<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Always-ON VPN ( Device &amp;amp; User tunnel ) together with Identity Collector question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/203103#M38212</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;is there any possibility to establish an user AND machine tunnel during the session?&lt;BR /&gt;&lt;BR /&gt;Terminal mode (in trac default) ist activated.&lt;BR /&gt;PC boots up. Machine tunnel will be established. User logs in, user tunnel will be established WITHOUT disconnecting the machine tunnel ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this possible?&lt;BR /&gt;&lt;BR /&gt;Thanks and kind regards,&lt;/P&gt;&lt;P&gt;Simon.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jan 2024 14:09:48 GMT</pubDate>
    <dc:creator>SimonSchreiber9</dc:creator>
    <dc:date>2024-01-15T14:09:48Z</dc:date>
    <item>
      <title>Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165888#M29788</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do have a question regarding the combination of Windows AO-VPN and IDC.&lt;/P&gt;&lt;P&gt;Our Windows AO-VPN solution on our Windows Endpoints consists of 2 tunnels.&lt;/P&gt;&lt;P&gt;1. Device Tunnel ( Is initiated when Windows boots and before user logs in )&lt;/P&gt;&lt;P&gt;2. User Tunnel ( is initiated after the user logs in into Windows )&lt;/P&gt;&lt;P&gt;The Device Tunnel is there purely for management purposes ( getting (AV)/Windows updates etc). The User Tunnel gets the corresponding routes which the user needs.&lt;/P&gt;&lt;P&gt;However in SmartConsole i see in the logs that the traffic which the user initiates does not has a source-username log entry.&lt;/P&gt;&lt;P&gt;Investigating it further , i see that the username of the corresponding user that has logged in to the endpoints is correlating with the Device-Tunnel IP address. However,&amp;nbsp; that IP is not used for resources behind the VPN.&lt;/P&gt;&lt;P&gt;The IDC is working correctly for internal traffic , but as the remote endpoint gets 2 IP addresses , IDC only correlates the Device IP instead of the User-Tunnel IP.&lt;/P&gt;&lt;P&gt;Currently the traffic flow is as follows&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Devices boots&lt;/LI&gt;&lt;LI&gt;Windows starts up and Device-Tunnel is initiated -&amp;gt; IP 10.10.10.1 is assigned.&lt;/LI&gt;&lt;LI&gt;User logs in into Windows before the User-Tunnel is initiated the IDC correlates the Device-Tunnel IP with the logged in user ( which is what gets into the AD Event logs ) so untill here everyhing works correctly&lt;/LI&gt;&lt;LI&gt;User-Tunnel is automatic initiated after user login and traffic to on-prem resources flows via User-Tunnel ( IP 10.10.10.2 )&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what we would actually like to establish is that the 10.10.10.2 is correlated in SmartConsole with the Windows Username. However , i doubt if that is possible as the real login on the Windows Endpoint happens before. Hopefully anybody here can point me in the right direction.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 18:29:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165888#M29788</guid>
      <dc:creator>NickDeGrootYama</dc:creator>
      <dc:date>2022-12-22T18:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165889#M29789</link>
      <description>&lt;P&gt;Identity Collector can only leverage information it gets from the Identity Source (in this case, Active Directory).&lt;BR /&gt;If there isn't a login event reported on the other IP address in the Windows Security Logs, we'll never know about it.&lt;/P&gt;
&lt;P&gt;The only thing I can suggest trying is using an Identity Agent on systems with AO-VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 19:27:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165889#M29789</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-22T19:27:29Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165891#M29790</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Just to confirm your identity awareness config has "remote access VPN" selected as an identity source correct?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If this VPN doesn't terminate on a CP gateway as such you can ignore the above however.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 21:37:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165891#M29790</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-12-22T21:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165892#M29791</link>
      <description>&lt;P&gt;We're talking about Microsoft's Always-on VPN...which doesn't use our client or terminate on our gateway.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 21:43:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165892#M29791</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-12-22T21:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165896#M29792</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/85582"&gt;@NickDeGrootYama&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My previous employer had the same set up. As &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;mentioned, we used Identity Agent (transparent Kerberos SSO) with Windows AOVPN and it worked as you required i.e. presented the user tunnel IP along with the user &amp;amp; device credentials from the Kerberos ticket.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Dec 2022 22:26:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165896#M29792</guid>
      <dc:creator>AaronCP</dc:creator>
      <dc:date>2022-12-22T22:26:36Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165918#M29795</link>
      <description>&lt;P&gt;Tested this on my own machine , and indeed that works as expected.&lt;/P&gt;&lt;P&gt;Was hoping this could be done clientless , but if we need this Identity Agent then we should do that!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Fri, 23 Dec 2022 06:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/165918#M29795</guid>
      <dc:creator>NickDeGrootYama</dc:creator>
      <dc:date>2022-12-23T06:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/203103#M38212</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;is there any possibility to establish an user AND machine tunnel during the session?&lt;BR /&gt;&lt;BR /&gt;Terminal mode (in trac default) ist activated.&lt;BR /&gt;PC boots up. Machine tunnel will be established. User logs in, user tunnel will be established WITHOUT disconnecting the machine tunnel ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this possible?&lt;BR /&gt;&lt;BR /&gt;Thanks and kind regards,&lt;/P&gt;&lt;P&gt;Simon.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2024 14:09:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/203103#M38212</guid>
      <dc:creator>SimonSchreiber9</dc:creator>
      <dc:date>2024-01-15T14:09:48Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Always-ON VPN ( Device &amp; User tunnel ) together with Identity Collector question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/203289#M38255</link>
      <description>&lt;P&gt;Not currently as it is operating as designed.&lt;BR /&gt;Please discuss your specific requirements with your Check Point SE.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jan 2024 06:11:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Windows-Always-ON-VPN-Device-amp-User-tunnel-together-with/m-p/203289#M38255</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-01-17T06:11:21Z</dc:date>
    </item>
  </channel>
</rss>

