<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: limiting devices for connecting to VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224074#M3312</link>
    <description>&lt;P&gt;If we talk about Windows and OS X, how can this be implemented? We tested using SCV and Harmony Endpoint policies, but in the end the entry in the registry can be done manually and then you can connect from any device.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Aug 2024 15:20:02 GMT</pubDate>
    <dc:creator>Corporal307</dc:creator>
    <dc:date>2024-08-20T15:20:02Z</dc:date>
    <item>
      <title>limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224063#M3308</link>
      <description>&lt;P&gt;Hi all! Please tell me, is it possible to limit VPN connections to only trusted devices? Goal: Users should use only corporate equipment to connect to the VPN. Windows, Linux and MacOS computers available. Restrictions through SCV policies cost only a couple of steps.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:19:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224063#M3308</guid>
      <dc:creator>Corporal307</dc:creator>
      <dc:date>2024-08-20T15:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224066#M3309</link>
      <description>&lt;P&gt;Question: How does a trusted device differ from another, untrusted device ? DId you ever4 think of using Machine Authentication instead ? SCV and Machine Authentication have originally only been usable for Win clients, now also support OS X, but not Linux afaik...&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 13:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224066#M3309</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-20T13:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224071#M3310</link>
      <description>&lt;P&gt;A trusted device is a corporate computer. Operating systems used: Windows, MacOS, Linux. There are domain computers, as well as computers that are not part of a domain. After studying the forum, documentation and watching webinars, there is a feeling that this will not be possible.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:19:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224071#M3310</guid>
      <dc:creator>Corporal307</dc:creator>
      <dc:date>2024-08-20T15:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224072#M3311</link>
      <description>&lt;P&gt;Only possible for Win and OS X, not for Linux, when using Enterprise Security VPN. If you use EPSS, that is Harmony Endpoint &lt;A href="https://support.checkpoint.com/results/sk/sk117536" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk117536&lt;/A&gt; and available for Win, OS X and Linux, you can only use VPN blade on Win and OS X, so the same situation...&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:22:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224072#M3311</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-20T14:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224074#M3312</link>
      <description>&lt;P&gt;If we talk about Windows and OS X, how can this be implemented? We tested using SCV and Harmony Endpoint policies, but in the end the entry in the registry can be done manually and then you can connect from any device.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:20:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224074#M3312</guid>
      <dc:creator>Corporal307</dc:creator>
      <dc:date>2024-08-20T15:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224076#M3313</link>
      <description>&lt;P&gt;Using Endpoint Security - the VPN blade is only installed as part of the EPS client. As all is controlled in EPSS portal, EPS clients can not be installed and used on other devices...&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 14:26:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224076#M3313</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-08-20T14:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224087#M3314</link>
      <description>&lt;P&gt;The only supported VPN client for Linux is SNX, which can be invoked through Mobile Access Blade, but that requires JDK to be installed on the clients.&lt;BR /&gt;It does have Endpoint Security on Demand, which can do some client-level checking (though not sure how much on Linux).&lt;/P&gt;
&lt;P&gt;For Windows and macOS, you have SCV or Harmony Endpoint's compliance checks.&lt;BR /&gt;If you goal is only "corporate computers" I'd go with Harmony Endpoint, the client for which would only be installed on corporate computers.&lt;BR /&gt;Also, the Harmony Endpoint compliance checks are a bit easier to configure than SCV.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Aug 2024 15:28:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224087#M3314</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-20T15:28:10Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224129#M3315</link>
      <description>&lt;PRE&gt;&lt;SPAN class=""&gt;The problem is that only Endpoint Seceruty was left in the vpn clients; using SCV policies we check the Harmony registry key. If we work honestly, then connection is only possible through Harmony. But you can install the Endpoint Security Standalone Client, manually specify the registry branch that is being checked, and I will also connect to the VPN through another client.&lt;/SPAN&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 21 Aug 2024 05:32:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224129#M3315</guid>
      <dc:creator>Corporal307</dc:creator>
      <dc:date>2024-08-21T05:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: limiting devices for connecting to VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224165#M3316</link>
      <description>&lt;P&gt;Authentication with Machine Certificates (in addition to other methods) is the best way to go here.&lt;BR /&gt;Machine Certificates usually come from Active Directory and would be installed in the device’s certificate store and cannot be exported.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 12:43:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/limiting-devices-for-connecting-to-VPN/m-p/224165#M3316</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-21T12:43:03Z</dc:date>
    </item>
  </channel>
</rss>

