<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220627#M3545</link>
    <description>&lt;P&gt;Forgot to mention vpn debug steps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;*****************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-do the test&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;Look for iked and vpnd files in $FWDIR/log directory&lt;/P&gt;</description>
    <pubDate>Sat, 13 Jul 2024 04:20:13 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-07-13T04:20:13Z</dc:date>
    <item>
      <title>Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220619#M3541</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am facing an issue after implementing 2MFA with IDP in RA VPN on Windows with SDL enabled.&lt;/P&gt;&lt;P&gt;Before implementing the second authentication factor, login with SDL worked perfectly, however after implementing 2MFA it is not possible to connect to the VPN because the client makes a redirect to open a kind of plugin and start the IDP screen, that's where it happens the error, for some reason it does not open 2mfa directly on the client screen, it has to consult this plugin first and in my opinion the error occurs because it is not possible to consult the plugin because it is not yet logged into Windows.&lt;/P&gt;&lt;P&gt;If I log on to the machine and try to connect to the VPN, the operation occurs successfully and the 2nd factor opens the screen in the client itself without any problem, however this is the perception that I would like to have in SDL before logging into Windows and I am not having it .&lt;/P&gt;&lt;P&gt;I tried to use the SK &lt;A href="https://support.checkpoint.com/results/sk/sk180395" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180395&lt;/A&gt; to make some adjustments to the client, but without success, IDP_BROWSER was already enabled as embedded in the client itself, but I think there is some validation operation that it confirms with a third party for it to work, outside the client.&lt;/P&gt;&lt;P&gt;Is it possible for SDL to work with 2MFA with IDPs like Azure, Cisco DUO and others?&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 01:20:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220619#M3541</guid>
      <dc:creator>jarvis_dantsrib</dc:creator>
      <dc:date>2024-07-13T01:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220621#M3542</link>
      <description>&lt;P&gt;I cant open all the attachments, just the 1st one...is the only error negotiation with site failed? Did you try do zdebug on the firewall to see if anything is dropped when this happens?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 01:47:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220621#M3542</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-13T01:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220625#M3543</link>
      <description>&lt;P&gt;Hello the_rock,&lt;/P&gt;&lt;P&gt;These are the images I imported.&lt;/P&gt;&lt;P&gt;I ran zdebug but didn't see any traffic blocks.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem_2024-07-12_225254135.png" style="width: 774px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26771i94AEB8224733376D/image-dimensions/774x456?v=v2" width="774" height="456" role="button" title="imagem_2024-07-12_225254135.png" alt="imagem_2024-07-12_225254135.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem_2024-07-12_225307489.png" style="width: 774px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26772iEBB0D345A91D12C3/image-dimensions/774x430?v=v2" width="774" height="430" role="button" title="imagem_2024-07-12_225307489.png" alt="imagem_2024-07-12_225307489.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WhatsApp Image 2024-07-12 at 22.03.12 (1).jpeg" style="width: 772px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26773i98EDFE4D77407FB6/image-dimensions/772x462?v=v2" width="772" height="462" role="button" title="WhatsApp Image 2024-07-12 at 22.03.12 (1).jpeg" alt="WhatsApp Image 2024-07-12 at 22.03.12 (1).jpeg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 01:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220625#M3543</guid>
      <dc:creator>jarvis_dantsrib</dc:creator>
      <dc:date>2024-07-13T01:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220626#M3544</link>
      <description>&lt;P&gt;If its urgent, I would contact TAC. Otherwise, would run basic vpn debugs.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 03:25:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220626#M3544</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-13T03:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220627#M3545</link>
      <description>&lt;P&gt;Forgot to mention vpn debug steps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;*****************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;vpn debug trunc&lt;/P&gt;
&lt;P&gt;vpn debug ikeon&lt;/P&gt;
&lt;P&gt;-do the test&lt;/P&gt;
&lt;P&gt;vpn debug ikeoff&lt;/P&gt;
&lt;P&gt;Look for iked and vpnd files in $FWDIR/log directory&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 04:20:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220627#M3545</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-13T04:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220632#M3546</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm?Highlight=secure%20domain%20logon" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm?Highlight=secure%20domain%20logon&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H2&gt;Known Limitations&lt;/H2&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="SearchHighlight SearchHighlight1"&gt;Secure&lt;/SPAN&gt; &lt;SPAN class="SearchHighlight SearchHighlight2"&gt;Domain&lt;/SPAN&gt; &lt;SPAN class="SearchHighlight SearchHighlight3"&gt;Logon&lt;/SPAN&gt; (SDL) with &lt;SPAN class="mc-variable Vars_BladesFeatures.tp_idprov variable"&gt;Identity Provider&lt;/SPAN&gt; is not supported.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Sat, 13 Jul 2024 08:39:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220632#M3546</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-07-13T08:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problem opening the 2MFA screen with IDP using Secure Domain Logon (SDL) Windows</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220635#M3547</link>
      <description>&lt;P&gt;Never seen that limitation before, thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Sat, 13 Jul 2024 11:59:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Problem-opening-the-2MFA-screen-with-IDP-using-Secure-Domain/m-p/220635#M3547</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-07-13T11:59:42Z</dc:date>
    </item>
  </channel>
</rss>

