<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict users to disconnect from remote access VPN client in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253648#M10698</link>
    <description>&lt;P&gt;Screenshot looks right, SMS version is 81.20 take 105.&lt;/P&gt;&lt;P&gt;This is a SmartDashboard for configuring desktop policy, screenshot below shows where you open it&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jul 2025 07:01:10 GMT</pubDate>
    <dc:creator>KirillMuravyev</dc:creator>
    <dc:date>2025-07-22T07:01:10Z</dc:date>
    <item>
      <title>Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253412#M10668</link>
      <description>&lt;P&gt;Hello mates!&lt;/P&gt;&lt;P&gt;We are looking for a solution for remote users to inspect all their Internet traffic while out of a corporate network.&lt;/P&gt;&lt;P&gt;Enabling fulltunnel makes all traffic to be routed through gateway for inspection, but users still able to click "disconnect" in the client.&lt;/P&gt;&lt;P&gt;I know about machine certificate only auth, but we cannot use it as less secure option.&lt;/P&gt;&lt;P&gt;Also, ATM looks not good as well.&lt;/P&gt;&lt;P&gt;I was hoping this can solve my problem:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#Desktop_Security" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#Desktop_Security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;section "Location-Based Policies". But I didn't get from the documentation exactly how to set this up, where to configure&amp;nbsp;"connected" and "disconnected" policy.&lt;/P&gt;&lt;P&gt;So ideally the idea is to restrict Internet access for users until they are connected to VPN.&lt;/P&gt;&lt;P&gt;has anyone tried this setup?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 08:28:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253412#M10668</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-18T08:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253536#M10676</link>
      <description>&lt;P&gt;You need to create a rule in the disconnected policy which blocks web access.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 08:36:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253536#M10676</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T08:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253542#M10678</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?Highlight=Location-Based%20Policies" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?Highlight=Location-Based%20Policies&lt;/A&gt;&amp;nbsp;for all necessary steps!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 09:40:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253542#M10678</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-21T09:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253548#M10679</link>
      <description>&lt;P&gt;Hi, can you share where exactly this disconnected policy exists and how to confgiure it?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:06:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253548#M10679</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-21T10:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253549#M10680</link>
      <description>&lt;P&gt;Hi, I know this doc as I shared it in initial message.&lt;/P&gt;&lt;P&gt;This page in guide regarding location-based policy does not specify where exactly should I configure connected/disconnected policy, this is not obvious.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:06:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253549#M10680</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-21T10:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253553#M10681</link>
      <description>&lt;P&gt;In that very document, it says (bold markings are mine):&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;The&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt;&amp;nbsp;defines &lt;STRONG&gt;the Desktop&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_secpol variable"&gt;Security Policy&lt;/SPAN&gt;&amp;nbsp;in the Desktop&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_rule variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#" data-mc-state="closed" data-aria-describedby="b39c1b06-b619-455f-8e00-6abaebc19a60" target="_blank"&gt;Rule Base&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;in&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#" data-mc-state="closed" data-aria-describedby="a2df30bd-857c-4a02-b129-9e97ce64e03b" target="_blank"&gt;SmartDashboard&lt;/A&gt;&lt;/SPAN&gt;.&lt;/STRONG&gt; You can assign rules to specified user groups or to all users.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;SmartDashboard, Desktop Policy, it is documented.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253553#M10681</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T10:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253554#M10682</link>
      <description>&lt;P&gt;Also, in the same document:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3&gt;Configuring Desktop Security&lt;/H3&gt;
&lt;P class="Procedure_Heading"&gt;To enable the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to be a Policy Server for Desktop Security:&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gate variable"&gt;Gateways &amp;amp; Servers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and double-click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window opens and shows the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;General Properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;On the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Network Security&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ipsecvpn variable"&gt;IPsec VPN&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Policy Server&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;OK.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Publish the changes.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="Procedure_Heading"&gt;To activate the Desktop Security policy:&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_secpols variable"&gt;Security Policies&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and open the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Manage Policies&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window (CTRL + T).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;Click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;All&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;icon.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;Select the policy to edit and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Edit&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;The policy window opens.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Desktop Security&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="5"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;OK.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="6"&gt;
&lt;P&gt;Install policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="Procedure_Heading"&gt;To configure the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_deskpol variable"&gt;Desktop Policy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rules:&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_secpols variable"&gt;Security Policies&lt;/SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and from the navigation tree, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_access variable"&gt;Access Control&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; Desktop&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Open&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_deskpol variable"&gt;Desktop Policy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;opens and shows the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Desktop&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;Configure the inbound rules: Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Rules&amp;gt;Add Rule&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to add rules to the policy.&lt;/P&gt;
&lt;P&gt;In inbound rules, the client computer (the desktop) is the destination. Select user groups to which the rule applies.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Configure the outbound rules. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Rules&amp;gt;Add Rule&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to add rules to the policy.&lt;/P&gt;
&lt;P&gt;In outbound rules, the client computer (the desktop) is the source. Select user groups to which the rule applies.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="5"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Save&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and close&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="6"&gt;
&lt;P&gt;Install the policy.&lt;/P&gt;
&lt;P&gt;Make sure that you install the Advanced Security policy on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and the Desktop Security policy on your Policy Servers.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:18:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253554#M10682</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T10:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253555#M10683</link>
      <description>&lt;P&gt;THanks, but I can read the guide as well and I followed all the steps.&lt;/P&gt;&lt;P&gt;Guide says that we have&amp;nbsp;&lt;STRONG&gt;Connected policy&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Disconnected policy.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It is not clear where you configure those 2 different policies?&lt;/P&gt;&lt;P&gt;Below is a screenshot from SmartDashboard, where should I configure&amp;nbsp;&lt;STRONG&gt;Connected policy&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Disconnected policy?&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:41:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253555#M10683</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-21T10:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253573#M10685</link>
      <description>&lt;P&gt;This screenshot does not look right. Which version are you using? The GUI looks like a very old version&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 12:44:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253573#M10685</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T12:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253626#M10695</link>
      <description>&lt;P&gt;You don't really configure a specific "disconnected" policy, but it changes the relevant "encrypt" rules to allow.&lt;BR /&gt;See here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Location-Based-Policies.htm?Highlight=disconnected" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Location-Based-Policies.htm?Highlight=disconnected&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 21:25:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253626#M10695</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-21T21:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253648#M10698</link>
      <description>&lt;P&gt;Screenshot looks right, SMS version is 81.20 take 105.&lt;/P&gt;&lt;P&gt;This is a SmartDashboard for configuring desktop policy, screenshot below shows where you open it&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 07:01:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253648#M10698</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-22T07:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253649#M10699</link>
      <description>&lt;P&gt;Again, I saw this doc and followed all the steps. If it was clear from the guide how it works I wouldn't create this topic.&lt;/P&gt;&lt;P&gt;The goal is to restrict user's Internet access while not connected to VPN. I was hoping to configure&amp;nbsp;&lt;STRONG&gt;connected/disconnected policy&amp;nbsp;&lt;/STRONG&gt;like it is mentioned in the guide, but it is not clear exactly how.&lt;/P&gt;&lt;P&gt;The guide says:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Connected Policy&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Enforced when:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;VPN is connected.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;VPN is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;disconnected&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and Location Awareness determines that the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;endpoint&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;computer is on an internal network. The Connected Policy is not enforced "as is" but modified according to the feature's mode (the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;disconnected&lt;/SPAN&gt;_in_house_fw_policy_mode&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;property).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Disconnected&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Policy&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Enforced when the VPN is not connected and Location Awareness sees that the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;endpoint&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;computer is not on an internal network.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So, it says that connected policy will be inforced also when VPN is disconnected but modified according to property&lt;/P&gt;&lt;P&gt;Later guide says regarding this property (&lt;SPAN class=""&gt;disconnected&lt;/SPAN&gt;_in_house_fw_policy_mode):&lt;/P&gt;&lt;P&gt;Possible values are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;encrypt_to_allow - Connected policy will be enforced, based on last connected user. Encrypt rules will be transformed to Allow rules&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;(default)&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;any_any_allow - "Any - Any - Allow" will be enforced.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, it is not clear what does it mean "based on last connected user" and&amp;nbsp;"Encrypt rules will be transformed to Allow rules", what user we talking about, what encrypt rules we talking about?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All in all not clear what this feature do exactly&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 07:40:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253649#M10699</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-22T07:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253669#M10701</link>
      <description>&lt;P&gt;As this is a legacy feature very seldom enabled and used, i would suggest to open SR# with CP TAC to get the procedure to accomplish your goal !&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 11:14:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253669#M10701</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-22T11:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253687#M10703</link>
      <description>&lt;P&gt;On way would be if you have IA enabled to set up access role for this. I attached a screenshot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 14:53:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253687#M10703</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-22T14:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253734#M10704</link>
      <description>&lt;P&gt;What is IA?&lt;/P&gt;&lt;P&gt;Can you elaborate please how access role in access rule can help accomplish the goal?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 07:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253734#M10704</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-23T07:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253763#M10705</link>
      <description>&lt;P&gt;Identity awareness. I will take video later and upload.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 11:15:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253763#M10705</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T11:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253773#M10711</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/81246"&gt;@KirillMuravyev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached. Btw, once you have access role configured, you can use it in policy rule to restrict access.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 12:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253773#M10711</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T12:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253795#M10713</link>
      <description>&lt;P&gt;Thanks for video, I do have IA enabled and I understand how to configure the access role.&lt;/P&gt;&lt;P&gt;The question was how this setup will help me restrict remote user's Internet access while not connected to VPN ?&lt;/P&gt;&lt;P&gt;The goal is to force people connect to VPN while they are remote, always-connect feature is on but it still allowes user to click "disconnect" button&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:24:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253795#M10713</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-23T14:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253797#M10714</link>
      <description>&lt;P&gt;One way it can help is to add type of clients in access role and then use that role to allow or restrict access.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:35:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253797#M10714</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T14:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253804#M10716</link>
      <description>&lt;P&gt;So how to set this policy work only for "disconnected" clients?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 15:06:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253804#M10716</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-23T15:06:38Z</dc:date>
    </item>
  </channel>
</rss>

