<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Remote Access VPN Secure Domain Logon Choice in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190116#M4616</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;a customer of ours uses the standalone Remote Access VPN Client with Secure Domain Login configured. When SDL is enabled, the user can only log in to windows with VPN. Is there a way, that the user can choose to connect to VPN or authenticate to Windows locally, as it´s possible with Cisco AnyConnect (picture below)?&lt;/P&gt;
&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AnyConnect-Windows-logon.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22163iA8740FA5DAB80823/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AnyConnect-Windows-logon.png" alt="AnyConnect-Windows-logon.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Aug 2023 12:38:52 GMT</pubDate>
    <dc:creator>mkoessler</dc:creator>
    <dc:date>2023-08-22T12:38:52Z</dc:date>
    <item>
      <title>Remote Access VPN Secure Domain Logon Choice</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190116#M4616</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;a customer of ours uses the standalone Remote Access VPN Client with Secure Domain Login configured. When SDL is enabled, the user can only log in to windows with VPN. Is there a way, that the user can choose to connect to VPN or authenticate to Windows locally, as it´s possible with Cisco AnyConnect (picture below)?&lt;/P&gt;
&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AnyConnect-Windows-logon.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22163iA8740FA5DAB80823/image-size/medium?v=v2&amp;amp;px=400" role="button" title="AnyConnect-Windows-logon.png" alt="AnyConnect-Windows-logon.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 12:38:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190116#M4616</guid>
      <dc:creator>mkoessler</dc:creator>
      <dc:date>2023-08-22T12:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Secure Domain Logon Choice</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190132#M4617</link>
      <description>&lt;P&gt;Amin note: credits removed&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 12:39:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190132#M4617</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-22T12:39:35Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Secure Domain Logon Choice</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190136#M4618</link>
      <description>&lt;P&gt;From the documentation (important part highlighted):&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_sdl variable"&gt;Secure Domain Logon&lt;/SPAN&gt;&amp;nbsp;&lt;U&gt;ensures that authentication credentials&lt;/U&gt; sent to the&amp;nbsp;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_domain variable"&gt;Domain&lt;/SPAN&gt;&lt;/EM&gt;&lt;SPAN&gt;&lt;EM&gt;&amp;nbsp;Controller &lt;U&gt;are sent through an encrypted channel&lt;/U&gt;.&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;If you do not need that, disable SDL.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 12:44:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190136#M4618</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-08-22T12:44:58Z</dc:date>
    </item>
    <item>
      <title>Re: Remote Access VPN Secure Domain Logon Choice</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190852#M4619</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;just wanted to share my solution for this. Our partner manager hinted us to the implicit and explicit SDL configuration.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/SDL-in-Windows.htm?tocpath=Configuring%20Client%20Features%7CSecure%20Domain%20Logon%20(SDL)%7C_____4" target="_blank"&gt;https://sc1.checkpoint.com/documents/RemoteAccessClients_forWindows_AdminGuide/Content/Topics-RA-VPN-for-Win/SDL-in-Windows.htm?tocpath=Configuring%20Client%20Features%7CSecure%20Domain%20Logon%20(SDL)%7C_____4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Through disabling implicit SDL the user now has a button in the Windows login screen where he can choose to connect to VPN or just log in to the client.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Aug 2023 06:15:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Remote-Access-VPN-Secure-Domain-Logon-Choice/m-p/190852#M4619</guid>
      <dc:creator>mkoessler</dc:creator>
      <dc:date>2023-08-29T06:15:18Z</dc:date>
    </item>
  </channel>
</rss>

