<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restrict laptop access on site to site vpn in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76419#M3096</link>
    <description>&lt;P&gt;I believe you need to use VTI for this.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 26 Feb 2020 04:32:08 GMT</pubDate>
    <dc:creator>HristoGrigorov</dc:creator>
    <dc:date>2020-02-26T04:32:08Z</dc:date>
    <item>
      <title>Restrict laptop access on site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76406#M3094</link>
      <description>&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Hi All-&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;I’m wondering if any of you could help me with the following. I’ve set up a site to site vpn between a checkpoint 14xx to a checkpoint 15xx located at the business owners home. He doesn’t want to have to go through the process of using endpoint protection software on his work laptop to connect into the corporate network. From his home location, I only want his work laptop to be able to traverse the site to site vpn for obvious security&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp; &lt;/SPAN&gt;reasons. I’ve tried tinkering around with the GUI options and can’t seem to figure out how to get this to work. &lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;My thought process / what I tried was assigning the laptop a static IP or dhcp reservation and basing a rule on that, but couldn’t seem to get a rule to work properly on either side.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;&lt;SPAN&gt;Any suggestions/ guidance would be most appreciated. I feel like I’m missing something obvious or maybe some simple tweaking in the cli could sort this out.&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2020 22:41:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76406#M3094</guid>
      <dc:creator>bsorgi</dc:creator>
      <dc:date>2020-02-25T22:41:09Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict laptop access on site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76407#M3095</link>
      <description>Redacted screenshots of exactly what you tried to configure would be helpful.</description>
      <pubDate>Tue, 25 Feb 2020 23:14:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76407#M3095</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-02-25T23:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict laptop access on site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76419#M3096</link>
      <description>&lt;P&gt;I believe you need to use VTI for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 04:32:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76419#M3096</guid>
      <dc:creator>HristoGrigorov</dc:creator>
      <dc:date>2020-02-26T04:32:08Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict laptop access on site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76486#M3097</link>
      <description>&lt;P&gt;This does only work if the main GW (or both) is (are) centrally managed - see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk107641&amp;amp;partition=Basic&amp;amp;product=Small" target="_blank"&gt;sk107641: Configure "&lt;STRONG&gt;Route&lt;/STRONG&gt; &lt;STRONG&gt;All&lt;/STRONG&gt; &lt;STRONG&gt;Traffic&lt;/STRONG&gt;" from locally managed &lt;STRONG&gt;SMB&lt;/STRONG&gt; appliances to a centrally managed gateway&lt;/A&gt;&amp;nbsp;for details!&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2020 15:55:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76486#M3097</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-02-26T15:55:17Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict laptop access on site to site vpn</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76498#M3098</link>
      <description>&lt;P&gt;This is a good case for captive portal if you're using a management server. It wouldn't limit access to just a laptop per say but what it would do is make it so anyone on the remote network would have to authenticate to the firewall in order to gain access to the corp network. Captival portal with Access Roles are pretty granular. You can say allow access to this without auth but require for that.&lt;/P&gt;&lt;P&gt;This way the door isn't always open, but if the right user requests access then they are allowed through.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now if you aren't using a management server there is something called User Awareness which is kind of similar. You basically say in order to access some remote resource you have to auth to the firewall. Only problem is all access to that destination will require auth meaning you CAN'T (type-o fixed) pick and chose what does and doesn't require auth.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2020 15:55:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Restrict-laptop-access-on-site-to-site-vpn/m-p/76498#M3098</guid>
      <dc:creator>John_Fleming</dc:creator>
      <dc:date>2020-02-27T15:55:52Z</dc:date>
    </item>
  </channel>
</rss>

