- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: VPN Remote Access - MFA with SAML and Google C...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
VPN Remote Access - MFA with SAML and Google Cloud as Identity Provider
Good morning everyone,
I am helping to implement two-factor authentication between Check Point and Google using SAML for Remote Access VPN connections. The Identity Provider settings are configured correctly and the client can successfully connect to the VPN. However, I cannot see the groups that the user belongs to and therefore I cannot create rules based on user groups. I followed this documentation -> https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C... (Step 6: Configure the Group Authorization), however, I cannot handle access by groups.
Do any of you have any experience with this type of implementation that you could share?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
If I understood correcly, you have to create manually with EXT_ID_ prefix.
if your grp attribute is "akos", then you need to create an user group with EXT_ID_akos name:
-
In SmartConsole, create an internal User Group object with this name (case-sensitive, spaces not supported):
EXT_ID_<Name_of_Role>
For example, for a role in the Identity Provider's interface with the name my_group, create an internal User Group object in SmartConsole with the name EXT_ID_my_group.
Note - In Microsoft Azure, Identity Tags are not supported for Remote Access connections.
I hope it helps
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you very much,
Can you tell me where I can correctly configure the groups parameter in Google Cloud?
I have already tried to do this configuration. I will validate it again and report the results.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I am not familiar with Google Cloud, maybe the Legends will help 🙂
Have you asked the ChatGPT already?
Ákos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @AkosBakos
I have tried to find out this information on ChatGPT but it wasn´t clear for me. Yesterday i had a meeting with TAC e some debugs was collected.
I´ll waiting for the results of analysis and i update this chat as soon as possible.
Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The relevant groups must be passed as part of the SAML assertion.
In Google Cloud, it looks like you configure this here: https://cloud.google.com/iap/docs/saml-attribute-propagation
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @PhoneBoy
Thanks for documentation. I´ll forward to the customer because i don´t have access on Google plataform.
