Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
dt7
Contributor

Centrally change remote access VPN browser setting used for SAML auth by all clients

Hello everyone,

I would like to know if there is a way to set the idp_browser_mode setting for all VPN clients centrally?

I know that you can change this setting for each client via the trac.defaults config file and I have done that before (cf. sk180395 for reference).

For the context, my issue is that this setting was set to "embedded" in my case when deploying the VPN client as part of Harmony Endpoint E87.31. However, recently when upgrading those clients to a newer Harmony Endpoint version (it seems since E88.41 and above), the SAML portal authentication page now opens using the default browser instead of being embedded, without me changing this. I am not sure if this is part of an included change from the more recent Harmony Endpoint versions (I couldn't find anything related to this in the version release notes). My understanding is that with newer versions, when upgrading versions the existing trac.defaults file is supposed to be kept as-is (and not overwritten), so I am not sure what is causing the change in this setting with the newer versions...

If anybody has more information on this sudden behavior change and if it is possible to rectify the setting back to a certain value (in my case back to "embedded") for all clients at once, that would be great. It's not really practical to have to update all the trac.defaults files for all the clients (in my case 100+) just for this..

Thank you in advance for your help.

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

You can force it on the gateway side by changing idp_browser_mode in the TTM file:  https://support.checkpoint.com/results/sk/sk75221

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events