<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Centrally change remote access VPN browser setting used for SAML auth by all clients in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226157#M3250</link>
    <description>&lt;P&gt;You can force it on the gateway side by changing idp_browser_mode in the TTM file: &amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk75221" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk75221&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 10 Sep 2024 14:17:46 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-09-10T14:17:46Z</dc:date>
    <item>
      <title>Centrally change remote access VPN browser setting used for SAML auth by all clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226105#M3249</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I would like to know if there is a way to set the idp_browser_mode setting for all VPN clients centrally?&lt;/P&gt;&lt;P&gt;I know that you can change this setting for each client via the &lt;STRONG&gt;trac.defaults&lt;/STRONG&gt; config file and I have done that before (cf. &lt;A href="https://support.checkpoint.com/results/sk/sk180395" target="_self"&gt;sk180395&lt;/A&gt; for reference).&lt;/P&gt;&lt;P&gt;For the context, my issue is that this setting was set to "embedded" in my case when deploying the VPN client as part of Harmony Endpoint E87.31. However, recently when upgrading those clients to a newer Harmony Endpoint version (it seems since E88.41 and above), the SAML portal authentication page now opens using the default browser instead of being embedded, without me changing this. I am not sure if this is part of an included change from the more recent Harmony Endpoint versions (I couldn't find anything related to this in the version release notes). My understanding is that with newer versions, when upgrading versions the existing trac.defaults file is supposed to be kept as-is (and not overwritten), so I am not sure what is causing the change in this setting with the newer versions...&lt;/P&gt;&lt;P&gt;If anybody has more information on this sudden behavior change and if it is possible to rectify the setting back to a certain value (in my case back to "embedded") for all clients at once, that would be great. It's not really practical to have to update all the trac.defaults files for all the clients (in my case 100+) just for this..&lt;/P&gt;&lt;P&gt;Thank you in advance for your help.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 07:45:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226105#M3249</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2024-09-10T07:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Centrally change remote access VPN browser setting used for SAML auth by all clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226157#M3250</link>
      <description>&lt;P&gt;You can force it on the gateway side by changing idp_browser_mode in the TTM file: &amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk75221" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk75221&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 14:17:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226157#M3250</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-10T14:17:46Z</dc:date>
    </item>
    <item>
      <title>Re: Centrally change remote access VPN browser setting used for SAML auth by all clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226211#M3251</link>
      <description>&lt;P&gt;Thanks for the reply, &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt; ,&lt;/P&gt;&lt;P&gt;Can I confirm my understanding on how it works with a few follow-up questions:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;1) In the SK and documentation they mention multiple times the file &lt;STRONG&gt;objects.C. &lt;/STRONG&gt;I believe it refers to the file &lt;EM&gt;$FWDIR/conf/objects.C&lt;/EM&gt; on the gateway? I do not understand this part and how you are supposed to use that file to know if you can use the same parameter as defined in &lt;STRONG&gt;trac.defaults&lt;/STRONG&gt; (meaning leaving gateway parameter empty) or not?&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-09-11 110050.png" style="width: 778px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27559i0CC9AF5FEC91FC7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-09-11 110050.png" alt="Screenshot 2024-09-11 110050.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;PRE&gt;:gateway (&amp;lt;gateway&amp;nbsp;parameter&amp;gt;) &lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;2) Currently, I don't see the setting &lt;STRONG&gt;&lt;EM&gt;idp_browser_mode&lt;/EM&gt;&lt;/STRONG&gt; defined on my cluster member VPN gateways, so I can edit the &lt;STRONG&gt;trac_client_1.ttm&lt;/STRONG&gt; with the following section to achieve my goal in setting back to &lt;STRONG&gt;&lt;EM&gt;embedded&lt;/EM&gt;&lt;/STRONG&gt;, correct?&lt;/P&gt;&lt;PRE&gt;:idp_browser_mode (&lt;BR /&gt;:gateway (&lt;BR /&gt;:map (&lt;BR /&gt;:embedded (embedded)&lt;BR /&gt;:default_browser (default_browser)&lt;BR /&gt;:client_decide (client_decide)&lt;BR /&gt;:IE (IE)&lt;BR /&gt;:Safari (Safari)&lt;BR /&gt;)&lt;BR /&gt;:default (embedded)&lt;BR /&gt;)&lt;BR /&gt;)&lt;/PRE&gt;&lt;P class="lia-indent-padding-left-30px"&gt;This parameter is already set to default_browser on my clients after the upgrade, but since I define it on the gateway it will take precedence, based on the info on the SK:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-09-11 104950.png" style="width: 985px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27561i95AD4DEF27DB14BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2024-09-11 104950.png" alt="Screenshot 2024-09-11 104950.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;3) I do already have other settings defined on the &lt;STRONG&gt;trac_client_1.ttm&lt;/STRONG&gt; of my gateway (MEP settings, ..) as well as on my clients directly (tunnel related) that are being enforced right now. Adding this new setting on the gateway side will not affect the current behavior of those settings I believe, right? Since in my current setup those settings are already configured as either enforced by the gateway (ex: MEP defined on the gateway) or on the client (ex: &lt;EM&gt;&lt;STRONG&gt;enable_machine_auth&lt;/STRONG&gt;&lt;/EM&gt;, &lt;EM&gt;&lt;STRONG&gt;machine_tunnel_site&lt;/STRONG&gt;&lt;/EM&gt;, etc.).&lt;/P&gt;&lt;P&gt;Sorry for the detailed post, just looking for clarifications to validate my understanding.&lt;/P&gt;&lt;P&gt;Thank you very much in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 03:07:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226211#M3251</guid>
      <dc:creator>dt7</dc:creator>
      <dc:date>2024-09-11T03:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: Centrally change remote access VPN browser setting used for SAML auth by all clients</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226217#M3252</link>
      <description>&lt;P&gt;I don't recall anything special with the gateway parameter.&lt;BR /&gt;However, if you can provide a specific reference to where it talks about objects.C, I can have a look.&lt;/P&gt;
&lt;P&gt;Yes, you should be able to add the configuration you mentioned to the trac_client_1.ttm and it should take priority over what is configured on the client.&lt;BR /&gt;It should not impact other settings there as well.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 04:21:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Centrally-change-remote-access-VPN-browser-setting-used-for-SAML/m-p/226217#M3252</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-11T04:21:41Z</dc:date>
    </item>
  </channel>
</rss>

