<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130103#M8296</link>
    <description>&lt;P&gt;I would work with your local Check Point SE.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2021 19:36:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-09-23T19:36:10Z</dc:date>
    <item>
      <title>MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124421#M8284</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Currently users are authenticating with Secure Envoy MFA and we are planning to move out of SecureEnvoy and use Azure MFA for the Mobile Access blade Client based VPN. May i know what all should be considered here for this change and as per my knowledge in Azure we use SAML authentication for MFA. So does our Checkpoint supports it? If yes, can you please share me any relavent docs that helps me in configuring it, as i did not find one.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 08:59:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124421#M8284</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-07-20T08:59:53Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124481#M8285</link>
      <description>&lt;P&gt;Only supported on R80.40 with a recent JHF.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909&amp;amp;partition=Advanced&amp;amp;product=Endpoint&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jul 2021 20:25:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124481#M8285</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-20T20:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124655#M8286</link>
      <description>&lt;P&gt;Thanks a lot PhoneBoy. This really helps.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jul 2021 10:02:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124655#M8286</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-07-22T10:02:53Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124917#M8287</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Can i configure 2 servers simultaneously for authentication?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 12:14:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124917#M8287</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-07-26T12:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124936#M8288</link>
      <description>&lt;P&gt;Given how SAML authentication works, don't believe that's possible.&lt;BR /&gt;For RADIUS, you can definitely do this (using a RADIUS Group object).&lt;/P&gt;</description>
      <pubDate>Mon, 26 Jul 2021 17:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/124936#M8288</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-07-26T17:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129521#M8289</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Is there any document that helps me in implementing the Azure SAML authentication for Mobile Access Remote Access VPN clients.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to remove the legacy Radius Authentication and put in SAML authentication in place without impact. So please suggest the best way.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 13:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129521#M8289</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-09-15T13:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129532#M8290</link>
      <description>&lt;P&gt;Mobile Access has supported SAML authentication since R80.40 for the portal itself.&amp;nbsp;&lt;BR /&gt;For the SNX client, you must use the Unified Policy mode as described here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170775&amp;amp;partition=Advanced&amp;amp;product=Mobile" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170775&amp;amp;partition=Advanced&amp;amp;product=Mobile&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;For other remote access clients,&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk172909&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 15:34:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129532#M8290</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-15T15:34:44Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129757#M8291</link>
      <description>&lt;P&gt;Thank you Phone Boy:)&lt;/P&gt;&lt;P&gt;Configuring the Intune complaince is compulsion for SAML Authentication?&lt;/P&gt;&lt;P&gt;Also if we have the Checkpoint Self-Signed certificate cant we get this working?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 09:10:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129757#M8291</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-09-20T09:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129810#M8292</link>
      <description>&lt;P&gt;I don't believe Intune is required here, but it can be used if desired.&lt;BR /&gt;As far as the SAML authentication piece goes, I don't believe the self-signed certificate is relevant to the flow.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 20:46:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129810#M8292</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-20T20:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129941#M8293</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;We have enabled Identity Awareness blade as well. Do we need to consider any changes to integrate while we setup SAML authentication? I have went through the configuration videos from the Youtube link that was updated in the SK. And now i have bit confidence on what to do, but just wanted to understand is there any config that needs to be considered for Identity Awareness Blade?&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 13:36:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129941#M8293</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-09-22T13:36:57Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129963#M8294</link>
      <description>&lt;P&gt;Make sure Remote Access is set as an Identity Source in the relevant gateway object(s).&lt;BR /&gt;Also, all gateways you are sharing identities with must be on the relevant version/JHF level in order to receive the acquired identities via Remote Access SAML.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Sep 2021 15:36:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/129963#M8294</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-22T15:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130098#M8295</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Is there any lab to test this?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 17:11:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130098#M8295</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-09-23T17:11:05Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130103#M8296</link>
      <description>&lt;P&gt;I would work with your local Check Point SE.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2021 19:36:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130103#M8296</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-23T19:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130457#M8297</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;I have another question here with this after going through the configuration guide below.&lt;/P&gt;&lt;P&gt;&lt;A href="https://dl3.checkpoint.com/paid/d9/d99fd83a9b0028e2e6ecb42ac23c840b/CP_R80.40_and_R81_Jumbo_Hotfix_SAML_For_VPN_RA.pdf?HashKey=1632825398_6786687bafbbcae2bb375612dc2ad008&amp;amp;xtn=.pdf" target="_blank"&gt;https://dl3.checkpoint.com/paid/d9/d99fd83a9b0028e2e6ecb42ac23c840b/CP_R80.40_and_R81_Jumbo_Hotfix_SAML_For_VPN_RA.pdf?HashKey=1632825398_6786687bafbbcae2bb375612dc2ad008&amp;amp;xtn=.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In Page 5 do we need to follow these below steps at all for the Mobile Access Client Based remote Access VPN at all?&lt;/P&gt;&lt;P&gt;i) From the left tree, click VPN Clients &amp;gt; SAML Portal Settings.&lt;BR /&gt;j) Make sure the Main URL contains the fully qualified domain name of the&lt;BR /&gt;gateway.&lt;BR /&gt;This domain name should end with a DNS suffix registered by your organization.&lt;BR /&gt;For example:&lt;BR /&gt;&lt;A href="https://gateway1.company.com/saml-vpn" target="_blank"&gt;https://gateway1.company.com/saml-vpn&lt;/A&gt;&lt;BR /&gt;k) Make sure the Certificate is trusted by the end users’ browser.&lt;/P&gt;&lt;P&gt;Because our customer uses the IP address to connect to the Remote access VPN.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 13:56:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130457#M8297</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-09-28T13:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130487#M8298</link>
      <description>&lt;P&gt;I guess you could use the IP here, but your users will likely encounter certificate errors doing so.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 19:12:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/130487#M8298</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-28T19:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/131502#M8299</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;Thanks for guiding me all over this thread. I have one more query. In the Youtube link in the SK there is nothing shown to make the changes in the&amp;nbsp;GuiDBEdit tool. But in the config guide from page 14 we see changes in the&amp;nbsp;GuiDBEdit. Is that necessary for those changes to get the SAML authentication working for Mobile Access Remote Access VPN clients?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sanjay S&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 12:41:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/131502#M8299</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-10-11T12:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/131518#M8300</link>
      <description>&lt;P&gt;I assume these are required if they are in the written documentation.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Oct 2021 18:40:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/131518#M8300</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-10-11T18:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: MFA Configuration for MobileAccess blade with Client(Checkpoint Endpoint Security)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/131560#M8301</link>
      <description>&lt;P&gt;Thanks PhoneBoy,&lt;/P&gt;&lt;P&gt;In case after making changes on&amp;nbsp;&lt;SPAN&gt;GuiDBEdit Tool, User Machine changes and also running script on particular domain in the MDS. If it doesn't work and we need to revert the changes and use the Radius authentication itself. Then what will be the best way to revert the above changes. Changes in the dashboard are easy to revert but when it comes these above changes how we can revert and how we can get the Radius working again?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sanjay S&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Oct 2021 11:42:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/MFA-Configuration-for-MobileAccess-blade-with-Client-Checkpoint/m-p/131560#M8301</guid>
      <dc:creator>Sanjay_S</dc:creator>
      <dc:date>2021-10-12T11:42:46Z</dc:date>
    </item>
  </channel>
</rss>

