<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent VPN from switching certificates in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/115710#M8889</link>
    <description>&lt;P&gt;Paging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5692"&gt;@AndreiR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2021 17:38:06 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-04-09T17:38:06Z</dc:date>
    <item>
      <title>Prevent VPN from switching certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/115487#M8888</link>
      <description>&lt;P&gt;Dear CheckMates,&lt;/P&gt;&lt;P&gt;we are using certificate based authentification to establish VPN connections.&lt;BR /&gt;The certificate is based in users personal store.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;When opening TrGui.exe, you can choose between those authentifications.&lt;BR /&gt;When deploying its set to "certificate" and the correct user certificate.&lt;/P&gt;&lt;P&gt;Whenever this certificate is renewed, checkpoint application will switch between those certificates and pick another one in this store.&lt;BR /&gt;That results in error when connection to site.&lt;BR /&gt;The end user can (if they remember) open TrGui.exe and switch it back.&lt;/P&gt;&lt;P&gt;But our environment is as large, as we have atleast 1 call every day, that the certificate is not working.&lt;/P&gt;&lt;P&gt;The Question:&lt;BR /&gt;Can I somehow force the endpoint to use exactly this certificate with specific name (for example).&lt;BR /&gt;Any regkey where the current choice is stored?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Apr 2021 10:49:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/115487#M8888</guid>
      <dc:creator>FloydG</dc:creator>
      <dc:date>2021-04-07T10:49:27Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent VPN from switching certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/115710#M8889</link>
      <description>&lt;P&gt;Paging&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/5692"&gt;@AndreiR&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 17:38:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/115710#M8889</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-09T17:38:06Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent VPN from switching certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/115825#M8890</link>
      <description>&lt;P&gt;I found the answer here&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169453" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk169453&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Apr 2021 08:21:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/115825#M8890</guid>
      <dc:creator>FloydG</dc:creator>
      <dc:date>2021-04-12T08:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent VPN from switching certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/116632#M8891</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;another question regarding SK article above.&lt;BR /&gt;&lt;BR /&gt;Can we modify&amp;nbsp;&lt;SPAN&gt;trac.defaults file and push it on all clients without any risks?&lt;BR /&gt;Or is this file personalized for every client, so that it does not work/fit on all devices/users?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 13:20:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/116632#M8891</guid>
      <dc:creator>FloydG</dc:creator>
      <dc:date>2021-04-22T13:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent VPN from switching certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/116635#M8892</link>
      <description>&lt;P&gt;There are two options in &lt;SPAN&gt;sk169453&lt;/SPAN&gt;:&lt;/P&gt;
&lt;P&gt;- use GW&amp;nbsp;&lt;SPAN&gt;trac_client_1.ttm for configuration, that will be downloaded by all clients when connecting&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- use&amp;nbsp;trac.defaults in client install package for configuration, then you can either roll out using one package or use packages with different&amp;nbsp;trac.defaults for different clients&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 13:32:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/116635#M8892</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-04-22T13:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent VPN from switching certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/117338#M8893</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;thank you for reply, but it does not really answer my question.&lt;BR /&gt;Is there any risk, when I create a trac.defaults file and replace this file on all systems in our environment (by basic copy &amp;amp; paste)?&lt;/P&gt;&lt;P&gt;Any user specific file metadata or something else, which could lead to issues in the future?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 08:58:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/117338#M8893</guid>
      <dc:creator>FloydG</dc:creator>
      <dc:date>2021-04-30T08:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent VPN from switching certificates</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/117339#M8894</link>
      <description>&lt;P&gt;No, not at all - see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk55502&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank" rel="noopener"&gt;sk55502: How to centrally manage the trac_client_1.ttm configuration file for Remote Access Clients&lt;/A&gt;&amp;nbsp;for the suggested way of managing extended configurations for all clients. Or you can use&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk122574" target="_blank" rel="noopener"&gt;sk122574 - VPN Configuration Utility for Endpoint Security VPN E80.71 (and above) Clients for Windows&lt;/A&gt;. The&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk121196&amp;amp;partition=Advanced&amp;amp;product=Endpoint" target="_blank" rel="noopener"&gt;sk121196: Remote Access client disconnects after upgrade&lt;/A&gt;&amp;nbsp;explains that you can use any track.defaults from same version clients for replacement. So nothing client-specific there...&lt;/P&gt;
&lt;P&gt;But all three possible methods have inherent weaknesses:&lt;/P&gt;
&lt;P&gt;- &lt;STRONG&gt;central managing the config following sk55502&lt;/STRONG&gt; will need manual editing again after SMS upgrade&lt;/P&gt;
&lt;P&gt;- &lt;STRONG&gt;creating client packages with changed trac.default&lt;/STRONG&gt; must be done for every new client version to be rolled out&lt;/P&gt;
&lt;P&gt;- &lt;STRONG&gt;manual changes to clients&amp;nbsp;trac.default&lt;/STRONG&gt; will be overwitten by any&amp;nbsp;new client version to be rolled out (this needs the most manual work that multiplies with the number of clients)&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 08:29:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Prevent-VPN-from-switching-certificates/m-p/117339#M8894</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-05-04T08:29:43Z</dc:date>
    </item>
  </channel>
</rss>

