Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Saranya_0305
Collaborator
Jump to solution

Microsoft Entra MFA Support for Check Point Capsule VPN and Multi-Gateway Configuration

Hi Mates,

I have one Check Point 9100 appliance running R82 and one AWS CloudGuard Firewall running R82.10, both managed by the same Management Server.

Both gateways are part of the same Remote Access VPN community, and the Mobile Access Blade is enabled on both.

Currently, most users connect using the built-in Windows Check Point Capsule VPN client, while a few users are using the Endpoint Security (Remote Access) client.

I have the following questions:

  1. We would like to enable MFA using Microsoft Entra ID (Azure Entra) for Remote Access VPN users. Is Microsoft Entra MFA supported with the built-in Windows Check Point Capsule VPN client? If not, what are the supported options for enabling MFA for users who continue to use the Capsule VPN client?
  2. Can the same Microsoft Entra Enterprise Application be used for both VPN gateways (the on-premises 9100 appliance and the AWS CloudGuard gateway)?

If Microsoft Entra ID is supported with the Windows Capsule VPN client, could you please share the relevant configuration guide or documentation?

 

Regards,

Saranya

0 Kudos
1 Solution

Accepted Solutions
simonemantovani
MVP Diamond
MVP Diamond

Hello

MFA on Capsule Client should be supported, as reported in this post: 

https://community.checkpoint.com/t5/Mobile/Failed-Authentication-with-MFA-in-capsule-app-VPN/td-p/20...

For my experience you should configure on your Entra ID, an application for every gateway with VPN enabled, because in your application you define the Entity ID and URL corresponding to your gateway, I know (but I'm not Azure expert) you can define only one Entity ID, etc, for evenry application, so if you have to different gateways you have to define two different application.

You can find all the configuration guide for MFA on Support Center and you can find also useful resources on youtube (there some great video made by Peter Elmer)

 

View solution in original post

0 Kudos
1 Reply
simonemantovani
MVP Diamond
MVP Diamond

Hello

MFA on Capsule Client should be supported, as reported in this post: 

https://community.checkpoint.com/t5/Mobile/Failed-Authentication-with-MFA-in-capsule-app-VPN/td-p/20...

For my experience you should configure on your Entra ID, an application for every gateway with VPN enabled, because in your application you define the Entity ID and URL corresponding to your gateway, I know (but I'm not Azure expert) you can define only one Entity ID, etc, for evenry application, so if you have to different gateways you have to define two different application.

You can find all the configuration guide for MFA on Support Center and you can find also useful resources on youtube (there some great video made by Peter Elmer)

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events