- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- SAML Authentication on VPN reauthentication timeou...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SAML Authentication on VPN reauthentication timeout
I have SAML up and running through AzureAD on my VPN gateways,
For testing purposes i have my AzureAD CA policy set to expire me after 6 hours, my vpn is set to reauthenticate every 12.
Whenever the vpn needs to reauthenticate, it will repeatedly send authentication requests to my phone until i accept the connection.
The result of this is if i leave my pc on and leave my house, every 2 minutes i will get an auth request until i get home and either connect to the VPN again or disconnect entirely.
Has anyone had this issue? is there anyway to force a timeout after no response on authenticator?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have a similar setup. At the end of the 12 hour period I get just 2 push notifications to the phone during a 5 minute window to reauthenticate but not repeatedly beyond that. Can't remember where we set it but I think the 5 minute reauth window is out of the box default on the Checkpoint end regardless of login method.
Update, reauth window (default 5 minutes) may be able to changed in the gateway's reauth_grace_period or client trac.default, reference link:
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
100% I can remember there is setting in Azure portal for this, I just cant recall which one. Let me see if I can find it through my notes and send it over.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See if anything from this link helps, if not, I will keep checking.
Andy
https://learn.microsoft.com/en-us/azure/azure-portal/set-preferences
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have a similar setup. At the end of the 12 hour period I get just 2 push notifications to the phone during a 5 minute window to reauthenticate but not repeatedly beyond that. Can't remember where we set it but I think the 5 minute reauth window is out of the box default on the Checkpoint end regardless of login method.
Update, reauth window (default 5 minutes) may be able to changed in the gateway's reauth_grace_period or client trac.default, reference link:
