<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict users to disconnect from remote access VPN client in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/254857#M10744</link>
    <description>&lt;P&gt;We have found a solution with support.&lt;/P&gt;&lt;P&gt;There is no way to disable "disconnect" button in the client for users, but you can restrict user's network access while they are disconnected from the VPN.&lt;/P&gt;&lt;P&gt;In order to to that you have to enable desktop security (policy server blade at SG properties). Then you have to configure outbound policies in Smartdashboard.&lt;/P&gt;&lt;P&gt;Important now, policies that you configure for "All users" are being downloaded by the VPN client initially and applies by default when client is disconnected. Any policy that is configured for specific user or ldap group will apply when user is connected to VPN.&lt;/P&gt;&lt;P&gt;So, you configure "All users" policy that restrics Internet access and allows only Public VPN gateway IP (so users can connect to VPN), and allow any any for specific ldap group (I just put group with all VPN users).&lt;/P&gt;&lt;P&gt;Also, look here&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#Desktop_Security" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#Desktop_Security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;if you configure network location awareness, so when client considers itself inside corporate network access would be allow any any&lt;/P&gt;</description>
    <pubDate>Mon, 11 Aug 2025 07:50:15 GMT</pubDate>
    <dc:creator>KirillMuravyev</dc:creator>
    <dc:date>2025-08-11T07:50:15Z</dc:date>
    <item>
      <title>Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253412#M10668</link>
      <description>&lt;P&gt;Hello mates!&lt;/P&gt;&lt;P&gt;We are looking for a solution for remote users to inspect all their Internet traffic while out of a corporate network.&lt;/P&gt;&lt;P&gt;Enabling fulltunnel makes all traffic to be routed through gateway for inspection, but users still able to click "disconnect" in the client.&lt;/P&gt;&lt;P&gt;I know about machine certificate only auth, but we cannot use it as less secure option.&lt;/P&gt;&lt;P&gt;Also, ATM looks not good as well.&lt;/P&gt;&lt;P&gt;I was hoping this can solve my problem:&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#Desktop_Security" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#Desktop_Security&lt;/A&gt;&lt;/P&gt;&lt;P&gt;section "Location-Based Policies". But I didn't get from the documentation exactly how to set this up, where to configure&amp;nbsp;"connected" and "disconnected" policy.&lt;/P&gt;&lt;P&gt;So ideally the idea is to restrict Internet access for users until they are connected to VPN.&lt;/P&gt;&lt;P&gt;has anyone tried this setup?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jul 2025 08:28:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253412#M10668</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-18T08:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253536#M10676</link>
      <description>&lt;P&gt;You need to create a rule in the disconnected policy which blocks web access.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 08:36:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253536#M10676</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T08:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253542#M10678</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?Highlight=Location-Based%20Policies" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?Highlight=Location-Based%20Policies&lt;/A&gt;&amp;nbsp;for all necessary steps!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 09:40:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253542#M10678</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-21T09:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253548#M10679</link>
      <description>&lt;P&gt;Hi, can you share where exactly this disconnected policy exists and how to confgiure it?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:06:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253548#M10679</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-21T10:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253549#M10680</link>
      <description>&lt;P&gt;Hi, I know this doc as I shared it in initial message.&lt;/P&gt;&lt;P&gt;This page in guide regarding location-based policy does not specify where exactly should I configure connected/disconnected policy, this is not obvious.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:06:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253549#M10680</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-21T10:06:06Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253553#M10681</link>
      <description>&lt;P&gt;In that very document, it says (bold markings are mine):&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;The&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt;&amp;nbsp;defines &lt;STRONG&gt;the Desktop&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_secpol variable"&gt;Security Policy&lt;/SPAN&gt;&amp;nbsp;in the Desktop&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_rule variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#" data-mc-state="closed" data-aria-describedby="b39c1b06-b619-455f-8e00-6abaebc19a60" target="_blank"&gt;Rule Base&lt;/A&gt;&amp;nbsp;&lt;/SPAN&gt;in&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_RemoteAccessVPN_AdminGuide/Content/Topics-VPNRG/Desktop-Security.htm?tocpath=Desktop%20Security%7C_____0#" data-mc-state="closed" data-aria-describedby="a2df30bd-857c-4a02-b129-9e97ce64e03b" target="_blank"&gt;SmartDashboard&lt;/A&gt;&lt;/SPAN&gt;.&lt;/STRONG&gt; You can assign rules to specified user groups or to all users.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;SmartDashboard, Desktop Policy, it is documented.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:16:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253553#M10681</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T10:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253554#M10682</link>
      <description>&lt;P&gt;Also, in the same document:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;H3&gt;Configuring Desktop Security&lt;/H3&gt;
&lt;P class="Procedure_Heading"&gt;To enable the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to be a Policy Server for Desktop Security:&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_gate variable"&gt;Gateways &amp;amp; Servers&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and double-click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window opens and shows the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;General Properties&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;page.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;On the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Network Security&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab, select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ipsecvpn variable"&gt;IPsec VPN&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Policy Server&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;OK.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Publish the changes.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="Procedure_Heading"&gt;To activate the Desktop Security policy:&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_secpols variable"&gt;Security Policies&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and open the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Manage Policies&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;window (CTRL + T).&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;Click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;All&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;icon.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;Select the policy to edit and click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Edit&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;The policy window opens.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Desktop Security&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="5"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;OK.&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="6"&gt;
&lt;P&gt;Install policy.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P class="Procedure_Heading"&gt;To configure the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_deskpol variable"&gt;Desktop Policy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;rules:&lt;/P&gt;
&lt;OL&gt;
&lt;LI value="1"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_Other.tp_secpols variable"&gt;Security Policies&lt;/SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and from the navigation tree, click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_access variable"&gt;Access Control&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&amp;gt; Desktop&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="2"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Open&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_deskpol variable"&gt;Desktop Policy&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;in&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;opens and shows the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Desktop&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;tab.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="3"&gt;
&lt;P&gt;Configure the inbound rules: Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Rules&amp;gt;Add Rule&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to add rules to the policy.&lt;/P&gt;
&lt;P&gt;In inbound rules, the client computer (the desktop) is the destination. Select user groups to which the rule applies.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="4"&gt;
&lt;P&gt;Configure the outbound rules. Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Rules&amp;gt;Add Rule&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;to add rules to the policy.&lt;/P&gt;
&lt;P&gt;In outbound rules, the client computer (the desktop) is the source. Select user groups to which the rule applies.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="5"&gt;
&lt;P&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="Menu_Options"&gt;Save&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and close&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_dash variable"&gt;SmartDashboard&lt;/SPAN&gt;.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI value="6"&gt;
&lt;P&gt;Install the policy.&lt;/P&gt;
&lt;P&gt;Make sure that you install the Advanced Security policy on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and the Desktop Security policy on your Policy Servers.&lt;/P&gt;
&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:18:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253554#M10682</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T10:18:24Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253555#M10683</link>
      <description>&lt;P&gt;THanks, but I can read the guide as well and I followed all the steps.&lt;/P&gt;&lt;P&gt;Guide says that we have&amp;nbsp;&lt;STRONG&gt;Connected policy&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Disconnected policy.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It is not clear where you configure those 2 different policies?&lt;/P&gt;&lt;P&gt;Below is a screenshot from SmartDashboard, where should I configure&amp;nbsp;&lt;STRONG&gt;Connected policy&amp;nbsp;&lt;/STRONG&gt;and&amp;nbsp;&lt;STRONG&gt;Disconnected policy?&lt;/STRONG&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 10:41:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253555#M10683</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-21T10:41:47Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253573#M10685</link>
      <description>&lt;P&gt;This screenshot does not look right. Which version are you using? The GUI looks like a very old version&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 12:44:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253573#M10685</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2025-07-21T12:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253626#M10695</link>
      <description>&lt;P&gt;You don't really configure a specific "disconnected" policy, but it changes the relevant "encrypt" rules to allow.&lt;BR /&gt;See here:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Location-Based-Policies.htm?Highlight=disconnected" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/Location-Based-Policies.htm?Highlight=disconnected&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2025 21:25:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253626#M10695</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-07-21T21:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253648#M10698</link>
      <description>&lt;P&gt;Screenshot looks right, SMS version is 81.20 take 105.&lt;/P&gt;&lt;P&gt;This is a SmartDashboard for configuring desktop policy, screenshot below shows where you open it&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 07:01:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253648#M10698</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-22T07:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253649#M10699</link>
      <description>&lt;P&gt;Again, I saw this doc and followed all the steps. If it was clear from the guide how it works I wouldn't create this topic.&lt;/P&gt;&lt;P&gt;The goal is to restrict user's Internet access while not connected to VPN. I was hoping to configure&amp;nbsp;&lt;STRONG&gt;connected/disconnected policy&amp;nbsp;&lt;/STRONG&gt;like it is mentioned in the guide, but it is not clear exactly how.&lt;/P&gt;&lt;P&gt;The guide says:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;Connected Policy&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Enforced when:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;VPN is connected.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;VPN is&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;disconnected&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;and Location Awareness determines that the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;endpoint&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;computer is on an internal network. The Connected Policy is not enforced "as is" but modified according to the feature's mode (the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;disconnected&lt;/SPAN&gt;_in_house_fw_policy_mode&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;property).&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;Disconnected&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Policy&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- Enforced when the VPN is not connected and Location Awareness sees that the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;endpoint&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;computer is not on an internal network.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;So, it says that connected policy will be inforced also when VPN is disconnected but modified according to property&lt;/P&gt;&lt;P&gt;Later guide says regarding this property (&lt;SPAN class=""&gt;disconnected&lt;/SPAN&gt;_in_house_fw_policy_mode):&lt;/P&gt;&lt;P&gt;Possible values are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;encrypt_to_allow - Connected policy will be enforced, based on last connected user. Encrypt rules will be transformed to Allow rules&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;(default)&lt;/STRONG&gt;.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;any_any_allow - "Any - Any - Allow" will be enforced.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, it is not clear what does it mean "based on last connected user" and&amp;nbsp;"Encrypt rules will be transformed to Allow rules", what user we talking about, what encrypt rules we talking about?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All in all not clear what this feature do exactly&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 07:40:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253649#M10699</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-22T07:40:10Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253669#M10701</link>
      <description>&lt;P&gt;As this is a legacy feature very seldom enabled and used, i would suggest to open SR# with CP TAC to get the procedure to accomplish your goal !&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 11:14:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253669#M10701</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-07-22T11:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253687#M10703</link>
      <description>&lt;P&gt;On way would be if you have IA enabled to set up access role for this. I attached a screenshot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2025 14:53:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253687#M10703</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-22T14:53:38Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253734#M10704</link>
      <description>&lt;P&gt;What is IA?&lt;/P&gt;&lt;P&gt;Can you elaborate please how access role in access rule can help accomplish the goal?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 07:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253734#M10704</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-23T07:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253763#M10705</link>
      <description>&lt;P&gt;Identity awareness. I will take video later and upload.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 11:15:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253763#M10705</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T11:15:43Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253773#M10711</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/81246"&gt;@KirillMuravyev&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Attached. Btw, once you have access role configured, you can use it in policy rule to restrict access.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 12:27:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253773#M10711</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T12:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253795#M10713</link>
      <description>&lt;P&gt;Thanks for video, I do have IA enabled and I understand how to configure the access role.&lt;/P&gt;&lt;P&gt;The question was how this setup will help me restrict remote user's Internet access while not connected to VPN ?&lt;/P&gt;&lt;P&gt;The goal is to force people connect to VPN while they are remote, always-connect feature is on but it still allowes user to click "disconnect" button&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:24:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253795#M10713</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-23T14:24:29Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253797#M10714</link>
      <description>&lt;P&gt;One way it can help is to add type of clients in access role and then use that role to allow or restrict access.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 14:35:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253797#M10714</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-07-23T14:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict users to disconnect from remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253804#M10716</link>
      <description>&lt;P&gt;So how to set this policy work only for "disconnected" clients?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jul 2025 15:06:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Restrict-users-to-disconnect-from-remote-access-VPN-client/m-p/253804#M10716</guid>
      <dc:creator>KirillMuravyev</dc:creator>
      <dc:date>2025-07-23T15:06:38Z</dc:date>
    </item>
  </channel>
</rss>

