<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How Certificate base Remote Access VPN exchange Certificate and Exchange keys ???? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81230#M10765</link>
    <description>For the gateway to trust certificates signed by anything other than the Internal CA, that CA has to be added to the gateway object as part of the IPSEC VPN configuration.&lt;BR /&gt;I assume whatever LDAP profile you've created would also refer to that CA for authentication (though I don't remember offhand).&lt;BR /&gt;The client certificate has an identifier for the user itself.&lt;BR /&gt;Assuming the certificate presented by the client is for the correct user and is valid per the CA, that part of the authentication should succeed.</description>
    <pubDate>Wed, 08 Apr 2020 00:38:47 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-04-08T00:38:47Z</dc:date>
    <item>
      <title>How Certificate base Remote Access VPN exchange Certificate and Exchange keys ????</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81150#M10764</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Recently, I have deployed Remote Access VPN with "Endpoint Security Client" - Windows. It is working fine as it should be by following the Remote Access VPN User guide and with TAC's help.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.10_andhigher/WebAdminGuides/EN/CP_RemoteAccessVPN_AdminGuide/html_frameset.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R80.10_andhigher/WebAdminGuides/EN/CP_RemoteAccessVPN_AdminGuide/html_frameset.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The deployment model is "Personal Certificate" and Username Password".&lt;/P&gt;&lt;P&gt;1 - First Certificate get Authenticated and then&lt;/P&gt;&lt;P&gt;2 - AD Username and Password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But I still don't understand how PKI is working with my Internal MS CA, Checkpoint Gateway and Endpoint Security Client where it looks into CAPI Storage.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please anyone could give insight between Certificate handling of HOW and WHERE key get installed?&lt;/P&gt;&lt;P&gt;In the log, I could see that Key Install and Cookies been Created.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT color="#FF0000"&gt;How can I verify&lt;/FONT&gt; that I'm using the &lt;U&gt;correct certificate&lt;/U&gt; that I exclusively created for this purpose from Internal MS CA and then imported into Checkpoint Gateway? &lt;FONT color="#0000FF"&gt;I used "cpopenssl" utility to create initial .csr and my_key.key&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;B&lt;/P&gt;</description>
      <pubDate>Tue, 07 Apr 2020 14:56:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81150#M10764</guid>
      <dc:creator>BeaconBits</dc:creator>
      <dc:date>2020-04-07T14:56:58Z</dc:date>
    </item>
    <item>
      <title>Re: How Certificate base Remote Access VPN exchange Certificate and Exchange keys ????</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81230#M10765</link>
      <description>For the gateway to trust certificates signed by anything other than the Internal CA, that CA has to be added to the gateway object as part of the IPSEC VPN configuration.&lt;BR /&gt;I assume whatever LDAP profile you've created would also refer to that CA for authentication (though I don't remember offhand).&lt;BR /&gt;The client certificate has an identifier for the user itself.&lt;BR /&gt;Assuming the certificate presented by the client is for the correct user and is valid per the CA, that part of the authentication should succeed.</description>
      <pubDate>Wed, 08 Apr 2020 00:38:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81230#M10765</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-08T00:38:47Z</dc:date>
    </item>
    <item>
      <title>Re: How Certificate base Remote Access VPN exchange Certificate and Exchange keys ????</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81237#M10766</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Where Checkpoint Gateway keeps the trusted Certificate. Is there any list that I could see?&lt;/P&gt;&lt;P&gt;I would like to see my Internal CA's Certificate on the Gateway. I'm using VSX cluster with Management Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Moreover,&amp;nbsp; a detailed description or any Checkpoint document of &lt;FONT color="#008080"&gt;&lt;STRONG&gt;Certificate Trust Process&lt;/STRONG&gt;&lt;/FONT&gt; where it shows the process of key exchange and key install would help the community.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 01:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81237#M10766</guid>
      <dc:creator>BeaconBits</dc:creator>
      <dc:date>2020-04-08T01:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: How Certificate base Remote Access VPN exchange Certificate and Exchange keys ????</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81246#M10767</link>
      <description>&lt;P&gt;As I said, it's in the relevant Gateway (or VS) object.&lt;BR /&gt;You should see it listed here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-04-07 at 7.54.02 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5456iC5FE763DF7036E2A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-04-07 at 7.54.02 PM.png" alt="Screen Shot 2020-04-07 at 7.54.02 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In my case, I only have the Internal CA.&lt;BR /&gt;If there are other CAs the gateway is configured to trust for VPN purposes, they should be listed here.&lt;BR /&gt;Also, there would be an object listed under Servers &amp;gt; Trusted CAs that would contain the CA Public Key.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In terms of validating certificates, we follow the various standards set forth in the RFCs for IPsec and IKE.&lt;BR /&gt;It's also shown visually in the product documentation: &lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/IPsec-and-IKE.htm?tocpath=IPsec" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_SitetoSiteVPN_AdminGuide/Content/Topics-VPNSG/IPsec-and-IKE.htm?tocpath=IPsec&lt;/A&gt; and IKE|_____0#IPsec_and_IKE&lt;BR /&gt;The "key install" message in the logs should show up once the DH-key has been generated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 03:14:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-Certificate-base-Remote-Access-VPN-exchange-Certificate-and/m-p/81246#M10767</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-08T03:14:36Z</dc:date>
    </item>
  </channel>
</rss>

