<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Preventing users from disconnecting remote access VPN client in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113993#M8998</link>
    <description>&lt;P&gt;That plus ATM mode (removing the GUI) would make it a little more difficult for users to disable the VPN (without knowing the CLI command).&lt;BR /&gt;You could also create a disconnected desktop policy that blocks most everything when not connected to the VPN, thus nudging people to keep the VPN on.&lt;/P&gt;</description>
    <pubDate>Thu, 18 Mar 2021 17:07:13 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-18T17:07:13Z</dc:date>
    <item>
      <title>Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113950#M8988</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know this may sound like a silly question, but not sure if its even possible. I know in dashboard, under global properties you can enable always connect for endpoint clients...BUT, is there any way at all, either for endpoint vpn or sandblast, to actually PREVENT people from disconnecting their vpn session once they connect?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I know there is trac_client_1.ttm file on the firewall where certain endpoint stuff can be modified, but I dont think there is anything for this specifically. Also, trac_defaults on client side has some settings too, but not sure this is one of them.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thoughts? : )&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 14:57:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113950#M8988</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T14:57:28Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113970#M8989</link>
      <description>&lt;P&gt;A possible workaround could be the use of machine certificate RA VPN, connecting automatically before Domain Logon - but you would have to somehow disable the GUI, as the client otherwise is able to disconnect or shutdown the RA client.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:01:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113970#M8989</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-18T16:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113976#M8990</link>
      <description>&lt;P&gt;Hm...thanks Gunter. Not sure if customer would be okay with that, but do you think its complicated to do?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:21:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113976#M8990</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T16:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113983#M8991</link>
      <description>&lt;P&gt;I had customers using it as a special HF from local SE and contacted me for the latest version, and since GA, i have never heard any complaint or trouble with this feature. Test it8)&lt;/img&gt;. And try to figure out how to disable the GUI.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113983#M8991</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-18T16:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113984#M8992</link>
      <description>&lt;P&gt;If I knew how to do it, would not be posting here, trust me LOL...anyway, let me open TAC case for it.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:48:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113984#M8992</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T16:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113987#M8993</link>
      <description>&lt;P&gt;"Always Connected" is a Global Properties setting.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2021-03-18 at 9.51.45 AM.png" style="width: 687px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11049iB7C89F682CF944CE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2021-03-18 at 9.51.45 AM.png" alt="Screen Shot 2021-03-18 at 9.51.45 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:52:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113987#M8993</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-18T16:52:24Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113988#M8994</link>
      <description>&lt;P&gt;If you can&amp;nbsp;&lt;SPAN&gt;figure out how to disable the GUI, you could leave it with that and Always Connected. I have some experience and would not know how to do it but with an OS hack.Usually, customers want safety for connections first and accept that users disconnect from VPN if they do not use its services. But the idea is valid: all connections from the client go thru company site (and its GW), CP included that a long time ago. But clients can disconnect (to print on their own printer)...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 17:00:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113988#M8994</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-18T17:00:11Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113989#M8995</link>
      <description>&lt;P&gt;A client always can disconnect from VPN or shutdown the client - any way to make this unavailable ?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 16:59:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113989#M8995</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-18T16:59:35Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113990#M8996</link>
      <description>&lt;P&gt;Hey D,&lt;/P&gt;
&lt;P&gt;Yes, Im very familiar with that setting, but thats not what Im looking for. Customer wants to PREVENT users from being able to manually disconnect the vpn client themselves.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 17:03:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113990#M8996</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T17:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113991#M8997</link>
      <description>&lt;P&gt;Right, thats what this customer is looking for...Personally, I never heard of anyone being able to do so.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 17:03:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113991#M8997</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T17:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113993#M8998</link>
      <description>&lt;P&gt;That plus ATM mode (removing the GUI) would make it a little more difficult for users to disable the VPN (without knowing the CLI command).&lt;BR /&gt;You could also create a disconnected desktop policy that blocks most everything when not connected to the VPN, thus nudging people to keep the VPN on.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 17:07:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/113993#M8998</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-18T17:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114013#M8999</link>
      <description>&lt;P&gt;Another possible way would be to create script which will do following:&lt;/P&gt;
&lt;P&gt;Check every XY seconds/minutes if VPN is established. If not, establish it.&lt;/P&gt;
&lt;P&gt;The main question is if such a solution would be possible. Trac.exe info can be used (find string of "Connected"). Maybe cpvn:// command in order to establish VPN in the background.&lt;/P&gt;
&lt;P&gt;Just an idea...&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 19:42:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114013#M8999</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2021-03-18T19:42:40Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114023#M9000</link>
      <description>&lt;P&gt;Oh yes, i forgot ATM mode !&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 20:54:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114023#M9000</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-18T20:54:30Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114030#M9001</link>
      <description>&lt;P&gt;This is probably as good as you're going to be able to get. After all, users could just unplug the computer from their network, unplug their Internet connection, or otherwise block the system's ability to talk to the VPN endpoint.&lt;/P&gt;
&lt;P&gt;While I'm not sure I understand why anybody would want to prevent users from disconnecting, it sounds like they're trying to solve a human problem with a technological solution. That never works well.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 22:10:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114030#M9001</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-03-18T22:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114032#M9002</link>
      <description>&lt;P&gt;Yea...I was thinking maybe modify some local files on client side, but they are more asking if this can be done globally from the fw side, which I am not so sure it can be done...&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 22:52:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114032#M9002</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-18T22:52:36Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114036#M9003</link>
      <description>&lt;P&gt;Don't believe it's possible to FORCE always on, nor is it a particularly good idea.&lt;BR /&gt;In order for things like DHCP or Captive Portal on a public WiFi hotspot to work, you have to allow the device to connect without VPN for a period of time.&lt;/P&gt;
&lt;P&gt;My ask back to the client would be: what problem are you trying to solve by forcing always-on VPN?&lt;BR /&gt;If it's to prevent access to specific websites (or whatever), there are other solutions to that problem that don't involve an always-on VPN (and add additional protection to boot).&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 23:23:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114036#M9003</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-18T23:23:02Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114058#M9004</link>
      <description>&lt;P&gt;Do you know ATM mode ?&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk133174&amp;amp;partition=Basic&amp;amp;product=Endpoint" media="" target="_blank"&gt;sk133174: Enterprise Endpoint Security Windows Client for &lt;STRONG&gt;ATM&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 08:03:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114058#M9004</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-19T08:03:45Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114077#M9005</link>
      <description>&lt;P&gt;I heard about it, but reading up from that link, I dont think that would achieve what customer wants.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 11:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114077#M9005</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-19T11:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114078#M9006</link>
      <description>&lt;H3&gt;You can use VPN client only, too (&lt;SPAN&gt;sk172325)&lt;/SPAN&gt;:&lt;/H3&gt;
&lt;H3&gt;&lt;EM&gt;E84.60 Standalone Clients&lt;/EM&gt;&lt;/H3&gt;
&lt;TABLE class="footnote" border="1" cellspacing="2" cellpadding="4"&gt;
&lt;TBODY&gt;
&lt;TR class="SubTitle" bgcolor="#d6dff0"&gt;
&lt;TD width="10%" class="style3"&gt;Platform&lt;/TD&gt;
&lt;TD width="40%" class="style3"&gt;Package&lt;/TD&gt;
&lt;TD width="40%" class="style3"&gt;Description&lt;/TD&gt;
&lt;TD width="10%" class="style3"&gt;Link&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD rowspan="2" bgcolor="#f3f6fb"&gt;&lt;STRONG&gt;Windows&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD&gt;E84.60 Remote Access VPN Clients for ATM&lt;/TD&gt;
&lt;TD&gt;Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface.&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV id="tinyMceEditor_4e78344d0426e5G_W_Albrecht_2" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
(MSI)&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD&gt;E84.60 Remote Access VPN Clients for ATM - Automatic Upgrade file&lt;/TD&gt;
&lt;TD&gt;Unattended Remote Access VPN clients, managed with CLI and API and do not have a User interface for automatic upgrade through the gateway. For SmartDashboard-managed clients only.&lt;/TD&gt;
&lt;TD&gt;
&lt;DIV id="tinyMceEditor_4e78344d0426e5G_W_Albrecht_3" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
(CAB)&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This documentation is valid for both EPS and RA VPN ATM clients:&amp;nbsp;&lt;A href="http://downloads.checkpoint.com/dc/download.htm?ID=70165" target="_blank" rel="noopener"&gt;E80.86 and higher Endpoint Security Client for ATMs Deployment Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 11:43:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114078#M9006</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2021-03-19T11:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing users from disconnecting remote access VPN client</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114099#M9007</link>
      <description>&lt;P&gt;I guess something to think about...&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 17:14:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Preventing-users-from-disconnecting-remote-access-VPN-client/m-p/114099#M9007</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-19T17:14:21Z</dc:date>
    </item>
  </channel>
</rss>

