Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Gaurav_Pandya
Advisor
Jump to solution

Remote access community participating group using Azure saml authentication

Hi Mates,

I have configured Azure saml authentication for remote access vpn. During testing, We are getting "Negotiation with site is failed" error message on client side and "user does not belong to remote access community" in smart console.

When I changed remote access vpn community participating group to "all user", we are able to authenticate for remote vpn using saml.

Question here is, can I map Azure identity provider group in remote access community participating group? because it does not show any identity provider group when I try to add in participating group. Or I need to keep "All user" in participating group?

 

0 Kudos
1 Solution

Accepted Solutions
the_rock
Legend
Legend

I attached a doc that hopefully is helpful to you.

Andy

View solution in original post

9 Replies
PhoneBoy
Admin
Admin

Create groups as described here: https://support.checkpoint.com/results/sk/sk177267

Gaurav_Pandya
Advisor

Thanks, Phoneboy. I have already created and tested with group name EXT_ID_ with no luck. I will verify configuration with Azure administrator.

0 Kudos
the_rock
Legend
Legend

The sk Phoneboy gave you is definitely good place to start. One of my colleagues and I had to do this for a large customer.

0 Kudos
the_rock
Legend
Legend

I attached a doc that hopefully is helpful to you.

Andy

Gaurav_Pandya
Advisor

Thanks @the_rock for sharing document. I will verify.

0 Kudos
the_rock
Legend
Legend

Hope it really helps you, as we always follow it and works fine. Let me know if any issues.

0 Kudos
Gaurav_Pandya
Advisor

We have followed sk177267 & sk172909 to define group in Azure. Still, it was not working, Lastly, we have configured each group has its own role which you mentioned in supplementary instruction document (Undocumented step – CRUCIAL). It did the trick. Now it is working as expected. 

Thanks again for sharing supplementary instruction document.

the_rock
Legend
Legend

I agree, thats super important step. My colleague and I got that from Azure documentation, I will write a feedback about it in the sk.

Best,

Andy

0 Kudos
the_rock
Legend
Legend

Okay, just submitted a feedback.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events