Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Simon_Macpherso
Advisor
Jump to solution

SAML Support for Remote Access VPN

Hello,

When configuring SAML integration for Remote Access VPN, the following documentation specifies Endpoint Security Client for Windows - version E84.70 build 986102705 or higher needs to be installed.

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...

Our Windows users are currently using the Checkpoint Capsule VPN client from the Windows store, which allows users to configure a VPN connection profile with the OS VPN settings.

Can the Checkpoint Capsule VPN client be used for SAML authentication for Windows users instead of deploying Endpoint Security Client for Windows - version E84.70 build 986102705 or higher to each machine?

Regards,
Simon

0 Kudos
4 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.

View solution in original post

0 Kudos
SenpaiNoticed_U
Employee
Employee

SK172909 states at the top, that SAML is not supported with 

  • Capsule VPN / Capsule Connect / Capsule for Windows

View solution in original post

(1)
SenpaiNoticed_U
Employee
Employee

Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114

 

View solution in original post

(1)
SenpaiNoticed_U
Employee
Employee

No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.

View solution in original post

(1)
29 Replies
Simon_Macpherso
Advisor
0 Kudos
_Val_
Admin
Admin

Look here: https://support.checkpoint.com/results/sk/sk172909

Capsule is not listed, which means SAML is not supported with it.

0 Kudos
SenpaiNoticed_U
Employee
Employee

SK172909 states at the top, that SAML is not supported with 

  • Capsule VPN / Capsule Connect / Capsule for Windows

(1)
Chris_Atkinson
Employee Employee
Employee

There has been progress in recent Jumbo's it seems: R81.10 JHF T113

PRJ-47677,PMTR-88036 - VPN - UPDATE: Added SAML authentication support for Capsule Connect / Capsule VPN.

 

CCSM R77/R80/ELITE
0 Kudos
SenpaiNoticed_U
Employee
Employee

Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114

 

(1)
PhoneBoy
Admin
Admin

While I agree this is positive movement, I assume this would also require client updates as well.

0 Kudos
SenpaiNoticed_U
Employee
Employee

No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.

(1)
gsciotti
Explorer

Hi Chris,

good news. Do you have any documentation about how to implement it? Does it just work updating to the jhf 113 if actually SAML is used on PC/MAC devices?

0 Kudos
(1)
Chris_Atkinson
Employee Employee
Employee

This is the gateway portion, likely a future client version is also needed to complete the picture at which time the documentation will be updated / made available. 

CCSM R77/R80/ELITE
0 Kudos
SenpaiNoticed_U
Employee
Employee

read the bottom of that SK


Capsule does support SAML under the Mobile Access Blade.
See SK181494
=========
also see SK172909
it also now says capsule support, see sk181494

0 Kudos
gsciotti
Explorer

ok thank you (you deserve a good pizza if you come in italy).

Any experience/test with okta if you know?

0 Kudos
PhoneBoy
Admin
Admin

Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.

0 Kudos
ClaudiaPeter
Contributor

Is there any roadmap for SAML support for iOS clients?

SAML is supported for Windows clients since nearly 2 years, but for iOS clients it is still "not currently supported". To use different authentication methods during a transition time period is okay, but after two years and with no chance to solve this, we are urged to migrate to another VPN solution.

0 Kudos
PhoneBoy
Admin
Admin

Recommend you engage with your Check Point SE on this requirement. 

0 Kudos
Sam2
Contributor

I have this working in my lab and we will be looking to roll it out into production later this year for our mobile clients. I patched the gateway to R81.10 Jumbo 113 and enabled the SAML auth profile on the VPN Clients section. 

Initially I got a white page only when attempting to connect. After collecting debugs from my phone it was related to a certificate issue. Worked with my cert people to get a new public certificate that included my lab gateways hostname and i was able to get redirected to azure AD on connection for sign in, and i connected to the VPN after successfully logging in. 

Below is the debug from Capsule VPN Android that showed me my cert wasn't trusted and it was causing the issue: 

* This can be ignored when using the Endpoint VPN solution (for lab) but it doesn't give an option to approve an untrusted cert on mobile.

CapsuleCertNotTrusted.png

0 Kudos
SenpaiNoticed_U
Employee
Employee

SK172909
Capsule VPN for Android and Iphone are not supported for SAML auth at this time.

0 Kudos
Peter_Lyndley
Advisor
Advisor

Someone must know if the updated client for SAML support is in the pipeline though ? Do we at least know if it is due before end 2023 ? 

0 Kudos
Sam2
Contributor

Working with my sales team the fix owner says it is supported, we already have it working on mobile now. 

0 Kudos
SenpaiNoticed_U
Employee
Employee

I know there is something in the works, but I have not been informed of any ETA or related data for it.
Once It is fully supported, I will know and the SK will be released.

0 Kudos
PhoneBoy
Admin
Admin

If you're working with your local Check Point office on this, it's very likely this is considered a "customer release" at present.
Given that it's rolled out to a public JHF, it's a good indication this will be formally supported in the near future.

0 Kudos
ClaudiaPeter
Contributor

Is there any new information when it will be formally supported?

We tested it and it works, we need it badly, but we will not rollout a unsupported solution.

0 Kudos
PhoneBoy
Admin
Admin

Unfortunately, I have no information on this.
Your best bet is to consult with your local Check Point office, who will likely need to engage with Solution Center internally.

0 Kudos
SenpaiNoticed_U
Employee
Employee

https://support.checkpoint.com/results/sk/sk181494

looks like the Capsule SK is released now

0 Kudos
gsciotti
Explorer

Hi, is there any document that explains how to implement it specifically for capsule app once gateway is updated?

0 Kudos
bzc
Explorer
Explorer

Hi,

 

Did you find any documentation on the Capsule SAML setup?

I'm also looking for any feedback on the difference and what is better/worse compared to the classic Endpoint VPN?

Thanks

0 Kudos
SenpaiNoticed_U
Employee
Employee

For Capsule VPN/Capsule Connect, for Iphone or Android,
install the App on the phone and create the site.

For gateway side configuration, only requires the necessary jumbo take.
and the Authentication page follows the same Remote Access configuration.
Set Auth type to Provider.

I have a Remote Access Gateway that already has SAML for the Endpoint clients, so it was just a matter of installing the correct Jumbo Take (sk181494) and create the site on the phone app.

So if this was a fresh environment, I would follow SK172909 for any R81.10 gateways, as you would still need the SAML script to be run on your Management server unless you are a full R81.20 environment. SK172909 for script, sk181494 for Capsule Jumbo requirement.

0 Kudos
bzc
Explorer
Explorer

Thanks but I'm a bit confused by the answer. Do you mean that SAML auth for Capsule is only for mobile Capsule client and not for the Windows Capsule client?

0 Kudos
SenpaiNoticed_U
Employee
Employee

Yes, capsule for the phones,
R81.20 jumbo take_43 PRJ-45338, PMTR-88036
SAML authentication support for Capsule Connect / Capsule VPN.
These are the phone Capsule clients.

Capsule for Windows is still unsupported based the statement on SK172909

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Note R81.20 JHF Take 43 includes: PRJ-45338,PMTR-88036 as related to the above.

 

CCSM R77/R80/ELITE
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events