<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Configure Check Point to forward VPN Certificate authentication request to Cisco ISE in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95454#M9952</link>
    <description>&lt;P&gt;Thanks PhoneBoy,&lt;/P&gt;
&lt;P&gt;Are you saying I still need to import the customers CA Key for verification using SSLVPN to do a cert request like the below example?&lt;/P&gt;
&lt;P&gt;Will this be one cert per cluster or do I need a cert per gateway?&lt;/P&gt;
&lt;P&gt;Do I then to add ISE as a Radius server and the Domain Controller as and LDAP server? I saw a few threads related to needing both configured in smartconsole&lt;/P&gt;</description>
    <pubDate>Fri, 28 Aug 2020 00:31:28 GMT</pubDate>
    <dc:creator>Edmund_Carbon</dc:creator>
    <dc:date>2020-08-28T00:31:28Z</dc:date>
    <item>
      <title>How to Configure Check Point to forward VPN Certificate authentication request to Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95449#M9950</link>
      <description>&lt;P&gt;Hi, has anyone configured Check Point Gateway to forward VPN request using Certificates to Cisco ISE for authentication to AD.&lt;/P&gt;
&lt;P&gt;Basically users with Capsule Connect client&amp;nbsp; will VPN into the Gateway using only a pre-configured certificate push by an MDM. Check Point will receive the request and forward ito ISE. Cisco ISE will authorize and authenticate using Active Directory. The request should come back to Check Point gateway and then user will be allowed access to the network.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 23:11:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95449#M9950</guid>
      <dc:creator>Edmund_Carbon</dc:creator>
      <dc:date>2020-08-27T23:11:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Check Point to forward VPN Certificate authentication request to Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95450#M9951</link>
      <description>&lt;P&gt;You don't really "forward" requests for certificate authentication anywhere.&lt;BR /&gt;You import the relevant CA key into the Check Point management (as an OPSEC CA) and set your gateway (cluster) object to accept this CA as valid for VPN purposes.&lt;BR /&gt;We can validate the certificate and the other attributes in the certificate, associating it to the relevant user.&lt;BR /&gt;I believe that can be Cisco ISE (via RADIUS), but haven't tried it myself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Aug 2020 23:49:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95450#M9951</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-27T23:49:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Check Point to forward VPN Certificate authentication request to Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95454#M9952</link>
      <description>&lt;P&gt;Thanks PhoneBoy,&lt;/P&gt;
&lt;P&gt;Are you saying I still need to import the customers CA Key for verification using SSLVPN to do a cert request like the below example?&lt;/P&gt;
&lt;P&gt;Will this be one cert per cluster or do I need a cert per gateway?&lt;/P&gt;
&lt;P&gt;Do I then to add ISE as a Radius server and the Domain Controller as and LDAP server? I saw a few threads related to needing both configured in smartconsole&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 00:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95454#M9952</guid>
      <dc:creator>Edmund_Carbon</dc:creator>
      <dc:date>2020-08-28T00:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to Configure Check Point to forward VPN Certificate authentication request to Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95457#M9953</link>
      <description>&lt;P&gt;You would import the CA key once and configure each gateway to accept it.&lt;BR /&gt;And yes ISE would be configured as RADIUS and AD for LDAP.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Aug 2020 04:52:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-Configure-Check-Point-to-forward-VPN-Certificate/m-p/95457#M9953</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-28T04:52:15Z</dc:date>
    </item>
  </channel>
</rss>

