<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allow Remote Access VPN from domain computers AND specific external computers? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218616#M3636</link>
    <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;yes I know about the Machine Identity but as you wrote it can be used for domain computers &lt;EM&gt;kerberos&lt;/EM&gt; authenticated machines, whilst I need another type of ID, not related to any domain I manage.&lt;/P&gt;&lt;P&gt;I tried to work with the Identity Tags, but I didn't understand well which sources are compatible.&lt;BR /&gt;&lt;BR /&gt;When I connect with a personal computer I can see a specific ID for the machine, the best would be use this ID in an Access Role so that external partners could connect with their specific machines only, or in the case of a credential theft a hacker won't be able to just install the CheckPoint client and use them to connect:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaa.png" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26437iAC32CB94AC561F20/image-size/large?v=v2&amp;amp;px=999" role="button" title="aaa.png" alt="aaa.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other option would be ok, but it must allow to connect a specific device only; I was trying to configure compliant rules as well, but if, for example, it checks for a registry key or file in the device, these could be replicated to any other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 25 Jun 2024 12:45:05 GMT</pubDate>
    <dc:creator>AkiYa</dc:creator>
    <dc:date>2024-06-25T12:45:05Z</dc:date>
    <item>
      <title>How to allow Remote Access VPN from domain computers AND specific external computers?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218489#M3632</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;we use the Endpoint Security client for the Remote Access VPN and I'm working to leverage the accessibility since I'd like to completely avoid that an external unauthorized user/device could install the client and connect from everywhere.&lt;/P&gt;&lt;P&gt;The connection is configured with Azure SAML, I know that with the conditional access rules I can limit the authentication to domain registered machines only, but in my case I also need to allow the connection from some external devices (ie. partners and a couple of admins with their personal pc).&lt;/P&gt;&lt;P&gt;Is there a way to configure something like an Access Role that matches for example a machine ID?&lt;BR /&gt;When a user connects with a personal device I can see a specific ID in the Host/device section of the log, would it possible to filter such ID?&lt;/P&gt;&lt;P&gt;Or is there any other way to allow the connection only for specific, known devices?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 13:43:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218489#M3632</guid>
      <dc:creator>AkiYa</dc:creator>
      <dc:date>2024-06-24T13:43:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow Remote Access VPN from domain computers AND specific external computers?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218559#M3634</link>
      <description>&lt;P&gt;Access Roles do support use of Machine Identities, which usually come from AD.&lt;BR /&gt;I believe this information should show in the logs if it's being gathered.&lt;BR /&gt;Not sure if it works for external (non-AD) attached).&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jun 2024 20:28:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218559#M3634</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-24T20:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow Remote Access VPN from domain computers AND specific external computers?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218564#M3635</link>
      <description>&lt;P&gt;Access roles came to my mind as well when I read your post.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 01:22:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218564#M3635</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-25T01:22:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow Remote Access VPN from domain computers AND specific external computers?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218616#M3636</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;yes I know about the Machine Identity but as you wrote it can be used for domain computers &lt;EM&gt;kerberos&lt;/EM&gt; authenticated machines, whilst I need another type of ID, not related to any domain I manage.&lt;/P&gt;&lt;P&gt;I tried to work with the Identity Tags, but I didn't understand well which sources are compatible.&lt;BR /&gt;&lt;BR /&gt;When I connect with a personal computer I can see a specific ID for the machine, the best would be use this ID in an Access Role so that external partners could connect with their specific machines only, or in the case of a credential theft a hacker won't be able to just install the CheckPoint client and use them to connect:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="aaa.png" style="width: 794px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/26437iAC32CB94AC561F20/image-size/large?v=v2&amp;amp;px=999" role="button" title="aaa.png" alt="aaa.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any other option would be ok, but it must allow to connect a specific device only; I was trying to configure compliant rules as well, but if, for example, it checks for a registry key or file in the device, these could be replicated to any other.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 12:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218616#M3636</guid>
      <dc:creator>AkiYa</dc:creator>
      <dc:date>2024-06-25T12:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow Remote Access VPN from domain computers AND specific external computers?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218634#M3637</link>
      <description>&lt;P&gt;Not sure this would give you much of a posture check...thats what most companies now offer as SASE solution.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 14:37:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218634#M3637</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-25T14:37:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow Remote Access VPN from domain computers AND specific external computers?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218658#M3638</link>
      <description>&lt;P&gt;Identity Tags are based on information that either comes from the Identity Awareness API or through SAML.&lt;BR /&gt;Which suggests if EntraID can identify the "authorized machines" and the SAML assertion includes this information...we can use it.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Using-Identity-Tags-in-Access-Role-Matching.htm#Using_Identity_Tags_in_Access_Role_Matching" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Using-Identity-Tags-in-Access-Role-Matching.htm#Using_Identity_Tags_in_Access_Role_Matching&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure we can use the contents of the "ID" field that you show in the log to match specific machines.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Jun 2024 15:57:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/How-to-allow-Remote-Access-VPN-from-domain-computers-AND/m-p/218658#M3638</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-25T15:57:38Z</dc:date>
    </item>
  </channel>
</rss>

