- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Introducing Check Point Quantum Spark 2500:
Smarter Security, Faster Connectivity, and Simpler MSP Management!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
I have R81.20 and a standalone VPN endpoint client on domain computers.
The mobile portal is enabled and remote access is configured. Authentication in the client by login and password.
How do I make sure that when logging into Windows, the client connects using the password entered in Windows?
@G_W_Albrecht Thank you for your answer, as a result we get 2 options:
1) suggested by you - using machine authorization after logging in
2) suggested @PhoneBoy - Using Harmony with Disk Encryption
I cant recall now, but I believe there is an option somewhere either in global properties or gw object to use os password as auth method.
Andy
Hello @the_rock
Unfortunately, I couldn't find this option.
Everything I've read talks about the portal and the applications on it, and I need it specifically in relation to the Windows account - interaction with Windows.
Let me see if I can find it.
Andy
Apologies mate, I think I mixed something else up. I thought there an option below, but does not appear so...
Andy
Hello @AkosBakos
I saw this option, without turning it on, I get the opportunity to enter a username, password and connection on the login screen, but at the same time to log into Windows you need to enter the password again, and the task is just to enter the password 1 time and log in to the system, and then connect to the VPN.
Hi @MiniNinja
Here is an older posts about this topic:
https://community.checkpoint.com/t5/Remote-Access-VPN/Secure-Domain-Logon/td-p/127190
Have a look at on this.
@AkosBakos Thanks for your reply, but I did not find how to transfer authorization to Windows when using SDL. SDL apparently works separately as a VPN connection functionality before logging in, and not as SSO in its usual sense. Goal: enter your username and password 1 time and log in + connect to the VPN.
Maybe I'm missing something or misunderstood.
@G_W_Albrecht Thank you, how do I understand on a standalone client authorization based on a machine certificate?
You will understand if you read the referenced document - it contains SDL, machine auth and all other config options. Machine auth makes the PC connect to RA VPN by itself, so if machine_tunnel_after_logon
is enabled, after user login the RA VPN comes up without user intervention.
@G_W_Albrecht Thank you for your answer, as a result we get 2 options:
1) suggested by you - using machine authorization after logging in
2) suggested @PhoneBoy - Using Harmony with Disk Encryption
First option is free, second has to be payed by seat - but if you need Harmony EPS it is a good choice !
@G_W_Albrecht Yes, I understand.
I'm fairly certain this requires Harmony Endpoint.
https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/...
@PhoneBoy Thanks, I already think this is the best option, but you need licenses and a dedicated management server that supports 500 connections.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
10 | |
7 | |
7 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
4 |
Wed 10 Sep 2025 @ 11:00 AM (CEST)
Effortless Web Application & API Security with AI-Powered WAF, an intro to CloudGuard WAFWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationWed 10 Sep 2025 @ 11:00 AM (EDT)
Quantum Spark Management Unleashed: Hands-On TechTalk for MSPs Managing SMB NetworksFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY