<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SmartCard Authentication for VPN users in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/131756#M7852</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We currently have our VPN users authenticating with domain (user/password) credentials.&lt;/P&gt;&lt;P&gt;We want to change the VPN authentication to the SmartCard which each user has connected to his laptop and which is normally used to login to the laptop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone configured VPN users with SmartCard authentication?&lt;/P&gt;&lt;P&gt;I was not able to find anything about this in Checkpoint site.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;micha&lt;/P&gt;</description>
    <pubDate>Thu, 14 Oct 2021 10:09:00 GMT</pubDate>
    <dc:creator>mkushner</dc:creator>
    <dc:date>2021-10-14T10:09:00Z</dc:date>
    <item>
      <title>SmartCard Authentication for VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/131756#M7852</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We currently have our VPN users authenticating with domain (user/password) credentials.&lt;/P&gt;&lt;P&gt;We want to change the VPN authentication to the SmartCard which each user has connected to his laptop and which is normally used to login to the laptop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone configured VPN users with SmartCard authentication?&lt;/P&gt;&lt;P&gt;I was not able to find anything about this in Checkpoint site.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;micha&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 10:09:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/131756#M7852</guid>
      <dc:creator>mkushner</dc:creator>
      <dc:date>2021-10-14T10:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: SmartCard Authentication for VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/131759#M7853</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;SPAN style="font-family: inherit; background-color: #ffffff;"&gt;Remote Access VPN R81 Administration Guide p.44fff !&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 10:55:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/131759#M7853</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-10-14T10:55:13Z</dc:date>
    </item>
    <item>
      <title>Re: SmartCard Authentication for VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/131767#M7854</link>
      <description>&lt;P&gt;Thanks, but I only see SmartCard mentioned regarding L2TP (which is not what we want) and it doesn't appear to really be with a SmartCard, rather with a regular certificate.&lt;/P&gt;&lt;P&gt;We want SmartCard authentication with Checkpoint VPN client, and that is not described there.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Oct 2021 12:19:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/131767#M7854</guid>
      <dc:creator>mkushner</dc:creator>
      <dc:date>2021-10-14T12:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: SmartCard Authentication for VPN users</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/133213#M7855</link>
      <description>&lt;P&gt;It was more complicated than I thought.&amp;nbsp; It took Checkpoint dealer two days to get it working and was not something that we could have done ourselves.&lt;/P&gt;&lt;P&gt;Some tips:&lt;/P&gt;&lt;P&gt;1. You need to activate Identity Awareness.&amp;nbsp; Don't need to run wizard, but will need to mark off VPN in IA configuration tab of firewall.&lt;/P&gt;&lt;P&gt;2. Changes needed to be done via DBEdit.&lt;/P&gt;&lt;P&gt;3. We are using UPN from the SmartCard and via Activedirectory.&lt;/P&gt;&lt;P&gt;4. Make sure that the connection to AD servers is working well.&amp;nbsp; We had problems of dedicated user locking in AD.&amp;nbsp; The solution was a CLI command to force use of NTLMv2.&lt;/P&gt;&lt;P&gt;5. We also configured the firewall to distribute addresses from DHCP servers.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Nov 2021 08:44:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/SmartCard-Authentication-for-VPN-users/m-p/133213#M7855</guid>
      <dc:creator>mkushner</dc:creator>
      <dc:date>2021-11-04T08:44:48Z</dc:date>
    </item>
  </channel>
</rss>

