<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forcing VPN with SAML (Google SSO) to re-authenticate in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/223068#M6103</link>
    <description>&lt;P&gt;Hello&amp;nbsp;nzmatto 1&lt;BR /&gt;Can u share how you configure SAML with Google? I'm try, but not work working.&lt;BR /&gt;Are u make&amp;nbsp;SAML Attribute Mapping on Google? If yes, how your configurated?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Aug 2024 13:16:35 GMT</pubDate>
    <dc:creator>Icaro_IT</dc:creator>
    <dc:date>2024-08-08T13:16:35Z</dc:date>
    <item>
      <title>Forcing VPN with SAML (Google SSO) to re-authenticate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/160005#M6100</link>
      <description>&lt;P&gt;Here's another wired request from the crazy kiwi.&amp;nbsp;&lt;BR /&gt;I have configured the Remote Access VPN to use Google SSO through a SMAL app. This seems to be working fine, however for further testing I wish to force my client to log out, including from the SSO session to force the 2FA again.&lt;/P&gt;&lt;P&gt;The process is I log on from the client for the first time on a device and I am prompted for a username and password, then for the Google MFA. This is fine, it's accepted and the VPN establishes. once I am finished with the VPN I can disconnect.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The next time I reconnect it doesn't prompt for anything, which from a user point of view is perfect. No username / password / 2fa just straight in. The secure way is the easy way.&amp;nbsp;&lt;/P&gt;&lt;P&gt;However for testing I wish to force my account to log out fully, requiring the username / password / 2fa again, and I can't work out how to achieve this from the client. I have even gone as far as deleting and reinstalling the client, however even then it only asks for a username and password as somewhere in the background Google magic knows I've recently done the 2fa so it just works.&amp;nbsp;&lt;/P&gt;&lt;P&gt;From the client / desktop side I he logged out from my google account and revoked all trusted devices but to no avail.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there some way from the client side I can force my account to require the 2fa like it was a new connection every time?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm wondering if this might be stored in the registry, or in a cookie or something like that.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 23:47:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/160005#M6100</guid>
      <dc:creator>nzmatto1</dc:creator>
      <dc:date>2022-10-19T23:47:06Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing VPN with SAML (Google SSO) to re-authenticate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/160148#M6101</link>
      <description>&lt;P&gt;To achieve the desired behavior, you have to have&amp;nbsp;ForceAuthn set to true as part of the SAML request.&lt;BR /&gt;This is not done by default currently, but a fix for this can be obtained from the TAC by referencing&amp;nbsp;&lt;SPAN&gt;TM-34402.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 22 Oct 2022 00:34:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/160148#M6101</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-22T00:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing VPN with SAML (Google SSO) to re-authenticate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/177686#M6102</link>
      <description>&lt;P&gt;We're using MS saml. I want to disable all network access unless VPNd, how can I do that?&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 19:08:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/177686#M6102</guid>
      <dc:creator>Agent_Smith</dc:creator>
      <dc:date>2023-04-07T19:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Forcing VPN with SAML (Google SSO) to re-authenticate</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/223068#M6103</link>
      <description>&lt;P&gt;Hello&amp;nbsp;nzmatto 1&lt;BR /&gt;Can u share how you configure SAML with Google? I'm try, but not work working.&lt;BR /&gt;Are u make&amp;nbsp;SAML Attribute Mapping on Google? If yes, how your configurated?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 13:16:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Forcing-VPN-with-SAML-Google-SSO-to-re-authenticate/m-p/223068#M6103</guid>
      <dc:creator>Icaro_IT</dc:creator>
      <dc:date>2024-08-08T13:16:35Z</dc:date>
    </item>
  </channel>
</rss>

