<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Moving from workstations to Laptop on Domain in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Moving-from-workstations-to-Laptop-on-Domain/m-p/93196#M10056</link>
    <description>&lt;P&gt;SmartEndpoint isn't required here at all, but enabling Identity Awareness will definitely be a good idea.&lt;BR /&gt;You could actually create two different Access Roles here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;One that is just specifies the relevant networks/hosts (optionally tie it to specific AD groups)&lt;/LI&gt;
&lt;LI&gt;Another that is Remote Access users&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-08-03 at 12.22.01 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7461i6FFDBB11A5382D03/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-08-03 at 12.22.01 PM.png" alt="Screen Shot 2020-08-03 at 12.22.01 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Make sure Remote Access is a valid identity source in the gateway/cluster object:  &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-08-03 at 12.23.21 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7462iD968864874C34842/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-08-03 at 12.23.21 PM.png" alt="Screen Shot 2020-08-03 at 12.23.21 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Note the reason I am suggesting an Access Role for the networks versus just using the network objects is because you generally can't mix regular network objects and access roles in the source/destination field of a rule.&lt;BR /&gt;Believe this limitation is removed in R80.40.&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2020 19:26:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-08-03T19:26:05Z</dc:date>
    <item>
      <title>Moving from workstations to Laptop on Domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Moving-from-workstations-to-Laptop-on-Domain/m-p/93188#M10055</link>
      <description>&lt;P&gt;We have currently workstations in office. For remote work we use Laptop as a tool to do VPN and RDP to workstations. We want Laptops to be on domain rather than using to it to do RDP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;now to have this feature working how should be the rules configured? currently to access servers rules are configured IP based. Now when Laptops will move to domain everytime user will do VPN it will have a new officemode IP. We dont have identity awareness blade enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also have doubt that do we need additional server other than management server for Smart Endpoint?&lt;/P&gt;&lt;P&gt;Please help me&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 17:51:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Moving-from-workstations-to-Laptop-on-Domain/m-p/93188#M10055</guid>
      <dc:creator>smohammed</dc:creator>
      <dc:date>2020-08-03T17:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: Moving from workstations to Laptop on Domain</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Moving-from-workstations-to-Laptop-on-Domain/m-p/93196#M10056</link>
      <description>&lt;P&gt;SmartEndpoint isn't required here at all, but enabling Identity Awareness will definitely be a good idea.&lt;BR /&gt;You could actually create two different Access Roles here:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;One that is just specifies the relevant networks/hosts (optionally tie it to specific AD groups)&lt;/LI&gt;
&lt;LI&gt;Another that is Remote Access users&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-08-03 at 12.22.01 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7461i6FFDBB11A5382D03/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-08-03 at 12.22.01 PM.png" alt="Screen Shot 2020-08-03 at 12.22.01 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Make sure Remote Access is a valid identity source in the gateway/cluster object:  &lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2020-08-03 at 12.23.21 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/7462iD968864874C34842/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screen Shot 2020-08-03 at 12.23.21 PM.png" alt="Screen Shot 2020-08-03 at 12.23.21 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Note the reason I am suggesting an Access Role for the networks versus just using the network objects is because you generally can't mix regular network objects and access roles in the source/destination field of a rule.&lt;BR /&gt;Believe this limitation is removed in R80.40.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 19:26:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Moving-from-workstations-to-Laptop-on-Domain/m-p/93196#M10056</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-08-03T19:26:05Z</dc:date>
    </item>
  </channel>
</rss>

