<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remote Access VPN with MacOS : certificate authentication don't work in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-MacOS-certificate-authentication-don-t/m-p/184057#M9526</link>
    <description>&lt;P&gt;also see the recently released &lt;SPAN&gt;&lt;SPAN class=""&gt;sk181067&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Jun 2023 09:48:10 GMT</pubDate>
    <dc:creator>LazarusG</dc:creator>
    <dc:date>2023-06-15T09:48:10Z</dc:date>
    <item>
      <title>Remote Access VPN with MacOS : certificate authentication don't work</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-MacOS-certificate-authentication-don-t/m-p/104252#M9524</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have a project to add a 2FA in our Remote Access VPN. Currently we have set to authenticate with username &amp;amp; passwords, and we want to add user certificate (issued by internal CA running on Microsoft, integrated with AD).&lt;/P&gt;&lt;P&gt;This is working fine for Microsoft computers with Check Point Endpoint Security VPN client (standalone). We just have a failure after a while (traffic blocked after a random amount of time, with logs like 'can't find user' or 'failed login'). This one is object of an ongoing TAC case. But still, for these, the authentication with certificate is working fine, and the VPN tunnel establishes.&lt;/P&gt;&lt;P&gt;Now we have a lot of users that have MacBooks, also running the CP Endpoint VPN client. The user certificate has been imported in the Key Chains. When we try to authenticate on the VPN client with the certificate, it doesn't work.&lt;/P&gt;&lt;P&gt;An example of log extract, showing failure of MacOS, and success of Windows (same user, same certificate) :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="100_LOGS_SHOWING_DIFFERENCE_WIN_VS_MACOS.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9492i069B49BF1AFC27BA/image-size/large?v=v2&amp;amp;px=999" role="button" title="100_LOGS_SHOWING_DIFFERENCE_WIN_VS_MACOS.PNG" alt="100_LOGS_SHOWING_DIFFERENCE_WIN_VS_MACOS.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The detail of the failure log, showing the user is not in the right format, expected here something like it is for Windows clients :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="101_Login_Auth_MAB_NOK_MACOS.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9491iEDF71D7EECA4E0FE/image-size/large?v=v2&amp;amp;px=999" role="button" title="101_Login_Auth_MAB_NOK_MACOS.PNG" alt="101_Login_Auth_MAB_NOK_MACOS.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is how the authentication is configured for certificate usage (again, working fine on Windows) :&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="102_GatewayProps_Authentication_2.PNG" style="width: 726px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/9493iB4D12E92EB190F00/image-size/large?v=v2&amp;amp;px=999" role="button" title="102_GatewayProps_Authentication_2.PNG" alt="102_GatewayProps_Authentication_2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you know if I have to create another Login Option especially for MacOS ? If so, what settings should I use ? I already tried various combination, none of them worked &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your help !&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Antoine&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 19:05:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-MacOS-certificate-authentication-don-t/m-p/104252#M9524</guid>
      <dc:creator>Ob1lan</dc:creator>
      <dc:date>2020-12-03T19:05:22Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with MacOS : certificate authentication don't work</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-MacOS-certificate-authentication-don-t/m-p/104274#M9525</link>
      <description>&lt;P&gt;Are you using the latest supported macOS VPN client? I saw E82.50 within your log card details. E84.30 was released within the last 2 weeks that has support for Bug Sur as well as Machine Authentication for the VPN client.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170513" target="_blank" rel="noopener"&gt;SK170513 - Enterprise Endpoint Security E84.30 macOS Clients - Early Availability&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 23:00:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-MacOS-certificate-authentication-don-t/m-p/104274#M9525</guid>
      <dc:creator>Matt_Ricketts</dc:creator>
      <dc:date>2020-12-03T23:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN with MacOS : certificate authentication don't work</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-MacOS-certificate-authentication-don-t/m-p/184057#M9526</link>
      <description>&lt;P&gt;also see the recently released &lt;SPAN&gt;&lt;SPAN class=""&gt;sk181067&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2023 09:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-with-MacOS-certificate-authentication-don-t/m-p/184057#M9526</guid>
      <dc:creator>LazarusG</dc:creator>
      <dc:date>2023-06-15T09:48:10Z</dc:date>
    </item>
  </channel>
</rss>

