- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- SmartCard Authentication for VPN users
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SmartCard Authentication for VPN users
Hi,
We currently have our VPN users authenticating with domain (user/password) credentials.
We want to change the VPN authentication to the SmartCard which each user has connected to his laptop and which is normally used to login to the laptop.
Has anyone configured VPN users with SmartCard authentication?
I was not able to find anything about this in Checkpoint site.
Thanks
micha
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
See Remote Access VPN R81 Administration Guide p.44fff !
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks, but I only see SmartCard mentioned regarding L2TP (which is not what we want) and it doesn't appear to really be with a SmartCard, rather with a regular certificate.
We want SmartCard authentication with Checkpoint VPN client, and that is not described there.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It was more complicated than I thought. It took Checkpoint dealer two days to get it working and was not something that we could have done ourselves.
Some tips:
1. You need to activate Identity Awareness. Don't need to run wizard, but will need to mark off VPN in IA configuration tab of firewall.
2. Changes needed to be done via DBEdit.
3. We are using UPN from the SmartCard and via Activedirectory.
4. Make sure that the connection to AD servers is working well. We had problems of dedicated user locking in AD. The solution was a CLI command to force use of NTLMv2.
5. We also configured the firewall to distribute addresses from DHCP servers.
