<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint Security VPN client configuration via cli in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35095#M13894</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When we import a certificate using Microsoft's tools, the VPN connection does not establish. When importing directly through the&amp;nbsp;CheckPoint VPN client - everything works.&lt;BR /&gt;Therefore, we are considering the option of importing through the &lt;SPAN&gt;CheckPoint VPN client&lt;/SPAN&gt;, but using the command line.&amp;nbsp;Why do we need the command line? We need to automate the process of installing the VPN client and its settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Mar 2018 08:12:26 GMT</pubDate>
    <dc:creator>Olga_Kuts</dc:creator>
    <dc:date>2018-03-14T08:12:26Z</dc:date>
    <item>
      <title>Endpoint Security VPN client configuration via cli</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35093#M13892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have a need of full configuration CheckPoint VPN client via cli (authentication method - CAPI certificate). We did all settings via cli using trac.exe except for certificate import.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can we import certificate using cli (in particular using trac.exe)?&amp;nbsp;The option of certificate importing the standard means of the&amp;nbsp;Windows does not suit us.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 09:40:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35093#M13892</guid>
      <dc:creator>Olga_Kuts</dc:creator>
      <dc:date>2018-03-13T09:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN client configuration via cli</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35094#M13893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you're using CAPI, then I presume you should use Microsoft's tools to manage the certificate store.&lt;/P&gt;&lt;P&gt;A quick Google search brought me to:&amp;nbsp;&lt;A class="link-titled" href="https://stackoverflow.com/questions/23869177/import-certificate-to-trusted-root-but-not-to-personal-command-line" title="https://stackoverflow.com/questions/23869177/import-certificate-to-trusted-root-but-not-to-personal-command-line"&gt;windows - Import Certificate to Trusted Root but not to Personal [Command Line] - Stack Overflow&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Mar 2018 23:37:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35094#M13893</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-13T23:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN client configuration via cli</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35095#M13894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When we import a certificate using Microsoft's tools, the VPN connection does not establish. When importing directly through the&amp;nbsp;CheckPoint VPN client - everything works.&lt;BR /&gt;Therefore, we are considering the option of importing through the &lt;SPAN&gt;CheckPoint VPN client&lt;/SPAN&gt;, but using the command line.&amp;nbsp;Why do we need the command line? We need to automate the process of installing the VPN client and its settings.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2018 08:12:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35095#M13894</guid>
      <dc:creator>Olga_Kuts</dc:creator>
      <dc:date>2018-03-14T08:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint Security VPN client configuration via cli</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35096#M13895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Afaik, this is not possible using standard means - see Remote Access VPN Administration Guide R80.10 for details. Here we find:&lt;/P&gt;&lt;P&gt;Check Point's Internal Certificate Authority (ICA) offers two ways to create and transfer certificates to remote users:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;1. The administrator generates a certificate in the Security Management Server for the remote user, saves it to removable media, and transfers it to the client "out-of-band."&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;2. The administrator initiates the certificate process on the Security Management Server (or ICA management tool), and is given a registration key. The administrator transfers the registration key to the user "out-of-band." The client establishes an SSL connection to the ICA (using the CMC protocol) and completes the certificate generation process using the registration key. In this way:&lt;BR /&gt;• Private keys are generated on the client.&lt;BR /&gt;• The created certificate can be stored as a file on the machines hard-drive, on a CAPI storage device, or on a hardware token.&lt;BR /&gt;This method is especially suitable for geographically spaced-remote users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But nothing about a CLI installation method ! I would suggest to ask CP TAC for a solution and update us when it has worked for you &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Mar 2018 12:46:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-Security-VPN-client-configuration-via-cli/m-p/35096#M13895</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-03-14T12:46:05Z</dc:date>
    </item>
  </channel>
</rss>

