<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN Identity Awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/50355#M12410</link>
    <description>&lt;P&gt;The gateway that I am connecting to does not have the AD server network in its encryption domain, and both gateways are part of the same RemoteAccess Community.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 01:31:43 GMT</pubDate>
    <dc:creator>Christopher_To</dc:creator>
    <dc:date>2019-04-10T01:31:43Z</dc:date>
    <item>
      <title>VPN Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/49835#M12406</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm trying to setup VPN for a remote site utilizing Identity Awareness.&amp;nbsp; The remote site doesn't have any local domain controllers, but it is connected via site2site tunnel with another site that has the domain controllers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When trying to connect via the End Point client the status hangs at 47% and then fails.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-04-04_1339.png" style="width: 353px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/646i62905AB52598DF4D/image-dimensions/353x233?v=v2" width="353" height="233" role="button" title="2019-04-04_1339.png" alt="2019-04-04_1339.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Here is the gateway's AD Query Status&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-04-04_1349.png" style="width: 563px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/647iE668983C671032FA/image-dimensions/563x126?v=v2" width="563" height="126" role="button" title="2019-04-04_1349.png" alt="2019-04-04_1349.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can anyone assist?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2019 17:58:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/49835#M12406</guid>
      <dc:creator>Christopher_To</dc:creator>
      <dc:date>2019-04-04T17:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/49854#M12407</link>
      <description>Hi, a few questions here:&lt;BR /&gt;&lt;BR /&gt;What version of gateway(s) involved here?&lt;BR /&gt;What version/flavor of VPN client?&lt;BR /&gt;Does the client encryption domain include the AD servers on the remote site?&lt;BR /&gt;Can the same client connect to other gateways ok?</description>
      <pubDate>Thu, 04 Apr 2019 23:07:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/49854#M12407</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-04T23:07:12Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/49929#M12408</link>
      <description>&lt;P&gt;&lt;SPAN&gt;What version of gateway(s) involved here?&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;Both gateways are on R77.30&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;What version/flavor of VPN client?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2019-04-05_1034.png" style="width: 373px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/663iA55E1B61EA3838D0/image-dimensions/373x274?v=v2" width="373" height="274" role="button" title="2019-04-05_1034.png" alt="2019-04-05_1034.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Does the client encryption domain include the AD servers on the remote site?&amp;nbsp;&lt;STRONG&gt;So the AD servers sit on a 10.1.1.x/24 network.&amp;nbsp; That network is defined in the encryption domain of the other gateway but not the encryption domain of the gateway I'm trying to connect to.&amp;nbsp; Do I need to add that network to the encryption domain of the gateway I am connecting to?&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Can the same client connect to other gateways ok?&amp;nbsp;&lt;STRONG&gt;Yes, I can connect to other gateways with the same client.&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2019 14:45:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/49929#M12408</guid>
      <dc:creator>Christopher_To</dc:creator>
      <dc:date>2019-04-05T14:45:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/50202#M12409</link>
      <description>The gateway you're connecting to shouldn't have the remote AD server's network as part of it's encryption domain.&lt;BR /&gt;That said, I think both gateways need to be part of the same RemoteAccess community.&lt;BR /&gt;Is that the case here or not?</description>
      <pubDate>Mon, 08 Apr 2019 20:11:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/50202#M12409</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-04-08T20:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/50355#M12410</link>
      <description>&lt;P&gt;The gateway that I am connecting to does not have the AD server network in its encryption domain, and both gateways are part of the same RemoteAccess Community.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 01:31:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-Identity-Awareness/m-p/50355#M12410</guid>
      <dc:creator>Christopher_To</dc:creator>
      <dc:date>2019-04-10T01:31:43Z</dc:date>
    </item>
  </channel>
</rss>

