<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Office Mode: Algorithm behind &amp;quot;Unique per machine&amp;quot; (MAC address for DHCP allocation) in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63450#M11917</link>
    <description>&lt;P&gt;Why not ask TAC on how to configure that ?&lt;/P&gt;</description>
    <pubDate>Mon, 23 Sep 2019 15:01:02 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2019-09-23T15:01:02Z</dc:date>
    <item>
      <title>Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63414#M11909</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;for special internal reasons we currently use "Calculate per user name", whit this the algorithm is clear:&lt;BR /&gt;Take the &amp;lt;username&amp;gt; make MD5 hash and the first 12 chars is the MAC used for DHCP requests.&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;User: sascha&lt;/LI&gt;&lt;LI&gt;MD5:&amp;nbsp;a624a33f3501afdc109103d1bdf80840&lt;/LI&gt;&lt;LI&gt;MAC: A6-24-A3-3F-35-01&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;This gives us the&amp;nbsp;opportunity to set static&amp;nbsp;DHCP entries&amp;nbsp;for every user.&lt;/P&gt;&lt;P&gt;Now we think about to give static VPN-IPs via DHCP to any connecting machine.&lt;BR /&gt;But we need to know the calculated MAC address before user connects.&lt;BR /&gt;Tried with 3 different machines and got those MAC addresses&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;5f:38:13:5c:cd:d9&lt;/LI&gt;&lt;LI&gt;9d:7b:a3:b6:d3:61&lt;/LI&gt;&lt;LI&gt;aa:7c:47:4a:f3:bc&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I have no Idea how those MACs where calculated.&lt;BR /&gt;Any hints from you?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and best regards,&lt;BR /&gt;Sascha&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 10:04:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63414#M11909</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-09-23T10:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63418#M11910</link>
      <description>&lt;P&gt;Usually, user connect either using LAN Ethernet Adapter and its MAC or WLAN Adapter and its MAC - so i do not understand your question...&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 10:14:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63418#M11910</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-23T10:14:53Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63422#M11911</link>
      <description>You are correct user connect with LAN or WIFI and its mac to local network.&lt;BR /&gt;Once VPN tunnel is established clients requests IP for Office mode.&lt;BR /&gt;Clinet uses therefore no known MAC (nither MAC of LAN nor WIFI adapter). It is a with CP magic calculated mac-address ...&lt;BR /&gt;</description>
      <pubDate>Mon, 23 Sep 2019 10:35:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63422#M11911</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-09-23T10:35:35Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63441#M11913</link>
      <description>&lt;P&gt;I don't know how it works for machine, so if it works the same, but for user you can use "vpn macutil".&lt;/P&gt;&lt;P&gt;# vpn macutil sascha&lt;BR /&gt;A6-24-A3-3F-35-01, "sascha"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 13:39:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63441#M11913</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2019-09-23T13:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63442#M11914</link>
      <description>&lt;P&gt;This is explained in&amp;nbsp;Mobile Access Administration Guide R80.30 p.87ff !&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 14:00:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63442#M11914</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-23T14:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63445#M11915</link>
      <description>&lt;P&gt;i know vpn macutil and the algorithm is described above: MD5 the usernam and take the first 12 chars.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to know the algorithm for the "unique per machine" part.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 14:18:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63445#M11915</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-09-23T14:18:02Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63446#M11916</link>
      <description>&lt;P&gt;Nope in Admin Guide is only described how to enable the magic, but not how the magic is done.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the end there is a unique MAC address for each connecting client.&lt;/P&gt;&lt;P&gt;I need to know the recipe and don't want to get surprised by any new client.&lt;/P&gt;&lt;P&gt;I need to configure any of our 800 clients in DHCP and IP pool is not allowed.&lt;/P&gt;&lt;P&gt;Works fine with username but in future we want to switch to machines (Same User should be able to login same time with different machines)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/BR&lt;/P&gt;&lt;P&gt;Sascha&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 14:25:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63446#M11916</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-09-23T14:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63450#M11917</link>
      <description>&lt;P&gt;Why not ask TAC on how to configure that ?&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 15:01:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63450#M11917</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-23T15:01:02Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63452#M11918</link>
      <description>&lt;P&gt;Mobile Access Administration Guide R80.30 p.87f :&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Automatically (Using DHCP) - &lt;/STRONG&gt;Specify the machine on which the DHCP server is installed. In addition, specify the virtual IP address to which the DHCP server replies. The DHCP server allocates addresses from the appropriate address range and relates to VPN as a DHCP relay agent. The virtual IP address must be routable to enable the DHCP send replies correctly.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;DHCP allocates IP addresses per MAC address. When VPN needs an Office Mode address, it creates a MAC address that represents the client and uses it in the address request. The&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;MAC address can be unique per machine or per user. If it is unique per machine, then VPN ignores the user identity. If different users work from the same Remote Access client they are allocated the same IP address.&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="Apple-converted-space"&gt;---&amp;gt; Looks like the machine MAC visible to the GW is used here...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Sep 2019 15:04:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63452#M11918</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-09-23T15:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63519#M11919</link>
      <description>Was hoping someone in community would know the answer.&lt;BR /&gt;Will turn to TAC...&lt;BR /&gt;Thanks so far for sharing your thoughts.&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Sep 2019 07:18:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/63519#M11919</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2019-09-24T07:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/85854#M11920</link>
      <description>&lt;P&gt;Hi, did you receive a response from TAC? I have a task similar to yours. I need to know the mac address calculation algorithm per machines. Please share the information.&lt;/P&gt;</description>
      <pubDate>Wed, 20 May 2020 09:26:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/85854#M11920</guid>
      <dc:creator>DexMorgan</dc:creator>
      <dc:date>2020-05-20T09:26:39Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86374#M11921</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;I'm trying to configure this "Unique per machine" but it changes UID every time machine restarts. So, it's more "Unique for boot".&lt;/P&gt;&lt;P&gt;Does yours do the same?&lt;/P&gt;&lt;P&gt;Do you know anything about it?&lt;/P&gt;&lt;P&gt;I'm using "Unique per user" and it's working and keeps same UID.&lt;/P&gt;&lt;P&gt;Best regards.&lt;/P&gt;&lt;P&gt;Nelson&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 16:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86374#M11921</guid>
      <dc:creator>NSerrao</dc:creator>
      <dc:date>2020-05-26T16:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86430#M11922</link>
      <description>&lt;P&gt;The reply for&amp;nbsp;C458715E&amp;nbsp; I got was:&lt;/P&gt;&lt;P&gt;"...Regarding the MAC location, the MAC location is:&lt;BR /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\CheckPoint\TRAC&lt;BR /&gt;The value will be taken from:&amp;nbsp;"fixed_om_mac_address"="0000"&lt;BR /&gt;Please let me know if any further clarification is required..."&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;and&lt;/P&gt;&lt;P&gt;"...Configuring the Registry this is our only option. Regarding IOS, according to sk61866 ;&lt;BR /&gt;Note: In OS X, this feature is not supported..."&lt;/P&gt;&lt;P&gt;They won't let us look into their cards &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I still use the good well reverse engineered "&lt;SPAN&gt;Calculate per user name&lt;/SPAN&gt;" -&amp;gt;&amp;nbsp;&lt;SPAN&gt;Take the &amp;lt;username&amp;gt;, make MD5 hash and the first 12 chars is the MAC used for DHCP requests.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Once we have same users with diferent devices we chosed the following workaround:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Remote-Access-Client (LDAP and RSA-SecurID) Users are written in lowercase&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Capsule VPN Users are authenticated with Certificate and we only enroll UPPERCASE Usernames in Certs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So I got 2 different MAC for same User and DHCP can provide different fixed IPs&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So only thing we have to monitor: No Normal VPN User should ever write uppercase Username, we do this with simple rule:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;SRC: &amp;lt;Range of Capsule IPs&amp;gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;DST: &amp;lt;Software deployment Server&amp;gt; &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Action: Reject &lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Log: Log+Alert(Mail)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;No Capsule Client is connecting to&amp;nbsp;Software deployment Server to the Port, so if some Capsule IP is connecting this must be a Normal Client and we got an alarm.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Same way vise versa we do for Remote-Access-Client-Range&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Hope this will help someone for a workaround, as CP is not really willing to help.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 06:31:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86430#M11922</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2020-05-27T06:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86487#M11923</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Thanks for the answer. Our task is to separate the domain work laptops that connect to the network via VPN, and other home machines that also connect via VPN. We thought to solve it through a dhcp server, but today I realized that this can be achieved with much less effort through Identity Awareness.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 13:51:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86487#M11923</guid>
      <dc:creator>DexMorgan</dc:creator>
      <dc:date>2020-05-27T13:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86492#M11924</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I don’t know about the UID, but with the option "Unique per machine" the MAC address generated by the CP did not change after a reboot. It changed, for example, if you reinstall the VPN client or rename the PC from which you are connecting.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 14:05:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86492#M11924</guid>
      <dc:creator>DexMorgan</dc:creator>
      <dc:date>2020-05-27T14:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86494#M11925</link>
      <description>&lt;P&gt;Now I'm curious.&lt;/P&gt;&lt;P&gt;How can you separate company and home PCs with&amp;nbsp;&lt;SPAN&gt;Identity Awareness.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 14:09:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/86494#M11925</guid>
      <dc:creator>Sascha_Bremshey</dc:creator>
      <dc:date>2020-05-27T14:09:28Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/88891#M11926</link>
      <description>&lt;P&gt;Create an Access Role, in the Machines option set the OU Computers or Domain Computers Security Group, apply the Access Role in the rule and set the extended rights for PCs covered by this Access Role. For all other PCs that are not in the domain, make a rule with truncated rights by default.&lt;/P&gt;&lt;P&gt;Or am I misunderstanding something? I am new to this profession, and I will be glad to advice. So far we have not implemented this scheme, but we are just going to do it.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Jun 2020 10:42:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/88891#M11926</guid>
      <dc:creator>DexMorgan</dc:creator>
      <dc:date>2020-06-17T10:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode: Algorithm behind "Unique per machine" (MAC address for DHCP allocation)</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/105207#M11927</link>
      <description>&lt;P&gt;May I ask you if you managed to separate AD and non AD connected PCs, I am very interested if it is actually possible to achieve separation using the method you propose?&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;Emil.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 08:13:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-Algorithm-behind-quot-Unique-per-machine-quot-MAC/m-p/105207#M11927</guid>
      <dc:creator>Emils_Zeliksons</dc:creator>
      <dc:date>2020-12-12T08:13:16Z</dc:date>
    </item>
  </channel>
</rss>

