85117#M10431</guid>
      <dc:creator>vivekumar1988</dc:creator>
      <dc:date>2020-05-13T22:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: Steps for using Third party CA for IPSEC Remote access VPN (Endpoint security client)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Steps-for-using-Third-party-CA-for-IPSEC-Remote-access-VPN/m-p/85323#M10432</link>
      <description>Multiple authentication schemes is described here: &lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86240" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86240&lt;/A&gt;&lt;BR /&gt;For a third party CA, you have to create an OPSEC CA object, import the public key, and set the gateway to authenticate VPN access via this CA.&lt;BR /&gt;It's described in the Remote Access VPN docs: &lt;A href="https://sc1.checkpoint.com/documents/R80.10_andhigher/WebAdminGuides/EN/CP_RemoteAccessVPN_AdminGuide/html_frameset.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.10_andhigher/WebAdminGuides/EN/CP_RemoteAccessVPN_AdminGuide/html_frameset.htm&lt;/A&gt;</description>
      <pubDate>Thu, 14 May 2020 18:20:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Steps-for-using-Third-party-CA-for-IPSEC-Remote-access-VPN/m-p/85323#M10432</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-14T18:20:44Z</dc:date>
    </item>
  </channel>
</rss>

