> Source: [sk180395](https://support.checkpoint.com/results/sk/sk180395)

# sk180395 - How to change Remote Access VPN Client's default browser for SAML Authentication

| Property | Value |
|----------|-------|
| Solution ID | sk180395 |
| Date Created | 2022-12-12 |
| Last Modified | 2025-10-23 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Windows, macOS |

## Solution

**Note** : Since [E88.40 Remote Access VPN Client for Windows](https://support.checkpoint.com/results/sk/sk182237), the default value of `idp_browser_mode `in the `trac.defaults` file has been changed to `default_browser` and added ability to centrally managed the browser for authentication using Identity Provider from the `trac_client_1.ttm` file. Refer to [sk75221 - Remote Access TTM Configuration](https://support.checkpoint.com/results/sk/sk75221).  

You can configure the Remote Access VPN Client to use the endpoint computer's default browser (example: Chrome).  

This procedure requires a change in the *trac.defaults file* on the endpoint computer. We can use an MSI package to distribute this file. See [sk122574](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122574).  

<br />

#### **This setting is now the default starting in:**

* [Endpoint Security Client for Windows - version E88.40](https://support.checkpoint.com/results/sk/sk117536)

<br />

**Setting included in:**   
[Endpoint Security Client for Windows](https://support.checkpoint.com/results/sk/sk117536) - version E87.30  
[Endpoint Security Client for macOS](https://support.checkpoint.com/results/sk/sk117536) - version E87.30**Manual configuration steps:**

1. On the endpoint computer, open a plain-text editor as an Administrator.
2. Open the trac.defaults file in the text editor.  

   On 32-bit Windows:  
   *%ProgramFiles%\\CheckPoint\\Endpoint Connect\\trac.defaults*   

   On 64-bit Windows:  
   *%ProgramFiles(x86)%\\CheckPoint\\Endpoint Connect\\trac.defaults*   

   On macOS: via Terminal  
   *sudo vi /Library/Application\\ Support/Checkpoint/Endpoint\\ Connect/Trac.defaults*
3. Change the value of the `idp_browser_mode` attribute from `embedded `to `default_browser`..
4. Keep the changes in the file and close the text editor.
5. Stop the Check Point Endpoint Security VPN client and start it again.  

   On Windows clients, open the Windows Command Prompt as an Administrator and run these commands:  
   1. `net stop TracSrvWrapper`
   2. `net start TracSrvWrapper`

   <br />

   Or on windows clients, In Windows Task Manager \> Services, restart TracSrvWrapper.  

   On macOS clients, open the Terminal and run these commands:  
   1. `sudo launchctl stop com.checkpoint.epc.service`
   2. `sudo launchctl start com.checkpoint.epc.service`  

<br />

|-----------------|-------------------------------------------------------------------------|
| **Values**      | Description                                                             |
| embedded        | Set to use the embedded browser from the Endpoint Client (Windows Only) |
| default_browser | Set to use the default system browser (Default value starting E88.40)   |
| safari          | Uses Safari (MacOS Only)                                                |
| IE              | Uses Internet Explorer (Windows Only)                                   |

<br />

**Notes:**   

* Microsoft does not support the Embedded Browser mode in Windows 11. See [sk182275](https://support.checkpoint.com/results/sk/sk182275)
* If using the Full Suite Endpoint Security client, you may need to disable self-protection in order to modify trac.defaults. See [sk171012](https://support.checkpoint.com/results/sk/sk171012).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
