<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Harmony connect Identity Provider SafeNet(Thales) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137418#M322</link>
    <description>&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;Do you happen to have a screenshot or a small documentation of the values you have stored in the Safenet portal for Check Poitn Harmony?&lt;BR /&gt;&lt;BR /&gt;Happy new Year !!&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
    <pubDate>Thu, 30 Dec 2021 09:59:48 GMT</pubDate>
    <dc:creator>smeny</dc:creator>
    <dc:date>2021-12-30T09:59:48Z</dc:date>
    <item>
      <title>Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137046#M311</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;We currently want to connect the identity provider SafeNet with Check Point Harmony. Unfortunately SafeNet is not listed as a native provider, so we have to use the generic SAML interface.&lt;/P&gt;&lt;P&gt;So far we have not been able to transfer the correct values (groups) to Harmony, which is why no user authentication can be performed.&lt;/P&gt;&lt;P&gt;Do any of you have experience or have even actively integrated SafeNet?&lt;/P&gt;&lt;P&gt;We are grateful for every tip&lt;/P&gt;&lt;P&gt;Greetings Stefan&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 07:20:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137046#M311</guid>
      <dc:creator>smeny</dc:creator>
      <dc:date>2021-12-23T07:20:01Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137322#M313</link>
      <description>&lt;P&gt;My understanding is that SAML itself isn't used for groups, or at least we're not using it for that.&lt;BR /&gt;In Azure AD, for instance, we use the Graph API to pull groups.&lt;BR /&gt;A specific integration would likely be an RFE.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 20:25:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137322#M313</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-28T20:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137353#M315</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Indeed SafeNet is not listed as one of the vendors in the Harmony Connect IDP wizard, so we need to use the generic option. It means that the users/groups will not be listed while trying to configure rules in the poilcy.&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9883"&gt;@Keren_Greenblat&lt;/a&gt;&amp;nbsp;maybe you can elaborate better about the needed steps to make it work from HC policy point of view?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 11:46:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137353#M315</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2021-12-29T11:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137355#M316</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;AFAIK, SafeNet was never tried with generic (I would have known).&lt;/P&gt;
&lt;P&gt;also there's no guarantee that it will work.&lt;/P&gt;
&lt;P&gt;please try these steps for your configuration:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2 id="SAMLserviceloginissuesandgenericsamlconf-GeneralSAMLIDP-howtoconfigurewithcustomer"&gt;General SAML IDP - how to configure with customer&lt;/H2&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Configure the wizard&lt;/LI&gt;
&lt;LI&gt;Be aware that full sync isn’t supported.&lt;/LI&gt;
&lt;LI&gt;On the IDP side use the URL’s from the connectivity page in the idp wizard (2 urls must be configured for Entity ID and reply URL(sso))&lt;/LI&gt;
&lt;LI&gt;Try to configure the following claims:&lt;/LI&gt;
&lt;/OL&gt;
&lt;UL&gt;
&lt;LI&gt;nameId – email format&lt;/LI&gt;
&lt;LI&gt;‘userId’ – user object id in the IDP.&lt;/LI&gt;
&lt;LI&gt;'First Name' – user first name&lt;/LI&gt;
&lt;LI&gt;'Last Name' – user last name&lt;/LI&gt;
&lt;LI&gt;‘email’ – user email&lt;/LI&gt;
&lt;LI&gt;‘groups’ &amp;nbsp;or “urn:mace:dir:attribute-def:groups” as key, value should be the group name&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if this still doesn't work, and it's a deal breaker, I will be able to join for a two hours (maximum) session to try and help.&lt;/P&gt;
&lt;P&gt;please note, I had similar session last week for KeyCloak over generic, but after two hours we still couldn't complete relevant configuration.&lt;/P&gt;
&lt;P&gt;Such cases are example why it cannot really done online with customer. IDP official support requires developer research that usually takes few days, and therefore closing it in a session with customer is less recommended (therefore I suggest to allocate 2 hours max for that).&lt;/P&gt;</description>
      <pubDate>Wed, 29 Dec 2021 12:15:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137355#M316</guid>
      <dc:creator>Keren_Greenblat</dc:creator>
      <dc:date>2021-12-29T12:15:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137416#M321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I have already integrated Harmony Connect with Thales STA (Safenet Trusted Access) and it worked. But I tried it only for Harmony Connect Internet Access if I remember correctly.&lt;/P&gt;
&lt;P&gt;I don't have it enabled anymore.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 09:28:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137416#M321</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2021-12-30T09:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137418#M322</link>
      <description>&lt;P&gt;Hi Norbert,&lt;/P&gt;&lt;P&gt;Do you happen to have a screenshot or a small documentation of the values you have stored in the Safenet portal for Check Poitn Harmony?&lt;BR /&gt;&lt;BR /&gt;Happy new Year !!&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 09:59:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137418#M322</guid>
      <dc:creator>smeny</dc:creator>
      <dc:date>2021-12-30T09:59:48Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137420#M323</link>
      <description>&lt;P&gt;Sorry, no, I have only tested it and removed the configuration directly afterwards.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Dec 2021 10:01:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/137420#M323</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2021-12-30T10:01:18Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Harmony connect Identity Provider SafeNet(Thales)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/143328#M353</link>
      <description>&lt;P&gt;Hi All,&lt;BR /&gt;we have managed to connect Safenet Thales to the Check Point Hamony Connect Cloud via genric SAML. attached you will find the screenshots of the configuration we created in the Safnet Thales portal. It is also important that the groups have to be created manually.&lt;/P&gt;&lt;P&gt;Just for Info, if somebody also want to use it&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2022 10:25:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Harmony-connect-Identity-Provider-SafeNet-Thales/m-p/143328#M353</guid>
      <dc:creator>smeny</dc:creator>
      <dc:date>2022-03-09T10:25:54Z</dc:date>
    </item>
  </channel>
</rss>

