<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228395#M11501</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Could you please check if there are any relevant logs on the security logs page? Also, are you using an NTP server?&lt;/P&gt;</description>
    <pubDate>Sun, 29 Sep 2024 19:30:45 GMT</pubDate>
    <dc:creator>Dafna</dc:creator>
    <dc:date>2024-09-29T19:30:45Z</dc:date>
    <item>
      <title>Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228367#M11498</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I recently upgraded our Check Point SMB 1800 firewall to the latest firmware version, &lt;STRONG&gt;R81.10.15&lt;/STRONG&gt;. One of the new features introduced in this release is the ability to authenticate VPN users via &lt;STRONG&gt;Azure AD (SAML)&lt;/STRONG&gt;, which I was excited to configure for our environment.&lt;/P&gt;&lt;H3&gt;Steps Taken:&lt;/H3&gt;&lt;OL&gt;&lt;LI&gt;I followed the instructions provided in the &lt;A href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-Remote-Access-Authentication-Servers.htm?Highlight=SAML" target="_new" rel="noopener"&gt;&lt;SPAN&gt;Check&lt;/SPAN&gt;&lt;SPAN&gt; Point&lt;/SPAN&gt;&lt;SPAN&gt; documentation&lt;/SPAN&gt;&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;Created a new &lt;STRONG&gt;Enterprise Application&lt;/STRONG&gt; on &lt;STRONG&gt;Azure AD&lt;/STRONG&gt; to enable VPN authentication for users using their Azure AD accounts.&lt;/LI&gt;&lt;LI&gt;After configuration, I tested the application using the &lt;STRONG&gt;"Test Sign-in"&lt;/STRONG&gt; feature on the Azure portal. The test was successful, and Microsoft Entra ID issued a &lt;STRONG&gt;SAML token&lt;/STRONG&gt; to the service provider (Check Point firewall).&lt;/LI&gt;&lt;/OL&gt;&lt;H3&gt;Issue:&lt;/H3&gt;&lt;P&gt;However, when I attempt to connect to the VPN using &lt;STRONG&gt;Check Point Endpoint Security&lt;/STRONG&gt;, the connection fails. Attached is a screenshot showing the error messages during the connection attempt.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The VPN client hangs during the connection process, and I receive a "Can't reach this page" message for the authentication step.&lt;/LI&gt;&lt;LI&gt;The logs indicate that the VPN client is trying to authenticate but does not seem to proceed beyond that.&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;What I've Verified:&lt;/H3&gt;&lt;UL&gt;&lt;LI&gt;Azure AD SAML authentication appears to be configured correctly based on the successful test sign-in from the Azure portal.&lt;/LI&gt;&lt;LI&gt;The firewall settings are configured as per the Check Point guide for SAML-based authentication.&lt;/LI&gt;&lt;LI&gt;I can confirm that the firewall upgrade to &lt;STRONG&gt;R81.10.15&lt;/STRONG&gt; was successful, and all other firewall features seem to be working as expected.&lt;/LI&gt;&lt;/UL&gt;&lt;H3&gt;Request for Assistance:&lt;/H3&gt;&lt;P&gt;Has anyone else encountered this issue with Azure AD SAML authentication for remote access VPN after upgrading to &lt;STRONG&gt;R81.10.15&lt;/STRONG&gt;? If so, could you share any insights or troubleshooting steps that might help resolve this problem?&lt;/P&gt;&lt;P&gt;Additionally, are there specific logs or debugging steps on the Check Point firewall side that could shed light on why the SAML authentication isn't proceeding during the VPN connection?&lt;/P&gt;&lt;P&gt;Any help would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thanks in advance for your assistance.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment&lt;/STRONG&gt;:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Check Point SMB 1800 firewall (R81.10.15)&lt;/LI&gt;&lt;LI&gt;Azure AD for SAML authentication&lt;/LI&gt;&lt;LI&gt;Check Point Endpoint Security VPN Client&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kristait_0-1727610719707.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27899iF24AF686B24857E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kristait_0-1727610719707.png" alt="kristait_0-1727610719707.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 11:54:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228367#M11498</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-29T11:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228394#M11500</link>
      <description>&lt;P&gt;Based on what I know about SAML, the client has to be able to reach a URL on the gateway to perform the authentication.&lt;BR /&gt;I assume this is in Step 7:&amp;nbsp;&lt;SPAN&gt;the &lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Unique identifier URL&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;value from the &lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_HW.tp_Quantum_Spark variable"&gt;Quantum Spark&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gwcap variable"&gt;Gateway&lt;/SPAN&gt; &lt;SPAN class="mc-variable Vars_Other.tp_webui variable"&gt;WebUI.&lt;BR /&gt;&lt;/SPAN&gt;Does this URL reflect an FQDN, IP address, or?&lt;BR /&gt;Can you confirm in a web browser this loads any page?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 19:26:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228394#M11500</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-29T19:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228395#M11501</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Could you please check if there are any relevant logs on the security logs page? Also, are you using an NTP server?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Sep 2024 19:30:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228395#M11501</guid>
      <dc:creator>Dafna</dc:creator>
      <dc:date>2024-09-29T19:30:45Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228402#M11502</link>
      <description>&lt;P&gt;I totally see what Phoneboy is saying, but it might be worth to confirm with TAC if its related to the version you upgraded to. To me, logically, if this worked BEFORE the upgrade, and no config was changed, most likely may have to do with the upgrade...just my logical reasoning.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 01:21:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228402#M11502</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-30T01:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228403#M11503</link>
      <description>&lt;P&gt;It was a new capability introduced with this GW version.&lt;/P&gt;
&lt;P&gt;With that said it's also worth confirming the Endpoint client version used for correlation purposes?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 02:28:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228403#M11503</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-30T02:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228405#M11505</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The &lt;STRONG&gt;Unique identifier URL&lt;/STRONG&gt; is currently set to reflect my primary ISP’s public IP in the format &lt;A href="https://xxx.xxx.xxx.xxx" target="_blank" rel="noopener"&gt;https://xxx.xxx.xxx.xxx&lt;/A&gt;.&lt;/LI&gt;&lt;LI&gt;When I attempt to load the URL in a web browser, I get the &lt;STRONG&gt;"Can't reach this page"&lt;/STRONG&gt; error.&lt;/LI&gt;&lt;LI&gt;We are not using &lt;STRONG&gt;DDNS&lt;/STRONG&gt; on our appliance, so I assume this might be causing issues when the IP address is used instead of an FQDN. Would changing this to an FQDN (by setting up DDNS) help in this case?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 30 Sep 2024 05:27:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228405#M11505</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-30T05:27:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228406#M11506</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/40801"&gt;@Dafna&lt;/a&gt;&amp;nbsp;:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We're using the default &lt;STRONG&gt;Check Point NTP server&lt;/STRONG&gt; settings, and the time is synced correctly on the gateway.&lt;/LI&gt;&lt;LI&gt;I checked the security logs, and this is what I found:&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;"10.xx.0.xxx (local IP) xxx.xx.xx.xxx (public IP) CP_SmartPortal 2 Accepted on rule 2 (Incoming/Internal Default Policy)."&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;It appears that something is being accepted via &lt;STRONG&gt;CP_SmartPortal&lt;/STRONG&gt;, but I’m unsure if this is related to the SAML authentication process. Could this log entry indicate an incomplete or incorrect configuration?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 30 Sep 2024 05:29:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228406#M11506</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-30T05:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228407#M11507</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Thanks for pointing that out! Just to clarify, we're using an &lt;STRONG&gt;SMB 1800 locally managed Firewall&lt;/STRONG&gt;, and this is the first time we’re setting up the new SAML authentication capability introduced with &lt;STRONG&gt;R81.10.15&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI&gt;So this isn’t an issue with a pre-existing configuration breaking after the upgrade—it’s just that the feature isn’t fully working after the first-time setup.&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Mon, 30 Sep 2024 05:30:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228407#M11507</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-30T05:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228408#M11508</link>
      <description>&lt;OL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3630"&gt;@Chris_Atkinson&lt;/a&gt;&amp;nbsp;:&lt;/STRONG&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;We have downloaded and installed the &lt;STRONG&gt;latest version of the Endpoint client&lt;/STRONG&gt;, which is &lt;STRONG&gt;E86.80_CheckPointVPN&lt;/STRONG&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Mon, 30 Sep 2024 05:33:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228408#M11508</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-30T05:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228411#M11509</link>
      <description>&lt;P&gt;Actually the latest client version is E88.x&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 08:56:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228411#M11509</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-09-30T08:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228416#M11510</link>
      <description>&lt;P&gt;Better open a SR# with CP TAC!&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 07:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228416#M11510</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-30T07:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228425#M11513</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We have installed the latest version of the client, &lt;STRONG&gt;E88.40&lt;/STRONG&gt;. I've now noticed that the page redirects through the browser (whereas earlier it would open in a small window), but I still receive the same error:&lt;BR /&gt;&lt;STRONG&gt;&lt;BR /&gt;"Hmmm… can't reach this page. xxx.xxx.xxx.xxx refused to connect."&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;It seems that the firewall may be blocking the SAML VPN connection, though I’m unsure which specific service or rule needs to be enabled to resolve this issue.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kristait_0-1727688282132.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27908iB795444E022AF207/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kristait_0-1727688282132.png" alt="kristait_0-1727688282132.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 09:25:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228425#M11513</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-30T09:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228430#M11514</link>
      <description>&lt;P&gt;Got it. I would still open TAC case to investigate.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 11:03:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228430#M11514</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-30T11:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228447#M11517</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;, I have created a TAC case, and the number is SR#&amp;nbsp;&lt;SPAN&gt;6-0004074266.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 12:25:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228447#M11517</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2024-09-30T12:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228448#M11518</link>
      <description>&lt;P&gt;Sounds good, keep us posted.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 12:27:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228448#M11518</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-09-30T12:27:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228499#M11526</link>
      <description>&lt;P&gt;I had this issue with an EA version of R81.10.15. upload of the metadatafile seemed OK, but it wasn't. There is no real message something went wrong.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you check if the metadata was imported and installed correctly?&amp;nbsp;there should be a green mark (or 2)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2024 15:13:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/228499#M11526</guid>
      <dc:creator>jurgenvrieze</dc:creator>
      <dc:date>2024-09-30T15:13:34Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/229149#M11563</link>
      <description>&lt;P&gt;AZURE AD for SAML is supported only on default port 443.&lt;/P&gt;
&lt;P&gt;According to the screenshot you are using 4433&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp; Dafna&lt;/P&gt;</description>
      <pubDate>Tue, 08 Oct 2024 06:54:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/229149#M11563</guid>
      <dc:creator>Dafna</dc:creator>
      <dc:date>2024-10-08T06:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/241346#M12067</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you had any reply from TAC to solve the issue?&lt;/P&gt;&lt;P&gt;I'm having the exact same problem with the same appliances, also centrally managed.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Feb 2025 11:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/241346#M12067</guid>
      <dc:creator>Oryx</dc:creator>
      <dc:date>2025-02-17T11:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/244983#M12345</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/72835"&gt;@Oryx&lt;/a&gt;,&amp;nbsp;I just saw your comment. The solution provided by TAC is:&lt;BR /&gt;&lt;BR /&gt;&lt;FONT face="Arial, sans-serif" size="4"&gt;Solution Description:&amp;nbsp;&lt;/FONT&gt;&lt;FONT face="Arial, sans-serif" size="4"&gt;I checked internally and also as you suspected it is the port which is causing this issue. The entire SAML authentication flow uses port 443.&lt;BR /&gt;&lt;/FONT&gt;&lt;BR /&gt;However, since I don’t want to lose UI control on my SMB device, I didn’t make any changes and instead switched to Pritunl VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2025 13:00:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/244983#M12345</guid>
      <dc:creator>kristait</dc:creator>
      <dc:date>2025-03-27T13:00:01Z</dc:date>
    </item>
    <item>
      <title>Re: Issue with Azure AD Authentication for Remote Access VPN after R81.10.15 Upgrade</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/246205#M12448</link>
      <description>&lt;P&gt;isnt it much easier to just change the UI port on the smb device instead? &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2025 19:15:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Issue-with-Azure-AD-Authentication-for-Remote-Access-VPN-after/m-p/246205#M12448</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2025-04-10T19:15:33Z</dc:date>
    </item>
  </channel>
</rss>

