Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Simon_Macpherso
Advisor
Jump to solution

SAML Support for Remote Access VPN

Hello,

When configuring SAML integration for Remote Access VPN, the following documentation specifies Endpoint Security Client for Windows - version E84.70 build 986102705 or higher needs to be installed.

https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...

Our Windows users are currently using the Checkpoint Capsule VPN client from the Windows store, which allows users to configure a VPN connection profile with the OS VPN settings.

Can the Checkpoint Capsule VPN client be used for SAML authentication for Windows users instead of deploying Endpoint Security Client for Windows - version E84.70 build 986102705 or higher to each machine?

Regards,
Simon

4 Solutions

Accepted Solutions
PhoneBoy
Admin
Admin

Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.

View solution in original post

SenpaiNoticed_U
Employee
Employee

SK172909 states at the top, that SAML is not supported with 

  • Capsule VPN / Capsule Connect / Capsule for Windows

View solution in original post

SenpaiNoticed_U
Employee
Employee

Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114

 

View solution in original post

SenpaiNoticed_U
Employee
Employee

No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.

View solution in original post

32 Replies
_Val_
Admin
Admin

Look here: https://support.checkpoint.com/results/sk/sk172909

Capsule is not listed, which means SAML is not supported with it.

SenpaiNoticed_U
Employee
Employee

SK172909 states at the top, that SAML is not supported with 

  • Capsule VPN / Capsule Connect / Capsule for Windows

Chris_Atkinson
Employee Employee
Employee

There has been progress in recent Jumbo's it seems: R81.10 JHF T113

PRJ-47677,PMTR-88036 - VPN - UPDATE: Added SAML authentication support for Capsule Connect / Capsule VPN.

 

CCSM R77/R80/ELITE
SenpaiNoticed_U
Employee
Employee

Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114

 

PhoneBoy
Admin
Admin

While I agree this is positive movement, I assume this would also require client updates as well.

SenpaiNoticed_U
Employee
Employee

No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.

gsciotti
Explorer

Hi Chris,

good news. Do you have any documentation about how to implement it? Does it just work updating to the jhf 113 if actually SAML is used on PC/MAC devices?

Chris_Atkinson
Employee Employee
Employee

This is the gateway portion, likely a future client version is also needed to complete the picture at which time the documentation will be updated / made available. 

CCSM R77/R80/ELITE
SenpaiNoticed_U
Employee
Employee

read the bottom of that SK


Capsule does support SAML under the Mobile Access Blade.
See SK181494
=========
also see SK172909
it also now says capsule support, see sk181494

gsciotti
Explorer

ok thank you (you deserve a good pizza if you come in italy).

Any experience/test with okta if you know?

PhoneBoy
Admin
Admin

Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.

ClaudiaPeter
Contributor

Is there any roadmap for SAML support for iOS clients?

SAML is supported for Windows clients since nearly 2 years, but for iOS clients it is still "not currently supported". To use different authentication methods during a transition time period is okay, but after two years and with no chance to solve this, we are urged to migrate to another VPN solution.

PhoneBoy
Admin
Admin

Recommend you engage with your Check Point SE on this requirement. 

Realeboga_Mashi
Contributor

Any plans to work on enabling SAML Auth on Capsule Connect client for Windows?

Chris_Atkinson
Employee Employee
Employee

I believe it was resolved per: SAML authentication in Capsule VPN/Connect (checkpoint.com)

But have sought clarification accordingly for Windows based clients specifically.

Edit: SK was amended to clarify it, if you require Windows support please consult with your SE regarding RFE submission for this.

CCSM R77/R80/ELITE
SenpaiNoticed_U
Employee
Employee

sk181494 only applies to the Capsule clients on the Phones,  

The Capsule Client from the Windows Store still does not support SAML at this time.

Sam2
Contributor

I have this working in my lab and we will be looking to roll it out into production later this year for our mobile clients. I patched the gateway to R81.10 Jumbo 113 and enabled the SAML auth profile on the VPN Clients section. 

Initially I got a white page only when attempting to connect. After collecting debugs from my phone it was related to a certificate issue. Worked with my cert people to get a new public certificate that included my lab gateways hostname and i was able to get redirected to azure AD on connection for sign in, and i connected to the VPN after successfully logging in. 

Below is the debug from Capsule VPN Android that showed me my cert wasn't trusted and it was causing the issue: 

* This can be ignored when using the Endpoint VPN solution (for lab) but it doesn't give an option to approve an untrusted cert on mobile.

CapsuleCertNotTrusted.png

SenpaiNoticed_U
Employee
Employee

SK172909
Capsule VPN for Android and Iphone are not supported for SAML auth at this time.

Peter_Lyndley
Advisor
Advisor

Someone must know if the updated client for SAML support is in the pipeline though ? Do we at least know if it is due before end 2023 ? 

Sam2
Contributor

Working with my sales team the fix owner says it is supported, we already have it working on mobile now. 

SenpaiNoticed_U
Employee
Employee

I know there is something in the works, but I have not been informed of any ETA or related data for it.
Once It is fully supported, I will know and the SK will be released.

PhoneBoy
Admin
Admin

If you're working with your local Check Point office on this, it's very likely this is considered a "customer release" at present.
Given that it's rolled out to a public JHF, it's a good indication this will be formally supported in the near future.

ClaudiaPeter
Contributor

Is there any new information when it will be formally supported?

We tested it and it works, we need it badly, but we will not rollout a unsupported solution.

PhoneBoy
Admin
Admin

Unfortunately, I have no information on this.
Your best bet is to consult with your local Check Point office, who will likely need to engage with Solution Center internally.

gsciotti
Explorer

Hi, is there any document that explains how to implement it specifically for capsule app once gateway is updated?

bzc
Explorer
Explorer

Hi,

 

Did you find any documentation on the Capsule SAML setup?

I'm also looking for any feedback on the difference and what is better/worse compared to the classic Endpoint VPN?

Thanks

SenpaiNoticed_U
Employee
Employee

For Capsule VPN/Capsule Connect, for Iphone or Android,
install the App on the phone and create the site.

For gateway side configuration, only requires the necessary jumbo take.
and the Authentication page follows the same Remote Access configuration.
Set Auth type to Provider.

I have a Remote Access Gateway that already has SAML for the Endpoint clients, so it was just a matter of installing the correct Jumbo Take (sk181494) and create the site on the phone app.

So if this was a fresh environment, I would follow SK172909 for any R81.10 gateways, as you would still need the SAML script to be run on your Management server unless you are a full R81.20 environment. SK172909 for script, sk181494 for Capsule Jumbo requirement.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events