<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine Authentication Pre-Windows Login Certificate Issue on Check Point Remote Access VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198421#M4378</link>
    <description>&lt;P&gt;Hi, my machine cert is in the personal store, intermediate in the intermediate and the root in the root. The Management server has also got both the Intermediate and the root certs installed. This is because the machine cert is signed by the intermediate as is the server cert configured on the gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the link you shared, however I am using R80.40 on the gateway.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Nov 2023 19:35:23 GMT</pubDate>
    <dc:creator>AshleyM</dc:creator>
    <dc:date>2023-11-20T19:35:23Z</dc:date>
    <item>
      <title>Machine Authentication Pre-Windows Login Certificate Issue on Check Point Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198181#M4376</link>
      <description>&lt;P&gt;Hello CheckMates Community,&lt;/P&gt;&lt;P&gt;I'm reaching out for some insights regarding a challenge I'm facing with the Check Point Remote Access VPN. Although the initial setup and machine authentication seem to be working fine, I'm encountering a specific issue at the pre-Windows login phase: the authentication certificate required for login isn't showing up.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Brief Overview of the Issue:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Successfully set up the Check Point Remote Access VPN and machine authentication. VPN authenticates with machine cert and SAML once logged into windows.&lt;/LI&gt;&lt;LI&gt;The problem occurs at the pre-Windows login stage, where no certificate appears for authentication. SDL is enabled for this, so the VPN client is available at pre-windows login.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;STRONG&gt;Troubleshooting Attempts:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Checked the certificate's installation in the Windows certificate store.&lt;/LI&gt;&lt;LI&gt;Configured the VPN client settings to align with certificate requirements.&lt;/LI&gt;&lt;LI&gt;Investigated potential group policy restrictions impacting certificate usage.&lt;/LI&gt;&lt;LI&gt;Updated the VPN client and related drivers.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Despite these steps, the issue remains unresolved. I'm hoping someone in the community might have encountered a similar situation or could offer some advice. Any suggestions or guidance would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="EPS-SDL.jpg" style="width: 600px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23274iDC3A2FB6DEE2BA09/image-size/large?v=v2&amp;amp;px=999" role="button" title="EPS-SDL.jpg" alt="EPS-SDL.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is some system information:&lt;/P&gt;&lt;P&gt;Host OS = Windows 10&lt;/P&gt;&lt;P&gt;Firewall version = R80.40 (with latest HF)&lt;/P&gt;&lt;P&gt;Here are some guides I've followed:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuration-Examples-for-Machine-and-User-Authentication.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Configuration-Examples-for-Machine-and-User-Authentication.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Remote-Access-VPN/Secure-Domain-Logon-with-certificate-based-authentication/m-p/173422#" target="_blank" rel="noopener"&gt;Solved: Re: Secure Domain Logon with certificate based aut... - Check Point CheckMates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Machine-Certificate.htm" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Machine-Certificate.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Looking forward to your responses and thank you in advance for your help!&lt;/P&gt;</description>
      <pubDate>Sat, 18 Nov 2023 14:45:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198181#M4376</guid>
      <dc:creator>AshleyM</dc:creator>
      <dc:date>2023-11-18T14:45:17Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication Pre-Windows Login Certificate Issue on Check Point Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198405#M4377</link>
      <description>&lt;P&gt;Where is the certificate stored in this case?&lt;BR /&gt;See also:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk121173" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk121173&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 16:24:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198405#M4377</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-20T16:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication Pre-Windows Login Certificate Issue on Check Point Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198421#M4378</link>
      <description>&lt;P&gt;Hi, my machine cert is in the personal store, intermediate in the intermediate and the root in the root. The Management server has also got both the Intermediate and the root certs installed. This is because the machine cert is signed by the intermediate as is the server cert configured on the gateway&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the link you shared, however I am using R80.40 on the gateway.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 19:35:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198421#M4378</guid>
      <dc:creator>AshleyM</dc:creator>
      <dc:date>2023-11-20T19:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication Pre-Windows Login Certificate Issue on Check Point Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198432#M4379</link>
      <description>&lt;P&gt;You're trying to use a CAPI certificate for SDL.&lt;BR /&gt;This is not supported and is noted as such in the product documentation:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/SDL-for-SmartConsole-Managed-Clients.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/SDL-for-SmartConsole-Managed-Clients.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 22:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-Pre-Windows-Login-Certificate-Issue-on/m-p/198432#M4379</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-20T22:05:22Z</dc:date>
    </item>
  </channel>
</rss>

