- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Re: How to Configure Check Point Endpoint Security...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to Configure Check Point Endpoint Security E88.60 Remote Access VPN to Use Azure AD or CA?
Hello,
I am currently using Check Point Endpoint Security E88.60 for Remote Access VPN, but whenever I try to connect, I'm always prompted to enter my username and password.
I would like to configure the VPN client to authenticate users using either Azure AD or Certificate Authentication (CA) instead of the standard username/password method.
Could anyone guide me on how to set this up? Specifically:
- How do I integrate Azure AD for authentication, or
- How can I configure Certificate-based Authentication (CA) for VPN access?
Any guidance or step-by-step instructions would be greatly appreciated!
Thank you in advance!
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Those options are only available if you are managing your SMB with a Smart-1 appliance.
Otherwise, you are limited to passwords or, upon upgrading your firmware to R81.10.15, you can also leverage Azure/Entra ID.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Both options are supported.
Refer to the relevant product documentation linked below.
- Azure AD: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...
- User Certificates: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...
- Machine Certificate (can be used with either): https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/C...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My apologies as I did not mention that I'm using Quantum Spark 1575 appliance as the firewall and Remote Access VPN. Not R81.20
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't believe you can do certificates from a locally managed SMB appliance.
However, SAML support for locally managed SMB appliances is supported from R81.10.15: https://sc1.checkpoint.com/documents/SMB_R81.10.X/CLI/EN/Content/Topics/Configuring-SAML-Identity-Pr...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm rather new to this appliance.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Those options are only available if you are managing your SMB with a Smart-1 appliance.
Otherwise, you are limited to passwords or, upon upgrading your firmware to R81.10.15, you can also leverage Azure/Entra ID.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thks for the suggestion. We are planning to upgrade the firmware to R81.10.15, so that we are able to leverage Azure/Entra ID.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Best you use 2FA together with UN / PW
