<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Machine based Access Roles with Office Mode/Remote Access VPN in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-based-Access-Roles-with-Office-Mode-Remote-Access-VPN/m-p/112842#M9069</link>
    <description>&lt;P&gt;&lt;BR /&gt;We have an R80.40 Gateway Cluster with Identity Awareness. The identity sources are AD Query and Remote Access. Mobile Access Office Mode is enabled. User-based access roles work fine for VPN users, but&amp;nbsp;the same can't be said for an access&amp;nbsp;role that defines the machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The AD Query is working fine for the other contexts, but it's not applied to VPN connection.&lt;/P&gt;&lt;P&gt;In PDPd and PEPd&amp;nbsp;logs I can see the AD connection for the machine in the VPN, but I think it's not processed by the identity Awareness.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[28237 4059047744]@CPFW01[25 Feb 14:01:17] [TRACKER]: #3326304 -&amp;gt; INCOMING -&amp;gt; ADQUERY_ASSOCIATION -&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Association&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ip: 10.18.172.130&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;user:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;machine: dxx-55375&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;domain:&amp;nbsp;xxx.jus.br&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;reason:&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there a way for the Remote Access and AD Query to work together to get the machine identification? What I'm trying to achieve here is to have identified domain machines hit a different rule/layer compared to a machine that remotely connects and is not identified.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Tue, 09 Mar 2021 13:28:06 GMT</pubDate>
    <dc:creator>saulosouza</dc:creator>
    <dc:date>2021-03-09T13:28:06Z</dc:date>
    <item>
      <title>Machine based Access Roles with Office Mode/Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-based-Access-Roles-with-Office-Mode-Remote-Access-VPN/m-p/112842#M9069</link>
      <description>&lt;P&gt;&lt;BR /&gt;We have an R80.40 Gateway Cluster with Identity Awareness. The identity sources are AD Query and Remote Access. Mobile Access Office Mode is enabled. User-based access roles work fine for VPN users, but&amp;nbsp;the same can't be said for an access&amp;nbsp;role that defines the machines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The AD Query is working fine for the other contexts, but it's not applied to VPN connection.&lt;/P&gt;&lt;P&gt;In PDPd and PEPd&amp;nbsp;logs I can see the AD connection for the machine in the VPN, but I think it's not processed by the identity Awareness.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;[28237 4059047744]@CPFW01[25 Feb 14:01:17] [TRACKER]: #3326304 -&amp;gt; INCOMING -&amp;gt; ADQUERY_ASSOCIATION -&amp;gt;&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Association&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ip: 10.18.172.130&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;user:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;machine: dxx-55375&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;domain:&amp;nbsp;xxx.jus.br&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;reason:&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there a way for the Remote Access and AD Query to work together to get the machine identification? What I'm trying to achieve here is to have identified domain machines hit a different rule/layer compared to a machine that remotely connects and is not identified.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 13:28:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-based-Access-Roles-with-Office-Mode-Remote-Access-VPN/m-p/112842#M9069</guid>
      <dc:creator>saulosouza</dc:creator>
      <dc:date>2021-03-09T13:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Machine based Access Roles with Office Mode/Remote Access VPN</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-based-Access-Roles-with-Office-Mode-Remote-Access-VPN/m-p/112857#M9070</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The R80.40 release adds a new VPN authentication capability to Security Gateway. Authentication with a machine certificate as of Endpoint Security Client E80.71 is now available for gateways. Refer to&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_RemoteAccessVPN_AdminGuide/Topics-VPNRG/Machine-Certificate.htm?tocpath=_____12" target="_blank" rel="noopener"&gt;Remote Access VPN R80.40 Administration Guide&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also, highly recommended is&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86240" target="_self"&gt;&lt;SPAN&gt;sk86240&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 14:53:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-based-Access-Roles-with-Office-Mode-Remote-Access-VPN/m-p/112857#M9070</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-03-09T14:53:12Z</dc:date>
    </item>
  </channel>
</rss>

