<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: remote client VPN authentication with Certificate in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/55255#M13858</link>
    <description>&lt;P&gt;This is all hilarious to me, because I agree on all points about their documentation lacking! Hell, I have too many other things to do, and hired a security consultant to do the cert based VPN, because we use 3rd party devices with dynamic IPs. These devices have to have dynamic IPs because of the LTE connection, along with some type of landline Internet eventually (construction sites). Well, even the the sec engineer and Check Point are having a problem with it right now. Check Point firewall portion is great. Everything else is pretty flaky!&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jun 2019 01:35:08 GMT</pubDate>
    <dc:creator>Tim_Cole</dc:creator>
    <dc:date>2019-06-07T01:35:08Z</dc:date>
    <item>
      <title>remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9949#M13837</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the moment we have the standard remote vpn for our users with office mode, authentication done through LDAP and MFA, which works perfectly, no complaints here until so far &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i want to start implement certificate based authentication on the remote vpn clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the CA is internal, our Active Directory will issue the certificates for the users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have an NPS server(RADIUS), policy is created, although could be wrongly configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i have the RADIUS server defined on the management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but i am missing 2 steps :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;1st : how do i enforce/allow users to user to use the certificate to authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;2nd : could someone provide some step-by-step or a policy configuration for the NPs server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the moment i have this :&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64132_pastedImage_3.png" style="width: 620px; height: 88px;" /&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64142_pastedImage_4.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and of course the firewalls defined as clients on the radius server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 14:57:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9949#M13837</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-03-27T14:57:21Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9950#M13838</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;During new Site creation at Remote VPN, You can select Certificate as authentication method.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64146_Capture2.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;Also there are option that which type of certificate you will use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64147_Capture1.JPG" style="height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 18:03:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9950#M13838</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2018-03-27T18:03:47Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9951#M13839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the feedback.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that is something i saw and tried it, but fails the authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;looks like i am missing more configuration the checkpoint and i am looking for a step-by-step how to enable it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2018 07:18:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9951#M13839</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-03-28T07:18:45Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9952#M13840</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is the R80.10 RemoteAccess VPN AdminGuide and the R77 VPN Admin Guide where the needed steps can be found.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2018 13:52:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9952#M13840</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-28T13:52:54Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9953#M13841</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i spent some time reading the manual and something is not clear.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i did the following, but something is missing :&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64538_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64539_pastedImage_2.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;i created a user_template&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64540_pastedImage_3.png" style="width: 620px; height: 195px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but here is what i am missing, on the ldap account unit i have no idea what option to chose , nothing is related to the certificates, just the radius, but i dont want to have a radius to do the certificate authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="jive-image image-4" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64541_pastedImage_4.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 13:35:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9953#M13841</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-04-11T13:35:08Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9954#M13842</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Then i would follow&amp;nbsp;Using Certificates Using Third Party PKI in Remote Access VPN Administration Guide R80.10 p.43f !&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 13:53:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9954#M13842</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-11T13:53:41Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9955#M13843</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i already read that part, and what is says is to create local users on the dashboard and this is not manageable.&lt;/P&gt;&lt;P&gt;as for the normal username+password authentication you do not need to create local users on the dashboard, but the firewall passes the authentication to the LDAP server, there should be a similar option for the certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring Third-Party PKI Certificates To use a third-party PKI solution:&lt;/P&gt;&lt;P&gt;1. In SmartConsole, from the Objects Bar click Users &amp;gt; Users.&lt;/P&gt;&lt;P&gt;2. Create a new user or double-click an existing user. The User Properties window opens.&lt;/P&gt;&lt;P&gt;3. From the navigation tree, click Encryption.&lt;/P&gt;&lt;P&gt;4. Click Edit. The IKE Phase 2 Properties window opens.&lt;/P&gt;&lt;P&gt;5. Click the Authentication tab and select Public key.&lt;/P&gt;&lt;P&gt;6. Define the third party Certificate Authority as an object in SmartDashboard.&lt;/P&gt;&lt;P&gt;9. Transfer the certificate to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please provide a proper answer, i read the manual from top to bottom and i am missing just one configuration which i am not able to find it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sending me all the time to the admin manual doesn't help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 14:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9955#M13843</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-04-11T14:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9956#M13844</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry - look here:&lt;/P&gt;&lt;H3 class=""&gt;User Authentication Options&lt;/H3&gt;&lt;P class=""&gt;Select the scheme to be used to authenticate users defined with this template. These schemes are used in authentication rules and in Remote Access (&lt;STRONG&gt;when the user is not identified using a certificate or an IKE preshared secret&lt;/STRONG&gt;).&lt;/P&gt;&lt;P class=""&gt;Select one of these authentication methods:&lt;/P&gt;&lt;UL class=""&gt;&lt;LI class=""&gt;&lt;STRONG class=""&gt;Undefined&lt;/STRONG&gt; - means that &lt;EM class=""&gt;either&lt;/EM&gt; no authentication is performed and access is always denied, &lt;EM class=""&gt;or&lt;/EM&gt; IKE authentication is used, as defined in the &lt;STRONG class=""&gt;Encryption&lt;/STRONG&gt; tab.&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 08:12:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9956#M13844</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-12T08:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9957#M13845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i had it set up as Undefined on the authentication method&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64573_pastedImage_1.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;P&gt;and then on the encryption i have this.&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64574_pastedImage_2.png" style="width: 620px; height: 174px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;for some reason it always the same error, i masked the username&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Category: Session&lt;BR /&gt;Event Type: Login&lt;BR /&gt;Name: Endpoint Security VPN&lt;BR /&gt;Version: E80.80&lt;BR /&gt;Build Number: 986005503&lt;BR /&gt;User: ******@*****.com&lt;BR /&gt;Authentication Method: Certificate&lt;BR /&gt;Login Option: Personal Certificate&lt;BR /&gt;Failed Login Factor: 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Data Protocol: IPSec&lt;BR /&gt;Status: Failure&lt;BR /&gt;Reason: DN ****@****.com unknown.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;although i think the missconfig comes from here since it doesnt give a proper authentication scheme for certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;any idea ? what i should pick or change? is this config correct?&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64575_pastedImage_3.png" style="width: auto; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 08:40:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9957#M13845</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-04-12T08:40:19Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9958#M13846</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have to add the users to a user group that is a participant in the RemoteAccess Community and add option Personal Certificate in GW &amp;gt; VPN clients &amp;gt; Authentication. Then you have to install databes and policy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 09:24:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9958#M13846</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-12T09:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9959#M13847</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that is already done, and works for username+password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is the authentication scheme correctly selected to allow certificates ? because as you can see i selected only the checkpoint password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;https://community.checkpoint.com/people/dwelccfe6e688-522c-305c-adaa-194bd7a7becc&lt;/A&gt;‌ maybe you could give some hint ? &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 09:45:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9959#M13847</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-04-12T09:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9960#M13848</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you follow the steps here?&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk99035" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk99035"&gt;LDAP users connecting from Check Point Capsule Connect / VPN client cannot authenticate using certificate&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 09:56:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9960#M13848</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-04-12T09:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9961#M13849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i would say i tried, but after so many tests i am not sure anymore &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i will try again this afternoon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 10:05:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9961#M13849</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-04-12T10:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9962#M13850</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just tried this option and still the same error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Category: Session&lt;BR /&gt;Event Type: Login&lt;BR /&gt;Name: Endpoint Security VPN&lt;BR /&gt;Version: E80.80&lt;BR /&gt;Build Number: 986005503&lt;BR /&gt;User: *****@******.com&lt;BR /&gt;Authentication Method: Certificate&lt;BR /&gt;Login Option: Personal Certificate&lt;BR /&gt;Failed Login Factor: 1&lt;BR /&gt;Model: PC&lt;BR /&gt;OS Name: Windows&lt;BR /&gt;OS Version: 10&lt;BR /&gt;OS Edition: Professional&lt;BR /&gt;OS Build: 16299&lt;BR /&gt;OS Bits: 64bit&lt;BR /&gt;ID: 9240021C-799E-4DB0-A2CC-E7A23670C716&lt;BR /&gt;Re-authentication every:&lt;BR /&gt;Login Timestamp: 2018-04-12T16:15:21Z&lt;BR /&gt;IP Protocol: 6&lt;BR /&gt;Destination Port: 443&lt;BR /&gt;Data Protocol: IPSec&lt;BR /&gt;Status: Failure&lt;BR /&gt;Reason: DN ******@*****.com unknown.&lt;BR /&gt;Suppressed Logs: 0&lt;BR /&gt;Action: Failed Log In&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Mobile Access&lt;BR /&gt;Origin:&amp;nbsp;*********&lt;BR /&gt;Service: TCP/443&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Marker: @A@@B@1523549079@C@2464621&lt;BR /&gt;Data Encryption: AES-256 + MD5&lt;BR /&gt;Severity: Informational&lt;BR /&gt;Rounded Sent Bytes: 0&lt;BR /&gt;Confidence Level: N/A&lt;BR /&gt;Rounded Bytes: 0&lt;BR /&gt;Rounded Received Bytes: 0&lt;BR /&gt;OS: Windows 10 Professional 64bit (build 16299) &lt;BR /&gt;Login Option Factors: Certificate&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 16:16:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9962#M13850</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-04-12T16:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9963#M13851</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest to let TAC find what goes wrong here!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Apr 2018 06:58:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9963#M13851</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-13T06:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9964#M13852</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64623_pastedImage_1.png" style="width: 620px; height: 380px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Apr 2018 03:35:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9964#M13852</guid>
      <dc:creator>Juan_Concepcion</dc:creator>
      <dc:date>2018-04-16T03:35:29Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9965#M13853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did anybody managed to solve this issue? I have the same issue here with the same log&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like something is missing with the authentication configuration but it is not stated in the R80.10 remote access documentation (or I missed it somehow)&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2018 18:28:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9965#M13853</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2018-09-14T18:28:11Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9966#M13854</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;I would still suggest to let TAC find what goes wrong here and post the result ! &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Sep 2018 07:15:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9966#M13854</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-09-17T07:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9967#M13855</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;After great remote session with Check Point Support we figured out that the microsoft CA has to be configured in SmartDashboard in addition to the LDAP server&amp;nbsp;&lt;/P&gt;&lt;P&gt;Unlike Domain User authentication It is a must to configure the Microsoft CA in order to authenticate with a certificate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The documentation is lacking and can definitely be improved since you need to search in 3 different locations (and in Check Mates) in order to figure out the complete configuration of this&amp;nbsp;deployment&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2018 13:48:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9967#M13855</guid>
      <dc:creator>Shahar_Grober</dc:creator>
      <dc:date>2018-09-19T13:48:42Z</dc:date>
    </item>
    <item>
      <title>Re: remote client VPN authentication with Certificate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9968#M13856</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;will you kind enough to share the details or the steps to proceed with the configuration ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;i really don't feel going through TAC for this, it should be documented since the config should be straight forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Sep 2018 16:49:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/remote-client-VPN-authentication-with-Certificate/m-p/9968#M13856</guid>
      <dc:creator>ovidiu_catrina</dc:creator>
      <dc:date>2018-09-19T16:49:08Z</dc:date>
    </item>
  </channel>
</rss>

