I have a very strange issue regarding our Checkpoint VPN utilizing Okta SAML Authentication for MFA. In most cases, it works fine but we are seeing some very odd issues.
1. Username/Password Auth - User signs in, Identity Collector verifies user with AD and allows a connection.
2. On the Client Endpoint, Users selects Okta SAML VPN, which was setup, with exact instructions from Checkpoint ADM.
3. When user launches client, it pops up the Okta screen, the user enters in ID/PW, selects SMS, Push, Email and etc.
4. Okta screen spins and then the Checkpoint Client will USUALLY complete the connection.
5. Randomly, the user will do step 3, the Okta screen spins a bit, as normal, but then the "Checkpoint VPN Client" will come throw back and error stating "Invalid User/Bad Password" and will never let them in.
6. If the user changes Authentication, on the client, back to Username/Password, then enters the same ID/PW used in step3 and 5, Checkpoint will successfully complete the connection.
7. Sometimes, the user, utilizing Okta SAML VPN, will successfully connect with no issues at all ...AND importantly, NO CHANGES at all on the Checkpoint VPN client side.
Our company is mandating MFA on our VPN connections so it is vital to have this working. The main ISP we see this happen with is TMobile 5g Wireless but in the last couple of days, I have seen this on an Indian ISP Railware or something and then this morning, A carrier in PA. Checkpoint TAC did some debugs and in the debugs...weirdly, they are seeing the request come in on 1 external IP, but Checkpoint TAC is saying that in the middle of the process or something, the IP is changing to a different external IP which Checkpoint is not recognizing and then denying the connection. This is being seen on T-Mobile mostly. But again...with no changes to Okta or Checkpoint, sometimes it will work.
AND...Our Checkpoint ADM says he has a couple other customers who are seeing this same behavior
Any thoughts....this is so HIGH Priority and doesn't appear to be any assistance on this anywhere.