<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/251376#M1916</link>
    <description>&lt;P&gt;Oh bother!&amp;nbsp;&lt;BR /&gt;I kind of figured that would be the case.&lt;/P&gt;&lt;P&gt;Moving this service to Harmony SASE is not an option as that would require additional licensing which is outside the scope of what is trying to be done at this time.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
    <pubDate>Mon, 16 Jun 2025 19:59:10 GMT</pubDate>
    <dc:creator>Ave_Joe</dc:creator>
    <dc:date>2025-06-16T19:59:10Z</dc:date>
    <item>
      <title>SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250499#M1912</link>
      <description>&lt;H3&gt;&lt;STRONG&gt;Remote Access VPN Setup&lt;/STRONG&gt;&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;The Remote Access VPN community consists of &lt;STRONG&gt;12 gateways&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Users typically connect to the &lt;STRONG&gt;primary gateway in the U.S. data center&lt;/STRONG&gt;, which issues Office Mode IP addresses.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;The VPN client utilizes &lt;STRONG&gt;Secondary Connect&lt;/STRONG&gt; to reach resources behind other gateways in the community.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;All gateways are configured for &lt;STRONG&gt;SAML-based Single Sign-On (SSO)&lt;/STRONG&gt; using &lt;STRONG&gt;Microsoft Entra ID&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;When a user accesses a resource behind a &lt;STRONG&gt;Secondary Connect gateway&lt;/STRONG&gt;, the VPN client triggers a &lt;STRONG&gt;new SAML authentication flow&lt;/STRONG&gt;. This opens the user's default browser and starts the SSO process again.&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;The repeated SAML prompt &lt;STRONG&gt;confuses users and interrupts their tasks&lt;/STRONG&gt;, leading to a &lt;STRONG&gt;frustrating VPN experience&lt;/STRONG&gt; and reduced productivity.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;H3&gt;&lt;STRONG&gt;Question&lt;/STRONG&gt;&lt;/H3&gt;&lt;P&gt;Is there a configuration that would allow the VPN client to &lt;STRONG&gt;reuse the initial SAML authentication&lt;/STRONG&gt; and avoid triggering a new browser-based authentication prompt when accessing resources behind a Secondary Connect gateway?&lt;/P&gt;&lt;P&gt;Could a &lt;STRONG&gt;single Remote Access identity provider configuration&lt;/STRONG&gt; be applied across all 12 participating gateways to streamline the authentication process and eliminate redundant prompts?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 16:06:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250499#M1912</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2025-06-03T16:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250520#M1913</link>
      <description>&lt;P&gt;If you've configured things per either&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180948" target="_blank"&gt;sk180948&lt;/A&gt; or&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182042" target="_blank"&gt;sk182042&lt;/A&gt;, you'll need to undo this configuration since the gateway sends an attribute to force reauthentication, which will also apply to Secondary Connect.&lt;BR /&gt;However, this creates a situation where if the user is authorized on the machine (i.e. with Entra ID) and the timeout hasn't expired, they will be able to connect to the VPN without authentication.&lt;BR /&gt;Whether this works the same way with Secondary Connect is a separate question.&lt;/P&gt;
&lt;P&gt;If your environment is complex enough that Secondary Connect is needed, Harmony SASE might be worth exploring.&lt;BR /&gt;Not sure if &lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Infinity-Identity.htm" target="_blank"&gt;Infinity Identity&lt;/A&gt; will help with this use case, but it will definitely centralize the configuration.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2025 20:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250520#M1913</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-03T20:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250530#M1914</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6878"&gt;@Ave_Joe&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;I will start with a disclaimer that I'm not well familiar with VPN internal flows.&lt;/P&gt;
&lt;P&gt;However, my assumption is that the issue you are facing is caused due to the fact the SAML configuration in Quantum requires different application on Entra side, and considered as separate "service". It means, each gateway acts as a different service, therefore there is no reuse of the SAML authentication.&lt;/P&gt;
&lt;P&gt;In R82, we have introduced a new SAML I/S powered by Infinity Identity. Once you configure the Entra ID integration in Infinity Portal, it is automatically replicated to your Quantum management (prerequisite to this is a trust between the Quantum management and Infinity Portal, under "Infinity Services"). In this scenario, Infinity services are the "service provider" and the gateway consume the SAML authentication result from Infinity.&lt;/P&gt;
&lt;P&gt;After explaining this, few notes:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;This I/S is currently consumed by Identity Awareness only. There is a planned effort to join VPN clients to this I/S, but I don't know the ETA for this. You are welcome to contact your SE and open RFE to get official answers from the relevant owners.&lt;/LI&gt;
&lt;LI&gt;This I/S will require R82 management and gateway (once step #1 will be finished for VPN clients).&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope it helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 05:21:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250530#M1914</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2025-06-04T05:21:28Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250595#M1915</link>
      <description>&lt;P&gt;I wasn't sure if the different "Service Providers" (in SAML terms) would allow credential reuse; thanks for confirming it doesn't.&lt;BR /&gt;That suggests&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6878"&gt;@Ave_Joe&lt;/a&gt;&amp;nbsp;that your requirement can't be met today with Quantum Security Gateways today.&amp;nbsp;&lt;BR /&gt;However it does sound like it will be possible in the future.&lt;/P&gt;
&lt;P&gt;Harmony SASE can support this use case today.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:27:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/250595#M1915</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-04T13:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/251376#M1916</link>
      <description>&lt;P&gt;Oh bother!&amp;nbsp;&lt;BR /&gt;I kind of figured that would be the case.&lt;/P&gt;&lt;P&gt;Moving this service to Harmony SASE is not an option as that would require additional licensing which is outside the scope of what is trying to be done at this time.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 19:59:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/251376#M1916</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2025-06-16T19:59:10Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/251377#M1917</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Thank you for the response.&lt;/STRONG&gt;&lt;BR /&gt;I was hoping there might be a viable solution, but we’ll continue to monitor for new features or updates that could help improve the user experience moving forward.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Jun 2025 20:08:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/251377#M1917</guid>
      <dc:creator>Ave_Joe</dc:creator>
      <dc:date>2025-06-16T20:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/252152#M1918</link>
      <description>&lt;P&gt;Until we can support this use case with Secondary Connect, it might provide a better user experience to disable Secondary Connect.&lt;BR /&gt;Traffic will be tunneled from whatever gateway the user connects to when Secondary Connect is disabled.&lt;/P&gt;
&lt;P&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Secondary-Connect.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Secondary-Connect.htm&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jun 2025 21:16:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/252152#M1918</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-06-27T21:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: SAML Re-authentication Prompt During Secondary Connect – Configuration Inquiry</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/254167#M1919</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;any news on this?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jul 2025 08:05:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SAML-Re-authentication-Prompt-During-Secondary-Connect/m-p/254167#M1919</guid>
      <dc:creator>CheckPointerXL</dc:creator>
      <dc:date>2025-07-29T08:05:33Z</dc:date>
    </item>
  </channel>
</rss>

