<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Auto Sign-In for Harmony SASE in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/241143#M1114</link>
    <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Currently, Always On and the Killswitch are enabled.&lt;BR /&gt;Attached is a screenshot of the pertinent settings.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Current Config.png" style="width: 785px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29612iBDA22A53E000BCE0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Current Config.png" alt="Current Config.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;While these settings do auto-connect to the specified VPN, and the killswitch does function correctly, it seems to occur &lt;STRONG&gt;ONLY&lt;/STRONG&gt; if the current user is already signed into the application.&lt;BR /&gt;Because we have an auto sign-out of the application set for 12 hours, when our staff begin work the next day, they are required to sign into the app again.&lt;BR /&gt;The issue is that before they manually click Sign In, they have free range access to the internet.&lt;BR /&gt;&lt;BR /&gt;We are thinking this can be circumvented if we increase the amount of time before the automatic sign out, but ultimately we would like our staff to authenticate themselves (Azure + DUO 2FA) each time they attempt to connect to the VPN.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Feb 2025 17:02:29 GMT</pubDate>
    <dc:creator>thelmer</dc:creator>
    <dc:date>2025-02-13T17:02:29Z</dc:date>
    <item>
      <title>Auto Sign-In for Harmony SASE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/240956#M1111</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We are inquiring on the ability to force users to sign into the Harmony SASE application once they are logged into Windows.&lt;BR /&gt;With our last VPN solution, we had the capabilities to lock down our users' ability to do anything other than authenticate themselves and connect to the VPN.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As of right now, our users are able to access the internet BEFORE connecting to the SASE gateway due to them having to click "Sign-In to Private Access" to start the process.&lt;BR /&gt;&lt;BR /&gt;We have "Always On VPN" enabled but that only seems to function AFTER they are signed in, during the allotted timeframe we have set in the SASE User Profile (12 hours).&lt;/P&gt;&lt;P&gt;We currently use Harmony Browse as well which does allow us to enforce threat prevention and DLP policies while our users are off the VPN, but we do not see a way to lock down sites before users get connected to the VPN.&lt;BR /&gt;&lt;BR /&gt;Please advise.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 20:44:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/240956#M1111</guid>
      <dc:creator>thelmer</dc:creator>
      <dc:date>2025-02-11T20:44:12Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Sign-In for Harmony SASE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/240963#M1112</link>
      <description>&lt;P&gt;In the relevant User Profile, what settings are set under Agent Configuration &amp;gt; General Settings?&lt;/P&gt;
&lt;P&gt;Also, did you use the Kill Switch with Always-On?&lt;BR /&gt;This seems like it'd be required for your desired use case.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29591iD19F777C466DA1F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 23:26:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/240963#M1112</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-11T23:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Sign-In for Harmony SASE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/240964#M1113</link>
      <description>&lt;P&gt;I believe what Phoneboy gave you is indeed what you need to do. P81 support gave me the same when my colleague and I did POC for the customer last year for Harmony Sase. Not sure if there are any additional settings now, but thats what fixed it for us.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2025 00:09:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/240964#M1113</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-12T00:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Sign-In for Harmony SASE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/241143#M1114</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Currently, Always On and the Killswitch are enabled.&lt;BR /&gt;Attached is a screenshot of the pertinent settings.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Current Config.png" style="width: 785px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29612iBDA22A53E000BCE0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Current Config.png" alt="Current Config.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;While these settings do auto-connect to the specified VPN, and the killswitch does function correctly, it seems to occur &lt;STRONG&gt;ONLY&lt;/STRONG&gt; if the current user is already signed into the application.&lt;BR /&gt;Because we have an auto sign-out of the application set for 12 hours, when our staff begin work the next day, they are required to sign into the app again.&lt;BR /&gt;The issue is that before they manually click Sign In, they have free range access to the internet.&lt;BR /&gt;&lt;BR /&gt;We are thinking this can be circumvented if we increase the amount of time before the automatic sign out, but ultimately we would like our staff to authenticate themselves (Azure + DUO 2FA) each time they attempt to connect to the VPN.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 17:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/241143#M1114</guid>
      <dc:creator>thelmer</dc:creator>
      <dc:date>2025-02-13T17:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Sign-In for Harmony SASE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/241144#M1115</link>
      <description>&lt;P&gt;In that case, I would open case with P81 support. Not sure how it works these days,as few months ago when I called TAC, they asked me to simply email &lt;A href="mailto:support@perimeter81.com" target="_blank"&gt;support@perimeter81.com &lt;/A&gt;and they then gave me a reference number, though it was only via email. I could not find phone number to call them anywhere and TAC did not have it either.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2025 17:15:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/241144#M1115</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-13T17:15:07Z</dc:date>
    </item>
    <item>
      <title>Re: Auto Sign-In for Harmony SASE</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/241151#M1116</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114740"&gt;@thelmer&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One other thing I forgot to say, if you do end up emailing them, they will eventually ask for access to the portal, so you may be required to provide that.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 00:14:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Auto-Sign-In-for-Harmony-SASE/m-p/241151#M1116</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-14T00:14:28Z</dc:date>
    </item>
  </channel>
</rss>

