- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Is it possible to perform posture checks with the latest ‘Standalone E88.50 Remote Access VPN Clients for Windows’?
Background to my question:
A customer wants to avoid using the ‘Remote Access VPN client’ on private PC. The user could install the software on his private PC and then set up a VPN tunnel to the company.
Are there posture checks here so that you can check whether the “Remote Access VPN Client” software only works on company PCs?
I had thought of something like this:
- Certificate check whether a company certificate is available.
- Check whether a company registry key is set.
- and and and
Is this possible with ‘Inline Layer’ or ‘Order Layer’?
The idea is to query the user certificate first and then the machine certificate if necessary.
Or perhaps with IA rule to use both certificates (user certificate and machine certificate).
Does anyone here have any ideas?
I have not found anything on this in the following documents:
- R81.20 Remote Access VPN Administration Guide
- Remote Access VPN Clients for Windows Admin Guide
- Remote Access TTM Configuration (sk75221)
- E88.x Remote Access VPN Clients
- E87.x Remote Access VPN Clients
Hi @HeikoAnkenbrand,
Maybe the Secure Configuration Verification - Advanced can be useful in this situation.
What if you check the logged in user is a DOMAIN user in the companies AD?
This checks that the logged on user belongs to the expected domain user groups.
|
Parameter |
Description |
|---|---|
|
|
A name of a user group. The user must belong to this group for the machine configuration to be verified. |
Cheers,
Akos
Proposal: Allow authentication only with password AND certificate. Only Company Devices receive the cert and you also include a second factor.
Hi @HeikoAnkenbrand,
Maybe the Secure Configuration Verification - Advanced can be useful in this situation.
What if you check the logged in user is a DOMAIN user in the companies AD?
This checks that the logged on user belongs to the expected domain user groups.
|
Parameter |
Description |
|---|---|
|
|
A name of a user group. The user must belong to this group for the machine configuration to be verified. |
Cheers,
Akos
Hi @AkosBakos,
I was probably blind when reading the manuals 😉
Thank you very much, that's exactly what I was looking for.
Cheers,
Heiko
Thought you could set it below, but guess not, has to be done through local.scv file...
Andy
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 11 | |
| 9 | |
| 9 | |
| 8 | |
| 6 | |
| 3 | |
| 2 | |
| 2 | |
| 2 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY