<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237957#M2599</link>
    <description>&lt;P&gt;Good morning everyone,&lt;/P&gt;&lt;P&gt;I am helping to implement two-factor authentication between Check Point and Google using SAML for Remote Access VPN connections. The Identity Provider settings are configured correctly and the client can successfully connect to the VPN. However, I cannot see the groups that the user belongs to and therefore I cannot create rules based on user groups. I followed this documentation -&amp;gt; &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm&lt;/A&gt; (Step 6: Configure the Group Authorization), however, I cannot handle access by groups.&lt;BR /&gt;Do any of you have any experience with this type of implementation that you could share?&lt;/P&gt;</description>
    <pubDate>Wed, 08 Jan 2025 11:45:41 GMT</pubDate>
    <dc:creator>j_silva</dc:creator>
    <dc:date>2025-01-08T11:45:41Z</dc:date>
    <item>
      <title>VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237957#M2599</link>
      <description>&lt;P&gt;Good morning everyone,&lt;/P&gt;&lt;P&gt;I am helping to implement two-factor authentication between Check Point and Google using SAML for Remote Access VPN connections. The Identity Provider settings are configured correctly and the client can successfully connect to the VPN. However, I cannot see the groups that the user belongs to and therefore I cannot create rules based on user groups. I followed this documentation -&amp;gt; &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm&lt;/A&gt; (Step 6: Configure the Group Authorization), however, I cannot handle access by groups.&lt;BR /&gt;Do any of you have any experience with this type of implementation that you could share?&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 11:45:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237957#M2599</guid>
      <dc:creator>j_silva</dc:creator>
      <dc:date>2025-01-08T11:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237964#M2600</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;If I understood correcly, you have to create manually with&amp;nbsp;&lt;SPAN&gt;EXT_ID_ prefix.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if your grp attribute is "akos", then you need to create an user group with&lt;EM&gt;&lt;STRONG&gt; EXT_ID_akos&lt;/STRONG&gt;&lt;/EM&gt; name:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2025-01-08 13_10_11-Cloud Demo Server [ID_726223510]-R81.20-SmartConsole.png" style="width: 153px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29130i8EDFBB51AE8527AC/image-size/small?v=v2&amp;amp;px=200" role="button" title="2025-01-08 13_10_11-Cloud Demo Server [ID_726223510]-R81.20-SmartConsole.png" alt="2025-01-08 13_10_11-Cloud Demo Server [ID_726223510]-R81.20-SmartConsole.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="2"&gt;
&lt;P&gt;&lt;EM&gt;In&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_con variable"&gt;SmartConsole&lt;/SPAN&gt;, create an internal User Group object with this name (case-sensitive, spaces not supported):&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="Menu_Options"&gt;EXT_ID_&amp;lt;Name_of_Role&amp;gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;For example, for a role in the&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_idprov variable"&gt;Identity Provider&lt;/SPAN&gt;'s interface with the name&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;my_group&lt;/SPAN&gt;, create an internal User Group object in&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_con variable"&gt;SmartConsole&lt;/SPAN&gt;&amp;nbsp;with the name&amp;nbsp;&lt;SPAN class="Menu_Options"&gt;EXT_ID_my_group.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;TABLE class="TableStyle-TP_Table_Notes" cellspacing="0"&gt;&lt;COLGROUP&gt;&lt;COL class="TableStyle-TP_Table_Notes-Column-Column_Style_Image" /&gt;&lt;COL class="TableStyle-TP_Table_Notes-Column-Column_Style_Text" /&gt;&lt;/COLGROUP&gt;
&lt;TBODY&gt;
&lt;TR class="TableStyle-TP_Table_Notes-Body-Body"&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyB-Column_Style_Image-Body"&gt;&lt;EM&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AkosBakos_0-1736338190637.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29129iFB43754BF6178F3D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AkosBakos_0-1736338190637.png" alt="AkosBakos_0-1736338190637.png" /&gt;&lt;/span&gt;&lt;/EM&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/TD&gt;
&lt;TD class="TableStyle-TP_Table_Notes-BodyA-Column_Style_Text-Body"&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="Note"&gt;Note&lt;/SPAN&gt;&amp;nbsp;- In&amp;nbsp;&lt;SPAN class="mc-variable Vars_CloudGuard.tp_azure_full variable"&gt;Microsoft Azure&lt;/SPAN&gt;,&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_idtags variable"&gt;Identity Tags&lt;/SPAN&gt;&amp;nbsp;are not supported for Remote Access connections.&lt;/EM&gt;&lt;/P&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope it helps&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 12:11:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237964#M2600</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-08T12:11:10Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237966#M2601</link>
      <description>&lt;P&gt;Thank you very much,&lt;/P&gt;&lt;P&gt;Can you tell me where I can correctly configure the groups parameter in Google Cloud?&lt;/P&gt;&lt;P&gt;I have already tried to do this configuration. I will validate it again and report the results.&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 12:16:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237966#M2601</guid>
      <dc:creator>j_silva</dc:creator>
      <dc:date>2025-01-08T12:16:00Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237969#M2602</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am not familiar with Google Cloud, maybe the Legends will help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Have you asked the ChatGPT already?&lt;/P&gt;
&lt;P&gt;Ákos&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jan 2025 12:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/237969#M2602</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-08T12:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/238039#M2603</link>
      <description>&lt;P&gt;The relevant groups must be passed as part of the SAML assertion.&lt;BR /&gt;In Google Cloud, it looks like you configure this here:&amp;nbsp;&lt;A href="https://cloud.google.com/iap/docs/saml-attribute-propagation" target="_blank"&gt;https://cloud.google.com/iap/docs/saml-attribute-propagation&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 02:46:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/238039#M2603</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-01-09T02:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/238160#M2604</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28415"&gt;@AkosBakos&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tried to find out this information on ChatGPT but it wasn´t clear for me. Yesterday i had a meeting with TAC e some debugs was collected.&lt;/P&gt;&lt;P&gt;I´ll waiting for the results of analysis and i update this chat as soon as possible.&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 12:25:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/238160#M2604</guid>
      <dc:creator>j_silva</dc:creator>
      <dc:date>2025-01-10T12:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/238162#M2605</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for documentation. I´ll forward to the customer because i don´t have access on Google plataform.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jan 2025 12:26:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Remote-Access-MFA-with-SAML-and-Google-Cloud-as-Identity/m-p/238162#M2605</guid>
      <dc:creator>j_silva</dc:creator>
      <dc:date>2025-01-10T12:26:24Z</dc:date>
    </item>
  </channel>
</rss>

