cancel
Showing results for 
Search instead for 
Did you mean: 
Post a Question

VPN access restriction based on domain membership

Hi.

I'm looking for an option to restrict VPN access only for laptops which are "domain members".

Is there a way to accomplish that? (All PCs/Part of them?)

Thanks,

Alex

0 Kudos
12 Replies
Admin
Admin

Re: VPN access restriction based on domain membership

Yes, there's an option in the Endpoint Security VPN client called "Secure Configuration Verification" (SCV).

One of the checks you can configure is "Verifies that the user logged into the operating system and is a member of specified Domain User Groups."

That should meet your specific requirement.

Note this only applies to Windows PCs as the Mac VPN client does not support these checks.

Refer to: Remote Access VPN R80.10 (Part of Check Point Infinity) 

Re: VPN access restriction based on domain membership

Thanks.

Two additional questions:

1. Does that require specific VPN client license/flavor?

2. How do I enforce that only this type of client can connect?

TIA

0 Kudos
Admin
Admin

Re: VPN access restriction based on domain membership

It requires the Endpoint Security VPN client, which requires a remote access VPN license for each user that connects.

In terms of our current Endpoint licenses, this includes:

  • Endpoint Access Control
  • Endpoint Complete

However, other legacy licenses may include this .

If you have questions about this, reach out to your Check Point account team or Partner.

The procedure for enforcing that only that client can connect includes:

  • Defining the SCV policy appropriately
  • Preventing clients that are NOT Endpoint Security VPN from connecting

This should be covered in the documentation I linked previously.

0 Kudos

Re: VPN access restriction based on domain membership

Apparently SCV policy is a global property, and if the customer has more than one gateway or more different policies for different type of users it's not possible, at least I couldn't find any documentation on this and support guys didn't also.

Anyone who has any field experience with the SCV policy, please comment.

Thanks

0 Kudos

Re: VPN access restriction based on domain membership

Hi Alex,

Did you manage to accomplish this in the end?

0 Kudos

Re: VPN access restriction based on domain membership

Hi Darran. 

Unfortunately there was no workaround. 

I was forced to implement this for all the gateways. 

Regards,

Alex

0 Kudos

Re: VPN access restriction based on domain membership

Hi 

can we restrict with windows domain member for example  : allow the only machine which is in abc.com & sampla.com

0 Kudos
Admin
Admin

Re: VPN access restriction based on domain membership

Yes, please see the docs I linked previously.
0 Kudos

Re: VPN access restriction based on domain membership

Hi

By group monitor, we can restrict allow only based on domain member.At endpoint side, the secure client is enough or i need to install endpoint security. 

0 Kudos

Re: VPN access restriction based on domain membership

HI

 

Can you please confirm below configuration for domain monitor in local.scv file.

 

: (groupmonitor
:type (plugin)
:parameters (
:begin_or (or1)
:begin_and (1)
:mydomian.com (true)
:end (1)
:end (or1)
:begin_admin (admin)
:send_log (alert)
:mismatchmessage ("You are using SecureClient with a non-authorized user.\nMake sure you are logged on as an authorized user.")
:securely_configured_no_active_user (false)
:end (admin)
)
)

 

0 Kudos

Re: VPN access restriction based on domain membership

Hi,

Other way of achieving your requirement (Only Domain users can connect remote VPN) is that you can enable Mobile access blade and create Native application for Domain check.

You need to enable Endpoint security scan check in Mobile access blade and create Native application for Domain check.

This is long process but it is very stable. I have enabled this scenario for one customer and it is working fine.

Re: VPN access restriction based on domain membership

What I need to is to only allow domain users to connect to VPN who are using corporate machines. Mac and Linux machines would be great but I at least need to check the Windows machines which will be joined to our corporate domain. 

0 Kudos