Hello
Tell me how to correctly add the item about checking whether the device is in the domain or not to the Secure Configuration Verification file?
I have it now and when I start the VPN it skips any device (below are two screenshots), the first is the parameters for checking whether the device is in the domain, the second is the parameters for checking and global parameters.
I do all the settings through the terminal on the gateway, in the vi editor, so that nothing goes.
And tell me, can there be only one policy file?
If so, is it possible that several criteria for verification are set in one file?
What's the point, in my organization there are several options for connecting to a VPN, from corporate devices and from personal devices to a VPN, so the result should be the following:
1. The vpn-users, vtn-term, vpn-route, vpn-constructors group should be checked.
2. If the user has a vpn-users group, then the domain computer is checked or not, if the domain computer is allowed, if the computer is not a domain computer, we do not let it.
3.If the user has a vpn-term group, vpn-routes, vpn-constractors, then the domain comp is checked or not, if the domain comp is not allowed, if the computer is not domainy, we check the Windows, antivirus and the relevance of the antivirus database. If there is at least one discrepancy, we do not let him in.
All groups and users are domain-specific.