- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello,
When configuring SAML integration for Remote Access VPN, the following documentation specifies Endpoint Security Client for Windows - version E84.70 build 986102705 or higher needs to be installed.
Our Windows users are currently using the Checkpoint Capsule VPN client from the Windows store, which allows users to configure a VPN connection profile with the OS VPN settings.
Can the Checkpoint Capsule VPN client be used for SAML authentication for Windows users instead of deploying Endpoint Security Client for Windows - version E84.70 build 986102705 or higher to each machine?
Regards,
Simon
Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.
SK172909 states at the top, that SAML is not supported with
Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114
No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.
Found sk177646 which is related
Look here: https://support.checkpoint.com/results/sk/sk172909
Capsule is not listed, which means SAML is not supported with it.
SK172909 states at the top, that SAML is not supported with
There has been progress in recent Jumbo's it seems: R81.10 JHF T113
PRJ-47677,PMTR-88036 - VPN - UPDATE: Added SAML authentication support for Capsule Connect / Capsule VPN.
Not seeing any Official Admin Guide nor an SK article. This may still be in development.
just that the Jumbo for R81.10 JHF Take_113 may have included the feature to be released, like how in R80.40 JHF Take_114
While I agree this is positive movement, I assume this would also require client updates as well.
No ETA on the feature release, but I would assume its more in align with when Jumbo release schedules are pushed out.
But at current state, Capsule is not yet fully supported with SAML.
Hi Chris,
good news. Do you have any documentation about how to implement it? Does it just work updating to the jhf 113 if actually SAML is used on PC/MAC devices?
This is the gateway portion, likely a future client version is also needed to complete the picture at which time the documentation will be updated / made available.
read the bottom of that SK
Capsule does support SAML under the Mobile Access Blade.
See SK181494
=========
also see SK172909
it also now says capsule support, see sk181494
ok thank you (you deserve a good pizza if you come in italy).
Any experience/test with okta if you know?
Capsule VPN clients on any platform (Windows, iOS, Android) do not currently support SAML authentication.
Is there any roadmap for SAML support for iOS clients?
SAML is supported for Windows clients since nearly 2 years, but for iOS clients it is still "not currently supported". To use different authentication methods during a transition time period is okay, but after two years and with no chance to solve this, we are urged to migrate to another VPN solution.
Recommend you engage with your Check Point SE on this requirement.
Any plans to work on enabling SAML Auth on Capsule Connect client for Windows?
I believe it was resolved per: SAML authentication in Capsule VPN/Connect (checkpoint.com)
But have sought clarification accordingly for Windows based clients specifically.
Edit: SK was amended to clarify it, if you require Windows support please consult with your SE regarding RFE submission for this.
sk181494 only applies to the Capsule clients on the Phones,
The Capsule Client from the Windows Store still does not support SAML at this time.
I have this working in my lab and we will be looking to roll it out into production later this year for our mobile clients. I patched the gateway to R81.10 Jumbo 113 and enabled the SAML auth profile on the VPN Clients section.
Initially I got a white page only when attempting to connect. After collecting debugs from my phone it was related to a certificate issue. Worked with my cert people to get a new public certificate that included my lab gateways hostname and i was able to get redirected to azure AD on connection for sign in, and i connected to the VPN after successfully logging in.
Below is the debug from Capsule VPN Android that showed me my cert wasn't trusted and it was causing the issue:
* This can be ignored when using the Endpoint VPN solution (for lab) but it doesn't give an option to approve an untrusted cert on mobile.
SK172909
Capsule VPN for Android and Iphone are not supported for SAML auth at this time.
Someone must know if the updated client for SAML support is in the pipeline though ? Do we at least know if it is due before end 2023 ?
Working with my sales team the fix owner says it is supported, we already have it working on mobile now.
I know there is something in the works, but I have not been informed of any ETA or related data for it.
Once It is fully supported, I will know and the SK will be released.
If you're working with your local Check Point office on this, it's very likely this is considered a "customer release" at present.
Given that it's rolled out to a public JHF, it's a good indication this will be formally supported in the near future.
Is there any new information when it will be formally supported?
We tested it and it works, we need it badly, but we will not rollout a unsupported solution.
Unfortunately, I have no information on this.
Your best bet is to consult with your local Check Point office, who will likely need to engage with Solution Center internally.
https://support.checkpoint.com/results/sk/sk181494
looks like the Capsule SK is released now
Hi, is there any document that explains how to implement it specifically for capsule app once gateway is updated?
Hi,
Did you find any documentation on the Capsule SAML setup?
I'm also looking for any feedback on the difference and what is better/worse compared to the classic Endpoint VPN?
Thanks
For Capsule VPN/Capsule Connect, for Iphone or Android,
install the App on the phone and create the site.
For gateway side configuration, only requires the necessary jumbo take.
and the Authentication page follows the same Remote Access configuration.
Set Auth type to Provider.
I have a Remote Access Gateway that already has SAML for the Endpoint clients, so it was just a matter of installing the correct Jumbo Take (sk181494) and create the site on the phone app.
So if this was a fresh environment, I would follow SK172909 for any R81.10 gateways, as you would still need the SAML script to be run on your Management server unless you are a full R81.20 environment. SK172909 for script, sk181494 for Capsule Jumbo requirement.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
1 | |
1 | |
1 | |
1 | |
1 | |
1 | |
1 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY