Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Andrew133900
Explorer
Jump to solution

Certificate authentication

Hello everyone. I am trying to clarify whether it is possible to use user machine certificates (in my specific case, an EAP-TLS certificate used for 802.1X authentication) for authorization in a Check Point proxy (Quantum Security Gateway). Not RA VPN and not Mobile Access.

The problem I am trying to solve is the following: at one of my locations (internal perimeter), there are users (top management) who use MacBooks. These users strongly dislike the need to manually authenticate via a portal to access the internet. Their MacBooks already have certificates installed for Wi-Fi connectivity. Is it possible to use this certificate to authenticate and authorize the user in Check Point?

My infrastructure: Check Point Quantum 82, Windows AD DS (PKI, and RADIUS/NPS)

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

Certificates are not an option for Captive Portal authentication.
However, there are other was to acquire the identity of said users more transparently via Identity Awareness:

  • Identity Agent
  • On-premise Active Directory
  • EntraID
  • Transparently via Kerberos (assuming Macs are integrated with on-premise Active Directory).

View solution in original post

(1)
1 Reply
PhoneBoy
Admin
Admin

Certificates are not an option for Captive Portal authentication.
However, there are other was to acquire the identity of said users more transparently via Identity Awareness:

  • Identity Agent
  • On-premise Active Directory
  • EntraID
  • Transparently via Kerberos (assuming Macs are integrated with on-premise Active Directory).
(1)

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events