Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TRajkumar
Contributor
Contributor

User Based policies with Azure AD

Hello Everyone,

 I have a requirement to enforce user based policies in checkpoint firewall with Azure AD. We have integrated the Azure AD with checkpoint firewall (MGMT server in S1C). I able to view the users when creating the access roles but policy enforcement is not happening during the traffic.

At the same time, i don't want captive portal authentication from firewall. since already user did multiple authentication to connect the network. If transparent authentication is possible please suggest.

Does any one have solution kindly help me on this.

Note: I don't have any Domain controller.

Thanks

Rajkumar T

0 Kudos
7 Replies
PhoneBoy
Admin
Admin

For Identity Awareness to work correctly with Azure AD, Captive Portal is required.
See: https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide...
Without this, the gateway cannot see the authentication and authorization information, which is otherwise encrypted via TLS.
This will be transparent to users.

0 Kudos
TRajkumar
Contributor
Contributor

Hi @PhoneBoy ,

 My case i don't need any authentication for the users, So can i enable the SSO with SAML ? 

 Is it required any IDP.

Thanks

Rajkumar T

0 Kudos
PhoneBoy
Admin
Admin

In SAML terms, Entra ID is an Identity Provider and the Check Point Firewall is a Service Provider.
When everything is configured correctly (including enabling Captive Portal), the Firewall will see the authentication with Entra ID and authorize the user with specific Access Roles or tags configured.
It doesn't require a separate authentication step for the end user.

If you have multiple gateways and/or also using Entra ID to authenticate Remote Access VPN users, you should consider the Identity and Trust offering mentioned by @Royi_Priov as it simplifies the configuration substantially.

0 Kudos
Royi_Priov
Employee
Employee

Hi @TRajkumar 

The proper way to allow SSO with Entra ID is with Check Point Identity and Trust (formerly known as Infinity Identity).

Identity and Trust gets the IP to identity association from both Microsoft Intune and Defender.

Please read more about it here:

https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Infinity-Identity-Admin-Guide...

 

https://www.checkpoint.com/resources/items/solution-brief-check-point-identity-and-trust

If you have additional questions, please let me know.

Thanks,
Royi Priov
R&D Group manager, Identity and Trust (formerly known as Infinity Identity)
TRajkumar
Contributor
Contributor

Hi Royi,

 I Hope this requires additional license.

Thanks

Rajkumar T

0 Kudos
Saranya_0305
Collaborator

Hi Mate,

I have also facing the same requirement and I have few queries below

- How Azure AD is connected to Checkpoint?

- In Azure are you using Microsoft Entra or Azure VM where Windows Server with AD configured in it?

- If Azure VM how you connect Azure VM with Checkpoint, is it using VPN?

- And finally is your requirement completed?

 

Regards,

Saranya

0 Kudos
TRajkumar
Contributor
Contributor

Hi Saranya,

My requirement is not closed.

- How Azure AD is connected to Checkpoint? - Created the Non-gallary application on Azure portal

- In Azure are you using Microsoft Entra or Azure VM where Windows Server with AD configured in it? - I'm using Entra AD

- If Azure VM how you connect Azure VM with Checkpoint, is it using VPN? - No

- And finally is your requirement completed? - No

Do let me know if you have answer.

Thanks

Rajkumar T

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events