<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Endpoint client option in trac.defaults to start at windows login in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-client-option-in-trac-defaults-to-start-at-windows/m-p/185924#M4747</link>
    <description>&lt;P&gt;Without SDL, the VPN client will start when the user logs in.&lt;BR /&gt;This is the default behavior.&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jul 2023 14:09:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-07-07T14:09:45Z</dc:date>
    <item>
      <title>Endpoint client option in trac.defaults to start at windows login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-client-option-in-trac-defaults-to-start-at-windows/m-p/185899#M4746</link>
      <description>&lt;P&gt;Working to implement machine tunnel VPN for remote access on gateway running R81.10 JHF Take 95, and clients are windows 10 using Endpoint Client E87.20.&amp;nbsp; Our existing remote access currently uses SDL, but part of the work is to disable this as an option, but is there a setting in the trac.defaults file that will do the job to start the Endpoint client when they login, rather than after this has completed.&amp;nbsp; Or would this need to be set via windows.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 09:01:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-client-option-in-trac-defaults-to-start-at-windows/m-p/185899#M4746</guid>
      <dc:creator>Peter_Dray</dc:creator>
      <dc:date>2023-07-07T09:01:10Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint client option in trac.defaults to start at windows login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-client-option-in-trac-defaults-to-start-at-windows/m-p/185924#M4747</link>
      <description>&lt;P&gt;Without SDL, the VPN client will start when the user logs in.&lt;BR /&gt;This is the default behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jul 2023 14:09:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-client-option-in-trac-defaults-to-start-at-windows/m-p/185924#M4747</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-07T14:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Endpoint client option in trac.defaults to start at windows login</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-client-option-in-trac-defaults-to-start-at-windows/m-p/185973#M4748</link>
      <description>&lt;P&gt;Do you mean you're trying to do a machine based VPN as the machine boots?&amp;nbsp; Instead of waiting until after CTRL+ALT+DEL before establishing a user-login based VPN?&lt;/P&gt;&lt;P&gt;This is possible and there are a few options around whether the VPN stays logged in as the machine based even after Windows login, or whether it is machine based up until the Windows login, then it drops and prompts for user login credentials.&amp;nbsp; You can also disable the ability for the user to disconnect, forcing them to stay on VPN permanently.&lt;/P&gt;&lt;P&gt;Machine based is good for people wishing to push down GPO updates etc. when they have a workforce that infrequently connects on the LAN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Machine based uses AD machine certificates.&amp;nbsp; So you need a CA on your AD, and all machines must have a machine certificate from your AD CA.&amp;nbsp; You need the root cert from the CA installed on the firewall (similar to&amp;nbsp;&lt;SPAN&gt;sk149253).&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;You possibly want&amp;nbsp;&lt;SPAN&gt;sk121173.&amp;nbsp; Although that it's the one I followed...&amp;nbsp; I can't recall which one it was but I'll have a dig and let you know if I find it.&amp;nbsp; The method I used also requires a tweak to set&amp;nbsp;&lt;STRONG&gt;enable_machine_auth=false&lt;/STRONG&gt; in &lt;STRONG&gt;trac.defaults&lt;/STRONG&gt;&amp;nbsp;(probably what you're alluding to?) on all client machines (so this needs some prior planning).&amp;nbsp; I don't think that change can be pushed out centrally&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;.&amp;nbsp; I think this stuff is in the VPN Admin guide too - presume you've checked there?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jul 2023 22:22:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Endpoint-client-option-in-trac-defaults-to-start-at-windows/m-p/185973#M4748</guid>
      <dc:creator>biskit</dc:creator>
      <dc:date>2023-07-08T22:22:57Z</dc:date>
    </item>
  </channel>
</rss>

