<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Login SAML + local fw login + AD in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158709#M6194</link>
    <description>&lt;P&gt;Ok, I'm confused.&lt;BR /&gt;If you're using Azure AD (which doesn't require LDAP) for your corporate users and locally defined users for your third party users, how are your Azure AD users just authenticating with username/password without going through the SAML dance?&lt;/P&gt;
&lt;P&gt;Do you have an LDAP Account Unit defined?&lt;BR /&gt;I imagine you might need that for Identity Awareness.&lt;BR /&gt;What authentication methods do you have configured as supported on the relevant gateway object?&lt;/P&gt;
&lt;P&gt;Screenshots of everything you've attempted to configure related to this would be exceptionally helpful.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Oct 2022 17:29:48 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-10-03T17:29:48Z</dc:date>
    <item>
      <title>VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158553#M6189</link>
      <description>&lt;P&gt;Hi! We had implemented Checkpoint firewalls with VPN Connections. Recently we implement SAML with AzureAD to secure the VPN Logins without technical issues, its working properly, but we had a issue : If the users change the Login options to user/password, this options works for local logins on Checkpoint &lt;STRONG&gt;and&lt;/STRONG&gt; AD.&lt;/P&gt;&lt;P&gt;We need to work &lt;STRONG&gt;only&lt;/STRONG&gt; with local fw login and SAML to the users, I understand the AD integration had to be implemented because this is part of the SAML integration, but i don't want to work this to the users to use user+password direct, because this mantains the vulnerability of use this login option.&lt;/P&gt;&lt;P&gt;Another thing I don't mentioned, I can't use ONLY azureAD, because had third part connections than use local login on checkpoint, so I had to mantain this option because had only Azure Users cost much money.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please if you can show me an option to use only SAML to users, and the option User+PASS only works to local login FW, no AD.&lt;/P&gt;&lt;P&gt;Thanks Checkmates!&lt;/P&gt;</description>
      <pubDate>Fri, 30 Sep 2022 23:32:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158553#M6189</guid>
      <dc:creator>jfernandezm</dc:creator>
      <dc:date>2022-09-30T23:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158564#M6190</link>
      <description>&lt;P&gt;Is it the case when the same user exists in both on-prem and Azure AD?&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 09:16:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158564#M6190</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-01T09:16:38Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158577#M6191</link>
      <description>&lt;P&gt;Yes Val, because the AD is synced with AzureAD, so the accounts was the same.&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 11:46:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158577#M6191</guid>
      <dc:creator>jfernandezm</dc:creator>
      <dc:date>2022-10-01T11:46:18Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158585#M6192</link>
      <description>&lt;P&gt;Users that are authenticating with AzureAD can get group information from Graph API (R81 and above).&lt;BR /&gt;Third party users not in AzureAD would obviously need to get their information from a different source (LDAP).&lt;/P&gt;
&lt;P&gt;The LDAP portion of the configuration will need to include only the precise branch that includes ONLY your third party users, not the entire AD tree.&lt;BR /&gt;Depending on how many third party users are involved, it might be better to locally define each one.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 14:55:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158585#M6192</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-01T14:55:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158587#M6193</link>
      <description>&lt;P&gt;Hi!!! The third parties only connect with user+pass from checkpoint local login, no need to acces to LDAP login. In the other side the corporative users is needed to use only AzureAD, no LDAP login, otherwise the implementation of SAML AzureAD is useless.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;</description>
      <pubDate>Sat, 01 Oct 2022 17:20:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158587#M6193</guid>
      <dc:creator>jfernandezm</dc:creator>
      <dc:date>2022-10-01T17:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158709#M6194</link>
      <description>&lt;P&gt;Ok, I'm confused.&lt;BR /&gt;If you're using Azure AD (which doesn't require LDAP) for your corporate users and locally defined users for your third party users, how are your Azure AD users just authenticating with username/password without going through the SAML dance?&lt;/P&gt;
&lt;P&gt;Do you have an LDAP Account Unit defined?&lt;BR /&gt;I imagine you might need that for Identity Awareness.&lt;BR /&gt;What authentication methods do you have configured as supported on the relevant gateway object?&lt;/P&gt;
&lt;P&gt;Screenshots of everything you've attempted to configure related to this would be exceptionally helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Oct 2022 17:29:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/158709#M6194</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-03T17:29:48Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/159063#M6195</link>
      <description>&lt;P&gt;I think this is the issue then. LDAP is checked before Azure, and since the accounts are there, it returns the authentication. See if you can set up your VPN in a way AD is not queried.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Oct 2022 13:35:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/159063#M6195</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-10-08T13:35:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Login SAML + local fw login + AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/159065#M6196</link>
      <description>&lt;P&gt;Yes, the implementing company is reviewing the configuration to dispense with the local AD. We check and the FW cfg is at 80.40 take 156&lt;/P&gt;</description>
      <pubDate>Sat, 08 Oct 2022 13:38:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Login-SAML-local-fw-login-AD/m-p/159065#M6196</guid>
      <dc:creator>jfernandezm</dc:creator>
      <dc:date>2022-10-08T13:38:24Z</dc:date>
    </item>
  </channel>
</rss>

