<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Spark: Entra ID SAML authentication for RA VPN illustrated configuration (locally managed R81.10 in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-Entra-ID-SAML-authentication-for-RA-VPN-illustrated/m-p/229496#M11570</link>
    <description>&lt;P&gt;FYI, I edited your post to embed the video you've referenced.&lt;BR /&gt;Great stuff!&lt;/P&gt;</description>
    <pubDate>Fri, 11 Oct 2024 20:05:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-11T20:05:31Z</dc:date>
    <item>
      <title>Spark: Entra ID SAML authentication for RA VPN illustrated configuration (locally managed R81.10.15)</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-Entra-ID-SAML-authentication-for-RA-VPN-illustrated/m-p/229490#M11569</link>
      <description>&lt;P&gt;Gentle reader,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;A title="documentation" href="https://sc1.checkpoint.com/documents/SMB_R81.10.X/AdminGuides_Locally_Managed/EN/Content/Topics/Configuring-Remote-Access-Authentication-Servers.htm" target="_blank" rel="noopener"&gt;documentation &lt;/A&gt;for SAML &lt;STRONG&gt;authentication&lt;/STRONG&gt; is correct and complete. There is also a &lt;A href="https://www.youtube.com/watch?v=4WCGGRegeHE&amp;amp;list=PLMAKXIJBvfAjPa7C36ANIsAv59kmtKFyL&amp;amp;index=3" target="_blank" rel="noopener"&gt;video&lt;/A&gt; in the &lt;A href="https://www.youtube.com/playlist?list=PLMAKXIJBvfAjPa7C36ANIsAv59kmtKFyL" target="_self"&gt;playlist&lt;/A&gt; dedicated to the new features introduced in R81.10.15. The steps are identical to those in the &lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/SAML-Support-for-Remote-Access-VPN.htm" target="_self"&gt;maintrain&lt;/A&gt; configuration.&lt;/P&gt;
&lt;P&gt;&lt;div class="video-embed-center video-embed"&gt;&lt;iframe class="embedly-embed" src="https://cdn.embedly.com/widgets/media.html?src=https%3A%2F%2Fwww.youtube.com%2Fembed%2F4WCGGRegeHE%3Ffeature%3Doembed&amp;amp;display_name=YouTube&amp;amp;url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3D4WCGGRegeHE&amp;amp;image=https%3A%2F%2Fi.ytimg.com%2Fvi%2F4WCGGRegeHE%2Fhqdefault.jpg&amp;amp;type=text%2Fhtml&amp;amp;schema=youtube" width="200" height="112" scrolling="no" title="Check Point Quantum Spark: VPN Remote Access with SAML Authentication" frameborder="0" allow="autoplay; fullscreen; encrypted-media; picture-in-picture;" allowfullscreen="true"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;To make it easier to follow the procedure (especially in Microsoft Entra ID portal) I illustrated each step with screenshots in the attached doc.&lt;/P&gt;
&lt;P&gt;Notes:&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;Microsoft Entra ID &lt;STRONG&gt;groups&lt;/STRONG&gt; could not be used in &lt;STRONG&gt;access policy&lt;/STRONG&gt; (neither group authorization based on identity tags available in maintrain Mobile Access and not [yet] in IPSec Remote Access, nor Entra ID as used in IDA on maintrain).&lt;/P&gt;
&lt;P&gt;There is a nice new feature in R81.10.15 that simplifies access control of remote vpn clients traffic, with a &lt;A href="https://www.youtube.com/watch?v=L_eff4ruRJQ&amp;amp;list=PLMAKXIJBvfAjPa7C36ANIsAv59kmtKFyL&amp;amp;index=5" target="_blank" rel="noopener"&gt;video&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;2. To force interactive authentication on every VPN connection attempt, regardless of whether a valid token and/or cookies are present, the optional forceAuthn SAML parameter has to be configured (big deal when the feature was introduced in maintrain, now documented by &lt;A href="https://support.checkpoint.com/results/sk/sk180948" target="_blank" rel="noopener"&gt;sk180948, How to force SAML authentication for users for each Remote Access VPN connection&lt;/A&gt;). On Spark (R81.10.15), I configured the parameter in both&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;/pfrm2.0/opt/fw1/portals/CPSamlPortal/phpincs/simplesamlphp/config/authsources.php&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;and&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;/pfrm2.0/opt/fw1/portals/CPSamlPortal/phpincs/simplesamlphp/config-templates/authsources.php&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;3. SAML-based authentication is not available on locally managed Spark for SSL VPN (including SNX) and I'm not sure that it was supposed to be aligned with MT even with centrally managed Sparks.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope these help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P. S. There is a new, simplified procedure available in R81.10.15 to &lt;A href="https://www.youtube.com/watch?v=sYM86SvPOWI&amp;amp;list=LL&amp;amp;index=2" target="_self"&gt;onboard&lt;/A&gt; a device to cloud services, that offers the log sorting and querying capabilities of Spark management right in the &lt;STRONG&gt;Enhanced monitoring&lt;/STRONG&gt; Spark WebUI and could be very useful especially for starting troubleshooting these new RA VPN features.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Oct 2024 08:03:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-Entra-ID-SAML-authentication-for-RA-VPN-illustrated/m-p/229490#M11569</guid>
      <dc:creator>APopisteru</dc:creator>
      <dc:date>2024-10-12T08:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Spark: Entra ID SAML authentication for RA VPN illustrated configuration (locally managed R81.10</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-Entra-ID-SAML-authentication-for-RA-VPN-illustrated/m-p/229496#M11570</link>
      <description>&lt;P&gt;FYI, I edited your post to embed the video you've referenced.&lt;BR /&gt;Great stuff!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2024 20:05:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Spark-Entra-ID-SAML-authentication-for-RA-VPN-illustrated/m-p/229496#M11570</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-11T20:05:31Z</dc:date>
    </item>
  </channel>
</rss>

