Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
simonemantovani
MVP Diamond
MVP Diamond

VPN Remote Access + OneLogin SAML provider for MFA authentication + On-prem LDAP authorization

Introduction

This document contains all the steps required to implement the Check Point Remote Access VPN connection with SAML authentication through the OneLogin Identity Provider (IdP).

By integrating OneLogin SAML authentication, multi-factor authentication is enabled for users accessing the VPN.

In this real case, these are the requirements requested by the customer:

  • Authentication based on SAML.
  • Authorization based on LDAP Account Unit to preserve all the existing policies created for the user that are authenticating using only LDAP credentials; these users will be migrated from LDAP to SAML authentication, to enable MFA.
  • Keep both authentication and authorization method enabled at the same time, to provide enough time to complete the migration of the users from one method to another.

For authentication, users are required to use their username (sAMAccountName) instead of their email address (like it happens when also authorization is performed on the IdP).

As previously reported, authorization is handled by the on-premises Active Directory. Therefore, OneLogin is used only as the authenticator.

Once the integration between the firewall and the IdP has been configured, the VPN client performs the following steps when connecting:

  1. Start negotiation with the firewall.
  2. The client is redirected to the IdP to perform authentication.
    1. The client displays a pop-up window containing the IdP authentication form.
  3. Once successfully authenticated, the client returns to the firewall to complete the VPN connection.
  4. The firewall checks the AD group to which the user belongs to match it against the configured policies.

 

 

 

SAML Configuration

This section describes the steps required to implement the SAML integration between the firewall and the IdP.

The following requirements must be met to enable this configuration:

  • Check Point Management: version R81 JHF 42 or later.
  • Check Point Gateway: version R81 JHF 42 or later.
  • VPN Client: Endpoint Security Client for Windows E84.70 (build 986102705) or later; Endpoint Security Client for macOS E85.30 or later.

SAML PORTAL Configuration

First, an FQDN must be registered for use by the Endpoint client to establish the connection; this FQDN must point to the public address of the Check Point cluster.

The FQDN must also be configured within the firewall cluster object (VPN Clients → SAML Portal Settings).

To avoid potential certificate-related warnings, a valid certificate can be uploaded.

simonemantovani_0-1787565751412.png

 

Identity Provider Configuration

The SAML integration between the IdP and the firewall is configured on OneLogin side, where a SAML 2.0 application is created according to the vendor procedure.

For correct integration with Check Point, the following fields must be configured correctly (within the application’s Configuration section on OneLogin tenant).

  • Audience: corresponds to the Identifier (Entity ID) field defined in Check Point.
  • Recipient: corresponds to the Reply URL field defined in Check Point.
  • ACS URL Validator: corresponds to the URL entered as the Main URL within the SAML Portal Settings configuration described in the previous section.
    • IMPORTANT: a backslash (\) must be inserted before every slash (/) in the URL, as follows: https:\/\/<SAML_Portal_FQDN>\/saml-vpn\/.
  • ACS URL: set to the same value as Recipient.
  • Login URL: corresponds to the Main URL configured in Check Point under SAML Portal Settings.
  • SAML Initiater: set to “Service Provider”.
  • SAML nameID format: set to “Email”.

The XML metadata file is then downloaded from the IdP and imported into Check Point as an Identity Provider object.

simonemantovani_1-1787565751413.png

 

The object provides the information that is also configured in OneLogin (Entity ID and Reply URL).

When configuring this object, the gateway on which SAML authentication will be enabled and the service (Remote Access VPN) are specified.

Since authentication is to be performed using the user’s sAMAccountName, the following configuration is set on the OneLogin side within the Parameters section of the SAML application created.

simonemantovani_2-1787565751414.png

 

Authentication and Authorization Configuration

A new authentication method is configured to permit to maintain the current authentication method based on LDAP still working and offer to the clients the new authentication method based on SAML.

On Endpoint Client side, to use SAML authentication, the method must be selected into the authentication settings of the VPN site.

When all the users are migrated to MFA, then the flag “Allow older clients to connect to the gateway” can be unchecked.

NOTE: the configuration normally indicated in the Check Point Admin Guide requires setting certain parameters in the Management database (using GuiDBEdit). For this specific SAML configuration, the Admin Guide procedure was not followed because setting the values suggested in the documentation would affect VPN connections currently using LDAP authentication.

The authentication and authorization configuration is set within the firewall object, VPN Clients → Authentication → Multiple Authentication Clients Settings.

simonemantovani_3-1787565751415.png

 

A new authentication method is created here, consisting of two sections:

  • Login Options.
  • User Directories.

Login Options

Defines how users are authenticated.

simonemantovani_4-1787565751416.png

 

The Identity Provider created previously is selected under Authentication Methods.

simonemantovani_5-1787565751417.png

 

User Directories

This section defines how user authorization is performed; as described above, in this case the process is based on the on-premises Active Directory.

simonemantovani_6-1787565751417.png

 

The LDAP Account Unit already configured on the Management is selected, and the SAM Account-Name (sAMAccountName) field is selected as the LDAP Lookup Type because this is the information used during authentication at the IdP.

Policy Configuration

With this setup, the policy configuration does not change; Access Roles can therefore be used within the rules, referencing the LDAP groups from Active Directory.

References

VPN Remote Access Admin Guide:

https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_RemoteAccessVPN_AdminGuide/Topics-...

SK for VPN Remote Access Authentication

https://support.checkpoint.com/results/sk/sk172909

 

1 Reply
AttiqRahman786
MVP Silver
MVP Silver

Very Good, Thanks !!

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events