- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: SAML Support for Remote Access VPN
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SAML Support for Remote Access VPN
Hello,
When configuring SAML integration for Remote Access VPN, the following documentation specifies Endpoint Security Client for Windows - version E84.70 build 986102705 or higher needs to be installed.
Our Windows users are currently using the Checkpoint Capsule VPN client from the Windows store, which allows users to configure a VPN connection profile with the OS VPN settings.
Can the Checkpoint Capsule VPN client be used for SAML authentication for Windows users instead of deploying Endpoint Security Client for Windows - version E84.70 build 986102705 or higher to each machine?
Regards,
Simon
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SK172909 states at the top, that SAML is not supported with
- Capsule VPN / Capsule Connect / Capsule for Windows
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Found sk177646 which is related
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Look here: https://support.checkpoint.com/results/sk/sk172909
Capsule is not listed, which means SAML is not supported with it.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SK172909 states at the top, that SAML is not supported with
- Capsule VPN / Capsule Connect / Capsule for Windows
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There has been progress in recent Jumbo's it seems: R81.10 JHF T113
PRJ-47677,PMTR-88036 - VPN - UPDATE: Added SAML authentication support for Capsule Connect / Capsule VPN.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
While I agree this is positive movement, I assume this would also require client updates as well.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Chris,
good news. Do you have any documentation about how to implement it? Does it just work updating to the jhf 113 if actually SAML is used on PC/MAC devices?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
This is the gateway portion, likely a future client version is also needed to complete the picture at which time the documentation will be updated / made available.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
read the bottom of that SK
Capsule does support SAML under the Mobile Access Blade.
See SK181494
=========
also see SK172909
it also now says capsule support, see sk181494
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ok thank you (you deserve a good pizza if you come in italy).
Any experience/test with okta if you know?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there any roadmap for SAML support for iOS clients?
SAML is supported for Windows clients since nearly 2 years, but for iOS clients it is still "not currently supported". To use different authentication methods during a transition time period is okay, but after two years and with no chance to solve this, we are urged to migrate to another VPN solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Recommend you engage with your Check Point SE on this requirement.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Any plans to work on enabling SAML Auth on Capsule Connect client for Windows?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe it was resolved per: SAML authentication in Capsule VPN/Connect (checkpoint.com)
But have sought clarification accordingly for Windows based clients specifically.
Edit: SK was amended to clarify it, if you require Windows support please consult with your SE regarding RFE submission for this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk181494 only applies to the Capsule clients on the Phones,
The Capsule Client from the Windows Store still does not support SAML at this time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have this working in my lab and we will be looking to roll it out into production later this year for our mobile clients. I patched the gateway to R81.10 Jumbo 113 and enabled the SAML auth profile on the VPN Clients section.
Initially I got a white page only when attempting to connect. After collecting debugs from my phone it was related to a certificate issue. Worked with my cert people to get a new public certificate that included my lab gateways hostname and i was able to get redirected to azure AD on connection for sign in, and i connected to the VPN after successfully logging in.
Below is the debug from Capsule VPN Android that showed me my cert wasn't trusted and it was causing the issue:
* This can be ignored when using the Endpoint VPN solution (for lab) but it doesn't give an option to approve an untrusted cert on mobile.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SK172909
Capsule VPN for Android and Iphone are not supported for SAML auth at this time.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Someone must know if the updated client for SAML support is in the pipeline though ? Do we at least know if it is due before end 2023 ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Working with my sales team the fix owner says it is supported, we already have it working on mobile now.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I know there is something in the works, but I have not been informed of any ETA or related data for it.
Once It is fully supported, I will know and the SK will be released.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you're working with your local Check Point office on this, it's very likely this is considered a "customer release" at present.
Given that it's rolled out to a public JHF, it's a good indication this will be formally supported in the near future.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there any new information when it will be formally supported?
We tested it and it works, we need it badly, but we will not rollout a unsupported solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unfortunately, I have no information on this.
Your best bet is to consult with your local Check Point office, who will likely need to engage with Solution Center internally.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
https://support.checkpoint.com/results/sk/sk181494
looks like the Capsule SK is released now
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi, is there any document that explains how to implement it specifically for capsule app once gateway is updated?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Did you find any documentation on the Capsule SAML setup?
I'm also looking for any feedback on the difference and what is better/worse compared to the classic Endpoint VPN?
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For Capsule VPN/Capsule Connect, for Iphone or Android,
install the App on the phone and create the site.
For gateway side configuration, only requires the necessary jumbo take.
and the Authentication page follows the same Remote Access configuration.
Set Auth type to Provider.
I have a Remote Access Gateway that already has SAML for the Endpoint clients, so it was just a matter of installing the correct Jumbo Take (sk181494) and create the site on the phone app.
So if this was a fresh environment, I would follow SK172909 for any R81.10 gateways, as you would still need the SAML script to be run on your Management server unless you are a full R81.20 environment. SK172909 for script, sk181494 for Capsule Jumbo requirement.