- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: SAML authentication for Remote access VPN- JHF...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SAML authentication for Remote access VPN- JHF Take 114
Dear All,
Very recently Checkpoint release Ongoing take Jumbo HF Take_114 to support SAML authentication for Remote access VPN.
Question:-
1. CheckPoint R80.40 /w JHF 114 duly support SAML authentication for Remote access VPN.
2. Does anyone started using this in production environment by running the Ongoing take instead of GA?
3. Are there any open caveat?
4. CheckPoint VPN client version are available for both Windows and Mac OS?
In the end, we were looking forward to run CheckPoint R80.40 to authenticate Mobile Access + Remote access VPN using SAML (Azure IdP) without any dependencies with internal AD or local authentication.
Any feedback or comments will be really appreciated.......
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BALAJIRAJAH_PB ,
- Yes, we do support SAML integration for RA VPN clients.
- This feature was delivered to some customers (on production environments) as customer release before delivered to the JHF.
- The feature passed both customer production coverage and QA tests.
- Yes.
If you have any additional questions, please tag me 🙂
Royi Priov
R&D Group manager, Infinity Identity
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks @Royi_Priov for your response. I will proceed with the installation of JHF Take 114 and post you the outcome.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For remote access VPN, IdP authentication with Azure is not working. EndPoint VPN client triggers the embedded Azure MFA authentication but results in HTTP 500 error. Any insight?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BALAJIRAJAH_PB ,
I'm sorry to understand this feature is not working for you out of the box.
Error 500 can be caused by few reasons - we first need to understand if it happens before or after the redirection to the IDP to give us lead to the area of the problem.
The best suggestion at this stage, is to open a new ticket to our support, and attach the logs from "/opt/CPVPNPortal/logs"
Royi Priov
R&D Group manager, Infinity Identity
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Royi_Priov , I already created a case with CheckPoint support. Started my troubleshooting session on 25th May 2021. Still now no improvement.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Using single Azure domain, Check Point gateway support IdP SAML 2.0 authentication either for Mobile Access or Remote access.
Not both at the same time. Looking for a hotfix
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BALAJIRAJAH_PB ,
Thank you for your feedback.
We are familiar with your ticket and we will handle it soon.
We will also remove this limitation in the next Jumbo HF.
Thanks,
Elad Shoval
Team leader, Identity Awareness R&D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
@Elad_Shoval , Many thanks for your swift response. May I know the ETA for the next on-going take?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BALAJIRAJAH_PB ,
The current ETA is beginning of July.
Thanks,
Elad Shoval
Team leader, Identity Awareness R&D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Dear @Elad_Shoval , Any update regarding this JHF?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BALAJIRAJAH_PB ,
The current ETA is still at beginning of July.
Thanks,
Elad Shoval
Team leader, Identity Awareness R&D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi All,
CheckPoint released Jumbo HF Take_119 on 4th July that support one single idP for authenticate for Mobile Access and EndPoint VPN. I tried and it's not working. Any inputs will be really appreciated.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @BALAJIRAJAH_PB ,
Sorry for the misunderstanding. In take 119, we added the ability to authenticate for Mobile Access and EndPoint VPN at the same time with the same Microsoft azure ad directory. However, each blade on each gateway requires its own Identity Provider object in SmartConsole.
Thanks,
Elad Shoval
Team leader, Identity Awareness R&D
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @Elad_Shoval - I'm also facing similar issue where mobile access users auth. is getting failed using SAML Auth. My standalone Security gateway (deployed in Azure IaaS )running with R8.10 version and mobile access + IPsec VPN blade enable and it is managed by MDS (R81 with T81). Kindly refer attached error.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do we support this feature in R81 ?
if so , is it supported in Smart-1 Cloud ?
