<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Endpoint Security VPN Service only on company-owned devices in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68580#M11715</link>
    <description>This is the kind of thing Endpoint Compliance should solve.&lt;BR /&gt;A thread that discusses this is here: &lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/Restricting-access-to-corporate-devices/m-p/50250" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-Solutions/Restricting-access-to-corporate-devices/m-p/50250&lt;/A&gt;&lt;BR /&gt;You can also achieve something similar with SCV.&lt;BR /&gt;See: &lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/White-Paper-Check-Point-Compliance-Checking-with-Secure/m-p/57123" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-Solutions/White-Paper-Check-Point-Compliance-Checking-with-Secure/m-p/57123&lt;/A&gt;</description>
    <pubDate>Wed, 27 Nov 2019 05:36:09 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-11-27T05:36:09Z</dc:date>
    <item>
      <title>Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68554#M11714</link>
      <description>&lt;P&gt;Hi Fellow Checkmate Members&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone help me in achieving this for my company pretty please&lt;/P&gt;&lt;P&gt;Scenario:&lt;/P&gt;&lt;P&gt;We are using "Check Point Endpoint Security" as a remote access client for VPN users. It is working great with no problem. We are currently "Username+Password" as an authentication mechanism.&amp;nbsp; The problem we are having is the following:&lt;/P&gt;&lt;P&gt;Users can install the client on their own personal devices and connect to the VPN because they are allowed to. Now we want to limit Remove Access VPN connection ONLY using company-owned or company-assigned devices to the user. How do I go about achieving that? We are trying to prevent users from installing the Check Point Endpoint Security client to their personal devices, while not removing their Remote access VPN right on company-owned devices. Please help&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":pensive_face:"&gt;😔&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Tue, 26 Nov 2019 20:50:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68554#M11714</guid>
      <dc:creator>Pierre_Bienaime</dc:creator>
      <dc:date>2019-11-26T20:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68580#M11715</link>
      <description>This is the kind of thing Endpoint Compliance should solve.&lt;BR /&gt;A thread that discusses this is here: &lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/Restricting-access-to-corporate-devices/m-p/50250" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-Solutions/Restricting-access-to-corporate-devices/m-p/50250&lt;/A&gt;&lt;BR /&gt;You can also achieve something similar with SCV.&lt;BR /&gt;See: &lt;A href="https://community.checkpoint.com/t5/Remote-Access-Solutions/White-Paper-Check-Point-Compliance-Checking-with-Secure/m-p/57123" target="_blank"&gt;https://community.checkpoint.com/t5/Remote-Access-Solutions/White-Paper-Check-Point-Compliance-Checking-with-Secure/m-p/57123&lt;/A&gt;</description>
      <pubDate>Wed, 27 Nov 2019 05:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68580#M11715</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-11-27T05:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68627#M11716</link>
      <description>&lt;P&gt;R80.40 may yield a feature of interest...&lt;/P&gt;
&lt;H3 id="toc-hId--331083868"&gt;&lt;STRONG&gt;Remote Access VPN&lt;/STRONG&gt;&lt;/H3&gt;
&lt;P&gt;Use machine certificate to distinguish between corporate and non-corporate assets and to set a&amp;nbsp;policy&amp;nbsp; enforcing the use of corporate assets only. Enforcement can be pre-logon (device&amp;nbsp;authentication only) or post-logon (device and user authentication).&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 11:14:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68627#M11716</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2019-11-27T11:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68639#M11717</link>
      <description>&lt;P&gt;Change your authentication method so that it is Username+Password+Certificate and only agree to allow them to register a corporate device with the generated Certificate.&lt;/P&gt;&lt;P&gt;While it isn't impossible to export certificates off of a Windows box, it takes some work to get it done and is beyond the capabilities of most users.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2019 12:36:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68639#M11717</guid>
      <dc:creator>Tommy_Forrest</dc:creator>
      <dc:date>2019-11-27T12:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68690#M11718</link>
      <description>Hi Tommy ,&lt;BR /&gt;That is the route that I am currently exploring. I see that you have mentioned the Registration of a Corporate device. I am not familiar with how to process will go after enabling the use of "Username+Password+Certificate" on my perimeter Gateways. I do not have a sandbox environment to try, and I want a clear path as to what would follow to complete the process after enabling the setting. I am glad you have mentioned this process, and if I can get a follow up on that, it will be great, thank you in advance</description>
      <pubDate>Wed, 27 Nov 2019 16:37:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68690#M11718</guid>
      <dc:creator>Pierre_Bienaime</dc:creator>
      <dc:date>2019-11-27T16:37:33Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68691#M11719</link>
      <description>Thank you Chris,&lt;BR /&gt;This is the path that I am intending to take, but I want to know how to I go about the certificate registration process</description>
      <pubDate>Wed, 27 Nov 2019 16:40:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68691#M11719</guid>
      <dc:creator>Pierre_Bienaime</dc:creator>
      <dc:date>2019-11-27T16:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68692#M11720</link>
      <description>That is a very good approach PhoneBoy thank you. I will dive through the links to have a deeper understanding</description>
      <pubDate>Wed, 27 Nov 2019 16:41:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/68692#M11720</guid>
      <dc:creator>Pierre_Bienaime</dc:creator>
      <dc:date>2019-11-27T16:41:44Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Endpoint Security VPN Service only on company-owned devices</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/85389#M11721</link>
      <description>Hi Pierre&lt;BR /&gt;&lt;BR /&gt;Did you perhaps found a solution for this?&lt;BR /&gt;&lt;BR /&gt;Thanks in advance</description>
      <pubDate>Fri, 15 May 2020 14:35:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Check-Point-Endpoint-Security-VPN-Service-only-on-company-owned/m-p/85389#M11721</guid>
      <dc:creator>Di_Junior</dc:creator>
      <dc:date>2020-05-15T14:35:15Z</dc:date>
    </item>
  </channel>
</rss>

