- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
IDC Spotlight -
Uplevel The SOC
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello,
is it possible to connect VPN clients with device certificate which is enrolled by Intune in Azure cloud solution.
Specifically, we have established SCEPman service which is intergrated with Intune in Azure. This service enroll device certificate on all our clients (MacOS,Windows,Android and IOS).
I have been research on SK but only founded intergration device certification on-premise AD.
Kind Regards
Sasa
You have to import the CA so the GW will know and use it, see sk103885: How to change the certificate presented by Security Gateway to Remote Access clients.
Hello, but on this tab I have only this option
This gateway authenticates with this certificate - defaultCert.
How/Where I can upload to see appropriate certificate?
Thanks
Sasa
For device certificate authentication you must be on R80.40 or above gateway.
You would still need to import a copy of the public CA key from whatever is providing the certificates to your clients.
This is necessary so the device certificate can be validated.
Hello,
yes, version R80.40 is on gateway. Just to be sure, adding/importing public CA is doing on Trusted CA and on IPSec VPN I should add created CA which will replace existing deafultCert.
After validatation, client should be able connect to VPN (with device certificate), right?
Kind Regards
Sasa
The defaultCert comes from the ICA, so you can't really delete it.
It's also the gateway certificate, not the certificate authority itself.
You have to create an OPSEC CA object where you import the relevant public key.
(That's what it used to be called, it's a Trusted CA object in R80.40)
If you want user group information, the gateway will need to be connected to an LDAP server of some sort.
Thanks for feedback.
So, conclusion is: gateway can not check/validate device certificate directly to Intune if it does not communicate with LDAP in any way.LDAP is mandatory.
Please correct me if I am wrong.
Kind Regards
Sasa
Certificate validation either requires LDAP or HTTPS for CRL checking.
Group information for users requires LDAP.
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY