<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Machine and User tunnel at the same time in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-and-User-tunnel-at-the-same-time/m-p/276768#M14494</link>
    <description>&lt;P&gt;Hello all,&lt;BR /&gt;I've successfully created the machine tunnel before user login.&lt;BR /&gt;We use a seperate Gateway with an own site and want now to establish the machine tunnel permanent beside the user tunnel (please, don't ask me why).&lt;BR /&gt;I configuered the trac.defaults (machine_tunnel_after_logon STRING true GLOBAL 1), but there's the following problem:&lt;BR /&gt;The machine tunnel works, but the client isn't able&amp;nbsp; to connect the user tunnel. I tried to activate the option "always connected" for the machine site, but it's gray.&lt;BR /&gt;Connectivity Settings&amp;nbsp;of&amp;nbsp;Global Properties&amp;gt;&amp;nbsp;Remote Access&amp;gt;&amp;nbsp;&lt;SPAN class=""&gt;Endpoint&lt;/SPAN&gt;&amp;nbsp;Connect are Manual.&lt;BR /&gt;So I have the following questions:&lt;BR /&gt;- Is it possible to activate always connected for the secondary site (machine) and leave the primary site (user) at manual?&lt;BR /&gt;- Is it necessary to change the global properties?&lt;BR /&gt;- What kind of effects has the change of the global properties from Manual to Configured on endpoint clients?&lt;BR /&gt;Thank you for any comments&lt;/P&gt;</description>
    <pubDate>Mon, 11 May 2026 11:06:52 GMT</pubDate>
    <dc:creator>Sokrates</dc:creator>
    <dc:date>2026-05-11T11:06:52Z</dc:date>
    <item>
      <title>Machine and User tunnel at the same time</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-and-User-tunnel-at-the-same-time/m-p/276768#M14494</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;I've successfully created the machine tunnel before user login.&lt;BR /&gt;We use a seperate Gateway with an own site and want now to establish the machine tunnel permanent beside the user tunnel (please, don't ask me why).&lt;BR /&gt;I configuered the trac.defaults (machine_tunnel_after_logon STRING true GLOBAL 1), but there's the following problem:&lt;BR /&gt;The machine tunnel works, but the client isn't able&amp;nbsp; to connect the user tunnel. I tried to activate the option "always connected" for the machine site, but it's gray.&lt;BR /&gt;Connectivity Settings&amp;nbsp;of&amp;nbsp;Global Properties&amp;gt;&amp;nbsp;Remote Access&amp;gt;&amp;nbsp;&lt;SPAN class=""&gt;Endpoint&lt;/SPAN&gt;&amp;nbsp;Connect are Manual.&lt;BR /&gt;So I have the following questions:&lt;BR /&gt;- Is it possible to activate always connected for the secondary site (machine) and leave the primary site (user) at manual?&lt;BR /&gt;- Is it necessary to change the global properties?&lt;BR /&gt;- What kind of effects has the change of the global properties from Manual to Configured on endpoint clients?&lt;BR /&gt;Thank you for any comments&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 11:06:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-and-User-tunnel-at-the-same-time/m-p/276768#M14494</guid>
      <dc:creator>Sokrates</dc:creator>
      <dc:date>2026-05-11T11:06:52Z</dc:date>
    </item>
    <item>
      <title>Re: Machine and User tunnel at the same time</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-and-User-tunnel-at-the-same-time/m-p/276791#M14495</link>
      <description>&lt;P&gt;The normal use case for Machine Tunnel works something like this:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;User boots computer&lt;/LI&gt;
&lt;LI&gt;Machine tunnel is established in the background&lt;/LI&gt;
&lt;LI&gt;Once user authenticates to Windows and logs in, VPN client terminates the Machine Tunnel and is switched to a User Tunnel&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;At no time is there both a User and Machine tunnel active.&lt;BR /&gt;Also, the User and Machine tunnel are expected to be with the same gateway (not a different one) with "Always On" configured.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In your specific case, "Configured on Endpoint Client" would allow the checkbox for "Always On" to be configured on the client, whereas "Manual" requires the end user to activate the VPN connection.&lt;BR /&gt;Note that any changes to Global Properties affects ALL gateways managed under the domain.&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2026 15:03:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-and-User-tunnel-at-the-same-time/m-p/276791#M14495</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-05-11T15:03:42Z</dc:date>
    </item>
  </channel>
</rss>

